File name:

a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe

Full analysis: https://app.any.run/tasks/4621bb36-ab54-46da-b9dc-992263536c1c
Verdict: Malicious activity
Analysis date: May 22, 2024, 07:22:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

184AF5A8887F85ABF477EDA088993855

SHA1:

A3C29773ACE6D921145B468C6BE14487C68E1F19

SHA256:

A87CB54986607413406F6F3E5B5B314B3871080658F5E73DDF77D9E40A635828

SSDEEP:

786432:C8zdgd5/aTRonl3/okFK7cocHyOLXv5Tq:C8zdgzWil3/UcocXTBu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Drops the executable file immediately after the start

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • The process drops C-runtime libraries

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Executable content was dropped or overwritten

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Creates a software uninstall entry

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • The process creates files with name similar to system file names

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Reads Internet Explorer settings

      • NirvanaFocus.exe (PID: 6216)
  • INFO

    • Checks supported languages

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Reads the computer name

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Creates files in the program directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Creates files or folders in the user directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Create files in a temporary directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Process checks computer location settings

      • NirvanaFocus.exe (PID: 6216)
    • Checks proxy server information

      • NirvanaFocus.exe (PID: 6216)
    • Reads the software policy settings

      • NirvanaFocus.exe (PID: 6216)
      • slui.exe (PID: 6820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe nirvanafocus.exe sppextcomobj.exe no specs slui.exe filecoauth.exe no specs slui.exe no specs a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
472"C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe" C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4148"C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe" C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6216"C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe"C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
User:
admin
Company:
NirvanaFocus
Integrity Level:
HIGH
Description:
NirvanaFocus
Version:
1.0.0.1
Modules
Images
c:\program files (x86)\kaizen nirvana focus\nirvanafocus.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6788C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6820"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6916C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe -EmbeddingC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDriveFile Co-Authoring Executable
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\19.043.0304.0013\filecoauth.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7132C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 229
Read events
7 221
Write events
8
Delete events
0

Modification events

(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayName
Value:
Kaizen Nirvana Focus 1.0.0.1
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\uninst.exe
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayVersion
Value:
1.0.0.1
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:URLInfoAbout
Value:
https://kaizen-apps.com
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:Publisher
Value:
StepForward Solutions LLP
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Kaizen Nirvana Focus
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
(PID) Process:(7132) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
Executable files
515
Suspicious files
11
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\InstallOptions.dllexecutable
MD5:D1EEFB07ABC2577DFB92EB2E95A975E4
SHA256:89DD7D646278D8BFC41D5446BDC348B9A9AFAA832ABF02C1396272BB7AC7262A
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\BaseDataValidatorLibrary.pdbbinary
MD5:B5DAD7984B1F81263F952F6751FF857D
SHA256:36663DCF0C7B161417EE536BEEE732B32A872092289A574CEA8B6984D9DFBA7E
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\Azure.Core.dllexecutable
MD5:65AF139BCAD87A3463FB776F51F60530
SHA256:9FDF65A3649BD909A2EC6182ED57A871FF8CEF4E17469F1FF8F057969B7D5BCC
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\BaseDataValidatorLibrary.dllexecutable
MD5:11B114EF85C29F1113C28AA87A0CDBD6
SHA256:9AE0E41DB8D675A164CBDFAAC16DAC27AF3B11A54EB7ED18B2B6107EE50E2695
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\coreclr.dllexecutable
MD5:811A7CE29EB8E99A6AE40FA05A94ECDE
SHA256:C691E62DFD44E55DFE54A340B7B9A83F946C1E38DFC0A06C4F6980BDDB7637EB
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\clretwrc.dllexecutable
MD5:4D3758DB6FEFC4E2EA4B480CE8A9F3A4
SHA256:5CE3F20A209E2F8373F10A4CAB43F2E612CED4A93CC89D0C386FD1F3977A4AD6
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\clrjit.dllexecutable
MD5:CB127C9DD4819BC2B436073626A083BB
SHA256:78E7A28E0E1F5D43C6F11B4D513CADE6D6E5F7BD646F3FB2CADCEC6AD968E258
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\ioSpecial.iniini
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\cs\Microsoft.VisualBasic.Forms.resources.dllexecutable
MD5:D4CF28846E6C1E81AF8A67FF78C9CB53
SHA256:2207CE62DCBB864EB36698DB136D3FC91D72D864E4F09A8563703EDD6103434F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
70
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
736
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
unknown
5140
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
5140
MoUsoCoreWorker.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4232
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
5004
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
5004
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
2908
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:1900
unknown
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2.23.209.133:443
r.bing.com
Akamai International B.V.
GB
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
736
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
4680
SearchApp.exe
2.23.209.181:443
r.bing.com
Akamai International B.V.
GB
unknown
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
unknown
736
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.75
whitelisted
r.bing.com
  • 2.23.209.181
  • 2.23.209.182
  • 2.23.209.130
  • 2.23.209.185
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.179
  • 2.23.209.183
  • 2.23.209.186
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 104.79.89.142
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

No threats detected
No debug info