| File name: | Dike_Infocert_upgrade.msi |
| Full analysis: | https://app.any.run/tasks/08851613-f63e-4c68-a692-70196df0f8d7 |
| Verdict: | Malicious activity |
| Analysis date: | July 08, 2021, 10:35:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: AteraAgent, Author: Atera networks, Keywords: Installer, Comments: This installer database contains the logic and data required to install AteraAgent., Template: Intel;1033, Revision Number: {D26CD6B3-CD6A-4A03-9A54-C92552FCD1DA}, Create Time/Date: Thu Mar 11 21:25:32 2021, Last Saved Time/Date: Thu Mar 11 21:25:32 2021, Number of Pages: 200, Number of Words: 6, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2 |
| MD5: | 0162581E46CFFB64D7C8C90C4134695B |
| SHA1: | 5AF1B43C0264814E030B0B0116A9CF998D1CE8CA |
| SHA256: | 67158EC3E3EDCAFF528CE829517C6AB20095B2DDA6A3F60A5EBF53025D116040 |
| SSDEEP: | 12288:wWUUzFROXNtICyMWjYyPkgNi/FRX35zE/ht2pTI+8jOZy2KsGU6a4Ks2H:BUmOXNq5YysgNUxE/1hOE2Z34KTH |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| Security: | Read-only recommended |
|---|---|
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Words: | 6 |
| Pages: | 200 |
| ModifyDate: | 2021:03:11 21:25:32 |
| CreateDate: | 2021:03:11 21:25:32 |
| RevisionNumber: | {D26CD6B3-CD6A-4A03-9A54-C92552FCD1DA} |
| Template: | Intel;1033 |
| Comments: | This installer database contains the logic and data required to install AteraAgent. |
| Keywords: | Installer |
| Author: | Atera networks |
| Subject: | AteraAgent |
| Title: | Installation Database |
| CodePage: | Windows Latin 1 (Western European) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 504 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 840 | "C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="amministrazione@universoinvestigazioni.it" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="0013z00002gg5y2AAA" | C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | — | msiexec.exe | |||||||||||
User: admin Company: ATERA Networks Ltd. Integrity Level: MEDIUM Description: AteraAgent Exit code: 0 Version: 1.8.0.10 Modules
| |||||||||||||||
| 1408 | "C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe" | C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | services.exe | ||||||||||||
User: SYSTEM Company: ATERA Networks Ltd. Integrity Level: SYSTEM Description: AteraAgent Exit code: 0 Version: 1.8.0.10 Modules
| |||||||||||||||
| 2080 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Dike_Infocert_upgrade.msi" | C:\Windows\System32\msiexec.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2260 | "cmd.exe" /c "cscript ospp.vbs /dstatus" | C:\Windows\system32\cmd.exe | — | AgentPackageAgentInformation.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2276 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2312 | C:\Windows\system32\MsiExec.exe -Embedding 386E00DE15D0CE91C21BC051D9BB8EE4 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2828 | cscript ospp.vbs /dstatus | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft � Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2928 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 9f4f4894-4365-4991-a237-2c95319a5772 "9b8d0020-5c0b-4410-915e-a6001d827609" agent-api.atera.com/Production 443 or8ixLi90Mf "initialIdentification" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageAgentInformation Exit code: 0 Version: 28.0.0.0 Modules
| |||||||||||||||
| 3440 | "C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000 | C:\Windows\System32\sc.exe | — | AteraAgent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2080) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2276) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000E80F890DE573D701E4080000B00D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2276) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000E80F890DE573D701E4080000B00D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2276) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 67 | |||
| (PID) Process: | (2276) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000CEF8D20DE573D701E4080000B00D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2276) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000CEF8D20DE573D701E4080000B80B0000E8030000010000000000000000000000440D5E134C73E84E963C7F224D37CEB10000000000000000 | |||
| (PID) Process: | (504) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000DC1FDA0DE573D701F8010000F40B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (504) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000DC1FDA0DE573D701F8010000D00A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (504) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000DC1FDA0DE573D701F8010000F80B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (504) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000DC1FDA0DE573D701F801000090010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2276 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Windows\Installer\19a39a.ipi | binary | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Windows\Installer\19a399.msi | executable | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFA24EABBC6FED746F.TMP | gmc | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Windows\Installer\MSIA781.tmp | binary | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{135e0d44-734c-4ee8-963c-7f224d37ceb1}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe | executable | |
MD5:— | SHA256:— | |||
| 2276 | msiexec.exe | C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe.config | xml | |
MD5:7FF0AC77806AED9588B143CD0FAB552B | SHA256:730D85D5EF4F0939154278949C126A444ED859E7718BB175CA3153CA6ED9D142 | |||
| 2276 | msiexec.exe | C:\Windows\Installer\MSIA791.tmp | executable | |
MD5:A3AE5D86ECF38DB9427359EA37A5F646 | SHA256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1408 | AteraAgent.exe | GET | 200 | 104.18.11.39:80 | http://cacerts.thawte.com/ThawteRSACA2018.crt | US | der | 1.14 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1408 | AteraAgent.exe | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
1408 | AteraAgent.exe | 54.93.254.236:443 | ps.pndsn.com | Amazon.com, Inc. | DE | suspicious |
1408 | AteraAgent.exe | 104.18.11.39:80 | cacerts.thawte.com | Cloudflare Inc | US | shared |
2928 | AgentPackageAgentInformation.exe | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
1408 | AteraAgent.exe | 191.239.203.0:443 | packagesstore.blob.core.windows.net | Microsoft Corporation | NL | whitelisted |
— | — | 191.239.203.0:443 | packagesstore.blob.core.windows.net | Microsoft Corporation | NL | whitelisted |
— | — | 152.199.23.209:443 | api.nuget.org | MCI Communications Services, Inc. d/b/a Verizon Business | US | suspicious |
— | — | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
— | — | 13.69.106.3:443 | atera-agent-heartbeat.servicebus.windows.net | Microsoft Corporation | NL | unknown |
— | — | 54.183.7.53:443 | my.splashtop.com | Amazon.com, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
agent-api.atera.com |
| suspicious |
cacerts.thawte.com |
| whitelisted |
ps.pndsn.com |
| suspicious |
packagesstore.blob.core.windows.net |
| unknown |
api.nuget.org |
| whitelisted |
atera-agent-heartbeat.servicebus.windows.net |
| unknown |
my.splashtop.com |
| suspicious |
download.splashtop.com |
| suspicious |