File name:

InstallSANHealth422d.exe

Full analysis: https://app.any.run/tasks/1c25066c-c4df-4af8-b5a0-d364a6d8a351
Verdict: Malicious activity
Analysis date: April 28, 2021, 20:44:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

19F2A774EB5B866F03622DF9F4F4B68B

SHA1:

8885102D9FB8B0E52CB947C8BD920A8C658ABBAF

SHA256:

B684703C011E34B92977AD2889EE69B070E5A133A2093D1062B9B9B31DD1FCE2

SSDEEP:

49152:p7FEvqM7C406UF4X1XqofVa3IDk+nBrOQkmlo6ZPq0W5mpP20YgfIjU:pkqM7C40jF45qoN7DkQwQkqZM5APYgfI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • InstallSANHealth422d.exe (PID: 3764)
    • Loads dropped or rewritten executable

      • InstallSANHealth422d.exe (PID: 3764)
      • regsvr32.exe (PID: 1460)
      • regsvr32.exe (PID: 2064)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2380)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 3004)
    • Application was dropped or rewritten from another process

      • regsvr32.exe (PID: 2204)
      • regsvr32.exe (PID: 4088)
      • regsvr32.exe (PID: 1460)
      • regsvr32.exe (PID: 2064)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2380)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 3004)
      • SANHealth.exe (PID: 396)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates files in the Windows directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Drops a file that was compiled in debug mode

      • InstallSANHealth422d.exe (PID: 3764)
    • Removes files from Windows directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates a directory in Program Files

      • InstallSANHealth422d.exe (PID: 3764)
    • Drops a file with too old compile date

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates files in the program directory

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4088)
      • regsvr32.exe (PID: 3544)
      • regsvr32.exe (PID: 2380)
      • regsvr32.exe (PID: 1524)
      • regsvr32.exe (PID: 3004)
    • Changes default file association

      • InstallSANHealth422d.exe (PID: 3764)
    • Creates a software uninstall entry

      • InstallSANHealth422d.exe (PID: 3764)
  • INFO

    • Manual execution by user

      • SANHealth.exe (PID: 396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

SpecialBuild: -
Arguments: -
PackageCode: {D310E81D-E530-4272-005F-FB3300111769}
ProductCode: {B23B03CF-8025-4308-859E-A39F3323FF90}
Comments: WinNT (x86) Unicode Lib Rel
InternalName: TSULoader
OriginalFileName: InstallSANHealth422d.exe
FileVersion: 2021.1.26.2022
FileDescription: Installer for SAN Health
WebSite: www.broadcom.com/sanhealth
Email: SANHealth.Admin@broadcom.com
LegalCopyright: Brocade Proprietary and Confidential. Copyright © 2021 Brocade
CompanyName: Brocade Communications
ProductVersion: 4.2.2b
ProductName: SAN Health
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: Special build
FileFlagsMask: 0x003f
ProductVersionNumber: 4.2.2.0
FileVersionNumber: 2021.1.26.2022
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 6
OSVersion: 4
EntryPoint: 0x15a9
UninitializedDataSize: -
InitializedDataSize: 2822144
CodeSize: 8192
LinkerVersion: 8
PEType: PE32
TimeStamp: 2020:07:31 11:12:41+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
11
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start start installsanhealth422d.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs sanhealth.exe no specs installsanhealth422d.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
396"C:\Program Files\Brocade\SAN Health 4\SANHealth.exe" C:\Program Files\Brocade\SAN Health 4\SANHealth.exeexplorer.exe
User:
admin
Company:
Brocade A Broadcom Inc. Company
Integrity Level:
MEDIUM
Description:
Program for Gathering Switch Diagnostic and Performance Data
Exit code:
0
Version:
4.02.0002
Modules
Images
c:\program files\brocade\san health 4\sanhealth.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1304"C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe" C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exeexplorer.exe
User:
admin
Company:
Brocade Communications
Integrity Level:
MEDIUM
Description:
Installer for SAN Health
Exit code:
3221226540
Version:
2021.1.26.2022
Modules
Images
c:\users\admin\appdata\local\temp\installsanhealth422d.exe
c:\systemroot\system32\ntdll.dll
1460"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\MSCOMCTL.OCX" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1524"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthH.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2064"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\RICHTX32.OCX" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2204"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Windows\system32\COMCAT.DLL" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2380"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthM.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3004"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthC.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
3544"C:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exe" "C:\Program Files\Brocade\SAN Health 4\SANHealthT.dll" /rC:\ProgramData\Brocade Communications\Uninstall\{B23B03CF-8025-4308-859E-A39F3323FF90}\x86\regsvr32.exeInstallSANHealth422d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Out-of-process DLL registration helper
Exit code:
0
Version:
2020.07.31.1011U
Modules
Images
c:\programdata\brocade communications\uninstall\{b23b03cf-8025-4308-859e-a39f3323ff90}\x86\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3764"C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe" C:\Users\admin\AppData\Local\Temp\InstallSANHealth422d.exe
explorer.exe
User:
admin
Company:
Brocade Communications
Integrity Level:
HIGH
Description:
Installer for SAN Health
Exit code:
0
Version:
2021.1.26.2022
Modules
Images
c:\users\admin\appdata\local\temp\installsanhealth422d.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
3 192
Read events
2 095
Write events
1 005
Delete events
92

Modification events

(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B40E0000DD0B24636F3CD701
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
41D65B00152DF946AC9436A02059831788430CDCA067AFE1E23604DD91EF59DA
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthH.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthT.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\msvbvm60.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Brocade\SAN Health 4\SANHealthC.dll
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\MSCOMCTL.OCX
Value:
2
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\RICHTX32.OCX
Value:
1
(PID) Process:(3764) InstallSANHealth422d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\system32\COMCAT.DLL
Value:
1
Executable files
17
Suspicious files
2
Text files
11
Unknown types
2

Dropped files

PID
Process
Filename
Type
3764InstallSANHealth422d.exeC:\Users\admin\AppData\Local\Temp\A2DE4D0A.dat
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealth.exe._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthM.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthH.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthT.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SANHealthC.dll._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Windows\system32\MSCOMCTL.OCX._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Windows\system32\RICHTX32.OCX._tm
MD5:
SHA256:
3764InstallSANHealth422d.exeC:\Users\admin\AppData\Local\Temp\A2DE4D0A\Setup.icoimage
MD5:CE8E81042845C8400C537097C7974E75
SHA256:5A678B003F92C1A7317907BC62ED760775F058D9B562C49C3C7F9EF7A2BA5A9A
3764InstallSANHealth422d.exeC:\Program Files\Brocade\SAN Health 4\SHDC.exe._tm
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info