File name:

InstallSANHealth422d.exe

Full analysis: https://app.any.run/tasks/1c25066c-c4df-4af8-b5a0-d364a6d8a351
Verdict: Malicious activity
Analysis date: April 28, 2021, 20:44:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

19F2A774EB5B866F03622DF9F4F4B68B

SHA1:

8885102D9FB8B0E52CB947C8BD920A8C658ABBAF

SHA256:

B684703C011E34B92977AD2889EE69B070E5A133A2093D1062B9B9B31DD1FCE2

SSDEEP:

49152:p7FEvqM7C406UF4X1XqofVa3IDk+nBrOQkmlo6ZPq0W5mpP20YgfIjU:pkqM7C40jF45qoN7DkQwQkqZM5APYgfI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • InstallSANHealth422d.exe (PID: 3764)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 2064)
      • regsvr32.exe (PID: 3544)
      • InstallSANHealth422d.exe (PID: 3764)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 3004)
      • regsvr32.exe (PID: 1460)
      • regsvr32.exe (PID: 2380)
    • Application was dropped or rewritten from another process

      • regsvr32.exe (PID: 1460)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2380)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 4088)
      • regsvr32.exe (PID: 2064)
      • regsvr32.exe (PID: 2204)
      • regsvr32.exe (PID: 3004)
      • SANHealth.exe (PID: 396)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • InstallSANHealth422d.exe (PID: 3764)
    • Drops a file that was compiled in debug mode

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4088)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2380)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 3004)
    • Creates files in the program directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates a directory in Program Files

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates files in the Windows directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Drops a file with too old compile date

      • InstallSANHealth422d.exe (PID: 3764)
    • Removes files from Windows directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Changes default file association

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates a software uninstall entry

      • InstallSANHealth422d.exe (PID: 3764)
  • INFO

    • Manual execution by user

      • SANHealth.exe (PID: 396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

SpecialBuild: -
Arguments: -
PackageCode: {D310E81D-E530-4272-005F-FB3300111769}
ProductCode: {B23B03CF-8025-4308-859E-A39F3323FF90}
Comments: WinNT (x86) Unicode Lib Rel
InternalName: TSULoader
OriginalFileName: InstallSANHealth422d.exe
FileVersion: 2021.1.26.2022
FileDescription: Installer for SAN Health
WebSite: www.broadcom.com/sanhealth
Email: SANHealth.Admin@broadcom.com
LegalCopyright: Brocade Proprietary and Confidential. Copyright © 2021 Brocade
CompanyName: Brocade Communications
ProductVersion: 4.2.2b
ProductName: SAN Health
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: Special build
FileFlagsMask: 0x003f
ProductVersionNumber: 4.2.2.0
FileVersionNumber: 2021.1.26.2022
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 6
OSVersion: 4
EntryPoint: 0x15a9
UninitializedDataSize: -
InitializedDataSize: 2822144
CodeSize: 8192
LinkerVersion: 8
PEType: PE32
TimeStamp: 2020:07:31 11:12:41+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
11
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start start installsanhealth422d.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs sanhealth.exe no specs installsanhealth422d.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396"C:\Program Files\Brocade\SAN Health 4\SANHealth.exe" C:\Program Files\Brocade\SAN Health 4\SANHealth.exeexplorer.exe
User:
admin
Company:
Brocade A Broadcom Inc. Company
Integrity Level:
MEDIUM
Description:
Program for Gathering Switch Diagnostic and Performance Data
Exit code:
0
Version:
4.02.0002
Modules
Images
c:\program files\brocade\san health 4\sanhealth.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1304"C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe" C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exeexplorer.exe
User:
admin
Company:
Brocade Communications
Integrity Level:
MEDIUM
Description:
Installer for SAN Health
Exit code:
3221226540
Version:
2021.1.26.2022
Modules
Images
c:\users\admin\appdata\local\temp\installsanhealth422d.exe
c:\systemroot\system32\ntdll.dll
1460"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\MSCOMCTL.OCX" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1524"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthH.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2064"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\RICHTX32.OCX" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2204"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\COMCAT.DLL" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2380"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthM.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3004"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthC.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
3544"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthT.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3764"C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe" C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe
explorer.exe
User:
admin
Company:
Brocade Communications
Integrity Level:
HIGH
Description:
Installer for SAN Health
Exit code:
0
Version:
2021.1.26.2022
Modules
Images
c:\users\admin\appdata\local\temp\installsanhealth422d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
3 192
Read events
2 095
Write events
1 005
Delete events
92

Modification events

(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B40E0000DD0B24636F3CD701
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
41D65B00152DF946AC9436A02059831788430CDCA067AFE1E23604DD91EF59DA
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthH.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthT.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\msvbvm60.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthC.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSCOMCTL.OCX
Value:
2
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\RICHTX32.OCX
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\COMCAT.DLL
Value:
1
Executable files
17
Suspicious files
2
Text files
11
Unknown types
2

Dropped files

PID
Process
Filename
Type
3764InstallSANHealth422d.exeC:\Users\admin\AppData\Local\Temp\A2DE4D0A.dat
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealth.exe._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthM.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthH.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthT.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthC.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Windows\system32\MSCOMCTL.OCX._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Windows\system32\RICHTX32.OCX._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\Readme.txttext
MD5:EF7E3BA2522437D44C66E869C547B79C
SHA256:DD014A60BE6577BBF0927BA02C8D5FDEFDCBF8A26693142928748EE583D6B3DA
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SHDC.exe._tm
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info