ocspackage.exe

Classification: Malicious

ocspackage.exe is a malicious file sample. Linked to Psexec malware. Reported by 1 threat source, last seen 2019-03-12. Detected by 2 antivirus engines.

Detection summary

  • 2 antivirus detections (1% detection ratio)
  • 0 IDS alerts
  • 11 processes observed
  • 7 contacted hosts
  • 10 DNS requests

MITRE ATT&CK associations

Malware families: PSEXEC (S0029)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
PsExec Hybrid-Analysis 2019-03-12 11:45:30 2019-03-12 11:45:30 S0029 PsExec

Sample information

Filenames
ocspackage.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows, ...
Size
5091899 bytes
MD5
7bdebae7b1447f5fbb95bbcf5883c3bc
SHA-1
da67564e0a5df3bdda1d2fbee8a828253a2dc2f2
SHA-256
6dab4610f3c696bd105bac86ad41bb5169c2e6813f54130dba40a19f58034229
First indexed
2019-03-12 11:45:30
Last updated
2026-01-05 01:34:53

Antivirus detections

EngineDetection
SophosPsExec (PUA)
DrWebTrojan.DownLoader27.38309

Network contacts

52.41.78.152 99.84.168.49 172.217.1.42 172.217.1.35 52.33.113.226 99.84.168.104 46.245.179.213

DNS requests

a1089.dscd.akamai.net com.cmtest.rocks cs9.wac.phicdn.net d1zkz3k4cclnv6.cloudfront.net dcky6u1m8u6el.cloudfront.net detectportal.firefox.com monitor.intra.comundus.de ocsp.pki.goog safebrowsing.googleapis.com shavar.prod.mozaws.net

Process list

NameCommand line
ocspackage.exe
instocs.exe
OcsSetup.exe/S /DEBUG /INSTALL /NP /notag /SERVER=http://monitor.intra.comundus.de/ocsinventory/
nsD878.tmpSetACL -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"
SetACL.exeSetACL -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-32-545;p:read_ex,change;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"
nsFC5D.tmpSetACL.exe -on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"
SetACL.exe-on "%ALLUSERSPROFILE%\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"
ns89AA.tmp"%PROGRAMFILES%\OCS Inventory Agent\ocsinventory.exe" /SAVE_CONF /SERVER=http://monitor.intra.comundus.de/ocsinventory/ /USER= /PWD= /SSL=1 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /NOTAG /TAG=""
OCSInventory.exe/SAVE_CONF /SERVER=http://monitor.intra.comundus.de/ocsinventory/ /USER= /PWD= /SSL=1 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=0 /NOTAG /TAG=""
nsC210.tmp%PROGRAMFILES%\OCS Inventory Agent\OcsService.exe -install
OcsService.exe-install