File name:

NVIDIA Profile Inspector 3.5.0.0.zip

Full analysis: https://app.any.run/tasks/e24887ca-50da-4b5e-bdca-f9b7bf340d4f
Verdict: Malicious activity
Threats:

Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.

Analysis date: May 01, 2024, 12:17:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

62D0B897F3D76117DF9656E6B6F57374

SHA1:

B1B81328F3CBBC052B2E43EEE6C760DE67062BB3

SHA256:

54DF6D48C377D97458D837BA65682B7CB42002204F552AEA2F5A146182C0160B

SSDEEP:

98304:kkN7jOq7NsK/n4JGKtfuE8ak2YsBX/e8dT/A1BFJS4poBUkM34PsWv/bdynl5Vvm:0cV+Kix

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3980)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • REMCOS has been detected (YARA)

      • cmd.exe (PID: 2512)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Application launched itself

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
    • Reads the Windows owner or organization settings

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
    • Reads security settings of Internet Explorer

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
    • Reads the Internet Settings

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • ipconfig.exe (PID: 1816)
    • Reads settings of System Certificates

      • ipconfig.exe (PID: 1816)
    • Starts CMD.EXE for commands execution

      • ipconfig.exe (PID: 1816)
    • Process uses IPCONFIG to get network configuration information

      • Nvidia Security Update.exe (PID: 1840)
    • Adds/modifies Windows certificates

      • ipconfig.exe (PID: 1816)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3980)
    • Manual execution by a user

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • wmpnscfg.exe (PID: 2556)
    • Checks supported languages

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVidiaProfileInspectorDmW.exe (PID: 1652)
      • Nvidia Security Update.exe (PID: 1840)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
      • wmpnscfg.exe (PID: 2556)
    • Reads the computer name

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1136)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVidiaProfileInspectorDmW.exe (PID: 1652)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
      • wmpnscfg.exe (PID: 2556)
      • Nvidia Security Update.exe (PID: 1840)
    • Create files in a temporary directory

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 1764)
      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Creates files in the program directory

      • NVIDIA Profile Inspector 3.5.0.0.exe (PID: 312)
    • Reads the machine GUID from the registry

      • NVidiaProfileInspectorDmW.exe (PID: 1652)
    • Creates files or folders in the user directory

      • ipconfig.exe (PID: 1816)
    • Reads security settings of Internet Explorer

      • ipconfig.exe (PID: 1816)
    • Checks proxy server information

      • ipconfig.exe (PID: 1816)
    • Reads the software policy settings

      • ipconfig.exe (PID: 1816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(2512) cmd.exe
C2 (1)45.147.230.213:5885
Botnet5885
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Setup_path%APPDATA%
Copy_fileremcos.exe
Startup_valueremcos
Hide_fileFalse
Mutex_nameRemcos-FF8L7S
Keylog_flag1
Keylog_path%TEMP%
Keylog_filehipster.bin
Keylog_cryptTrue
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_namewikipedia;solitaire;
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%APPDATA%
Audio_dirMicRecords
Connect_delay0
Copy_dirremcos
Keylog_dirsvchost
Max_keylog_file10000
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:03:26 02:35:12
ZipCRC: 0x33420732
ZipCompressedSize: 3660
ZipUncompressedSize: 8704
ZipFileName: NVIDIA Profile Inspector 3.5.0.0/AutoClosingMessageBox.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
9
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe nvidia profile inspector 3.5.0.0.exe no specs nvidia profile inspector 3.5.0.0.exe nvidia profile inspector 3.5.0.0.exe nvidiaprofileinspectordmw.exe nvidia security update.exe no specs ipconfig.exe #REMCOS cmd.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /VERYSILENTC:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1136"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exeexplorer.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1652"C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe"C:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
NVidiaProfileInspectorDmW
Version:
3.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nvidiaprofileinspectordmw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1764"C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe" /SPAWNWND=$101B4 /NOTIFYWND=$101B4 C:\Users\admin\Desktop\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exe
NVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Company:
Modified by DeadManWalking (DeadManWalkingTO-Github)
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\nvidia profile inspector 3.5.0.0\nvidia profile inspector 3.5.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1816"C:\Windows\system32\ipconfig.exe"C:\Windows\System32\ipconfig.exe
Nvidia Security Update.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1840"C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exe"C:\Users\admin\AppData\Local\Temp\Nvidia Security Update.exeNVIDIA Profile Inspector 3.5.0.0.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nvidia security update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
2512"C:\Windows\system32\cmd.exe"C:\Windows\System32\cmd.exe
ipconfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Remcos
(PID) Process(2512) cmd.exe
C2 (1)45.147.230.213:5885
Botnet5885
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Setup_path%APPDATA%
Copy_fileremcos.exe
Startup_valueremcos
Hide_fileFalse
Mutex_nameRemcos-FF8L7S
Keylog_flag1
Keylog_path%TEMP%
Keylog_filehipster.bin
Keylog_cryptTrue
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_namewikipedia;solitaire;
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%APPDATA%
Audio_dirMicRecords
Connect_delay0
Copy_dirremcos
Keylog_dirsvchost
Max_keylog_file10000
2556"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3980"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
130 257
Read events
130 155
Write events
79
Delete events
23

Modification events

(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3980) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NVIDIA Profile Inspector 3.5.0.0.zip
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3980) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
8
Text files
6
Unknown types
1

Dropped files

PID
Process
Filename
Type
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Nvidia Profile test.txt
MD5:
SHA256:
312NVIDIA Profile Inspector 3.5.0.0.exeC:\Users\admin\AppData\Local\Temp\NVidiaProfileInspectorDmW.exe
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\AutoClosingMessageBox.dllexecutable
MD5:22784F6F6D9714D920D6FC11EE3699EE
SHA256:8F94F24B6C089C86ACFB94C592820731B6F303A694D8AA98407135252F4D1E20
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Performance profile.7zcompressed
MD5:A4ADCCBB6B3731959248888D123B47A8
SHA256:D2676BFFE13E45DCB76A958F4DFCB3637DD03341D642BBD78B9E80A2F553F240
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\Performance profile.nipxml
MD5:DFA4855C121D2C558DAB457A42951EA4
SHA256:D1422C72CEBD6311B985E01022184C7706C26A779F5B1F1E9C06C03AA4194542
2512cmd.exeC:\Users\admin\AppData\Local\Temp\2f205cd2.lnk
MD5:
SHA256:
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0.exeexecutable
MD5:35E9FB365044AEDE6CFE1099E2CB9F8B
SHA256:03C7BC92859DCA2EDFEA1903131FE7897DF7A41E4FB65C660511CD22DC789E19
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0-0.binbinary
MD5:CEE33BC514D9763032E087B5677C552C
SHA256:7B3925BEEDE2CD7A21B3FBF56D41950E8C706AA28F168CCF98CFCFCC8551B0B2
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVIDIA Profile Inspector 3.5.0.0-1.binbinary
MD5:CA57B8B613422FC930793891093BD39F
SHA256:604C70BA3207BF3B81B46B7387D53E9E60204DFB59D2BDF7E84CFD94C561EF1F
3980WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3980.19143\NVIDIA Profile Inspector 3.5.0.0\NVidiaProfileInspectorDmW.exe.configxml
MD5:10AC8BFC8E450B2AAC4A9F1B90892C57
SHA256:F3F4847275F08DB429019EE65F0DD8E3D2384A35035322DE949EB43009FD1A57
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
304
23.45.119.165:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f4dd37beaa18db38
unknown
unknown
1816
ipconfig.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
1816
ipconfig.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
1640
svchost.exe
239.255.255.250:1900
unknown
1816
ipconfig.exe
146.75.120.193:443
i.imgur.com
FASTLY
US
unknown
1816
ipconfig.exe
23.45.119.165:80
ctldl.windowsupdate.com
Akamai International B.V.
US
unknown
1816
ipconfig.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1816
ipconfig.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
i.imgur.com
  • 146.75.120.193
shared
ctldl.windowsupdate.com
  • 23.45.119.165
  • 23.45.119.174
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info