| File name: | PulseUpgradeHelperInstaller.msi |
| Full analysis: | https://app.any.run/tasks/dc246169-bb2a-4756-a987-c0a63579fe0b |
| Verdict: | Malicious activity |
| Analysis date: | May 05, 2024, 14:34:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: PulseUpgradeHelper 22.04.1803.4839 by Pulse Secure, LLC., Author: Pulse Secure, LLC., Keywords: Installer, Comments: This installer database contains the logic and data required to install PulseUpgradeHelper., Template: Intel;1033, Revision Number: {4428FA02-6A95-454B-84AF-066669DEEFAA}, Create Time/Date: Mon Apr 18 06:30:56 2022, Last Saved Time/Date: Mon Apr 18 06:30:56 2022, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.0.5722), Security: 2 |
| MD5: | F1068A59FE501714980C0B62DA37FABF |
| SHA1: | 7AA842C2844E903322ED9A841B0DED290B1CB767 |
| SHA256: | 2425F1E1185EC5DEAF95B83888D09A8F2F399EFF455CA8722C66519DE6362C62 |
| SSDEEP: | 98304:+P35VPqFeGKezbpJG1FwiMCtoiRfhjNmbMkYtoFBEKkkRfE/y+jDXl/cML0oFDWR:ec3yHcUrben68KK4UbF |
| .msi | | | Microsoft Installer (100) |
|---|
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | PulseUpgradeHelper 22.04.1803.4839 by Pulse Secure, LLC. |
| Author: | Pulse Secure, LLC. |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install PulseUpgradeHelper. |
| Template: | Intel;1033 |
| RevisionNumber: | {4428FA02-6A95-454B-84AF-066669DEEFAA} |
| CreateDate: | 2022:04:18 06:30:56 |
| ModifyDate: | 2022:04:18 06:30:56 |
| Pages: | 200 |
| Words: | 10 |
| Software: | Windows Installer XML Toolset (3.14.0.5722) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1864 | "C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe" -forceReRun: True -puhMSIProdCode: {570B2DA9-460A-44F8-876F-D58E07E8D3D6} | C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe | msiexec.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Pulse Client upgrade helper (for versions with old code-sign certificates) Version: 22.04.1803.4839 Modules
| |||||||||||||||
| 1884 | "C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\AX3F446.exe" | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\AX3F446.exe | — | PANEF34.exe | |||||||||||
User: admin Company: Pulse Secure, LLC Integrity Level: HIGH Version: 2.3.0.0 | |||||||||||||||
| 1928 | "C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PCMF5FC.exe" | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PCMF5FC.exe | PANEF34.exe | ||||||||||||
User: admin Company: Pulse Secure, LLC Integrity Level: HIGH Description: Pulse Secure Component Manager Installer Exit code: 0 Version: 9.1.14.13525 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\AX3F446.exe" | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\AX3F446.exe | PANEF34.exe | ||||||||||||
User: admin Company: Pulse Secure, LLC Integrity Level: HIGH Exit code: 0 Version: 2.3.0.0 Modules
| |||||||||||||||
| 2172 | "C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PCMF5FC.exe" | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PCMF5FC.exe | — | PANEF34.exe | |||||||||||
User: admin Company: Pulse Secure, LLC Integrity Level: HIGH Description: Pulse Secure Component Manager Installer Version: 9.1.14.13525 | |||||||||||||||
| 2240 | "C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe" -forceReRun: True -elevateFor: C:\Users\admin\AppData\Roaming\ | C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe | PulseUpgradeHelper.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Pulse Client upgrade helper (for versions with old code-sign certificates) Exit code: 0 Version: 22.04.1803.4839 Modules
| |||||||||||||||
| 2368 | "C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PANEF34.exe" -forceReRun: True -elevateFor: C:\Users\admin\AppData\Roaming\ -fixMachineWide: True | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\PANEF34.exe | PulseUpgradeHelper.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Pulse Client upgrade helper (for versions with old code-sign certificates) Exit code: 0 Version: 22.04.1803.4839 Modules
| |||||||||||||||
| 3960 | "C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\PulseUpgradeHelperInstaller.msi | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4008 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4052 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000D874E55DF99EDA01A80F0000CC0F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000D874E55DF99EDA01A80F0000CC0F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 75 | |||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000147FB25EF99EDA01A80F0000CC0F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000147FB25EF99EDA01A80F00000C040000E8030000010000000000000000000000299CF54F18D3A5418AB21FB869BEFE3F0000000000000000 | |||
| (PID) Process: | (4052) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007C08BC5EF99EDA01D40F0000DC0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4052) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007C08BC5EF99EDA01D40F0000F8070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4052) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007C08BC5EF99EDA01D40F0000E00F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4052) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D66ABE5EF99EDA01D40F000054070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4008 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | — | |
MD5:— | SHA256:— | |||
| 4008 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 4008 | msiexec.exe | C:\Windows\Installer\10613c.msi | — | |
MD5:— | SHA256:— | |||
| 4008 | msiexec.exe | C:\Windows\Installer\10613f.msi | — | |
MD5:— | SHA256:— | |||
| 4008 | msiexec.exe | C:\Windows\Installer\MSI6860.tmp | binary | |
MD5:2826AE585535B1BCD7198868B82AF33A | SHA256:D23BDA37B464A49311625A616F2DD2FC69119FFEBF1DC46783512CCECE00A58A | |||
| 4008 | msiexec.exe | C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe | executable | |
MD5:D9156678CC814F7D5EC979DF548F57F4 | SHA256:F6FF36E246A91DAEDEB841F0F721B8B3246F7631D9641A804906E8C92F84F95E | |||
| 4008 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF74C56BBAD3436765.TMP | binary | |
MD5:4D18EBF4AC2BFCD12007656CBF5FAFD3 | SHA256:0B148EE14EB26DDC08198FFBBD4E340DF9079B4BFDDC0567623E9EA6901CAEE7 | |||
| 4008 | msiexec.exe | C:\Config.Msi\10613e.rbs | binary | |
MD5:0568B0E86E9C88C97F51E5502CA81810 | SHA256:E643B77D180CBCCE1213ADD16E61D43B6B8D1839B713DB2358C5F73D2C90A16E | |||
| 2240 | PulseUpgradeHelper.exe | C:\Users\Public\Pulse Secure\Logging\PulseSecure_KB44781_2240.log | text | |
MD5:1734F38CE95482CE4604F272547CE98E | SHA256:B4C003C31287B10833C1D9B3F1177C12DF199FCF11675B572B1F2BAFB6268962 | |||
| 2368 | PANEF34.exe | C:\Program Files\PulseSecure\PulseUpgradeHelper\Temp\AX3F446.exe | executable | |
MD5:518507BDB16C2A5F5AF104CCBEECF6D4 | SHA256:B177705B25B8C0210C6A87CE49D8CA493518F6DE706EAD63745C6EFD816D2432 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
PulseUpgradeHelper.exe | ===PulseSecure Panacea Launched at 1076281 ticks===
|
PulseUpgradeHelper.exe | >>> |
PulseUpgradeHelper.exe | >>> |
PulseUpgradeHelper.exe | PerUserCompMode::UnInstall |
PulseUpgradeHelper.exe |
Running from: C:\Users\admin\AppData\Local\Pulse Secure\PulseUpgradeHelper\PulseUpgradeHelper.exe
ArgsParseResult: 0
64BitOS: False
IsUserAdmin: False
IsUserLocalSystem: False
-msiInteractive: False
-forceReRun: True
-fixMachineWide: False
-puhMSIProdCode: {570B2DA9-460A-44F8-876F-D58E07E8D3D6}
ActiveXDetected: 0
ActiveXReplaced: 0
IEProcessCount: 0
ProcessesKilled: 0
AppsUnInstalled: 0
AppsInstalled: 0
|
PulseUpgradeHelper.exe | <<< ; Calculated Process Integrity Level for Process [1864] is 2 |
PulseUpgradeHelper.exe | BUILDTS: 2022-04-18 03:48:39 UTC |
PulseUpgradeHelper.exe | DEVIATION: YnVnZml4LVBSUy00MDgxMDYtVW5hYmxlLXRvLWluc3RhbGwtUHVsc2UtVXBncmFkZS1IZWxwZXItdG9vbC1vbmUtYS1XaW5kb3dzLW1hY2hpbmUtaGF2aW5nLTItYnl0ZS1jaGFyYWN0ZXItbmFtZQ== |
PulseUpgradeHelper.exe | BUILDCONFIG: Release |
PulseUpgradeHelper.exe | >>> |