File name:

MSBuildStructuredLogSetup.exe

Full analysis: https://app.any.run/tasks/864f7689-0d02-4c1d-9f66-4bd35362aa66
Verdict: Malicious activity
Analysis date: November 28, 2023, 10:03:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

83C29A9292D891EF1AB9D018581B6FB8

SHA1:

9F2F6B25AA9654A8BB83394F3BA377AC69AF54D8

SHA256:

39E25EBDD246FB5FAE3B9CD01641AD6E386824E89B3499F1FE39A864CE0BE7D9

SSDEEP:

98304:xJNa/lGD56kDImYo7+3GyezDajvhcOz+0ewic3/mJTY5uErIUEZvcmrZVwyK41uz:qkojOm/ieGVh52

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MSBuildStructuredLogSetup.exe (PID: 2708)
      • Update.exe (PID: 2168)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
    • Process drops legitimate windows executable

      • Update.exe (PID: 2168)
  • INFO

    • Creates files or folders in the user directory

      • Update.exe (PID: 2168)
      • MSBuildStructuredLogSetup.exe (PID: 2708)
    • Checks supported languages

      • MSBuildStructuredLogSetup.exe (PID: 2708)
      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Reads the computer name

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Create files in a temporary directory

      • Update.exe (PID: 2168)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Reads Environment values

      • StructuredLogViewer.exe (PID: 2864)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 580)
    • Application launched itself

      • msedge.exe (PID: 2468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (54.3)
.exe | Win64 Executable (generic) (34.8)
.exe | Win32 Executable (generic) (5.6)
.exe | Generic Win/DOS Executable (2.5)
.exe | DOS Executable Generic (2.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:10 20:14:50+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 107008
InitializedDataSize: 4579328
UninitializedDataSize: -
EntryPoint: 0xa5f9
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.2.100.0
ProductVersionNumber: 2.2.100.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Structured logger and viewer to investigate MSBuild builds
FileVersion: 2.2.100
InternalName: Setup.exe
LegalCopyright: Copyright © 2023 Kirill Osenkov
OriginalFileName: Setup.exe
ProductName: A logger that can be passed to MSBuild to record a detailed log file and a WPF viewer app to view the log files in a tree form.
ProductVersion: 2.2.100
SquirrelAwareVersion: 1
CompanyName: Kirill Osenkov
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
22
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msbuildstructuredlogsetup.exe no specs update.exe no specs structuredlogviewer.exe taskrunner.exe no specs wmpnscfg.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
880"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1424 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3668 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3620 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . C:\Users\admin\AppData\Local\SquirrelTemp\Update.exeMSBuildStructuredLogSetup.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.4.3.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2468"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://github.com/KirillOsenkov/MSBuildStructuredLogC:\Program Files\Microsoft\Edge\Application\msedge.exe
StructuredLogViewer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2708"C:\Users\admin\AppData\Local\Temp\MSBuildStructuredLogSetup.exe" C:\Users\admin\AppData\Local\Temp\MSBuildStructuredLogSetup.exeexplorer.exe
User:
admin
Company:
Kirill Osenkov
Integrity Level:
MEDIUM
Description:
Structured logger and viewer to investigate MSBuild builds
Exit code:
0
Version:
2.2.100
Modules
Images
c:\users\admin\appdata\local\temp\msbuildstructuredlogsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2844"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6b6af598,0x6b6af5a8,0x6b6af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2864"C:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\StructuredLogViewer.exe" --squirrel-firstrunC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\StructuredLogViewer.exe
Update.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
MSBuild Structured Log Viewer
Exit code:
0
Version:
2.2.100.57553
Modules
Images
c:\users\admin\appdata\local\msbuildstructuredlogviewer\app-2.2.100\structuredlogviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
7 596
Read events
7 515
Write events
74
Delete events
7

Modification events

(PID) Process:(2168) Update.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2864) StructuredLogViewer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Update.exe
(PID) Process:(580) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2B907570-1254-4357-8C01-59E3EFB6CF0D}\{0F061EA5-AFB8-4CC8-B1B8-AD542FCDDB08}
Operation:delete keyName:(default)
Value:
(PID) Process:(580) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2B907570-1254-4357-8C01-59E3EFB6CF0D}
Operation:delete keyName:(default)
Value:
(PID) Process:(580) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{B08E24A9-FA0D-479C-8EF2-D2080F7603F4}
Operation:delete keyName:(default)
Value:
Executable files
35
Suspicious files
133
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
2708MSBuildStructuredLogSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\MSBuildStructuredLogViewer-2.2.100-full.nupkgcompressed
MD5:E0C4A2407166E2004E91EEDC793283CF
SHA256:4E2CBC0BC481E2FEBE96B8EADE3505BA351D852072582DFB1EA219BE3CE93A8C
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\Update.exeexecutable
MD5:CF7BB58375F35583DB4FBC0F33DC2A1E
SHA256:235E9AD902DB500B4E063A223354CAA85C826E3E51808C69AB131BE509404A72
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\packages\MSBuildStructuredLogViewer-2.2.100-full.nupkgcompressed
MD5:E0C4A2407166E2004E91EEDC793283CF
SHA256:4E2CBC0BC481E2FEBE96B8EADE3505BA351D852072582DFB1EA219BE3CE93A8C
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\AutomaticGraphLayout.Drawing.dllexecutable
MD5:BA962C1E88ED542D1BD9DAC9C8D95C18
SHA256:4AB7ED50303663EFBA9D872300412BC72506A72B373042E80F473C796275D58E
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\AdonisUI.ClassicTheme.dllexecutable
MD5:5C10377E0D2E489BDEE5C94AA4278439
SHA256:7BF973905E94F80771EFC3EF866DF5B1DE06C0F62A863CEFEDDD328203AA6366
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\DeltaCompressionDotNet.dllexecutable
MD5:3CE9C038499D47BFDFABC197F34E04F8
SHA256:2F2FAEBE394F94EAF7F0FBDC09E43F8370717F5C684B66AB61A7DABB755EF4BF
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\AdonisUI.dllexecutable
MD5:C8EEC087E9B24DEA55C0826446455180
SHA256:5AA8170B4894FE5B4CECB35A507A977192E06E0165A14E0174FB2C6DC612D788
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\DeltaCompressionDotNet.MsDelta.dllexecutable
MD5:F6437EBA2912907A6F13CC18E17239F0
SHA256:7C64414EF3A6E73D3CE5761DC964EB27DA68F70F8B0C04AD62DEE0AA9EAF1BEB
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\DeltaCompressionDotNet.PatchApi.dllexecutable
MD5:7F610F38778BFDF3E86C037A434C48D0
SHA256:DD7FBBC300AA7C1B478E008C769C4D51BE9326EA64B0D347E925BAF55817EA47
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\Microsoft.Build.Locator.dllexecutable
MD5:A1D6CAA63CA5D188D7CA1D9B780E2D0D
SHA256:8F223D6C9436B6F5E9DBF40E51016921400783FEFADF40A1134075EE96FFA4F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
39
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
2864
StructuredLogViewer.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown
3636
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2468
msedge.exe
239.255.255.250:1900
whitelisted
3636
msedge.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
3636
msedge.exe
20.105.95.163:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3636
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.6
  • 140.82.121.5
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
github.com
  • 140.82.121.4
shared
nav-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
github.githubassets.com
  • 185.199.108.154
  • 185.199.110.154
  • 185.199.111.154
  • 185.199.109.154
whitelisted
avatars.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
whitelisted
github-cloud.s3.amazonaws.com
  • 3.5.17.112
  • 3.5.29.116
  • 3.5.25.118
  • 54.231.140.121
  • 52.217.8.52
  • 54.231.234.9
  • 54.231.224.129
  • 52.217.171.57
shared
camo.githubusercontent.com
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.108.133
shared

Threats

No threats detected
No debug info