analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe

Full analysis: https://app.any.run/tasks/4621bb36-ab54-46da-b9dc-992263536c1c
Verdict: Malicious activity
Analysis date: May 22, 2024, 07:22:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

184AF5A8887F85ABF477EDA088993855

SHA1:

A3C29773ACE6D921145B468C6BE14487C68E1F19

SHA256:

A87CB54986607413406F6F3E5B5B314B3871080658F5E73DDF77D9E40A635828

SSDEEP:

786432:C8zdgd5/aTRonl3/okFK7cocHyOLXv5Tq:C8zdgzWil3/UcocXTBu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Drops the executable file immediately after the start

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Process drops legitimate windows executable

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • The process drops C-runtime libraries

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • The process creates files with name similar to system file names

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Creates a software uninstall entry

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Reads Internet Explorer settings

      • NirvanaFocus.exe (PID: 6216)
  • INFO

    • Checks supported languages

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Reads the computer name

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Create files in a temporary directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Creates files in the program directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
      • NirvanaFocus.exe (PID: 6216)
    • Creates files or folders in the user directory

      • a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe (PID: 4148)
    • Process checks computer location settings

      • NirvanaFocus.exe (PID: 6216)
    • Checks proxy server information

      • NirvanaFocus.exe (PID: 6216)
    • Reads the software policy settings

      • NirvanaFocus.exe (PID: 6216)
      • slui.exe (PID: 6820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 6
OSVersion: 4
EntryPoint: 0x3552
UninitializedDataSize: 2048
InitializedDataSize: 184832
CodeSize: 27136
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2024:03:30 16:55:23+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe no specs a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe nirvanafocus.exe sppextcomobj.exe no specs slui.exe filecoauth.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
472"C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe" C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4148"C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe" C:\Users\admin\AppData\Local\Temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6216"C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe"C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exe
User:
admin
Company:
NirvanaFocus
Integrity Level:
HIGH
Description:
NirvanaFocus
Version:
1.0.0.1
Modules
Images
c:\program files (x86)\kaizen nirvana focus\nirvanafocus.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6788C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6820"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6916C:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exe -EmbeddingC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDriveFile Co-Authoring Executable
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\19.043.0304.0013\filecoauth.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7132C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 229
Read events
7 221
Write events
8
Delete events
0

Modification events

(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayName
Value:
Kaizen Nirvana Focus 1.0.0.1
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\uninst.exe
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:DisplayVersion
Value:
1.0.0.1
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:URLInfoAbout
Value:
https://kaizen-apps.com
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kaizen Nirvana Focus
Operation:writeName:Publisher
Value:
StepForward Solutions LLP
(PID) Process:(4148) a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Kaizen Nirvana Focus
Value:
C:\Program Files (x86)\Kaizen Nirvana Focus\NirvanaFocus.exe
(PID) Process:(7132) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
Executable files
515
Suspicious files
11
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\ioSpecial.iniini
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\BaseDataValidatorLibrary.dllexecutable
MD5:11B114EF85C29F1113C28AA87A0CDBD6
SHA256:9AE0E41DB8D675A164CBDFAAC16DAC27AF3B11A54EB7ED18B2B6107EE50E2695
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\cs\PresentationUI.resources.dllexecutable
MD5:4D08490B24891319B77FBE7CF7CADE43
SHA256:90432D8A20CC4D9AFE027D067B252AF9C8D8D5D185A0666A4A5B060BD1566B3B
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\clrgc.dllexecutable
MD5:5BBE9CC11A135E1FA57FF7A3C16148A7
SHA256:AD26A49214AA020917933E362C0E422841DF24EC5853DDA72073140C957F4860
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\Azure.Identity.dllexecutable
MD5:462482B966B07F3B3917F6FE6BC22F2E
SHA256:FC2A610675B1803176706E7EFFF8C6242DA082E4DF4EFE3B3BF37D65E476535D
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\cs\PresentationCore.resources.dllexecutable
MD5:6FF4222393FA458C885E0A110E25CF15
SHA256:767114565D8B9B6FF57EB083AB4250A5F85184ADC72130E8BCA18C85C33D0680
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Program Files (x86)\Kaizen Nirvana Focus\BaseDataValidatorLibrary.pdbbinary
MD5:B5DAD7984B1F81263F952F6751FF857D
SHA256:36663DCF0C7B161417EE536BEEE732B32A872092289A574CEA8B6984D9DFBA7E
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\Desktop\Kaizen Nirvana Focus.lnklnk
MD5:F4DD888D349A99E2E05959C86AF88DA0
SHA256:E99181623D433CA4C217538DC72D0E4B3BC7AE158C058088428C27C34E604C17
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
4148a87cb54986607413406f6f3e5b5b314b3871080658f5e73ddf77d9e40a635828.exeC:\Users\admin\AppData\Local\Temp\nsj72DC.tmp\InstallOptions.dllexecutable
MD5:D1EEFB07ABC2577DFB92EB2E95A975E4
SHA256:89DD7D646278D8BFC41D5446BDC348B9A9AFAA832ABF02C1396272BB7AC7262A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
70
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
736
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5140
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
5004
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
4232
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
unknown
5004
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
2908
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
5140
MoUsoCoreWorker.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:1900
unknown
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2.23.209.133:443
r.bing.com
Akamai International B.V.
GB
unknown
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
736
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
4680
SearchApp.exe
2.23.209.181:443
r.bing.com
Akamai International B.V.
GB
unknown
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
unknown
736
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.75
whitelisted
r.bing.com
  • 2.23.209.181
  • 2.23.209.182
  • 2.23.209.130
  • 2.23.209.185
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.179
  • 2.23.209.183
  • 2.23.209.186
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.49
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 104.79.89.142
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

No threats detected
No debug info