File name:

NSClient.msi

Full analysis: https://app.any.run/tasks/ddcbb2b2-16ab-4feb-af89-b73bfe9dd103
Verdict: Malicious activity
Analysis date: March 30, 2021, 14:59:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Netskope Client 80.0.0.520, Author: Netskope, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Netskope Client., Template: Intel;1033, Revision Number: {70C9558C-0E95-405C-813A-743157A1F6A3}, Create Time/Date: Thu Oct 22 07:53:20 2020, Last Saved Time/Date: Thu Oct 22 07:53:20 2020, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

092E7E563258D92D9E07F3168CE1E3FB

SHA1:

AF7EEB0192DC86B0BF5C861B9D6BF111E0124D82

SHA256:

473C1342FE95D64785988199F5713E9F0B44096797F1E55EA845C1013DD44A22

SSDEEP:

98304:8gG4bSjam2bC7jkLza0RT/K/THg66cmItZk0PtFnPYU8i8yg1yrJbCYc:8nESulvXTzcmSPPPY4V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • stAgentSvc.exe (PID: 2896)
      • stAgentUI.exe (PID: 2092)
      • stAgentUI.exe (PID: 3872)
    • Loads the Task Scheduler COM API

      • logman.exe (PID: 1896)
  • SUSPICIOUS

    • Executed as Windows Service

      • stAgentSvc.exe (PID: 2896)
    • Uses TASKKILL.EXE to kill process

      • MsiExec.exe (PID: 1520)
    • Uses NETSH.EXE for network configuration

      • stAgentSvc.exe (PID: 2896)
    • Changes IE settings (feature browser emulation)

      • stAgentSvc.exe (PID: 2896)
    • Reads internet explorer settings

      • stAgentUI.exe (PID: 2092)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1520)
      • MsiExec.exe (PID: 1988)
    • Creates files in the program directory

      • MsiExec.exe (PID: 1520)
      • MsiExec.exe (PID: 1988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Netskope Client 80.0.0.520
Author: Netskope, Inc.
Keywords: Installer
Comments: This installer database contains the logic and data required to install Netskope Client.
Template: Intel;1033
RevisionNumber: {70C9558C-0E95-405C-813A-743157A1F6A3}
CreateDate: 2020:10:22 06:53:20
ModifyDate: 2020:10:22 06:53:20
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs stagentsvc.exe logman.exe no specs netsh.exe no specs stagentui.exe stagentui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1520C:\Windows\system32\MsiExec.exe -Embedding D9A37627C071510089E953BA54AA4756C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1896C:\Windows\system32/logman.exe query nsDriverLogSessionC:\Windows\system32\logman.exestAgentSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Performance Log Utility
Exit code:
2150629378
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\logman.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1988C:\Windows\system32\MsiExec.exe -Embedding 8196DCC703A4436E91D9B703A5AD29C6 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2092"C:\Program Files\Netskope\STAgent\stAgentUI.exe"C:\Program Files\Netskope\STAgent\stAgentUI.exe
stAgentSvc.exe
User:
admin
Company:
Netskope, Inc.
Integrity Level:
MEDIUM
Description:
Netskope Client
Exit code:
0
Version:
80.0.0.520
Modules
Images
c:\program files\netskope\stagent\stagentui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2680"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\NSClient.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2896"C:\Program Files\Netskope\STAgent\stAgentSvc.exe"C:\Program Files\Netskope\STAgent\stAgentSvc.exe
services.exe
User:
SYSTEM
Company:
Netskope, Inc.
Integrity Level:
SYSTEM
Description:
Netskope Client Service
Exit code:
0
Version:
80.0.0.520
Modules
Images
c:\program files\netskope\stagent\stagentsvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3872"C:\Program Files\Netskope\STAgent\stAgentUI.exe"C:\Program Files\Netskope\STAgent\stAgentUI.exeMsiExec.exe
User:
admin
Company:
Netskope, Inc.
Integrity Level:
MEDIUM
Description:
Netskope Client
Exit code:
0
Version:
80.0.0.520
Modules
Images
c:\program files\netskope\stagent\stagentui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3932C:\Windows\system32/netsh.exe trace show statusC:\Windows\system32\netsh.exestAgentSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
Total events
310
Read events
245
Write events
65
Delete events
0

Modification events

(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
(PID) Process:(2680) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-844
Value:
BitLocker Data Recovery Agent
(PID) Process:(2896) stAgentSvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:stAgentUI.exe
Value:
11000
(PID) Process:(3932) netsh.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2092) stAgentUI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2092) stAgentUI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
0
Suspicious files
0
Text files
232
Unknown types
0

Dropped files

PID
Process
Filename
Type
1520MsiExec.exeC:\ProgramData\Netskope\STAgent\nsconfig.jsontext
MD5:
SHA256:
1520MsiExec.exeC:\Users\Public\netSkope\nsdebuglog.logtext
MD5:
SHA256:
2896stAgentSvc.exeC:\Users\Public\netSkope\nsdebuglog.logtext
MD5:
SHA256:
1988MsiExec.exeC:\Users\Public\netSkope\nsdebuglog.logtext
MD5:
SHA256:
1520MsiExec.exeC:\ProgramData\Netskope\STAgent\nsuser.conftext
MD5:
SHA256:
1988MsiExec.exeC:\ProgramData\Netskope\STAgent\data\nsinternal.jsontext
MD5:
SHA256:
2896stAgentSvc.exeC:\Users\Public\netSkope\logmanOutput.txttext
MD5:39B96B646D8573D9F3E666B638A7E1F0
SHA256:936500B2E4625FFDC26F248CB86A4905CEB3B0E276B386D21FA4DC2E347ABA54
2092stAgentUI.exeC:\Users\Public\netSkope\nsdebuglog.logtext
MD5:
SHA256:
1988MsiExec.exeC:\ProgramData\Netskope\STAgent\installereventcache.jsontext
MD5:
SHA256:
3872stAgentUI.exeC:\Users\Public\netSkope\nsdebuglog.logtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info