| File name: | VMware Workstation Pro - CHIP Installer _5rgfv.exe |
| Full analysis: | https://app.any.run/tasks/a4de4548-8b15-4988-835e-8e5af6c4d495 |
| Verdict: | Malicious activity |
| Analysis date: | November 15, 2024, 19:40:18 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 11 sections |
| MD5: | F5980F17F44DA870072C5CE396EB01BF |
| SHA1: | 22CE208ACB16875CDD9D42A794557A56068220C2 |
| SHA256: | 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B |
| SSDEEP: | 49152:xhx7dxx15qe01xtgx41J/StY/yuiYWLmgpaRZkDuZdTNACtn:JV1JALgvz4ACtn |
| .exe | | | Generic Win/DOS Executable (49.6) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.5) |
| .vxd | | | VXD Driver (0.7) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2022:04:16 09:34:08+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 8 |
| CodeSize: | 4237824 |
| InitializedDataSize: | 1083392 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x3f8020 |
| OSVersion: | 5.2 |
| ImageVersion: | 5.2 |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.100.6 |
| ProductVersionNumber: | 1.0.100.6 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | CHIP Digital GmbH |
| FileDescription: | CHIP Secured Installer |
| FileVersion: | 1.0.100.6 |
| LegalCopyright: | Copyright 2021 CHIP Digital GmbH |
| ProductName: | LgInstall |
| ProductVersion: | 1.0.100.6 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | net start vmware-view-usbd | C:\Windows\SysWOW64\net.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 624 | "C:\WINDOWS\Temp\{24B35C87-FFBF-4D61-914C-E6ECABAE77DD}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{0B8107A2-007A-4A6D-95E1-C9C507CA6233} {FB151453-BFB5-4D00-B9DF-8A32654528A1} 6992 | C:\Windows\Temp\{24B35C87-FFBF-4D61-914C-E6ECABAE77DD}\.be\VC_redist.x64.exe | — | vcredist_x64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 Exit code: 0 Version: 14.36.32532.0 Modules
| |||||||||||||||
| 696 | "C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet9 | C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: VMware, Inc. Integrity Level: SYSTEM Description: VMware network install library executable Exit code: 4 Version: 17.6.1 build-24319023 Modules
| |||||||||||||||
| 700 | C:\WINDOWS\SysWOW64\vmnetdhcp.exe | C:\Windows\SysWOW64\vmnetdhcp.exe | services.exe | ||||||||||||
User: SYSTEM Company: VMware, Inc. Integrity Level: SYSTEM Description: VMware VMnet DHCP service Version: 17.6.1 build-24319023 Modules
| |||||||||||||||
| 744 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 824 | "C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet5 | C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: VMware, Inc. Integrity Level: SYSTEM Description: VMware network install library executable Exit code: 4 Version: 17.6.1 build-24319023 Modules
| |||||||||||||||
| 848 | "C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe" -- remove adapter vmnet1 | C:\Program Files (x86)\VMware\VMware Workstation\vnetlib64.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: VMware, Inc. Integrity Level: SYSTEM Description: VMware network install library executable Exit code: 4 Version: 17.6.1 build-24319023 Modules
| |||||||||||||||
| 1376 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:12 | C:\Windows\System32\SrTasks.exe | — | dllhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1376 | "C:\Program Files (x86)\Common Files\VMware\USB\DriverCache\vnetlib64.exe" -- install vmusb Win8 | C:\Program Files (x86)\Common Files\VMware\USB\DriverCache\vnetlib64.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: VMware, Inc. Integrity Level: SYSTEM Description: VMware network install library executable Exit code: 12 Version: e.x.p build-24127552 Modules
| |||||||||||||||
| 1524 | DrvInst.exe "4" "1" "C:\Program Files (x86)\VMware\VMware Workstation\netadapter.inf" "9" "4d396c847" "00000000000001FC" "WinSta0\Default" "0000000000000204" "208" "C:\Program Files (x86)\VMware\VMware Workstation" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5828) VMware Workstation Pro - CHIP Installer _5rgfv.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (5828) VMware Workstation Pro - CHIP Installer _5rgfv.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (5828) VMware Workstation Pro - CHIP Installer _5rgfv.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 4800000000000000914F8C6E9637DB01040C0000DC1B0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (5948) VC_redist.x86.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000914F8C6E9637DB013C1700000C170000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000A130C36E9637DB01040C0000DC1B0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000A130C36E9637DB01040C0000DC1B0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 48000000000000003C94C56E9637DB01040C0000DC1B0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 480000000000000066ABCC6E9637DB01040C0000DC1B0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3076) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 11 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\VMware-workstation-17_6_1-24319023_exe.parts | — | |
MD5:— | SHA256:— | |||
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\VMware-workstation-17.6.1-24319023.exe | — | |
MD5:— | SHA256:— | |||
| 5624 | VMware-workstation-17.6.1-24319023.exe | C:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\VMwareWorkstation.msi | — | |
MD5:— | SHA256:— | |||
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\30924F1897AA8F5452EA0D0C29524135 | binary | |
MD5:EEBC190A0326B70C037039ED8D9ACAAD | SHA256:8353C04FEB98C9DE8E88C393EF0C2040481305AC152DAF663D4C5C238D78C04D | |||
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:3DFCA46E00FFA4795C72A41375F159D3 | SHA256:DCBA1A505396539BAC40A7253C9F5DCCF06CBB79957E21D56305E1FC3AF5F40E | |||
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8181B549A398A45D986EDB81C19830 | binary | |
MD5:FA60C5CA96E3B2AE4F3C8B84D9F71DF5 | SHA256:534CE601F6C6AC7AF4C1D2D584F00DE2836C9C7F7B1BA2842A8EF0FFE9112B7C | |||
| 5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\PPD_Bit-Driver-Updater_1[1].png | image | |
MD5:4FA788C006BA2C165DFB15A20DD408D8 | SHA256:AA0A1A9E282167A2A8BA84CED85760DF64311B6A2F60BF44E7BB17AAD3780C95 | |||
| 5624 | VMware-workstation-17.6.1-24319023.exe | C:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\vcredist_x64.exe | executable | |
MD5:077F0ABDC2A3881D5C6C774AF821F787 | SHA256:917C37D816488545B70AFFD77D6E486E4DD27E2ECE63F6BBAAF486B178B2B888 | |||
| 5624 | VMware-workstation-17.6.1-24319023.exe | C:\Users\admin\AppData\Local\Temp\vminst.log | text | |
MD5:C99DE7CC24CBAACF75BC09B9129CCD57 | SHA256:12A71B6E9F4BF0C63DB9B6D7132817B4DE2E86704B11EE5241617267E25BCAAB | |||
| 4692 | vcredist_x86.exe | C:\Windows\Temp\{C6DA32F8-B8FA-4690-B49D-2655409213BE}\.ba\1028\thm.wxl | xml | |
MD5:472ABBEDCBAD24DBA5B5F5E8D02C340F | SHA256:8E2E660DFB66CB453E17F1B6991799678B1C8B350A55F9EBE2BA0028018A15AD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.131:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2776 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | GET | 200 | 116.203.169.156:80 | http://static.chip-secured-download.de/gfx/progress/BitGuardian/PPD_Bit-Driver-Updater_1.png | unknown | — | — | unknown |
5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | GET | 200 | 95.101.54.211:80 | http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgSN4UViCPaq6i9dycwvhsE0XQ%3D%3D | unknown | — | — | whitelisted |
632 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | GET | 200 | 95.101.54.99:80 | http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgTxYwFIWmiIoVMCsA0oT%2B6h3g%3D%3D | unknown | — | — | whitelisted |
2936 | svchost.exe | GET | 304 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
632 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6944 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1588 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4360 | SearchApp.exe | 2.23.209.133:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5828 | VMware Workstation Pro - CHIP Installer _5rgfv.exe | 83.125.106.237:443 | chip-cluster.de | 3U TELECOM GmbH | DE | unknown |
2776 | svchost.exe | 20.190.160.14:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2776 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
chip-cluster.de |
| unknown |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
VMware-workstation-17.6.1-24319023.exe | Start Pre-load DLLs.
|
VMware-workstation-17.6.1-24319023.exe | Win32U_GetFileAttributes: GetFileAttributesExW("C:\Users\admin\AppData\Local\Temp\VMware-workstation-17_6_1-24319023_exe_911152024740466162167432\1033.bmp", ...) failed, error: 2
|
VMware-workstation-17.6.1-24319023.exe | Win32U_GetFileAttributes: GetFileAttributesExW("C:\Users\admin\AppData\Local\Temp\{6D4305A8-0DE1-4AB9-893B-D4913D7181BE}~setup\", ...) failed, error: 2
|
vmnat.exe | CodeSet_Init: no ICU
|
vmnetdhcp.exe | CodeSet_Init: no ICU
|
vmware-usbarbitrator64.exe | CodeSet_Init: no ICU
|
vmware.exe | VMListReg::Listener - Initial registry scan completed. |