File name:

ErrorNukerSetup.exe

Full analysis: https://app.any.run/tasks/56cd54ae-a686-4a64-92f7-f6816820f4b2
Verdict: Malicious activity
Analysis date: March 03, 2024, 17:31:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

47248BC7A6D5B43B09F1664FA2D518B1

SHA1:

C8924B1B0EB403736DFEDE3FA144A69860B8CD86

SHA256:

6F93539FF9801733D8883F4C44C0316B721F6A1C9914A5D3C07F764AAA068579

SSDEEP:

49152:B20QBnypjfoV1xlbsG1zrZICqBtxKqn0ZG5ZR31gCQ91PZebs33o8jZ8Kgh9f35O:80QBnEzi7l4Gd1qN0ZaZgCQ7Zeba4yWW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ErrorNukerSetup.exe (PID: 3216)
    • Changes the autorun value in the registry

      • ErrorNukerSetup.exe (PID: 3216)
  • SUSPICIOUS

    • Reads the Internet Settings

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Creates a software uninstall entry

      • ErrorNukerSetup.exe (PID: 3216)
    • Executable content was dropped or overwritten

      • ErrorNukerSetup.exe (PID: 3216)
    • Reads settings of System Certificates

      • ErrorNuker.exe (PID: 4084)
    • Checks Windows Trust Settings

      • ErrorNuker.exe (PID: 4084)
    • Reads security settings of Internet Explorer

      • ErrorNuker.exe (PID: 4084)
  • INFO

    • Checks supported languages

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Reads the computer name

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Checks proxy server information

      • ErrorNuker.exe (PID: 4084)
    • Creates files in the program directory

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Create files in a temporary directory

      • ErrorNukerSetup.exe (PID: 3216)
    • Reads the machine GUID from the registry

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Application launched itself

      • msedge.exe (PID: 2624)
      • msedge.exe (PID: 2064)
    • Manual execution by a user

      • msedge.exe (PID: 2064)
    • Reads the software policy settings

      • ErrorNuker.exe (PID: 4084)
    • Creates files or folders in the user directory

      • ErrorNuker.exe (PID: 4084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2003:03:16 17:41:08+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 155136
UninitializedDataSize: -
EntryPoint: 0x4046
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
21
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start errornukersetup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs errornuker.exe errornukersetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2184 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1236 --field-trial-handle=1404,i,8421442368822862217,3214742886519327853,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1404,i,8421442368822862217,3214742886519327853,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1600 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2052"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3556 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2060"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1472 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://www.errornuker.com/welcome/?address=dadwwdwC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2308"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3620 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3636 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2472"C:\Users\admin\AppData\Local\Temp\ErrorNukerSetup.exe" C:\Users\admin\AppData\Local\Temp\ErrorNukerSetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\errornukersetup.exe
c:\windows\system32\ntdll.dll
Total events
8 989
Read events
8 884
Write events
88
Delete events
17

Modification events

(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Error Nuker 2004
Value:
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:InstallDir
Value:
C:\Program Files\Error Nuker
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:UpdateVersion
Value:
10206
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:Campaign
Value:
HOME
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Error Nuker
Operation:writeName:DisplayName
Value:
Error Nuker
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Error Nuker
Operation:writeName:UninstallString
Value:
C:\Program Files\Error Nuker\uninstall.exe
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Error Nuker
Value:
C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
Executable files
8
Suspicious files
36
Text files
72
Unknown types
22

Dropped files

PID
Process
Filename
Type
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\UserInfo.dllexecutable
MD5:8CF925160FEC4CFB61660511E182D588
SHA256:08076A8C61EAA8D3B7F54DA05AEB8EC89CC03C2C1C12F00CBD07568F61FFF4D2
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\modern-header.bmpimage
MD5:60D95CBE4E65AFA8E138A28F039095B6
SHA256:338C492DAD1407918FAFB9FBA8AAE404F434F00246792DB1529DE66568B70869
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\startup.icoimage
MD5:887132581B753DD96BD72106ADC87367
SHA256:E8934BC0A37BEE470FE0A650BA2AC5B6A8B1A71EFD9E8CE96FBF1606709F92E7
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\uninst.icoimage
MD5:9E6071437BB6FEFF3718A90445C85F3E
SHA256:999E251D1E7FB916FFD1C526D175C8EEC0C14448AEB59002E07CFD74D0027509
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\config\drr_conf.iniini
MD5:6946DAA66CA2F0B4B4593D0ED122DCF9
SHA256:471CBB96832FC7665D50537722BDD67E7BEC710750334A0FE2347192EE86C49B
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\doc\readme.txttext
MD5:82092616CEE87B2DDE2153904E968276
SHA256:1B0A90CA9911876E49A263C86C01B0CF78139FA5134B1A966D4F3E9C4D43E959
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\~trash.icoimage
MD5:02431D45BA9563E7D96331898331C7D0
SHA256:6635FC5820F89199066ED68547367802356CD9C0BE1C2DF0EEB387B71D7EF1BB
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\doc\errornuker.chmbinary
MD5:65BB8CEB1E367F488162E8210495B029
SHA256:4233B52D2E2666808F55A74B51D35D8D6B99D5F9E7D16FDE4702B08F17F7B093
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\~xpinstall.icoimage
MD5:9E6071437BB6FEFF3718A90445C85F3E
SHA256:999E251D1E7FB916FFD1C526D175C8EEC0C14448AEB59002E07CFD74D0027509
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
16
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4084
ErrorNuker.exe
GET
302
3.18.7.81:80
http://www.errornuker.com/products/errn2004/update.php?version=10206
unknown
unknown
4084
ErrorNuker.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7e60884410d0cf51
unknown
unknown
4084
ErrorNuker.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2064
msedge.exe
239.255.255.250:1900
unknown
2060
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2060
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2064
msedge.exe
224.0.0.251:5353
unknown
2060
msedge.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
unknown
2060
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
4084
ErrorNuker.exe
3.18.7.81:80
www.errornuker.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
www.errornuker.com
  • 3.18.7.81
  • 3.19.116.195
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.168
  • 104.126.37.160
  • 104.126.37.161
  • 104.126.37.163
  • 104.126.37.154
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
www.hugedomains.com
  • 104.26.7.37
  • 172.67.70.191
  • 104.26.6.37
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info