File name:

PulseSecureAppLauncher.msi

Full analysis: https://app.any.run/tasks/39ea6bb5-0a83-4440-99ab-c53b7b71d901
Verdict: Malicious activity
Analysis date: July 18, 2025, 08:33:57
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Pulse Application Launcher, Author: Ivanti, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Pulse Application Launcher., Template: Intel;1033, Revision Number: {6AA15FA6-A504-4D12-8AB0-2C320EEE9B08}, Create Time/Date: Thu Dec 28 10:03:24 2023, Last Saved Time/Date: Thu Dec 28 10:03:24 2023, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.0.4118), Security: 2
MD5:

9FADC49EA06140E22DD3025384D8DDE0

SHA1:

A0C005E2E4DB3F84F9E0404C6FFBC1FFD264E652

SHA256:

2390077EB538A20BBE188B52C7189B7D8E62CED9C44A6E8FA11A65E2CAA80226

SSDEEP:

98304:dn1unZmT1TaT1I5KKB2nODZLN5qsSUelSbMwvuJyzro3fDklOoRl/LXLErfLuO57:y5LSQCmADY9/J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 7008)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6264)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6264)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6264)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 5552)
    • The sample compiled with english language support

      • msiexec.exe (PID: 5552)
      • msiexec.exe (PID: 6264)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 5552)
      • msiexec.exe (PID: 6264)
      • PulseApplicationLauncher.exe (PID: 6892)
    • Checks proxy server information

      • msiexec.exe (PID: 5552)
    • Checks supported languages

      • msiexec.exe (PID: 6264)
      • msiexec.exe (PID: 1880)
      • PulseApplicationLauncher.exe (PID: 6892)
    • Reads the software policy settings

      • msiexec.exe (PID: 5552)
      • msiexec.exe (PID: 6264)
    • Reads the computer name

      • msiexec.exe (PID: 6264)
      • msiexec.exe (PID: 1880)
      • PulseApplicationLauncher.exe (PID: 6892)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6264)
    • Manages system restore points

      • SrTasks.exe (PID: 2312)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6264)
      • PulseApplicationLauncher.exe (PID: 6892)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Pulse Application Launcher
Author: Ivanti, Inc.
Keywords: Installer
Comments: This installer database contains the logic and data required to install Pulse Application Launcher.
Template: Intel;1033
RevisionNumber: {6AA15FA6-A504-4D12-8AB0-2C320EEE9B08}
CreateDate: 2023:12:28 10:03:24
ModifyDate: 2023:12:28 10:03:24
Pages: 300
Words: 10
Software: Windows Installer XML Toolset (3.14.0.4118)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs pulseapplicationlauncher.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1880C:\Windows\syswow64\MsiExec.exe -Embedding B764634A74F3A709ECDC63847437CBC0C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2312C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4820\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5552"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\PulseSecureAppLauncher.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6264C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6408C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6892"C:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exe" PSALInstallFinishedC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\PulseApplicationLauncher.exemsiexec.exe
User:
admin
Company:
Ivanti, Inc.
Integrity Level:
MEDIUM
Description:
Pulse Secure Application Launcher
Exit code:
0
Version:
22, 7, 1, 28369
Modules
Images
c:\users\admin\appdata\roaming\pulse secure\psal\pulseapplicationlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7008C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 834
Read events
9 548
Write events
268
Delete events
18

Modification events

(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000BA4AA7B8BEF7DB0178180000DC1A0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000BA4AA7B8BEF7DB0178180000DC1A0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000010AFC8B8BEF7DB0178180000DC1A0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000003600CBB8BEF7DB0178180000DC1A0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000003600CBB8BEF7DB0178180000DC1A0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000003466CDB8BEF7DB0178180000DC1A0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000BB9A06B9BEF7DB0178180000DC1A0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6264) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000098FE08B9BEF7DB0178180000F8020000E80300000100000000000000000000009D801D6B77A1344B9C09D303F6A881AA00000000000000000000000000000000
(PID) Process:(7008) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
Executable files
52
Suspicious files
24
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
6264msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6264msiexec.exeC:\Windows\Installer\18f49c.msi
MD5:
SHA256:
5552msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\42B9A473B4DAF01285A36B4D3C7B1662_178C086B699FD6C56B804AF3EF759CB5binary
MD5:94B7EB366AC898432572759446D51D47
SHA256:39E86701D2CEE2EF6F93A9DB9D7F42A5C67AD83D2FF0C2CAC0D41090D77508C6
5552msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\66AE3BFDF94A732B262342AD2154B86E_6F051139928C549506C1CA842E999B7Fbinary
MD5:16299AA20E6BD848639EDC998E50F829
SHA256:7574C4ADC324AE6A63A3B5528F2170D8AC92DE5FBE4C818383013BB08EB2F2F9
5552msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66AE3BFDF94A732B262342AD2154B86E_6F051139928C549506C1CA842E999B7Fbinary
MD5:D03CF284BD4CCF70F3D7F54A5CE0EE4D
SHA256:99A9AEE609D47B6242A856BFEECAE88E104F8931BF7478085E8277953F54E9DC
6264msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:F55CA8CE44DF56FD6EB3E5BD3F779D9B
SHA256:5EEBF4C25807D7DBBB1E99D2A226F005998D4F7491F1785F8F472C459C97F14A
6264msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{6b1d809d-a177-4b34-9c09-d303f6a881aa}_OnDiskSnapshotPropbinary
MD5:E8BB39991AFDFD7385065065AE6514A5
SHA256:443EE601367F6464F2FBB6D11C409227B8AF7488E5494E6EE18748D6C52165ED
6264msiexec.exeC:\Windows\Temp\~DF7DE2F10A22C158FB.TMPbinary
MD5:F55CA8CE44DF56FD6EB3E5BD3F779D9B
SHA256:5EEBF4C25807D7DBBB1E99D2A226F005998D4F7491F1785F8F472C459C97F14A
6264msiexec.exeC:\Users\admin\AppData\Roaming\Pulse Secure\PSAL\dsOpenSSL.dllexecutable
MD5:13AA4DB710A0CC2153F6ABD57A53F70C
SHA256:1A7A7784A0D487B169158321D2045E5A9C58F51E7D4B7BF2503D93D611D5A029
6264msiexec.exeC:\Windows\Installer\MSIF5E4.tmpexecutable
MD5:E05884F57BC8BC8E131C2B0E50CEDEF0
SHA256:7548A0F20CB0AE214DA3F0A4D3F21A59C6F50CE9F2E5BD666A471D6BB70BE74C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
28
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5552
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
5552
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAPEpQvvR5yitJDAp%2BSvuUc%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3872
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3852
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3852
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1636
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5552
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3872
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3872
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.138
  • 40.126.32.140
  • 20.190.160.65
  • 20.190.160.67
  • 20.190.160.66
  • 20.190.160.130
  • 20.190.160.17
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
self.events.data.microsoft.com
  • 20.42.73.30
whitelisted

Threats

No threats detected
No debug info