| File name: | openconnect-gui-1.6.2-win64.exe |
| Full analysis: | https://app.any.run/tasks/ffb88e97-b1dd-4b90-85fc-7a5e28a88439 |
| Verdict: | Malicious activity |
| Analysis date: | August 25, 2024, 17:31:56 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows |
| MD5: | 9FCAB367F128AD37A28D58106AC2BDD8 |
| SHA1: | 08031905F19365786FBA625034BA29D36EDC6125 |
| SHA256: | DE08D8968E40E219932D01025521F879178EC99246802DB488C0FDAC9FCEF11A |
| SSDEEP: | 98304:NpWUwWAaqKBUbN0dDYgbBYD53Jq4VQwjwvkwWNcJ1xImZSPLjiWA38UGhxupTwFW:NDbnoUne4DxUMJr9FB7TVg9NHhmz2S |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:05:28 20:31:59+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Large address aware, No debug |
| PEType: | PE32+ |
| LinkerVersion: | 2.42 |
| CodeSize: | 36352 |
| InitializedDataSize: | 73728 |
| UninitializedDataSize: | 402432 |
| EntryPoint: | 0x444d |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6180 | "C:\Program Files\OpenConnect-GUI\.\openconnect-gui.exe" | C:\Program Files\OpenConnect-GUI\openconnect-gui.exe | openconnect-gui-1.6.2-win64.exe | ||||||||||||
User: admin Company: OpenConnect-GUI Team Integrity Level: HIGH Description: OpenConnect VPN graphical client Version: 1.6.2 Modules
| |||||||||||||||
| 6812 | "C:\Users\admin\Desktop\openconnect-gui-1.6.2-win64.exe" | C:\Users\admin\Desktop\openconnect-gui-1.6.2-win64.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 7020 | "C:\Users\admin\Desktop\openconnect-gui-1.6.2-win64.exe" | C:\Users\admin\Desktop\openconnect-gui-1.6.2-win64.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | DisplayName |
Value: OpenConnect-GUI | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | DisplayVersion |
Value: 1.6.2 | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | Publisher |
Value: OpenConnect-GUI Team | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\OpenConnect-GUI\Uninstall.exe" | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\OpenConnect-GUI\openconnect-gui.exe | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | HelpLink |
Value: https://gitlab.com/openconnect/openconnect-gui/-/wikis/FAQ | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | URLInfoAbout |
Value: https://gui.openconnect-vpn.net/ | |||
| (PID) Process: | (7020) openconnect-gui-1.6.2-win64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenConnect-GUI |
| Operation: | write | Name: | StartMenu |
Value: OpenConnect-GUI | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Users\admin\AppData\Local\Temp\nshF963.tmp\modern-header.bmp | image | |
MD5:DB915DB23FCDC4700989AD484A63BAF1 | SHA256:D73084B2F73CB3E13708D2DEF8F09D6421D919229DB8087B6EF5812552AB1EDE | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Users\admin\AppData\Local\Temp\nshF963.tmp\StartMenu.dll | executable | |
MD5:65C301D9A85F4342CDEF7FEDEABAFD5D | SHA256:48765294AA273EC2FD55CC5F9301E138B4D56A9F6D00FCF24473788E64B52BFD | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Users\admin\AppData\Local\Temp\nshF963.tmp\UserInfo.dll | executable | |
MD5:5DF25C042BDDA748D1F396B4FE070EDE | SHA256:C9DD715D31C8CDF763F5EDC92B8228DF617BC528D7F558D6E531434C62A4B37B | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Users\admin\AppData\Local\Temp\nshF963.tmp\InstallOptions.dll | executable | |
MD5:A7D3A18DDC6206B7D980A40700EA6619 | SHA256:C555C346CC1F80FF0CB9AEAAB8875A10C15EA4E5CF445A0F1597363FCF686924 | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Users\admin\AppData\Local\Temp\nshF963.tmp\ioSpecial.ini | ini | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Program Files\OpenConnect-GUI\Qt6Gui.dll | executable | |
MD5:88CBB6E1C333DA43ACC2E3D285AE40FD | SHA256:0ADF6DC1181E1ADFE945B0E20FF4DDBC5C223CA8178838170B5714F9D29B361C | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Program Files\OpenConnect-GUI\Qt6Core.dll | executable | |
MD5:804232193FCBAF1F9E082CA49F0B56B5 | SHA256:1A1F91E89D1F0AD27E4CAEFC46980D3BC7E8B6952974343D89C7E1BD670D4131 | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Program Files\OpenConnect-GUI\Qt6StateMachine.dll | executable | |
MD5:8F9A8262D779BF95ACE3742049505C09 | SHA256:6FB7332A36D1FD242DBA056344627C15FCDAB8175D4124EFCD781FA57924B857 | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Program Files\OpenConnect-GUI\libffi-8.dll | executable | |
MD5:65F6ABD875511657FD918ADD6C969BE5 | SHA256:F1ED51652B3746C1B4BCE497B7041E677E5D80C5AB8198EFEBB8FC6F75329AE8 | |||
| 7020 | openconnect-gui-1.6.2-win64.exe | C:\Program Files\OpenConnect-GUI\LICENSE.txt | text | |
MD5:FDAFC691AA5FB7F8E2A9E9521FEF771B | SHA256:19404E184CF45EC991B54E1E6F05F847AD8F13FEE2A51F3A2D9A960C8F7CB26B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 302 | 172.64.144.122:443 | https://gitlab.com/api/v4/projects/12274423/releases/permalink/latest | unknown | text | 88 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3176 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6180 | openconnect-gui.exe | 172.65.251.78:443 | gitlab.com | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
gitlab.com |
| whitelisted |