File name:

apache-tomcat-7.0.79.exe

Full analysis: https://app.any.run/tasks/43980f48-56a1-4ceb-8dc5-f3654158e7a4
Verdict: Malicious activity
Analysis date: May 12, 2024, 19:04:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

F321B1CE1952CBC90F9B96B616C566B6

SHA1:

4F5291F157F48689E018A6AB6410FAE52476732A

SHA256:

7A8A67BCB84CE10A7C907F9340B9BBD315D3E6D87466AE66564AE0C8A9C68F38

SSDEEP:

98304:qwlV2iUQIvQE40una1hg2lPLeN7gCZvsF61aGAF6j9ZKH39eKyB/RS7PDxWnGwKO:GHk0+DFHjuDoHb0xq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Changes the autorun value in the registry

      • apache-tomcat-7.0.79.exe (PID: 4076)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Checks for Java to be installed

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Executable content was dropped or overwritten

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Starts application with an unusual extension

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • The process creates files with name similar to system file names

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Reads the Internet Settings

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Creates a software uninstall entry

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Reads security settings of Internet Explorer

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Start notepad (likely ransomware note)

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Executes as Windows Service

      • Tomcat7.exe (PID: 1604)
  • INFO

    • Reads the computer name

      • Tomcat7.exe (PID: 112)
      • apache-tomcat-7.0.79.exe (PID: 4076)
      • Tomcat7.exe (PID: 328)
      • Tomcat7.exe (PID: 2316)
      • Tomcat7.exe (PID: 660)
      • Tomcat7w.exe (PID: 1856)
    • Checks supported languages

      • Tomcat7.exe (PID: 112)
      • apache-tomcat-7.0.79.exe (PID: 4076)
      • nsE88.tmp (PID: 2028)
      • Tomcat7.exe (PID: 328)
      • ns908.tmp (PID: 1116)
      • Tomcat7.exe (PID: 2316)
      • nsF06.tmp (PID: 1292)
      • nsF84.tmp (PID: 1628)
      • Tomcat7.exe (PID: 660)
      • Tomcat7w.exe (PID: 1856)
    • Creates files in the program directory

      • Tomcat7.exe (PID: 112)
      • apache-tomcat-7.0.79.exe (PID: 4076)
      • Tomcat7.exe (PID: 660)
    • Create files in a temporary directory

      • apache-tomcat-7.0.79.exe (PID: 4076)
    • Creates files or folders in the user directory

      • apache-tomcat-7.0.79.exe (PID: 4076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:11 21:50:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x32bf
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 7.0.79.0
ProductVersionNumber: 7.0.79.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: tomcat.apache.org
CompanyName: Apache Software Foundation
FileDescription: Apache Tomcat Installer
FileVersion: 2
InternalName: apache-tomcat-7.0.79.exe
LegalCopyright: Copyright (c) 1999-2017 The Apache Software Foundation
ProductName: Apache Tomcat
ProductVersion: 7.0.79
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
13
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start apache-tomcat-7.0.79.exe ns908.tmp no specs tomcat7.exe no specs nse88.tmp no specs tomcat7.exe no specs nsf06.tmp no specs tomcat7.exe no specs nsf84.tmp no specs tomcat7.exe no specs tomcat7w.exe no specs notepad.exe no specs tomcat7.exe no specs apache-tomcat-7.0.79.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
112"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //IS//Tomcat7 --DisplayName "Apache Tomcat 7.0 Tomcat7" --Description "Apache Tomcat 7.0.79 Server - http://tomcat.apache.org/" --LogPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0\logs" --Install "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" --Jvm "C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll" --StartPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0" --StopPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exens908.tmp
User:
admin
Company:
Apache Software Foundation
Integrity Level:
HIGH
Description:
Commons Daemon Service Runner
Exit code:
0
Version:
1.0.15.0
Modules
Images
c:\program files\apache software foundation\tomcat 7.0\bin\tomcat7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
328"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //US//Tomcat7 --Classpath "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\bootstrap.jar;C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\tomcat-juli.jar" --StartClass org.apache.catalina.startup.Bootstrap --StopClass org.apache.catalina.startup.Bootstrap --StartParams start --StopParams stop --StartMode jvm --StopMode jvmC:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exensE88.tmp
User:
admin
Company:
Apache Software Foundation
Integrity Level:
HIGH
Description:
Commons Daemon Service Runner
Exit code:
0
Version:
1.0.15.0
Modules
Images
c:\program files\apache software foundation\tomcat 7.0\bin\tomcat7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
660"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //US//Tomcat7 --StdOutput auto --StdError auto --JvmMs 128 --JvmMx 256C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exensF84.tmp
User:
admin
Company:
Apache Software Foundation
Integrity Level:
HIGH
Description:
Commons Daemon Service Runner
Exit code:
0
Version:
1.0.15.0
Modules
Images
c:\program files\apache software foundation\tomcat 7.0\bin\tomcat7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1116"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\ns908.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //IS//Tomcat7 --DisplayName "Apache Tomcat 7.0 Tomcat7" --Description "Apache Tomcat 7.0.79 Server - http://tomcat.apache.org/" --LogPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0\logs" --Install "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" --Jvm "C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll" --StartPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0" --StopPath "C:\Program Files\Apache Software Foundation\Tomcat 7.0"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\ns908.tmpapache-tomcat-7.0.79.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nse350e.tmp\ns908.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1236"C:\Windows\system32\NOTEPAD.EXE" C:\Program Files\Apache Software Foundation\Tomcat 7.0\webapps\ROOT\RELEASE-NOTES.txtC:\Windows\System32\notepad.exeapache-tomcat-7.0.79.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1292"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsF06.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //US//Tomcat7 --JvmOptions "-Dcatalina.home=C:\Program Files\Apache Software Foundation\Tomcat 7.0#-Dcatalina.base=C:\Program Files\Apache Software Foundation\Tomcat 7.0#-Djava.endorsed.dirs=C:\Program Files\Apache Software Foundation\Tomcat 7.0\endorsed#-Djava.io.tmpdir=C:\Program Files\Apache Software Foundation\Tomcat 7.0\temp#-Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager#-Djava.util.logging.config.file=C:\Program Files\Apache Software Foundation\Tomcat 7.0\conf\logging.properties"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsF06.tmpapache-tomcat-7.0.79.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nse350e.tmp\nsf06.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1604"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //RS//Tomcat7C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exeservices.exe
User:
SYSTEM
Company:
Apache Software Foundation
Integrity Level:
SYSTEM
Description:
Commons Daemon Service Runner
Version:
1.0.15.0
Modules
Images
c:\program files\apache software foundation\tomcat 7.0\bin\tomcat7.exe
c:\windows\system32\ntdll.dll
1628"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsF84.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //US//Tomcat7 --StdOutput auto --StdError auto --JvmMs 128 --JvmMx 256C:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsF84.tmpapache-tomcat-7.0.79.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nse350e.tmp\nsf84.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1856"C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7w.exe" //MR//Tomcat7C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7w.exeapache-tomcat-7.0.79.exe
User:
admin
Company:
Apache Software Foundation
Integrity Level:
HIGH
Description:
Commons Daemon Service Manager
Version:
1.0.15.0
Modules
Images
c:\program files\apache software foundation\tomcat 7.0\bin\tomcat7w.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2028"C:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsE88.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7.exe" //US//Tomcat7 --Classpath "C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\bootstrap.jar;C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\tomcat-juli.jar" --StartClass org.apache.catalina.startup.Bootstrap --StopClass org.apache.catalina.startup.Bootstrap --StartParams start --StopParams stop --StartMode jvm --StopMode jvmC:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsE88.tmpapache-tomcat-7.0.79.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nse350e.tmp\nse88.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
3 210
Read events
3 179
Write events
31
Delete events
0

Modification events

(PID) Process:(112) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Java
Operation:writeName:Jvm
Value:
C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll
(PID) Process:(112) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Stop
Operation:writeName:WorkingPath
Value:
C:\Program Files\Apache Software Foundation\Tomcat 7.0
(PID) Process:(112) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Start
Operation:writeName:WorkingPath
Value:
C:\Program Files\Apache Software Foundation\Tomcat 7.0
(PID) Process:(112) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Log
Operation:writeName:Path
Value:
C:\Program Files\Apache Software Foundation\Tomcat 7.0\logs
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Java
Operation:writeName:Classpath
Value:
C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\bootstrap.jar;C:\Program Files\Apache Software Foundation\Tomcat 7.0\bin\tomcat-juli.jar
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Stop
Operation:writeName:Class
Value:
org.apache.catalina.startup.Bootstrap
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Stop
Operation:writeName:Params
Value:
stop
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Stop
Operation:writeName:Mode
Value:
jvm
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Start
Operation:writeName:Class
Value:
org.apache.catalina.startup.Bootstrap
(PID) Process:(328) Tomcat7.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat7\Parameters\Start
Operation:writeName:Params
Value:
start
Executable files
14
Suspicious files
32
Text files
179
Unknown types
0

Dropped files

PID
Process
Filename
Type
4076apache-tomcat-7.0.79.exeC:\Users\admin\AppData\Local\Temp\nse350E.tmp\modern-wizard.bmpimage
MD5:4F7C3FD818EA30571D84FD9D217A60C5
SHA256:DD41483287B5A50DEB16FC587FC5654D25F6B5E1680CF400B21CABE86D925F67
4076apache-tomcat-7.0.79.exeC:\Users\admin\AppData\Local\Temp\nse350E.tmp\System.dllexecutable
MD5:3F176D1EE13B0D7D6BD92E1C7A0B9BAE
SHA256:FA4AB1D6F79FD677433A31ADA7806373A789D34328DA46CCB0449BBF347BD73E
4076apache-tomcat-7.0.79.exeC:\Users\admin\AppData\Local\Temp\nse350E.tmp\modern-header.bmpimage
MD5:46F339AA9B187E4B5736DEA11883AEB6
SHA256:82F819B9281F6A7799A3A000F03555B52E6AF990E2D9B2F68A5A82045681951A
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\lib\annotations-api.jarjava
MD5:B7CBA845CB73A0AF74BB15DD5E57AEC9
SHA256:F7B48010AF646DED42121E6E5C50746FF1DBA46CD68662DCEC60C17F4E68ACED
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\NOTICEtext
MD5:3D2AE4FDCAB64C2A19B0AE33F2BB19F2
SHA256:B8333256622ECB70DB060D67523C8C304561C200461A300520E6B04EDEC15206
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\LICENSEtext
MD5:77CDEAA98DEF0E01E61A53D09BFDE75D
SHA256:235D08270681F90E9151773D197D7EBAF52E99D95D1F4630328EF1D70EF8C3A4
4076apache-tomcat-7.0.79.exeC:\Users\admin\AppData\Local\Temp\nse350E.tmp\nsDialogs.dllexecutable
MD5:B3070CF20DB659FDFB3CB2ED38130E8D
SHA256:F2C1409FAF2952C1C91F4B5495158EF5C7D1A1DB6EEA4A18F163574BD52FCAD0
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\tomcat.icoimage
MD5:4644F2D45601037B8423D45E13194C93
SHA256:64A3170A912786E9EECE7E347B58F36471CB9D0BC790697B216C61050E6B1F08
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\RELEASE-NOTEStext
MD5:40B6C77FF60661A6FF755DC29DF412B1
SHA256:8F8A915BB6655182BA03CD0D62CC0A01EC9946F67F5138CEAEA6D143DD51AD67
4076apache-tomcat-7.0.79.exeC:\Program Files\Apache Software Foundation\Tomcat 7.0\lib\catalina-ant.jarcompressed
MD5:DF03FD93AEFB5678E1D5D29168E34D85
SHA256:18BD74BA6CAF57357EDCFDA80FDDF0C1295D000C90934847DCD07315597DF916
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info