File name:

OCS-NG-Windows-Agent-Setup.exe

Full analysis: https://app.any.run/tasks/bd3a683b-bf40-4343-bd07-cfe4e2fc608b
Verdict: Malicious activity
Analysis date: May 23, 2024, 19:23:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

6DA2E004351D253FCE9005EC10BCE77B

SHA1:

A2C74473CC50FB9AC24E525021E638CDA5E50922

SHA256:

59F807844A17564C4DE25E92E2E1F4A7F623DB54C36DFFD438B735E8B806AAB4

SSDEEP:

98304:hOUJxPi3ayjw4gvWXKJR4W22ROeGSty18D56umBnuiJBEkHQnRVkf6GlwdfX63ZR:5rKTXrIz8Hn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Create files in the Startup directory

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Executable content was dropped or overwritten

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • The process creates files with name similar to system file names

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Process drops legitimate windows executable

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • The process drops C-runtime libraries

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Starts application with an unusual extension

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Executes as Windows Service

      • OcsService.exe (PID: 1652)
    • Creates a software uninstall entry

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Starts CMD.EXE for commands execution

      • OcsService.exe (PID: 1652)
  • INFO

    • Reads the computer name

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
      • SetACL.exe (PID: 1136)
      • SetACL.exe (PID: 372)
      • OcsService.exe (PID: 728)
      • OcsService.exe (PID: 1652)
      • ocsinventory.exe (PID: 1284)
      • OcsSystray.exe (PID: 2060)
    • Checks supported languages

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
      • nsAA4E.tmp (PID: 820)
      • nsAB49.tmp (PID: 2044)
      • SetACL.exe (PID: 1136)
      • SetACL.exe (PID: 372)
      • nsF7A5.tmp (PID: 2180)
      • ocsinventory.exe (PID: 1768)
      • OcsService.exe (PID: 1652)
      • ocsinventory.exe (PID: 1284)
      • nsFD73.tmp (PID: 308)
      • OcsService.exe (PID: 728)
      • OcsSystray.exe (PID: 2060)
    • Create files in a temporary directory

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
    • Creates files in the program directory

      • OCS-NG-Windows-Agent-Setup.exe (PID: 4072)
      • ocsinventory.exe (PID: 1768)
      • OcsService.exe (PID: 1652)
      • ocsinventory.exe (PID: 1284)
    • Reads the machine GUID from the registry

      • OcsService.exe (PID: 1652)
      • ocsinventory.exe (PID: 1284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 22:50:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.5.0
ProductVersionNumber: 2.0.5.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: Setup OCS Inventory NG Agent
CompanyName: OCS Inventory NG Team
FileDescription: OCS Inventory NG Agent
FileVersion: 2.0.5.0
LegalCopyright: Distributed under GNU GPL Version 2 Licence
LegalTrademarks: http://www.ocsinventory-ng.org
ProductName: OCS Inventory NG Agent
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
14
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ocs-ng-windows-agent-setup.exe nsaa4e.tmp no specs setacl.exe no specs nsab49.tmp no specs setacl.exe no specs nsf7a5.tmp no specs ocsinventory.exe no specs nsfd73.tmp no specs ocsservice.exe no specs ocsservice.exe no specs cmd.exe no specs ocsinventory.exe no specs ocssystray.exe no specs ocs-ng-windows-agent-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsFD73.tmp" C:\Program Files\OCS Inventory Agent\OcsService.exe -installC:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsFD73.tmpOCS-NG-Windows-Agent-Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nst595f.tmp\nsfd73.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
372SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\SetACL.exensAB49.tmp
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL 2
Exit code:
0
Version:
2, 1, 2, 0
Modules
Images
c:\users\admin\appdata\local\temp\nst595f.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
728"C:\Program Files\OCS Inventory Agent\OcsService.exe" -installC:\Program Files\OCS Inventory Agent\OcsService.exensFD73.tmp
User:
admin
Company:
OCS Inventory NG
Integrity Level:
HIGH
Description:
OCS Inventory NG Service
Exit code:
0
Version:
2, 0, 5, 0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\gdi32.dll
820"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAA4E.tmp" SetACL -on "C:\ProgramData\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAA4E.tmpOCS-NG-Windows-Agent-Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nst595f.tmp\nsaa4e.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1136SetACL -on "C:\ProgramData\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\SetACL.exensAA4E.tmp
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL 2
Exit code:
0
Version:
2, 1, 2, 0
Modules
Images
c:\users\admin\appdata\local\temp\nst595f.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
1284"C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Program Files\OCS Inventory Agent\ocsinventory.execmd.exe
User:
SYSTEM
Company:
OCS Inventory NG
Integrity Level:
SYSTEM
Description:
OCS Inventory NG Agent
Version:
2, 0, 5, 0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ocs inventory agent\ocsinventory front.dll
c:\program files\ocs inventory agent\zlib1.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
1620"C:\Windows\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1652"C:\Program Files\OCS Inventory Agent\OcsService.exe"C:\Program Files\OCS Inventory Agent\OcsService.exeservices.exe
User:
SYSTEM
Company:
OCS Inventory NG
Integrity Level:
SYSTEM
Description:
OCS Inventory NG Service
Version:
2, 0, 5, 0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\gdi32.dll
1768"C:\Program Files\OCS Inventory Agent\ocsinventory.exe" /SAVE_CONF /SERVER=http://ocsinventory-ng/ocsinventory /USER= /PWD= /SSL=0 /CA=cacert.pem /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /TAG=C:\Program Files\OCS Inventory Agent\ocsinventory.exensF7A5.tmp
User:
admin
Company:
OCS Inventory NG
Integrity Level:
HIGH
Description:
OCS Inventory NG Agent
Exit code:
0
Version:
2, 0, 5, 0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\ocs inventory agent\ocsinventory front.dll
c:\program files\ocs inventory agent\zlib1.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
2044"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAB49.tmp" SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAB49.tmpOCS-NG-Windows-Agent-Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nst595f.tmp\nsab49.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
3 353
Read events
3 345
Write events
8
Delete events
0

Modification events

(PID) Process:(728) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\OCS Inventory Service
Operation:writeName:EventMessageFile
Value:
C:\Program Files\OCS Inventory Agent\OcsService.exe
(PID) Process:(728) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\OCS Inventory Service
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:DisplayName
Value:
OCS Inventory NG Agent 2.0.5.0
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:UninstallString
Value:
C:\Program Files\OCS Inventory Agent\uninst.exe
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:DisplayIcon
Value:
C:\Program Files\OCS Inventory Agent\OCSInventory.exe
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:DisplayVersion
Value:
2.0.5.0
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:URLInfoAbout
Value:
http://www.ocsinventory-ng.org
(PID) Process:(4072) OCS-NG-Windows-Agent-Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OCS Inventory NG Agent
Operation:writeName:Publisher
Value:
OCS Inventory NG Team
Executable files
34
Suspicious files
7
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\agent.inibinary
MD5:40BF9BF3AE964CEFBD9789FE31F8BAB4
SHA256:F10360D371807782E8284FF7964DCB17E485A8573580EE015477721AACCDE8AF
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\OCS-NG-Windows-Agent-Setup.logtext
MD5:85CB0A7C85F412D906A259BF9492EE74
SHA256:432203B41A8E419BCD746E5922A2EB43C3502C6799302F117D59DC58D1E662FC
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\modern-header.bmpimage
MD5:D49A7C26CC8AA4BFF7C18F1A4532AA84
SHA256:A23CFDB2CD3557CECA5CB74B45131DFCBBAB658A7F2CD44EC58E43FE8E1C9AC6
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAA4E.tmpexecutable
MD5:ACC2B699EDFEA5BF5AAE45ABA3A41E96
SHA256:168A974EAA3F588D759DB3F47C1A9FDC3494BA1FA1A73A84E5E3B2A4D58ABD7E
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsAB49.tmpexecutable
MD5:ACC2B699EDFEA5BF5AAE45ABA3A41E96
SHA256:168A974EAA3F588D759DB3F47C1A9FDC3494BA1FA1A73A84E5E3B2A4D58ABD7E
4072OCS-NG-Windows-Agent-Setup.exeC:\ProgramData\OCS Inventory NG\Agent\ocsinventory.initext
MD5:1CA5FA9D60E0F6C935AFFC33E2C5DEDA
SHA256:034991233E3E01DB6BA6FF9E06AEB13E56A6D9BF0AD3772B1A8FB6589EB5704A
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\KillProcDLL.dllexecutable
MD5:83142EAC84475F4CA889C73F10D9C179
SHA256:AE2F1658656E554F37E6EAC896475A3862841A18FFC6FAD2754E2D3525770729
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\InstallOptions.dllexecutable
MD5:325B008AEC81E5AAA57096F05D4212B5
SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B
4072OCS-NG-Windows-Agent-Setup.exeC:\Users\admin\AppData\Local\Temp\nst595F.tmp\nsExec.dllexecutable
MD5:ACC2B699EDFEA5BF5AAE45ABA3A41E96
SHA256:168A974EAA3F588D759DB3F47C1A9FDC3494BA1FA1A73A84E5E3B2A4D58ABD7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info