File name:

Webex.exe

Full analysis: https://app.any.run/tasks/5f2e6945-6ecb-4b5f-b20a-b887ea23f9e8
Verdict: Malicious activity
Analysis date: August 12, 2024, 14:34:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

6673801495157686AB317C8244A1BC36

SHA1:

BF83F34EA56C13C2E2E9D0789BC10F70030B1D97

SHA256:

0BA1763E9962C802F855E5CFA14FBF24C529467EF7914CAE22A32660392C0020

SSDEEP:

49152:w8uz8rmDNuILxkDEAKObVxo1pw2FhQq9AFKvGn2lehB472EAdQxm8+DNtotWcCWf:wcrmDNuI9MFb7o1e2FaqlvG2ohS7+X/y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • msiexec.exe (PID: 6600)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6600)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6600)
    • Drops the executable file immediately after the start

      • Webex.exe (PID: 6384)
      • msiexec.exe (PID: 6600)
      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • setup.exe (PID: 6324)
    • Executable content was dropped or overwritten

      • Webex.exe (PID: 6384)
      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • setup.exe (PID: 6324)
    • Uses TASKKILL.EXE to kill process

      • msiexec.exe (PID: 6816)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 6600)
      • Webex.exe (PID: 6384)
    • Process drops legitimate windows executable

      • Webex.exe (PID: 6384)
      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • setup.exe (PID: 6324)
    • Reads security settings of Internet Explorer

      • Webex.exe (PID: 6384)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
    • Starts itself from another location

      • CiscoCollabHost.exe (PID: 6892)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
    • The process drops C-runtime libraries

      • Webex.exe (PID: 6384)
    • Reads the date of Windows installation

      • Webex.exe (PID: 6384)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
    • Starts CMD.EXE for commands execution

      • CiscoCollabHost.exe (PID: 1608)
    • The executable file from the user directory is run by the CMD process

      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6992)
      • MicrosoftEdgeUpdate.exe (PID: 2536)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1128)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6596)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 4040)
    • Creates a software uninstall entry

      • setup.exe (PID: 6324)
    • Searches for installed software

      • setup.exe (PID: 6324)
  • INFO

    • Checks supported languages

      • Webex.exe (PID: 6384)
      • msiexec.exe (PID: 6600)
      • msiexec.exe (PID: 6816)
      • msiexec.exe (PID: 7032)
      • CiscoCollabHost.exe (PID: 6892)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • MicrosoftEdgeUpdate.exe (PID: 2536)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1128)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6596)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6992)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • MicrosoftEdgeUpdate.exe (PID: 1020)
      • MicrosoftEdgeUpdate.exe (PID: 4996)
      • setup.exe (PID: 6324)
      • MicrosoftEdgeUpdate.exe (PID: 6832)
    • Reads the computer name

      • Webex.exe (PID: 6384)
      • msiexec.exe (PID: 6600)
      • msiexec.exe (PID: 6816)
      • CiscoCollabHost.exe (PID: 6892)
      • msiexec.exe (PID: 7032)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6596)
      • MicrosoftEdgeUpdate.exe (PID: 2536)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6992)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1128)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • MicrosoftEdgeUpdate.exe (PID: 1020)
      • MicrosoftEdgeUpdate.exe (PID: 4996)
      • setup.exe (PID: 6324)
      • MicrosoftEdgeUpdate.exe (PID: 6832)
    • Checks proxy server information

      • Webex.exe (PID: 6384)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeUpdate.exe (PID: 1020)
      • MicrosoftEdgeUpdate.exe (PID: 6832)
    • Create files in a temporary directory

      • Webex.exe (PID: 6384)
      • MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe (PID: 1108)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • CiscoCollabHost.exe (PID: 1608)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6600)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
    • Reads the software policy settings

      • msiexec.exe (PID: 6600)
      • Webex.exe (PID: 6384)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeUpdate.exe (PID: 1020)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 6832)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6600)
      • CiscoCollabHost.exe (PID: 6892)
      • Webex.exe (PID: 6384)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeWebview_X64_118.0.2088.69.exe (PID: 6396)
      • setup.exe (PID: 6324)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6600)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6600)
    • Dropped object may contain TOR URL's

      • Webex.exe (PID: 6384)
    • Reads Microsoft Office registry keys

      • Webex.exe (PID: 6384)
      • OpenWith.exe (PID: 236)
    • Process checks computer location settings

      • Webex.exe (PID: 6384)
      • CiscoCollabHost.exe (PID: 1608)
      • MicrosoftEdgeUpdate.exe (PID: 6288)
    • UPX packer has been detected

      • Webex.exe (PID: 6384)
      • CiscoCollabHost.exe (PID: 1608)
    • Reads Environment values

      • msiexec.exe (PID: 7032)
      • MicrosoftEdgeUpdate.exe (PID: 1020)
      • MicrosoftEdgeUpdate.exe (PID: 6832)
    • Application launched itself

      • msiexec.exe (PID: 6600)
    • Reads the time zone

      • CiscoCollabHost.exe (PID: 1608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:24 13:12:56+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 1548288
InitializedDataSize: 53248
UninitializedDataSize: 3035136
EntryPoint: 0x45e720
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.19.3.29764
ProductVersionNumber: 4.19.3.29764
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Unknown (1809)
CharacterSet: Unicode
CompanyName: Cisco Systems, Inc
FileDescription: Webex
FileVersion: 4.19.3.29764
InternalName: Webex
LegalCopyright: Copyright (C) 2024 Cisco Systems Inc.
OriginalFileName: -
ProductName: Webex
ProductVersion: 4.19.3.29764
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
26
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT webex.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs taskkill.exe no specs conhost.exe no specs msiexec.exe no specs ciscocollabhost.exe no specs THREAT ciscocollabhost.exe cmd.exe no specs conhost.exe no specs microsoftedgewebview2runtimeinstaller_118.0.2088.69.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgewebview_x64_118.0.2088.69.exe setup.exe rundll32.exe no specs Shell Security Editor no specs microsoftedgeupdate.exe openwith.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1020"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzcuMTEiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzcuMTEiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7NjgxMDIyQTgtMzA5RC00RUMwLUI1QkEtRUYzMDFCQkRCRjQ5fSIgdXNlcmlkPSJ7QTc3Q0NCMTctRkVFMC00Mzc4LUIyMDMtRkE5QTU5RjMyREFGfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9IntBNjQ2QjNBNC1CQTQ1LTQ2RDYtODI3Qy02NUExMEYyRjA4OTF9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE3Ny4xMSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTE4NzA5MTg5ODIiIGluc3RhbGxfdGltZV9tcz0iNjE3Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.177.11
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1108"C:\Users\admin\AppData\Local\Temp\\WebView2Runtime\MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe" /silent /installC:\Users\admin\AppData\Local\Temp\WebView2Runtime\MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.177.11
Modules
Images
c:\users\admin\appdata\local\temp\webview2runtime\microsoftedgewebview2runtimeinstaller_118.0.2088.69.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1128"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.177.11\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.177.11\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.177.11
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.177.11\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1608"C:\Users\admin\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe" "C:\Users\admin\AppData\Local\CiscoSparkLauncher\44.8.0.30404_a5e8d55e-af94-4383-96d1-305b5dca9abf" spark-windows-app.dll /Hosted=true "C:\Users\admin\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex:///"C:\Users\admin\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
CiscoCollabHost.exe
User:
admin
Company:
Cisco Systems, Inc
Integrity Level:
MEDIUM
Description:
Webex
Version:
1.0.0.2
Modules
Images
c:\users\admin\appdata\local\ciscosparklauncher\ciscocollabhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2536"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.177.11
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4024C:\WINDOWS\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
4040"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.177.11
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4060cmd /c start /B /WAIT "WebView2Installer" "C:\Users\admin\AppData\Local\Temp\\WebView2Runtime\MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exe" /silent /installC:\Windows\System32\cmd.exeCiscoCollabHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
4064C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
30 998
Read events
29 356
Write events
1 559
Delete events
83

Modification events

(PID) Process:(6600) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
C819000066783DCEC4ECDA01
(PID) Process:(6600) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
084AB1C7E866A7952F40C5BD31B9ABCEA4D1E3F36BBAABD0E2B04070650821B7
(PID) Process:(6600) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\e5f25.rbs
Value:
31124676
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\e5f25.rbsLow
Value:
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Users\admin\AppData\Roaming\Microsoft\Installer\
Value:
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\5734F1AFAD1716E4A920EBF72D4D8CD7
Operation:writeName:69DF9DB9D63D4D254B31ADBF570CA4D2
Value:
21:\Software\Cisco\Spark\PrivateFolderCiscoSpark
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\18F66A267A0F7FA569FAB82D4D64AAE9
Operation:writeName:69DF9DB9D63D4D254B31ADBF570CA4D2
Value:
21:\Software\Cisco\Spark\PrivateFolderCiscoSparkLauncher
(PID) Process:(6600) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\81B71F9BD85029540AB2247E1F98862D
Operation:writeName:69DF9DB9D63D4D254B31ADBF570CA4D2
Value:
Executable files
499
Suspicious files
39
Text files
526
Unknown types
14

Dropped files

PID
Process
Filename
Type
6384Webex.exeC:\Users\admin\AppData\Local\Temp\56473ab0-3dc7-4a07-a9a3-2a56d00c38e4.msiexecutable
MD5:F1D3ABBE0AC29EAFB37738C1731E8FFB
SHA256:935161FD5A1389525A208F68663CC4A4B4FDC6405BCCDE334C4C1F7704CF95E8
6600msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141der
MD5:469E41B26C0F1DCA03A634AF2E3EB946
SHA256:FFD999584E4AFD9BDFC38E8773BAE76E37B01899FDC956D96D2328B5F3907B24
6600msiexec.exeC:\Users\admin\AppData\Roaming\Microsoft\Installer\{9BD9FD96-D36D-52D4-B413-DAFB75C04A2D}\ProductIcon.icoimage
MD5:0A9BF46691CD4DC4D8ADB773ED79076D
SHA256:24D538CEC1A46EFF37DEBC694E13B29C9D7B60FB1BC3B1E0BD704DA1927C46AC
6600msiexec.exeC:\Windows\Temp\~DFCF7B3F70E29F4999.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
6600msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_A3EC40476A9D69CF1356D24ADB0E26D8der
MD5:CA1BB28A8D8555978569EEA9F4113134
SHA256:61ACC4D2A77205802E0C5AA5B226F6B337AFB528AAD1AC61F38B508DCEA5421B
6600msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_A3EC40476A9D69CF1356D24ADB0E26D8binary
MD5:502216FAC6F1C15077565DC711C4CB4B
SHA256:A25294573C86A4C780001490479365BC701A6071FC878A134594DF9FA064DE45
6600msiexec.exeC:\Windows\Installer\MSI6241.tmpexecutable
MD5:A3AE5D86ECF38DB9427359EA37A5F646
SHA256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
6600msiexec.exeC:\Windows\Installer\MSI61E2.tmpexecutable
MD5:A3AE5D86ECF38DB9427359EA37A5F646
SHA256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
6600msiexec.exeC:\Users\admin\Desktop\Webex.lnklnk
MD5:1A86EEEDC1EC5DB47A8684DB64D01612
SHA256:9A1BA0C5AF7E693F38467C7A414D5EE9D15673E5AD7EE330354E9329727023DE
6600msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:B171D572F6244F40D11C923DA0A03FED
SHA256:6DEBF609215FBFCABA388AAD6AEF3AA4D5F4BAF7AB466E76C778BF5E5CD4BA8B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
50
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6600
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEASTW7oja%2FIfDgHMX%2BN4kLI%3D
unknown
whitelisted
6600
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
5540
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2268
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5540
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2180
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
192.168.100.255:138
whitelisted
4708
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1536
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6384
Webex.exe
170.133.160.218:443
ds.ciscospark.com
13445
US
unknown
6384
Webex.exe
170.72.245.107:443
client-upgrade-a.wbx2.com
US
unknown
6384
Webex.exe
13.224.189.96:443
binaries.webex.com
AMAZON-02
US
unknown
6600
msiexec.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
ds.ciscospark.com
  • 170.133.160.218
  • 170.133.161.135
unknown
client-upgrade-a.wbx2.com
  • 170.72.245.107
  • 170.72.245.151
  • 170.72.245.227
unknown
binaries.webex.com
  • 13.224.189.96
  • 13.224.189.77
  • 13.224.189.86
  • 13.224.189.107
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 184.86.251.15
  • 184.86.251.26
  • 184.86.251.20
  • 184.86.251.28
  • 184.86.251.25
  • 184.86.251.19
  • 184.86.251.27
  • 184.86.251.30
  • 184.86.251.16
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.20
  • 20.190.160.14
  • 40.126.32.138
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.76
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 184.86.251.28
  • 184.86.251.11
  • 184.86.251.4
  • 184.86.251.5
  • 184.86.251.15
  • 184.86.251.10
  • 184.86.251.9
  • 184.86.251.30
  • 184.86.251.14
whitelisted

Threats

No threats detected
Process
Message
CiscoCollabHost.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
CiscoCollabHost.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
CiscoCollabHost.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
CiscoCollabHost.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
CiscoCollabHost.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.