File name:

spacedesk_driver_Win_10_64_v2140.msi

Full analysis: https://app.any.run/tasks/56e06cf5-e213-4dfb-8e28-46021f337268
Verdict: Malicious activity
Analysis date: March 28, 2025, 18:09:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: spacedesk 2.1.40 Driver Installer, Author: datronicsoft Inc., Keywords: Installer, Comments: Windows Network Display Monitor Software, Template: x64;1033, Revision Number: {269F2A76-5CCF-43EF-8929-5F7D33E8ACCF}, Create Time/Date: Wed Mar 19 01:25:46 2025, Last Saved Time/Date: Wed Mar 19 01:25:46 2025, Number of Pages: 500, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

FBA6B83A5284AFE406A4346C988EAEDA

SHA1:

ED1920BC9EE707C123816C0669FF989EB2D6031F

SHA256:

1F5A374FD43526E0A832B133868440A9049638514578A7EFDA67836D702F5733

SSDEEP:

98304:hNBk1YjzJHN7RjUldca1lmiS6KM4GKzFGZplv9oK7eJSdnQpOK9s+WCtRqovHdkJ:inp+t4Ui/Kh9cQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 6044)
      • spacedeskService.exe (PID: 6108)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7608)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 7608)
      • MSI5E8C.tmp (PID: 8076)
      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 632)
      • drvinst.exe (PID: 6080)
      • MSI644B.tmp (PID: 2240)
      • drvinst.exe (PID: 5968)
      • MSI68F1.tmp (PID: 7204)
      • MSI6AD7.tmp (PID: 4200)
      • drvinst.exe (PID: 2284)
      • MSI6C7E.tmp (PID: 2316)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 6728)
    • Executable content was dropped or overwritten

      • MSI5E8C.tmp (PID: 8076)
      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 632)
      • MSI644B.tmp (PID: 2240)
      • drvinst.exe (PID: 6080)
      • MSI6594.tmp (PID: 2552)
      • drvinst.exe (PID: 2040)
      • MSI66FC.tmp (PID: 4488)
      • drvinst.exe (PID: 7816)
      • MSI68F1.tmp (PID: 7204)
      • drvinst.exe (PID: 5968)
      • MSI6AD7.tmp (PID: 4200)
      • drvinst.exe (PID: 2284)
      • MSI6C7E.tmp (PID: 2316)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 6728)
    • Creates files in the driver directory

      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 632)
      • drvinst.exe (PID: 6080)
      • drvinst.exe (PID: 2040)
      • drvinst.exe (PID: 7816)
      • drvinst.exe (PID: 5968)
      • drvinst.exe (PID: 2284)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 6728)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 5156)
      • drvinst.exe (PID: 6728)
    • Likely accesses (executes) a file from the Public directory

      • powershell.exe (PID: 812)
      • powershell.exe (PID: 7344)
      • powershell.exe (PID: 7220)
    • Reads security settings of Internet Explorer

      • spacedeskConsole.exe (PID: 5164)
    • Starts POWERSHELL.EXE for commands execution

      • spacedeskConsole.exe (PID: 5164)
  • INFO

    • Checks proxy server information

      • msiexec.exe (PID: 7480)
      • spacedeskConsole.exe (PID: 5164)
      • slui.exe (PID: 4008)
    • Reads the computer name

      • msiexec.exe (PID: 7608)
      • msiexec.exe (PID: 7400)
      • MSI5E8C.tmp (PID: 8076)
      • drvinst.exe (PID: 7276)
      • MSI5D32.tmp (PID: 7896)
      • drvinst.exe (PID: 5156)
      • MSI6302.tmp (PID: 3676)
      • drvinst.exe (PID: 632)
      • MSI644B.tmp (PID: 2240)
      • MSI6594.tmp (PID: 2552)
      • drvinst.exe (PID: 2040)
      • MSI66FC.tmp (PID: 4488)
      • drvinst.exe (PID: 6080)
      • drvinst.exe (PID: 7816)
      • MSI68F1.tmp (PID: 7204)
      • drvinst.exe (PID: 5968)
      • MSI6AD7.tmp (PID: 4200)
      • MSI6C7E.tmp (PID: 2316)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 2284)
      • spacedeskService.exe (PID: 6108)
      • MSI6E44.tmp (PID: 3176)
      • spacedeskServiceTray.exe (PID: 6476)
      • MSI6F00.tmp (PID: 4108)
      • MSI7115.tmp (PID: 7596)
      • drvinst.exe (PID: 6728)
      • spacedeskConsole.exe (PID: 5164)
    • Checks supported languages

      • msiexec.exe (PID: 7608)
      • msiexec.exe (PID: 7400)
      • MSI5CE3.tmp (PID: 8112)
      • MSI5E5C.tmp (PID: 7860)
      • MSI5D32.tmp (PID: 7896)
      • MSI5E8C.tmp (PID: 8076)
      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 5156)
      • drvinst.exe (PID: 632)
      • MSI644B.tmp (PID: 2240)
      • drvinst.exe (PID: 6080)
      • MSI6302.tmp (PID: 3676)
      • drvinst.exe (PID: 2040)
      • MSI66FC.tmp (PID: 4488)
      • drvinst.exe (PID: 7816)
      • MSI6594.tmp (PID: 2552)
      • drvinst.exe (PID: 5968)
      • MSI68F1.tmp (PID: 7204)
      • MSI6AD7.tmp (PID: 4200)
      • drvinst.exe (PID: 2284)
      • MSI6C7E.tmp (PID: 2316)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 6728)
      • MSI6F00.tmp (PID: 4108)
      • spacedeskService.exe (PID: 6108)
      • MSI7115.tmp (PID: 7596)
      • spacedeskServiceTray.exe (PID: 6476)
      • MSI6FDC.tmp (PID: 1760)
      • MSI6E44.tmp (PID: 3176)
      • spacedeskConsole.exe (PID: 5164)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 7480)
    • Reads the software policy settings

      • msiexec.exe (PID: 7480)
      • msiexec.exe (PID: 7608)
      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 632)
      • drvinst.exe (PID: 6080)
      • drvinst.exe (PID: 2040)
      • drvinst.exe (PID: 5968)
      • drvinst.exe (PID: 7816)
      • drvinst.exe (PID: 2284)
      • drvinst.exe (PID: 7228)
      • slui.exe (PID: 7628)
      • spacedeskConsole.exe (PID: 5164)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7480)
    • An automatically generated document

      • msiexec.exe (PID: 7480)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7480)
      • msiexec.exe (PID: 7608)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 7608)
      • drvinst.exe (PID: 7276)
      • drvinst.exe (PID: 632)
      • drvinst.exe (PID: 2040)
      • drvinst.exe (PID: 6080)
      • drvinst.exe (PID: 7816)
      • drvinst.exe (PID: 5968)
      • drvinst.exe (PID: 2284)
      • drvinst.exe (PID: 7228)
      • spacedeskConsole.exe (PID: 5164)
    • Manages system restore points

      • SrTasks.exe (PID: 7980)
    • The sample compiled with english language support

      • msiexec.exe (PID: 7608)
      • drvinst.exe (PID: 7276)
      • MSI5E8C.tmp (PID: 8076)
      • MSI6594.tmp (PID: 2552)
      • drvinst.exe (PID: 2040)
      • MSI66FC.tmp (PID: 4488)
      • drvinst.exe (PID: 7816)
      • MSI6C7E.tmp (PID: 2316)
      • drvinst.exe (PID: 7228)
      • drvinst.exe (PID: 6728)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 7608)
    • Create files in a temporary directory

      • MSI6594.tmp (PID: 2552)
      • MSI66FC.tmp (PID: 4488)
      • MSI68F1.tmp (PID: 7204)
      • MSI6AD7.tmp (PID: 4200)
      • MSI6C7E.tmp (PID: 2316)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 7608)
    • Manual execution by a user

      • spacedeskConsole.exe (PID: 5164)
    • Disables trace logs

      • spacedeskConsole.exe (PID: 5164)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7220)
    • Reads Environment values

      • spacedeskConsole.exe (PID: 5164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: spacedesk 2.1.40 Driver Installer
Author: datronicsoft Inc.
Keywords: Installer
Comments: Windows Network Display Monitor Software
Template: x64;1033
RevisionNumber: {269F2A76-5CCF-43EF-8929-5F7D33E8ACCF}
CreateDate: 2025:03:19 01:25:46
ModifyDate: 2025:03:19 01:25:46
Pages: 500
Words: 2
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
186
Monitored processes
43
Malicious processes
9
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe sppextcomobj.exe no specs msiexec.exe slui.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msi5ce3.tmp no specs msi5d32.tmp no specs msi5e5c.tmp no specs msi5e8c.tmp drvinst.exe drvinst.exe no specs msi6302.tmp no specs drvinst.exe msi644b.tmp drvinst.exe msi6594.tmp drvinst.exe msi66fc.tmp drvinst.exe msi68f1.tmp drvinst.exe msi6ad7.tmp drvinst.exe msi6c7e.tmp drvinst.exe drvinst.exe msi6e44.tmp no specs spacedeskservice.exe no specs spacedeskservicetray.exe no specs msi6f00.tmp no specs msi6fdc.tmp no specs msi7115.tmp no specs slui.exe spacedeskconsole.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632DrvInst.exe "4" "1" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\spacedeskDriverAndroidUsb.inf" "9" "4c4c2d17b" "000000000000022C" "WinSta0\Default" "0000000000000230" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
668\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
812"powershell.exe" /c Get-AppXPackage -Name AppleInc.iTunes > "C:\Users\Public\spAppxpackageinstalled.txt"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exespacedeskConsole.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
872\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\WINDOWS\Installer\MSI6FDC.tmp" -spacedeskProgramFilesDelete,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSI6FDC.tmpmsiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.40
Modules
Images
c:\windows\installer\msi6fdc.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2040DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2e6441fb-e956-cf4e-b4d3-266d8cbd1b9c}\spacedeskDriverHid.inf" "9" "4427793e7" "00000000000001EC" "WinSta0\Default" "0000000000000220" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2240"C:\WINDOWS\Installer\MSI644B.tmp" -install_ktm,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSI644B.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.40
Modules
Images
c:\windows\installer\msi644b.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2284DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{75763ad1-b812-4145-81c2-df7a76848f5a}\spacedeskVideoCapture.inf" "9" "434d37797" "0000000000000240" "WinSta0\Default" "00000000000001EC" "208" "C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2316"C:\WINDOWS\Installer\MSI6C7E.tmp" -install_bus,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSI6C7E.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.40
Modules
Images
c:\windows\installer\msi6c7e.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2552"C:\WINDOWS\Installer\MSI6594.tmp" -install_hid,C:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\C:\Windows\Installer\MSI6594.tmp
msiexec.exe
User:
admin
Company:
datronicsoft
Integrity Level:
MEDIUM
Description:
spacedesk Setup Custom Action
Exit code:
0
Version:
0.2.1.40
Modules
Images
c:\windows\installer\msi6594.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
56 462
Read events
56 079
Write events
349
Delete events
34

Modification events

(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000001B65BE960CA0DB01B81D0000D4150000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000AB14BC960CA0DB01B81D0000D4150000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000008D2A01970CA0DB01B81D0000D4150000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000A28E03970CA0DB01B81D0000D4150000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000A173FC960CA0DB01B81D0000D4150000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000A173FC960CA0DB01B81D0000D4150000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(7608) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6044) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000037F381970CA0DB019C17000088140000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6044) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000037F381970CA0DB019C170000D81A0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6044) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000037F381970CA0DB019C17000028150000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
66
Suspicious files
113
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
7608msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
7608msiexec.exeC:\Windows\Installer\115783.msi
MD5:
SHA256:
7608msiexec.exeC:\Windows\Installer\MSI5A71.tmp
MD5:
SHA256:
7480msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:AC2C9610C02BD2101086468D9F2ED862
SHA256:88E8406C40FC31DA505A278EB7E4DFE84CD1350A02B70DA518440D1EFF1C356E
7480msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_74F67001B3C2D533D99B6A2860970A04binary
MD5:FAED34C17D838C5357AAE4DBC9380992
SHA256:99C604337A7F1D65D574D96BE1D49DBB24AA5C59A0F6E8354B7F9F182F24581F
7608msiexec.exeC:\Program Files\datronicsoft\spacedesk\spacedeskTemporarySetupFiles\spacedeskdisplay.infbinary
MD5:EA10C31E8F6A1C41AC900593CBECD855
SHA256:031FA5DC36E8218D44CE8C589AA0D49AF6345534E800822AEB3FAC92ABA87A22
7480msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:7FEA803E1F6CAB3833F2E77ADB033CA9
SHA256:7A404A7A356004FDD3CACADE6CC3BAB350D49A4EBDC411526A936E8B8CF2D887
7608msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:7550E60CD516E3F6451FC163213FF6B1
SHA256:DFAE3327A0A2F4FB96323C52830D0213A86D06D6C0926E21E91221A718658927
7480msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_74F67001B3C2D533D99B6A2860970A04binary
MD5:93A2E2A6388DFDC2B00180661048728E
SHA256:907EE428C3C401F719AEE08D607DACF316EFB9AA2363E56677FA14A902D4FB62
7480msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI52D.tmpexecutable
MD5:CFBB8568BD3711A97E6124C56FCFA8D9
SHA256:7F47D98AB25CFEA9B3A2E898C3376CC9BA1CD893B4948B0C27CAA530FD0E34CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
44
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7480
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4bLnp0JeaKiM0Z462JHJc%3D
unknown
whitelisted
7480
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
7480
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7808
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2088
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2088
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7480
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
20.198.162.76:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
7808
backgroundTaskHost.exe
20.74.47.205:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7808
backgroundTaskHost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
google.com
  • 142.250.186.174
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 20.198.162.76
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.4
  • 40.126.31.128
  • 20.190.159.64
  • 40.126.31.0
  • 20.190.159.130
  • 40.126.31.130
  • 20.190.159.129
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 23.209.214.100
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info