File name:

8x8 Network Utility Setup.exe

Full analysis: https://app.any.run/tasks/c3e710a3-8ffc-492a-8837-5a3974887c01
Verdict: Malicious activity
Analysis date: November 23, 2023, 16:42:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6504ED5D3A8E4B00BC85EDB1E438B0CF

SHA1:

9ACB93BA27DEB53A4CB7DFE7B5D4A3FC104FF277

SHA256:

5627E70C644683DCD1A80AF49BBEAEF003E61EE64816A8F35F5B2A3C398668F6

SSDEEP:

98304:dP/h/5E1SZVY4MGfSi+OBHfallc5lKF8WVjoe+VtgOZ56NNFbzxAGo8iQMWhiiJk:Yr8L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 8x8 Network Utility Setup.exe (PID: 3448)
      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility Setup.exe (PID: 3576)
      • msiexec.exe (PID: 3960)
  • SUSPICIOUS

    • Searches for installed software

      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility Setup.exe (PID: 3576)
    • Reads the Internet Settings

      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility.exe (PID: 3236)
    • Starts itself from another location

      • 8x8 Network Utility Setup.exe (PID: 3432)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3444)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3960)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3960)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3960)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3960)
    • Creates a software uninstall entry

      • 8x8 Network Utility Setup.exe (PID: 3576)
  • INFO

    • Create files in a temporary directory

      • 8x8 Network Utility Setup.exe (PID: 3448)
      • 8x8 Network Utility Setup.exe (PID: 3432)
      • msiexec.exe (PID: 3960)
      • 8x8 Network Utility Setup.exe (PID: 3576)
    • Checks supported languages

      • 8x8 Network Utility Setup.exe (PID: 3448)
      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility Setup.exe (PID: 3576)
      • msiexec.exe (PID: 3960)
      • 8x8 Network Utility.exe (PID: 3236)
      • wmpnscfg.exe (PID: 2056)
    • Reads the computer name

      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility Setup.exe (PID: 3576)
      • msiexec.exe (PID: 3960)
      • 8x8 Network Utility.exe (PID: 3236)
      • wmpnscfg.exe (PID: 2056)
    • Reads the machine GUID from the registry

      • 8x8 Network Utility Setup.exe (PID: 3432)
      • 8x8 Network Utility Setup.exe (PID: 3576)
      • msiexec.exe (PID: 3960)
      • 8x8 Network Utility.exe (PID: 3236)
      • wmpnscfg.exe (PID: 2056)
    • Creates files in the program directory

      • 8x8 Network Utility Setup.exe (PID: 3576)
    • Creates files or folders in the user directory

      • 8x8 Network Utility.exe (PID: 3236)
    • Manual execution by a user

      • 8x8 Network Utility.exe (PID: 3236)
      • wmpnscfg.exe (PID: 2056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:11:18 23:00:38+01:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.11
CodeSize: 301568
InitializedDataSize: 258048
UninitializedDataSize: -
EntryPoint: 0x2e2a6
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.3.1324.0
ProductVersionNumber: 2.3.1324.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: 8x8, Inc.
FileDescription: 8x8 Network Utility
FileVersion: 2.3.1324
InternalName: setup
LegalCopyright: Copyright (c) 8x8, Inc.. All rights reserved.
OriginalFileName: 8x8 Network Utility Setup.exe
ProductName: 8x8 Network Utility
ProductVersion: 2.3.1324
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 8x8 network utility setup.exe no specs 8x8 network utility setup.exe no specs 8x8 network utility setup.exe vssvc.exe no specs msiexec.exe no specs 8x8 network utility.exe wmpnscfg.exe no specs wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
1152"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe8x8 Network Utility.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
1840"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
8x8 Network Utility.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2056"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3236"C:\Program Files\8x8, Inc\Network Utility\8x8 Network Utility.exe" C:\Program Files\8x8, Inc\Network Utility\8x8 Network Utility.exe
explorer.exe
User:
admin
Company:
8x8
Integrity Level:
MEDIUM
Description:
8x8NetworkUtility
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\program files\8x8, inc\network utility\8x8 network utility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3432"C:\Users\admin\AppData\Local\Temp\{33CCB9EF-CAF7-4448-8DE7-C4ED3FC88F3E}\.cr\8x8 Network Utility Setup.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\8x8 Network Utility Setup.exe" -burn.filehandle.attached=152 -burn.filehandle.self=160 C:\Users\admin\AppData\Local\Temp\{33CCB9EF-CAF7-4448-8DE7-C4ED3FC88F3E}\.cr\8x8 Network Utility Setup.exe8x8 Network Utility Setup.exe
User:
admin
Company:
8x8, Inc.
Integrity Level:
MEDIUM
Description:
8x8 Network Utility
Exit code:
0
Version:
2.3.1324
Modules
Images
c:\users\admin\appdata\local\temp\{33ccb9ef-caf7-4448-8de7-c4ed3fc88f3e}\.cr\8x8 network utility setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3444C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3448"C:\Users\admin\AppData\Local\Temp\8x8 Network Utility Setup.exe" C:\Users\admin\AppData\Local\Temp\8x8 Network Utility Setup.exeexplorer.exe
User:
admin
Company:
8x8, Inc.
Integrity Level:
MEDIUM
Description:
8x8 Network Utility
Exit code:
0
Version:
2.3.1324
Modules
Images
c:\users\admin\appdata\local\temp\8x8 network utility setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3576"C:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\.be\8x8 Network Utility Setup.exe" -q -burn.elevated BurnPipe.{C75BF04D-0576-4693-B208-DECB6329A555} {72044CF7-3708-46FE-841C-D9DB0189D36E} 3432C:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\.be\8x8 Network Utility Setup.exe
8x8 Network Utility Setup.exe
User:
admin
Company:
8x8, Inc.
Integrity Level:
HIGH
Description:
8x8 Network Utility
Exit code:
0
Version:
2.3.1324
Modules
Images
c:\users\admin\appdata\local\temp\{3b07f4b0-8f31-4ce9-8bb5-0c0ab08d28fc}\.be\8x8 network utility setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3960C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
7 230
Read events
7 164
Write events
50
Delete events
16

Modification events

(PID) Process:(3432) 8x8 Network Utility Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3432) 8x8 Network Utility Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3432) 8x8 Network Utility Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3432) 8x8 Network Utility Setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
72
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3576) 8x8 Network Utility Setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
18
Suspicious files
12
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
35768x8 Network Utility Setup.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
34328x8 Network Utility Setup.exeC:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\.ba\thm.xmlxml
MD5:C29A69F34FF31FF63C3EC6B2D4F903E5
SHA256:8D67851408A62B0F04DBAADDC588CD98499CF3630EC5DF9F7C0699F0D367F79C
35768x8 Network Utility Setup.exeC:\System Volume Information\SPP\OnlineMetadataCache\{b74594f9-4496-4500-adc6-4762c869308d}_OnDiskSnapshotPropbinary
MD5:F30DC6BBFE1123FD96584A0F45088745
SHA256:57999BA79A6B81758A5BFF426279CD8E7BAF018D507D06166FA3914B77FA9B60
34328x8 Network Utility Setup.exeC:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\.ba\thm.wxlxml
MD5:FC0DB4142556D3F38B0744A12F5F9D3D
SHA256:8FBEB7F0B546D394D99B49D678D516402E8F54E5DEA590CC91733F502F288019
34328x8 Network Utility Setup.exeC:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\.ba\BootstrapperApplicationData.xmlxml
MD5:9315106F8B9BF6A6ED518D69CC26B978
SHA256:04A5174E60C8D55ECE71E698F21AF2B88391FDA6ED2214348F44952CC0DB1619
35768x8 Network Utility Setup.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:F30DC6BBFE1123FD96584A0F45088745
SHA256:57999BA79A6B81758A5BFF426279CD8E7BAF018D507D06166FA3914B77FA9B60
34328x8 Network Utility Setup.exeC:\Users\admin\AppData\Local\Temp\{3B07F4B0-8F31-4CE9-8BB5-0C0AB08D28FC}\NetUtilApplicationexecutable
MD5:6B8E6FC0587DF8E6FECCFFC2A943B3D9
SHA256:3C5E011EDEF2193BFF6EA8A85CED69A7BC9FA104CEBC1E960D93EFC5613B5475
35768x8 Network Utility Setup.exeC:\ProgramData\Package Cache\{636c1dd3-2014-4174-b925-089829e8c0c3}\state.rsmbinary
MD5:91225FAA119B3A90CD6E6307F2C3E0DA
SHA256:D75C626B0B679A9172A4F7729F7C4D7996397AE98C681A734CC9B984B106D6A8
35768x8 Network Utility Setup.exeC:\ProgramData\Package Cache\.unverified\NetUtilApplicationexecutable
MD5:6B8E6FC0587DF8E6FECCFFC2A943B3D9
SHA256:3C5E011EDEF2193BFF6EA8A85CED69A7BC9FA104CEBC1E960D93EFC5613B5475
35768x8 Network Utility Setup.exeC:\ProgramData\Package Cache\{5167821B-3CD2-49CD-8725-3BE60305AFF5}v2.3.1324\WixInstaller.msiexecutable
MD5:6B8E6FC0587DF8E6FECCFFC2A943B3D9
SHA256:3C5E011EDEF2193BFF6EA8A85CED69A7BC9FA104CEBC1E960D93EFC5613B5475
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
484
lsass.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?440741f4bd306e5a
unknown
compressed
4.66 Kb
unknown
484
lsass.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
484
lsass.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAU%2F07frv7msefUGfjRQON0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3236
8x8 Network Utility.exe
216.58.206.36:80
www.google.com
whitelisted
3236
8x8 Network Utility.exe
162.221.236.25:443
netutil-key.8x8.com
8X8-AS
US
unknown
484
lsass.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
484
lsass.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
www.google.com
  • 216.58.206.36
whitelisted
netutil-key.8x8.com
  • 162.221.236.25
unknown
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
pcsbc.packet8.net
  • 158.101.200.10
  • 130.61.163.33
  • 158.101.200.5
  • 130.61.163.34
unknown

Threats

No threats detected
No debug info