File name:

Nero5580.exe

Full analysis: https://app.any.run/tasks/7a7fb329-793b-4225-a20f-0a2947394aeb
Verdict: Malicious activity
Analysis date: April 14, 2025, 13:59:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

A52607B5399A331D379670432765E725

SHA1:

B0949A1E98868F6B3FB32A550B298943E976E1FE

SHA256:

B1130AA214A5BA0B06D6F282346976826839D5F15CF9A5369BA598000C8AE6D6

SSDEEP:

98304:yuuubxN62m5bObtHuqOxcYYG1aBOGPnF+HFhvF0JrkiSlIi+AtwNd9F1uXDuR2Ud:6N0EwopmlNKnscZodQjPcT55

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • rundll32.exe (PID: 208)
      • Setup.exe (PID: 5392)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • Nero5580.exe (PID: 5544)
    • Executable content was dropped or overwritten

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • The process creates files with name similar to system file names

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • Process drops legitimate windows executable

      • Nero5580.exe (PID: 5544)
    • There is functionality for taking screenshot (YARA)

      • Nero5580.exe (PID: 5544)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2240)
      • regsvr32.exe (PID: 5756)
      • regsvr32.exe (PID: 5728)
      • regsvr32.exe (PID: 1040)
    • Creates a software uninstall entry

      • Setup.exe (PID: 5392)
  • INFO

    • The sample compiled with english language support

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • Reads the computer name

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • Checks supported languages

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
      • NeroCheck.exe (PID: 3896)
    • Create files in a temporary directory

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • The sample compiled with german language support

      • Nero5580.exe (PID: 5544)
      • Setup.exe (PID: 5392)
    • Creates files in the program directory

      • Setup.exe (PID: 5392)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 5228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:12:19 16:50:36+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 233472
InitializedDataSize: 98304
UninitializedDataSize: -
EntryPoint: 0x8733
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.5.8.0
ProductVersionNumber: 5.5.8.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Ahead Software Gmbh im Stoeckmaedle 6 76307 Karlsbad, germany e-mail: info@nero.com
FileDescription: Web installer
FileVersion: 1
InternalName: Web installer
LegalCopyright: Copyright 1996-2001 ahead software gmbh and its licensors
LegalTrademarks: -
OriginalFileName: Installer.exe
PrivateBuild: -
ProductName: Nero - Burning Rom
ProductVersion: 5, 5, 8, 0
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
14
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start nero5580.exe setup.exe pcaui.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs rundll32.exe runonce.exe no specs rundll32.exe no specs grpconv.exe no specs nerocheck.exe no specs regsvr32.exe no specs nero5580.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208 setupapi,InstallHinfSection DefaultInstall 132 C:\Program Files (x86)\ahead\Nero\Misc\NeroCd2kUninstall.infC:\Windows\SysWOW64\rundll32.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
516"C:\Windows\System32\grpconv.exe" -oC:\Windows\SysWOW64\grpconv.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
896"C:\Windows\System32\rundll32.exe" MultiSZ,RemoveString HKLM SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318} LowerFilters NeroCd2kC:\Windows\SysWOW64\rundll32.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
900"C:\Users\admin\AppData\Local\Temp\Nero5580.exe" C:\Users\admin\AppData\Local\Temp\Nero5580.exeexplorer.exe
User:
admin
Company:
Ahead Software Gmbh im Stoeckmaedle 6 76307 Karlsbad, germany e-mail: info@nero.com
Integrity Level:
MEDIUM
Description:
Web installer
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\nero5580.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1040 /s "C:\Program Files (x86)\ahead\Nero\WaveEditor\Recording.ocx"C:\Windows\SysWOW64\regsvr32.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2240 /s "C:\Program Files (x86)\ahead\Nero\WaveEditor\AudioControl.ocx"C:\Windows\SysWOW64\regsvr32.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3896"C:\WINDOWS\system32\NeroCheck.exe" silentC:\Windows\SysWOW64\NeroCheck.exeSetup.exe
User:
admin
Company:
Ahead Software Gmbh
Integrity Level:
HIGH
Description:
NeroCheck
Exit code:
9
Version:
1, 0, 0, 2
Modules
Images
c:\windows\syswow64\nerocheck.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5228"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\SysWOW64\runonce.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
5344"C:\WINDOWS\system32\pcaui.exe" -g {11111111-1111-1111-1111-111111111111} -x {df3215eb-44c0-4610-9105-0178565debf8} -a "Nero - Burning Rom" -v "Ahead Software" -s "This app can't run because it causes security or performance issues on Windows. A new version may be available. Check with your software provider for an updated version that runs on this version of Windows." -n 1 -f 0 -k 0 -e "C:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Setup.exe"C:\Windows\System32\pcaui.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Program Compatibility Assistant User Interface
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pcaui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
5360 /s "C:\Program Files (x86)\ahead\Nero\WaveEditor\Axis.ocx"C:\Windows\SysWOW64\regsvr32.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
1 090
Read events
1 009
Write events
78
Delete events
3

Modification events

(PID) Process:(5392) Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\NeroTest
Operation:delete keyName:(default)
Value:
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{751524D1-BCCF-4192-9EEB-94C08BDC0753}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B4CE98B0-6CD1-4F5E-87C9-EA9FFC913329}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B4CE98B0-6CD1-4F5E-87C9-EA9FFC913329}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{B61D46BE-00D9-4F7C-87AE-5A3B55E76A3D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B61D46BE-00D9-4F7C-87AE-5A3B55E76A3D}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{70758027-7D3B-4B50-A276-30FD0FCD20FA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{70758027-7D3B-4B50-A276-30FD0FCD20FA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{1E5A37C4-605F-4ABD-A5EA-569893A1F472}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(2240) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E5A37C4-605F-4ABD-A5EA-569893A1F472}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
152
Suspicious files
79
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\DingDong.wavbinary
MD5:E415853EE7BE73C3926C41F123AEADFF
SHA256:131D7F3AE4073095FD99EF154DCF014451C46FBB1A8A8531D11CF02B8EFE3E8B
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\CDROM.CFGtext
MD5:21F78B44A9D06E0552F1774CFFE0143F
SHA256:18422ADBFF5E260575D7F7D2458B311D2BE45AAFDBDA086D772205E6E6509E7B
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\CDCopy.dllexecutable
MD5:02AB52B508BEA48F10DE29460469CEC9
SHA256:2E570FC95AB9003FCBE520DB295DABBDD326E7B2418A6D19C389DCEED3A6776A
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\Boo.wavbinary
MD5:C1B6BDA7931C1FE99589D7A9D0A0223E
SHA256:7E62946949E6982633ECF3C5A67121C6A101407E6DEB6C01D21A97344175ACC5
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Setup.exeexecutable
MD5:8FCD3E26D32FA5A836EA19717E3EA6A8
SHA256:676D87FD3CF92070CEC217707FDB98895C58F196EA7D24634DACE056B1160F21
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\CDROM.dllexecutable
MD5:BD1B0716A040C78C7678C234E463B2C2
SHA256:237D9C88F21AE28951EFB1B6FD192717E3E1EB6A01252E0E25A11CD9E1CF45F3
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\cdu920.dllexecutable
MD5:B176F7239E4E125188179EF2269A1C8B
SHA256:85073ED79EA80876A50354D1C8AEFB404EFEC83DCE9755E880027C99DFCEDA8E
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\Drweb32.dllexecutable
MD5:5B9C5A67FE6D918031F79CB8EB7BEF53
SHA256:AA8458741E1841E437793365B05D25936FF7EED16F65AD8D03E5F09A1713BB29
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\cdr50s.dllexecutable
MD5:C49213E369B5A9CBDD40D1E1A1449178
SHA256:CA001EDA31BC9068B8818D5C72E0F2F6C5EFD1C64B6F86BAEB6428204956992A
5544Nero5580.exeC:\Users\admin\AppData\Local\Temp\67EDD589.tmp\Nero\Dws114x.dllexecutable
MD5:454C1C6D8113DA1466085E5BBB3BF471
SHA256:ECE224F6EF780D5AC6776ED43A5255D2D66528788DBC374844FE614525ACF7FA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.48.23.180:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
664
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
664
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.180:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
664
SIHClient.exe
52.149.20.212:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
664
SIHClient.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.180
  • 23.48.23.193
  • 23.48.23.158
  • 23.48.23.141
  • 23.48.23.177
  • 23.48.23.145
  • 23.48.23.143
  • 23.48.23.194
  • 23.48.23.147
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.20
  • 40.126.32.72
  • 20.190.160.2
  • 20.190.160.3
  • 20.190.160.64
  • 20.190.160.14
  • 20.190.160.5
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
self.events.data.microsoft.com
  • 13.89.179.14
whitelisted

Threats

No threats detected
No debug info