File name:

MSBuildStructuredLogSetup.exe

Full analysis: https://app.any.run/tasks/864f7689-0d02-4c1d-9f66-4bd35362aa66
Verdict: Malicious activity
Analysis date: November 28, 2023, 10:03:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

83C29A9292D891EF1AB9D018581B6FB8

SHA1:

9F2F6B25AA9654A8BB83394F3BA377AC69AF54D8

SHA256:

39E25EBDD246FB5FAE3B9CD01641AD6E386824E89B3499F1FE39A864CE0BE7D9

SSDEEP:

98304:xJNa/lGD56kDImYo7+3GyezDajvhcOz+0ewic3/mJTY5uErIUEZvcmrZVwyK41uz:qkojOm/ieGVh52

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MSBuildStructuredLogSetup.exe (PID: 2708)
      • Update.exe (PID: 2168)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Update.exe (PID: 2168)
    • Reads the Internet Settings

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
  • INFO

    • Checks supported languages

      • MSBuildStructuredLogSetup.exe (PID: 2708)
      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Reads the computer name

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Creates files or folders in the user directory

      • MSBuildStructuredLogSetup.exe (PID: 2708)
      • Update.exe (PID: 2168)
    • Create files in a temporary directory

      • Update.exe (PID: 2168)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 2168)
      • StructuredLogViewer.exe (PID: 2864)
      • TaskRunner.exe (PID: 3352)
      • wmpnscfg.exe (PID: 580)
    • Reads Environment values

      • StructuredLogViewer.exe (PID: 2864)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 580)
    • Application launched itself

      • msedge.exe (PID: 2468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (54.3)
.exe | Win64 Executable (generic) (34.8)
.exe | Win32 Executable (generic) (5.6)
.exe | Generic Win/DOS Executable (2.5)
.exe | DOS Executable Generic (2.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:10 20:14:50+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 107008
InitializedDataSize: 4579328
UninitializedDataSize: -
EntryPoint: 0xa5f9
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.2.100.0
ProductVersionNumber: 2.2.100.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Structured logger and viewer to investigate MSBuild builds
FileVersion: 2.2.100
InternalName: Setup.exe
LegalCopyright: Copyright © 2023 Kirill Osenkov
OriginalFileName: Setup.exe
ProductName: A logger that can be passed to MSBuild to record a detailed log file and a WPF viewer app to view the log files in a tree form.
ProductVersion: 2.2.100
SquirrelAwareVersion: 1
CompanyName: Kirill Osenkov
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
22
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msbuildstructuredlogsetup.exe no specs update.exe no specs structuredlogviewer.exe taskrunner.exe no specs wmpnscfg.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
880"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1424 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1248"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3668 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3620 --field-trial-handle=1272,i,16164359055615342768,1118958441637203578,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . C:\Users\admin\AppData\Local\SquirrelTemp\Update.exeMSBuildStructuredLogSetup.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.4.3.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2468"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://github.com/KirillOsenkov/MSBuildStructuredLogC:\Program Files\Microsoft\Edge\Application\msedge.exe
StructuredLogViewer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2708"C:\Users\admin\AppData\Local\Temp\MSBuildStructuredLogSetup.exe" C:\Users\admin\AppData\Local\Temp\MSBuildStructuredLogSetup.exeexplorer.exe
User:
admin
Company:
Kirill Osenkov
Integrity Level:
MEDIUM
Description:
Structured logger and viewer to investigate MSBuild builds
Exit code:
0
Version:
2.2.100
Modules
Images
c:\users\admin\appdata\local\temp\msbuildstructuredlogsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2844"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6b6af598,0x6b6af5a8,0x6b6af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2864"C:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\StructuredLogViewer.exe" --squirrel-firstrunC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\StructuredLogViewer.exe
Update.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
MSBuild Structured Log Viewer
Exit code:
0
Version:
2.2.100.57553
Modules
Images
c:\users\admin\appdata\local\msbuildstructuredlogviewer\app-2.2.100\structuredlogviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
7 596
Read events
7 515
Write events
74
Delete events
7

Modification events

(PID) Process:(2168) Update.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2168) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2864) StructuredLogViewer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Update.exe
(PID) Process:(580) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2B907570-1254-4357-8C01-59E3EFB6CF0D}\{0F061EA5-AFB8-4CC8-B1B8-AD542FCDDB08}
Operation:delete keyName:(default)
Value:
(PID) Process:(580) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2B907570-1254-4357-8C01-59E3EFB6CF0D}
Operation:delete keyName:(default)
Value:
(PID) Process:(580) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{B08E24A9-FA0D-479C-8EF2-D2080F7603F4}
Operation:delete keyName:(default)
Value:
Executable files
35
Suspicious files
133
Text files
42
Unknown types
0

Dropped files

PID
Process
Filename
Type
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\Microsoft.Build.SensitiveDataDetector.dllexecutable
MD5:7CB573A4CAFDAF0875DC7E4AD87E2B39
SHA256:97A39616F946FBF04E61C9232E84E2715BB89556226FFC6FAFD5E226F5554B42
2708MSBuildStructuredLogSetup.exeC:\Users\admin\AppData\Local\SquirrelTemp\MSBuildStructuredLogViewer-2.2.100-full.nupkgcompressed
MD5:E0C4A2407166E2004E91EEDC793283CF
SHA256:4E2CBC0BC481E2FEBE96B8EADE3505BA351D852072582DFB1EA219BE3CE93A8C
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\AdonisUI.dllexecutable
MD5:C8EEC087E9B24DEA55C0826446455180
SHA256:5AA8170B4894FE5B4CECB35A507A977192E06E0165A14E0174FB2C6DC612D788
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\DeltaCompressionDotNet.PatchApi.dllexecutable
MD5:7F610F38778BFDF3E86C037A434C48D0
SHA256:DD7FBBC300AA7C1B478E008C769C4D51BE9326EA64B0D347E925BAF55817EA47
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\ICSharpCode.SharpZipLib.dllexecutable
MD5:F2BF7155CDB0F7E7ED3AF446BA588D8E
SHA256:B6BC2CCDD4E72C087B5D9D19E29F5069310EEF5ADE4B42D367960997433F0C05
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\AutomaticGraphLayout.dllexecutable
MD5:A1DCB11BD95AABFCF1A852367A51F999
SHA256:18E7F6552166AE4008942EB6B3633F6BAA9119263A5C9A453B8DA5DD49509972
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\ICSharpCode.AvalonEdit.dllexecutable
MD5:B6142F182A86ADF382EA845935A327BC
SHA256:7225253A9CA59DB879340F9EA8EE4F48006CEADF878D04B446522007FBE3EBB3
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\Mono.Cecil.Mdb.dllexecutable
MD5:3C6CFF9EF0BA7748D6C61DFACB6890A7
SHA256:B8625ACE855A3086E2086AF418E17DAF24A30A4FBFFC559C42F329EDEC52806E
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\Microsoft.Build.Locator.dllexecutable
MD5:A1D6CAA63CA5D188D7CA1D9B780E2D0D
SHA256:8F223D6C9436B6F5E9DBF40E51016921400783FEFADF40A1134075EE96FFA4F8
2168Update.exeC:\Users\admin\AppData\Local\MSBuildStructuredLogViewer\app-2.2.100\Microsoft.Language.Xml.dllexecutable
MD5:E7BDB82A0313F72B8BBE04A6E42887A4
SHA256:B28B888C1B042DF856237A757A735FE5E87611B53E672EBEDA9F844AF002B01A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
39
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
2864
StructuredLogViewer.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown
3636
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2468
msedge.exe
239.255.255.250:1900
whitelisted
3636
msedge.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
3636
msedge.exe
20.105.95.163:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3636
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.6
  • 140.82.121.5
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
github.com
  • 140.82.121.4
shared
nav-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
github.githubassets.com
  • 185.199.108.154
  • 185.199.110.154
  • 185.199.111.154
  • 185.199.109.154
whitelisted
avatars.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
whitelisted
github-cloud.s3.amazonaws.com
  • 3.5.17.112
  • 3.5.29.116
  • 3.5.25.118
  • 54.231.140.121
  • 52.217.8.52
  • 54.231.234.9
  • 54.231.224.129
  • 52.217.171.57
shared
camo.githubusercontent.com
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.108.133
shared

Threats

No threats detected
No debug info