| File name: | naticord-setup.exe |
| Full analysis: | https://app.any.run/tasks/5eaa8c8f-a03a-465b-8a03-f7f800697d8e |
| Verdict: | Malicious activity |
| Analysis date: | May 22, 2024, 14:50:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0A9B602457147C49891DE6396BE3821D |
| SHA1: | 5EE38684E071A6B70895D0D596F80947AB0D4153 |
| SHA256: | A8F33BE867E4A17FFF47C6C8BF8C1832C0B95FD4B2538C16DF75374753139954 |
| SSDEEP: | 98304:m+cD4dn8ZTQZPosM0lnClSUyNIkWnXFopLQ3iUrex4vkY7mZNmijVPiZQQ:ykWYm |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 89600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | naticord Setup |
| FileVersion: | |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | naticord |
| ProductVersion: | 0.1.1 Beta 4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 928 | "C:\Users\admin\AppData\Local\Temp\is-8DKHJ.tmp\naticord-setup.tmp" /SL5="$2013A,1270559,832512,C:\Users\admin\AppData\Local\Temp\naticord-setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\is-8DKHJ.tmp\naticord-setup.tmp | naticord-setup.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1200 | "C:\Users\admin\AppData\Local\Temp\naticord-setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\naticord-setup.exe | naticord-setup.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: naticord Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1680 | "C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints" | C:\Program Files\Google\Chrome\Application\chrome.exe | — | explorer.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 | |||||||||||||||
| 2028 | "C:\Users\admin\AppData\Roaming\naticord\Naticord.exe" | C:\Users\admin\AppData\Roaming\naticord\Naticord.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Naticord Version: 1.0.0.0 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\AppData\Local\Temp\naticord-setup.exe" | C:\Users\admin\AppData\Local\Temp\naticord-setup.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: naticord Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3984 | "C:\Users\admin\AppData\Local\Temp\is-CKQ09.tmp\naticord-setup.tmp" /SL5="$20138,1270559,832512,C:\Users\admin\AppData\Local\Temp\naticord-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-CKQ09.tmp\naticord-setup.tmp | — | naticord-setup.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: A00300000EA4276957ACDA01 | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: E88F6F5102885CB740671CA8986205CAC27DFFF923C24B0D0176CD5EA02F8DF9 | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Roaming\naticord\Naticord.exe | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 1E1E5C4E9D1FEF0F9A2A94F78DDC9B0E882C7B1163C71443236996AD39D96E74 | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\naticord_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.2 | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\naticord_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Users\admin\AppData\Roaming\naticord | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\naticord_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\naticord\ | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\naticord_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: naticord | |||
| (PID) Process: | (928) naticord-setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\naticord_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\is-NIQ1I.tmp | pdb | |
MD5:13633615AAD5EF1C522C43B672317139 | SHA256:5F3B39CF994F087F77758D129A450E323EDA2FC68A633EF4903CE2A2056414EF | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\is-449LD.tmp | executable | |
MD5:6C901446E95B532EAD315C190F7F99B4 | SHA256:B592DA5A0208909BFB34D928DB47E671B3A1149A5FAD327B91181B8ADCC3B6BA | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\unins000.exe | executable | |
MD5:6C901446E95B532EAD315C190F7F99B4 | SHA256:B592DA5A0208909BFB34D928DB47E671B3A1149A5FAD327B91181B8ADCC3B6BA | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\is-QFI1N.tmp | xml | |
MD5:47FCD701FC39687097E7311A75A772C0 | SHA256:FCF95979205E1937078154BF501BAC57047E48BCA2E7FEEF2B425185545B483F | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\Naticord.exe.config | xml | |
MD5:47FCD701FC39687097E7311A75A772C0 | SHA256:FCF95979205E1937078154BF501BAC57047E48BCA2E7FEEF2B425185545B483F | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\is-VG5D2.tmp | executable | |
MD5:4B75F93A0D8D2F39EDAF5568977CC7DC | SHA256:E6D1371D1AA774D155E9A4A89DA32B87FD4928650F4D76A1CF68C8C88283693C | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\Naticord.pdb | pdb | |
MD5:13633615AAD5EF1C522C43B672317139 | SHA256:5F3B39CF994F087F77758D129A450E323EDA2FC68A633EF4903CE2A2056414EF | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\Newtonsoft.Json.dll | executable | |
MD5:4B75F93A0D8D2F39EDAF5568977CC7DC | SHA256:E6D1371D1AA774D155E9A4A89DA32B87FD4928650F4D76A1CF68C8C88283693C | |||
| 3968 | naticord-setup.exe | C:\Users\admin\AppData\Local\Temp\is-CKQ09.tmp\naticord-setup.tmp | executable | |
MD5:84744B47461B352A11C2E55EBCB9C425 | SHA256:4310C1FAAE8EC3C2FE387BC37063D04C3FEF8D81ED5D0AD38B41C56CA7F2317A | |||
| 928 | naticord-setup.tmp | C:\Users\admin\AppData\Roaming\naticord\is-NONUD.tmp | executable | |
MD5:B5ABCC88494796B69BC15438366405A0 | SHA256:80DC6CD5D96E6A33BF3814399848E8FBE48D10815F2AA2112195AF54C290A681 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |