| File name: | apache-tomcat-8.5.98.exe |
| Full analysis: | https://app.any.run/tasks/0266485b-5638-416e-a34f-7c9be01fad89 |
| Verdict: | Malicious activity |
| Analysis date: | February 15, 2024, 09:03:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 23C528062E2D1119A6A2B1A1BD77FB66 |
| SHA1: | 214A846AED9D5C5DF0BE36B9180702ADC550CE17 |
| SHA256: | 902BECFDEAD59261910B7CB3E42EB9BBF64304C271AA5D51BD9EBD48C3F1EA78 |
| SSDEEP: | 98304:4hPlpG5FbXVylr6ZgbEh8A7q2F7iRqAAdljNFQcktJ72j6bJNNnr+UfFsyQuIxJj:40TWmPcMkpPUWOjKLTKOsB |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:07:02 02:09:43+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 139776 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x3645 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.5.98.0 |
| ProductVersionNumber: | 8.5.98.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | tomcat.apache.org |
| CompanyName: | Apache Software Foundation |
| FileDescription: | Apache Tomcat Installer |
| FileVersion: | 2 |
| InternalName: | apache-tomcat-8.5.98.exe |
| LegalCopyright: | Copyright (c) 1999-2024 The Apache Software Foundation |
| ProductName: | Apache Tomcat |
| ProductVersion: | 8.5.98 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3567.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" //US//Tomcat8 --Classpath "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\bootstrap.jar;C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\tomcat-juli.jar" --StartClass org.apache.catalina.startup.Bootstrap --StopClass org.apache.catalina.startup.Bootstrap --StartParams start --StopParams stop --StartMode jvm --StopMode jvm | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3567.tmp | — | apache-tomcat-8.5.98.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 240 | icacls "C:\Program Files\Apache Software Foundation\Tomcat 8.5\Uninstall.exe" /inheritance:e /grant *S-1-5-11:(RX) | C:\Windows\System32\icacls.exe | — | ns38E7.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | icacls "C:\Program Files\Apache Software Foundation\Tomcat 8.5" /inheritance:r /grant *S-1-5-19:(OI)(CI)(F) /grant *S-1-5-32-544:(OI)(CI)(F) /grant *S-1-5-18:(OI)(CI)(F) | C:\Windows\System32\icacls.exe | — | ns37EB.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1560 | "C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns38E7.tmp" icacls "C:\Program Files\Apache Software Foundation\Tomcat 8.5\Uninstall.exe" /inheritance:e /grant *S-1-5-11:(RX) | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns38E7.tmp | — | apache-tomcat-8.5.98.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1656 | "C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3869.tmp" icacls "C:\Program Files\Apache Software Foundation\Tomcat 8.5\tomcat.ico" /inheritance:e /grant *S-1-5-11:(R) | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3869.tmp | — | apache-tomcat-8.5.98.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\AppData\Local\Temp\apache-tomcat-8.5.98.exe" | C:\Users\admin\AppData\Local\Temp\apache-tomcat-8.5.98.exe | — | explorer.exe | |||||||||||
User: admin Company: Apache Software Foundation Integrity Level: MEDIUM Description: Apache Tomcat Installer Exit code: 3221226540 Version: 2.0 Modules
| |||||||||||||||
| 2184 | icacls "C:\Program Files\Apache Software Foundation\Tomcat 8.5\tomcat.ico" /inheritance:e /grant *S-1-5-11:(R) | C:\Windows\System32\icacls.exe | — | ns3869.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2332 | "C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3036.tmp" "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" //IS//Tomcat8 --DisplayName "Apache Tomcat 8.5 Tomcat8" --Description "Apache Tomcat 8.5.98 Server - https://tomcat.apache.org/" --LogPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5\logs" --Install "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" --Jvm "C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll" --StartPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5" --StopPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5" | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\ns3036.tmp | — | apache-tomcat-8.5.98.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2572 | "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" //US//Tomcat8 --JvmOptions "-Dcatalina.home=C:\Program Files\Apache Software Foundation\Tomcat 8.5#-Dcatalina.base=C:\Program Files\Apache Software Foundation\Tomcat 8.5#-Djava.io.tmpdir=C:\Program Files\Apache Software Foundation\Tomcat 8.5\temp#-Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager#-Djava.util.logging.config.file=C:\Program Files\Apache Software Foundation\Tomcat 8.5\conf\logging.properties" | C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe | — | ns35E5.tmp | |||||||||||
User: admin Company: Apache Software Foundation Integrity Level: HIGH Description: Apache Commons Daemon Service Runner Exit code: 0 Version: 1.3.4.0 Modules
| |||||||||||||||
| 2636 | "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" //IS//Tomcat8 --DisplayName "Apache Tomcat 8.5 Tomcat8" --Description "Apache Tomcat 8.5.98 Server - https://tomcat.apache.org/" --LogPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5\logs" --Install "C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe" --Jvm "C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll" --StartPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5" --StopPath "C:\Program Files\Apache Software Foundation\Tomcat 8.5" | C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\Tomcat8.exe | — | ns3036.tmp | |||||||||||
User: admin Company: Apache Software Foundation Integrity Level: HIGH Description: Apache Commons Daemon Service Runner Exit code: 0 Version: 1.3.4.0 Modules
| |||||||||||||||
| (PID) Process: | (2636) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Java |
| Operation: | write | Name: | Jvm |
Value: C:\Program Files\Java\jre1.8.0_271\bin\client\jvm.dll | |||
| (PID) Process: | (2636) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Stop |
| Operation: | write | Name: | WorkingPath |
Value: C:\Program Files\Apache Software Foundation\Tomcat 8.5 | |||
| (PID) Process: | (2636) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Start |
| Operation: | write | Name: | WorkingPath |
Value: C:\Program Files\Apache Software Foundation\Tomcat 8.5 | |||
| (PID) Process: | (2636) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Log |
| Operation: | write | Name: | Path |
Value: C:\Program Files\Apache Software Foundation\Tomcat 8.5\logs | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Java |
| Operation: | write | Name: | Classpath |
Value: C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\bootstrap.jar;C:\Program Files\Apache Software Foundation\Tomcat 8.5\bin\tomcat-juli.jar | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Stop |
| Operation: | write | Name: | Class |
Value: org.apache.catalina.startup.Bootstrap | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Stop |
| Operation: | write | Name: | Params |
Value: stop | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Stop |
| Operation: | write | Name: | Mode |
Value: jvm | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Start |
| Operation: | write | Name: | Class |
Value: org.apache.catalina.startup.Bootstrap | |||
| (PID) Process: | (3936) Tomcat8.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Apache Software Foundation\Procrun 2.0\Tomcat8\Parameters\Start |
| Operation: | write | Name: | Params |
Value: start | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3944 | apache-tomcat-8.5.98.exe | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\System.dll | executable | |
MD5:4ADD245D4BA34B04F213409BFE504C07 | SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706 | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Users\admin\AppData\Local\Temp\nsdFCB1.tmp\modern-wizard.bmp | image | |
MD5:9AA25769704A4D36E8E4327BA6431E6D | SHA256:C47099A48561B5F50C3669FA1EB6BED8B05A14C5FB442995DEA9FBC49AFFFCB5 | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\RELEASE-NOTES | text | |
MD5:90CEBDA9357B515CD235974C424A2002 | SHA256:CDECA901C815848B5B6AC36705F88439046978A104709E6EC21DB7562B79659B | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\catalina-ant.jar | java | |
MD5:72DC671057BB6CCCA1203FC795DAF507 | SHA256:087031BB067C38397A354630E7CABB6C67B5A525ECF7437231CDF71D15321CAD | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\annotations-api.jar | java | |
MD5:F7EF9DF111F937E1870A90A4BFA178BB | SHA256:DF0FE2C6249F431B13DF8FC4C0C547FEA6C9BF4C6948E441957FA521B69A7F3A | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\catalina-tribes.jar | java | |
MD5:070E531807FD256243A3A94F9331545A | SHA256:2731CD40BD8467D4514908123C6F56D232BD929F07A32153D618708F1398687F | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\ecj-4.6.3.jar | compressed | |
MD5:33E190A0F0745306DE54FBA90F381FC3 | SHA256:4374EE22AD38E04EE6BCAF781611F2BE9D5EE01D7BA84AC55794BAA732CCE371 | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\catalina-storeconfig.jar | java | |
MD5:EDBBD26BD19B1DC4B97D6C148296EE6A | SHA256:7600A0F86A38C82B0BC7AA8A680074293B2BB01E398BC861112EB1E7D1BECE6D | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\catalina-ha.jar | java | |
MD5:6CEC862E2F7EE4F8BB738559E711E233 | SHA256:B1EFCE722B5C4B742C73A2F5A818DCD5F0DFF0EAF53371B5EDBE6420983F6680 | |||
| 3944 | apache-tomcat-8.5.98.exe | C:\Program Files\Apache Software Foundation\Tomcat 8.5\lib\jsp-api.jar | java | |
MD5:AF813A91CD466E1F149994948087FE71 | SHA256:6A16D14164C38B90BFFFEF4C463865D2AA191DFB85AC608A694CA52551231320 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |