File name:

ErrorNukerSetup.exe

Full analysis: https://app.any.run/tasks/56cd54ae-a686-4a64-92f7-f6816820f4b2
Verdict: Malicious activity
Analysis date: March 03, 2024, 17:31:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

47248BC7A6D5B43B09F1664FA2D518B1

SHA1:

C8924B1B0EB403736DFEDE3FA144A69860B8CD86

SHA256:

6F93539FF9801733D8883F4C44C0316B721F6A1C9914A5D3C07F764AAA068579

SSDEEP:

49152:B20QBnypjfoV1xlbsG1zrZICqBtxKqn0ZG5ZR31gCQ91PZebs33o8jZ8Kgh9f35O:80QBnEzi7l4Gd1qN0ZaZgCQ7Zeba4yWW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ErrorNukerSetup.exe (PID: 3216)
    • Changes the autorun value in the registry

      • ErrorNukerSetup.exe (PID: 3216)
  • SUSPICIOUS

    • Reads the Internet Settings

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Executable content was dropped or overwritten

      • ErrorNukerSetup.exe (PID: 3216)
    • Creates a software uninstall entry

      • ErrorNukerSetup.exe (PID: 3216)
    • Reads security settings of Internet Explorer

      • ErrorNuker.exe (PID: 4084)
    • Reads settings of System Certificates

      • ErrorNuker.exe (PID: 4084)
    • Checks Windows Trust Settings

      • ErrorNuker.exe (PID: 4084)
  • INFO

    • Reads the computer name

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Checks supported languages

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Create files in a temporary directory

      • ErrorNukerSetup.exe (PID: 3216)
    • Reads the machine GUID from the registry

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Application launched itself

      • msedge.exe (PID: 2624)
      • msedge.exe (PID: 2064)
    • Creates files in the program directory

      • ErrorNukerSetup.exe (PID: 3216)
      • ErrorNuker.exe (PID: 4084)
    • Manual execution by a user

      • msedge.exe (PID: 2064)
    • Checks proxy server information

      • ErrorNuker.exe (PID: 4084)
    • Creates files or folders in the user directory

      • ErrorNuker.exe (PID: 4084)
    • Reads the software policy settings

      • ErrorNuker.exe (PID: 4084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2003:03:16 17:41:08+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 155136
UninitializedDataSize: -
EntryPoint: 0x4046
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
21
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start errornukersetup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs errornuker.exe errornukersetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2184 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1236 --field-trial-handle=1404,i,8421442368822862217,3214742886519327853,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1404,i,8421442368822862217,3214742886519327853,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1600 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2052"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3556 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2060"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1472 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://www.errornuker.com/welcome/?address=dadwwdwC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2308"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3620 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2344"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3636 --field-trial-handle=1244,i,10323208291555604285,14818434558082049168,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2472"C:\Users\admin\AppData\Local\Temp\ErrorNukerSetup.exe" C:\Users\admin\AppData\Local\Temp\ErrorNukerSetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\errornukersetup.exe
c:\windows\system32\ntdll.dll
Total events
8 989
Read events
8 884
Write events
88
Delete events
17

Modification events

(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Error Nuker 2004
Value:
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:InstallDir
Value:
C:\Program Files\Error Nuker
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:UpdateVersion
Value:
10206
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker
Operation:writeName:Campaign
Value:
HOME
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Error Nuker
Operation:writeName:DisplayName
Value:
Error Nuker
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Error Nuker
Operation:writeName:UninstallString
Value:
C:\Program Files\Error Nuker\uninstall.exe
(PID) Process:(3216) ErrorNukerSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Error Nuker
Value:
C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2624) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
Executable files
8
Suspicious files
36
Text files
72
Unknown types
22

Dropped files

PID
Process
Filename
Type
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\error_nuker.icoimage
MD5:51D0361BCDA0244CE06270F48FD7D84E
SHA256:E90BE2D481A3CBDA9D61717E397C3ECD757C985EA97ABD4EB21E6CA81D5C4F82
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\uninstall.exeexecutable
MD5:94A55D5D5A71BD84FE6FF705B476AA5F
SHA256:A41AFB8FE563EF21A037121FF4D575D0053A73C5AC2F63BE799B7F1357C90871
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\startup.icoimage
MD5:887132581B753DD96BD72106ADC87367
SHA256:E8934BC0A37BEE470FE0A650BA2AC5B6A8B1A71EFD9E8CE96FBF1606709F92E7
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\finish_page.initext
MD5:338DC648666C5C0C5989C45889C93954
SHA256:A70D854EF3D694E66EDB8E624E36D2010330E2F504B3FA3A7C0EE3E1295AB777
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\vssver.sccbinary
MD5:9AB6E61899338C5833EB1648556DF5E1
SHA256:8DDDBDA88855854FA81F1559D1B65D5AC2A61ED176E303513C5D8E035D31FBBF
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\res\~trash.icoimage
MD5:02431D45BA9563E7D96331898331C7D0
SHA256:6635FC5820F89199066ED68547367802356CD9C0BE1C2DF0EEB387B71D7EF1BB
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\ioSpecial.iniini
MD5:868155CC636E29D578EF6CFCCDC8CAA6
SHA256:618126F3CFE3C2629753199455E573753BB8457B6E73C180085B8C24DE0CF8DC
3216ErrorNukerSetup.exeC:\Users\admin\AppData\Local\Temp\nstF760.tmp\InstallOptions.dllexecutable
MD5:5EC2356B7AD6993D3D4BF31A8DD45473
SHA256:E2F63AEA3F1FF6D8F075A2A8D386ACBD4888C08B01B7CF5FFDC3B1570D2F2109
3216ErrorNukerSetup.exeC:\Program Files\Error Nuker\doc\errornuker.chmbinary
MD5:65BB8CEB1E367F488162E8210495B029
SHA256:4233B52D2E2666808F55A74B51D35D8D6B99D5F9E7D16FDE4702B08F17F7B093
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
16
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4084
ErrorNuker.exe
GET
302
3.18.7.81:80
http://www.errornuker.com/products/errn2004/update.php?version=10206
unknown
unknown
4084
ErrorNuker.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7e60884410d0cf51
unknown
unknown
4084
ErrorNuker.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2064
msedge.exe
239.255.255.250:1900
unknown
2060
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2060
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2064
msedge.exe
224.0.0.251:5353
unknown
2060
msedge.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
unknown
2060
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
4084
ErrorNuker.exe
3.18.7.81:80
www.errornuker.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
www.errornuker.com
  • 3.18.7.81
  • 3.19.116.195
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.168
  • 104.126.37.160
  • 104.126.37.161
  • 104.126.37.163
  • 104.126.37.154
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
www.hugedomains.com
  • 104.26.7.37
  • 172.67.70.191
  • 104.26.6.37
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info