| File name: | oalinst (1).zip |
| Full analysis: | https://app.any.run/tasks/4d9dc19f-8104-4bb3-862e-0ed57764dfe3 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | February 22, 2024, 23:27:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 47F53B4B655A9F8124687141B0F94D92 |
| SHA1: | 45E08368C6755C58902B7746FF3E51AD2DF8A8B8 |
| SHA256: | D165BCB7628FD950D14847585468CC11943B2A1DA92A59A839D397C68F9D4B06 |
| SSDEEP: | 24576:9IUamkvZeLROU1fhdX8XV7b+5swOBHWmpwrFIxcbKKSznhbFEtpK2:9IUamkvZeLRD1fhdX8XV7b+57OBHWmpI |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2009:06:03 11:25:14 |
| ZipCRC: | 0x154bebc3 |
| ZipCompressedSize: | 590314 |
| ZipUncompressedSize: | 809496 |
| ZipFileName: | oalinst.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | "C:\Users\admin\Desktop\gfwlivesetup.exe" | C:\Users\admin\Desktop\gfwlivesetup.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Games for Windows® - LIVE Game Setup Exit code: 0 Version: 3.5.0089.0 (WGX_XLIVE_V3.05_RTM(panblder).110411-1052) Modules
| |||||||||||||||
| 796 | "C:\Users\admin\Desktop\NordVPNSetup (1).exe" | C:\Users\admin\Desktop\NordVPNSetup (1).exe | explorer.exe | ||||||||||||
User: admin Company: NordVPN Integrity Level: MEDIUM Description: NordVPN Web Installer Exit code: 0 Version: 0.0.4.0 Modules
| |||||||||||||||
| 1112 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1624 | "C:\Program Files\NordUpdater\NordUpdateService.exe" | C:\Program Files\NordUpdater\NordUpdateService.exe | services.exe | ||||||||||||
User: SYSTEM Company: TEFINCOM S.A. Integrity Level: SYSTEM Description: NordSec Update Service Exit code: 0 Version: 1.0.2.26 Modules
| |||||||||||||||
| 1628 | "C:\Windows\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\{97DEC5D6-2BE9-45BB-BFC5-274B851B486B}\NordVPNTapSetup.msi /qn /norestart AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\is-OMAJM.tmp\NordVPNTapSetup.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\is-OMAJM.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /qn /norestart " REBOOT="ReallySuppress" AI_EUIMSI="" | C:\Windows\System32\msiexec.exe | — | NordVPNTapSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1740 | "C:\Users\admin\AppData\Local\Temp\is-Q81MF.tmp\NordVPNSetup (1).tmp" /SL5="$D01D2,918814,893440,C:\Users\admin\Desktop\NordVPNSetup (1).exe" | C:\Users\admin\AppData\Local\Temp\is-Q81MF.tmp\NordVPNSetup (1).tmp | — | NordVPNSetup (1).exe | |||||||||||
User: admin Company: NordVPN Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1824 | "C:\Windows\system32\icacls.exe" "C:\Program Files\NordUpdater" /grant *S-1-5-18:(OI)(CI)(F) | C:\Windows\System32\icacls.exe | — | NordUpdaterSetup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1832 | "C:\Users\admin\AppData\Local\Temp\is-9RQA1.tmp\HxDSetup.tmp" /SL5="$302AA,2973524,121344,C:\Users\admin\Desktop\HxDSetup\HxDSetup.exe" /SPAWNWND=$202AC /NOTIFYWND=$202C0 | C:\Users\admin\AppData\Local\Temp\is-9RQA1.tmp\HxDSetup.tmp | HxDSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2000 | "C:\Users\admin\AppData\Local\Temp\is-TNLL7.tmp\NordVPNSetup (1).tmp" /SL5="$1801A4,918814,893440,C:\Users\admin\Desktop\NordVPNSetup (1).exe" /SPAWNWND=$D01E0 /NOTIFYWND=$D01D2 | C:\Users\admin\AppData\Local\Temp\is-TNLL7.tmp\NordVPNSetup (1).tmp | NordVPNSetup (1).exe | ||||||||||||
User: admin Company: NordVPN Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2056 | "C:\Users\admin\Desktop\BRenamerl\BRenamerl.exe" | C:\Users\admin\Desktop\BRenamerl\BRenamerl.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\oalinst (1).zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2256 | InternetHostingToolSetup.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.ba\thm.xml | xml | |
MD5:F62729C6D2540015E072514226C121C7 | SHA256:F13BAE0EC08C91B4A315BB2D86EE48FADE597E7A5440DCE6F751F98A3A4D6916 | |||
| 3500 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{211260B7-B550-4DFB-9F30-265314E81F24}\.cr\InternetHostingToolSetup-v5.5.4.exe | executable | |
MD5:68F77BB8CC3983B7EE274AC068C42CDC | SHA256:0E5DB58BAADF92FFD0FCE0D0E8D7D4350BAF8DCC9C7E8DEB510B9BCC63C65BED | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.be\InternetHostingToolSetup.exe | executable | |
MD5:68F77BB8CC3983B7EE274AC068C42CDC | SHA256:0E5DB58BAADF92FFD0FCE0D0E8D7D4350BAF8DCC9C7E8DEB510B9BCC63C65BED | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.ba\wixstdba.dll | executable | |
MD5:5A0F6133B8FCC0FF56CA7B53C111D385 | SHA256:BC3C0301EAA65AB0969B5717962EFAABC1E48E77231778F04F2CC61449C6A481 | |||
| 2256 | InternetHostingToolSetup.exe | C:\ProgramData\Package Cache\{210f720b-43b5-4e48-8d2b-e5afc28cddf7}\InternetHostingToolSetup.exe | executable | |
MD5:68F77BB8CC3983B7EE274AC068C42CDC | SHA256:0E5DB58BAADF92FFD0FCE0D0E8D7D4350BAF8DCC9C7E8DEB510B9BCC63C65BED | |||
| 2000 | NordVPNSetup (1).tmp | C:\Users\admin\AppData\Local\Temp\is-3FJK9.tmp\Nord.Setup.dll | executable | |
MD5:0FFAE833B8745FC12DE1009E96815A4A | SHA256:D918AD96533148CF58E10B328FF919B9AE7BC066233DC9F94470224994A1D9D3 | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.ba\license.rtf | text | |
MD5:E5FD6FF9DA4108010DF00690BB779981 | SHA256:656EE2547F55772A4DA5A44032DAE69DD700F22DF9B384ECA6A56BE6424A4D16 | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.ba\logo.png | image | |
MD5:8346E21859A269DCCF1E408DC7593CCA | SHA256:CD2E8ED1FBB308D9D166F49794D323A9B22EFBA1033CDF906D1F4B030319E01B | |||
| 3936 | InternetHostingToolSetup-v5.5.4.exe | C:\Users\admin\AppData\Local\Temp\{E8F91280-41FB-4495-A788-E3987BE8BE64}\.ba\BootstrapperApplicationData.xml | xml | |
MD5:9B8A68CB2BB51AD298BF084637160328 | SHA256:76A92CA1D02965A4948A693ADD1557A7544FC8F6794506875D6D9E7828D2A34B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2000 | NordVPNSetup (1).tmp | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAp6SoieyZlCkAZjOE2Gl50%3D | unknown | binary | 727 b | unknown |
1624 | NordUpdateService.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?9e4fbecd8579a65a | unknown | compressed | 65.2 Kb | unknown |
392 | gfwlivesetup.exe | GET | — | 2.16.164.58:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/gfwlclient.msi | unknown | — | — | unknown |
1624 | NordUpdateService.exe | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D | unknown | binary | 1.41 Kb | unknown |
392 | gfwlivesetup.exe | GET | 302 | 2.19.246.123:80 | http://go.microsoft.com/fwlink/?LinkID=201133 | unknown | — | — | unknown |
392 | gfwlivesetup.exe | GET | 302 | 2.19.246.123:80 | http://go.microsoft.com/fwlink/?LinkID=194359&clcid=0x409 | unknown | — | — | unknown |
392 | gfwlivesetup.exe | GET | 200 | 2.16.164.58:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/gfwlivesetup.txt | unknown | text | 10 b | unknown |
2000 | NordVPNSetup (1).tmp | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?19838b2ae250760d | unknown | — | — | unknown |
2000 | NordVPNSetup (1).tmp | GET | 200 | 104.18.21.226:80 | http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D | unknown | binary | 1.41 Kb | unknown |
392 | gfwlivesetup.exe | GET | 200 | 2.16.164.58:80 | http://download.gfwl.xboxlive.com/content/gfwl-public/redists/production/xliveredist.msi | unknown | executable | 20.6 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2000 | NordVPNSetup (1).tmp | 104.19.159.190:443 | api.nordvpn.com | CLOUDFLARENET | — | unknown |
2000 | NordVPNSetup (1).tmp | 104.19.185.81:443 | applytics.zwyr157wwiu6eior.com | CLOUDFLARENET | — | unknown |
2000 | NordVPNSetup (1).tmp | 104.17.208.237:443 | downloads.nordcdn.com | CLOUDFLARENET | — | unknown |
2560 | miss.exe | 192.168.100.2:5351 | — | — | — | whitelisted |
2560 | miss.exe | 239.255.255.250:1900 | — | — | — | unknown |
3456 | IPUtility.exe | 224.0.0.251:5353 | — | — | — | unknown |
392 | gfwlivesetup.exe | 2.19.246.123:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
api.nordvpn.com |
| unknown |
applytics.zwyr157wwiu6eior.com |
| unknown |
downloads.nordcdn.com |
| unknown |
moonlight-stream.org |
| unknown |
1.0.0.127.dnsbugtest.1.0.0.127.in-addr.arpa |
| unknown |
191.100.168.192.in-addr.arpa |
| unknown |
go.microsoft.com |
| whitelisted |
download.gfwl.xboxlive.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
Process | Message |
|---|---|
IPUtility.exe | IPUtilityApp
|
IPUtility.exe | Current PATH
|
IPUtility.exe | C:\Users\admin\Desktop |
IPUtility.exe | localPath PATH
|
IPUtility.exe | C:\Users\admin\Desktop |
IPUtility.exe | C:\Windows\system32\UxTheme.dll |
IPUtility.exe | C:\Windows\system32\dwmapi.dll |
IPUtility.exe | C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll |
IPUtility.exe | C:\Windows\system32\SHLWAPI.dll |
IPUtility.exe | C:\Windows\system32\ADVAPI32.dll |