ocspackage.exe
Classification: Malicious
ocspackage.exe is a malicious file sample. Linked to Psexec malware. Reported by 1 threat source, last seen 2019-03-12. Detected by 2 antivirus engines.
Detection summary
- 2 antivirus detections (1% detection ratio)
- 0 IDS alerts
- 11 processes observed
- 7 contacted hosts
- 10 DNS requests
MITRE ATT&CK associations
Malware families: PSEXEC (S0029)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| PsExec | Hybrid-Analysis | 2019-03-12 11:45:30 | 2019-03-12 11:45:30 | S0029 PsExec |
Sample information
- Filenames
- ocspackage.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows, ...
- Size
- 5091899 bytes
- MD5
7bdebae7b1447f5fbb95bbcf5883c3bc- SHA-1
da67564e0a5df3bdda1d2fbee8a828253a2dc2f2- SHA-256
6dab4610f3c696bd105bac86ad41bb5169c2e6813f54130dba40a19f58034229- First indexed
- 2019-03-12 11:45:30
- Last updated
- 2026-01-05 01:34:53
Antivirus detections
| Engine | Detection |
|---|---|
| Sophos | PsExec (PUA) |
| DrWeb | Trojan.DownLoader27.38309 |
Network contacts
52.41.78.152 99.84.168.49 172.217.1.42 172.217.1.35 52.33.113.226 99.84.168.104 46.245.179.213
DNS requests
a1089.dscd.akamai.net com.cmtest.rocks cs9.wac.phicdn.net d1zkz3k4cclnv6.cloudfront.net dcky6u1m8u6el.cloudfront.net detectportal.firefox.com monitor.intra.comundus.de ocsp.pki.goog safebrowsing.googleapis.com shavar.prod.mozaws.net
Process list
| Name | Command line |
|---|---|
| ocspackage.exe | |
| instocs.exe | |
| OcsSetup.exe | /S /DEBUG /INSTALL /NP /notag /SERVER=http://monitor.intra.comundus.de/ocsinventory/ |
| nsD878.tmp | SetACL -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl" |
| SetACL.exe | SetACL -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl" |
| nsFC5D.tmp | SetACL.exe -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl" |
| SetACL.exe | -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl" |
| ns89AA.tmp | "%PROGRAMFILES%\OCS Inventory Agent\ocsinventory.exe" /SAVE_CONF /SERVER=http://monitor.intra.comundus.de/ocsinventory/ /USER= /PWD= /SSL=1 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /NOTAG /TAG="" |
| OCSInventory.exe | /SAVE_CONF /SERVER=http://monitor.intra.comundus.de/ocsinventory/ /USER= /PWD= /SSL=1 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /NOTAG /TAG="" |
| nsC210.tmp | %PROGRAMFILES%\OCS Inventory Agent\OcsService.exe -install |
| OcsService.exe | -install |