File name:

Dike_Infocert_upgrade.msi

Full analysis: https://app.any.run/tasks/08851613-f63e-4c68-a692-70196df0f8d7
Verdict: Malicious activity
Analysis date: July 08, 2021, 10:35:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: AteraAgent, Author: Atera networks, Keywords: Installer, Comments: This installer database contains the logic and data required to install AteraAgent., Template: Intel;1033, Revision Number: {D26CD6B3-CD6A-4A03-9A54-C92552FCD1DA}, Create Time/Date: Thu Mar 11 21:25:32 2021, Last Saved Time/Date: Thu Mar 11 21:25:32 2021, Number of Pages: 200, Number of Words: 6, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

0162581E46CFFB64D7C8C90C4134695B

SHA1:

5AF1B43C0264814E030B0B0116A9CF998D1CE8CA

SHA256:

67158EC3E3EDCAFF528CE829517C6AB20095B2DDA6A3F60A5EBF53025D116040

SSDEEP:

12288:wWUUzFROXNtICyMWjYyPkgNi/FRX35zE/ht2pTI+8jOZy2KsGU6a4Ks2H:BUmOXNq5YysgNUxE/1hOE2Z34KTH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • AteraAgent.exe (PID: 1408)
    • Application was dropped or rewritten from another process

      • AteraAgent.exe (PID: 1408)
      • AgentPackageAgentInformation.exe (PID: 2928)
      • AteraAgent.exe (PID: 840)
    • Loads dropped or rewritten executable

      • AteraAgent.exe (PID: 1408)
      • AgentPackageAgentInformation.exe (PID: 2928)
  • SUSPICIOUS

    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 2276)
      • msiexec.exe (PID: 2080)
    • Reads Environment values

      • vssvc.exe (PID: 504)
      • AteraAgent.exe (PID: 1408)
      • AgentPackageAgentInformation.exe (PID: 2928)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 1408)
    • Searches for installed software

      • msiexec.exe (PID: 2276)
      • AgentPackageAgentInformation.exe (PID: 2928)
    • Application launched itself

      • msiexec.exe (PID: 2276)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 2276)
      • msiexec.exe (PID: 2080)
    • Executed as Windows Service

      • vssvc.exe (PID: 504)
      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 1408)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 1408)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 1408)
    • Checks supported languages

      • AteraAgent.exe (PID: 840)
      • AteraAgent.exe (PID: 1408)
      • AgentPackageAgentInformation.exe (PID: 2928)
      • cmd.exe (PID: 2260)
      • cscript.exe (PID: 2828)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 2276)
    • Reads the computer name

      • AteraAgent.exe (PID: 840)
      • AteraAgent.exe (PID: 1408)
      • cscript.exe (PID: 2828)
      • AgentPackageAgentInformation.exe (PID: 2928)
    • Creates files in the program directory

      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 840)
      • AteraAgent.exe (PID: 1408)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2276)
    • Creates files in the Windows directory

      • AteraAgent.exe (PID: 840)
      • AteraAgent.exe (PID: 1408)
    • Starts SC.EXE for service management

      • AteraAgent.exe (PID: 1408)
    • Reads Windows Product ID

      • AgentPackageAgentInformation.exe (PID: 2928)
    • Starts CMD.EXE for commands execution

      • AgentPackageAgentInformation.exe (PID: 2928)
    • Executes scripts

      • cmd.exe (PID: 2260)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 2080)
      • msiexec.exe (PID: 2276)
      • vssvc.exe (PID: 504)
      • MsiExec.exe (PID: 2312)
      • sc.exe (PID: 3440)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 2080)
      • msiexec.exe (PID: 2276)
      • AteraAgent.exe (PID: 1408)
    • Reads the computer name

      • msiexec.exe (PID: 2080)
      • msiexec.exe (PID: 2276)
      • vssvc.exe (PID: 504)
      • MsiExec.exe (PID: 2312)
      • sc.exe (PID: 3440)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 2276)
      • msiexec.exe (PID: 2080)
      • cscript.exe (PID: 2828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: Read-only recommended
Software: Windows Installer XML Toolset (3.11.2.4516)
Words: 6
Pages: 200
ModifyDate: 2021:03:11 21:25:32
CreateDate: 2021:03:11 21:25:32
RevisionNumber: {D26CD6B3-CD6A-4A03-9A54-C92552FCD1DA}
Template: Intel;1033
Comments: This installer database contains the logic and data required to install AteraAgent.
Keywords: Installer
Author: Atera networks
Subject: AteraAgent
Title: Installation Database
CodePage: Windows Latin 1 (Western European)
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs ateraagent.exe no specs ateraagent.exe sc.exe no specs agentpackageagentinformation.exe cmd.exe no specs cscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
504C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft� Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
840"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="amministrazione@universoinvestigazioni.it" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="0013z00002gg5y2AAA"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exemsiexec.exe
User:
admin
Company:
ATERA Networks Ltd.
Integrity Level:
MEDIUM
Description:
AteraAgent
Exit code:
0
Version:
1.8.0.10
Modules
Images
c:\program files\atera networks\ateraagent\ateraagent.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
1408"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe
services.exe
User:
SYSTEM
Company:
ATERA Networks Ltd.
Integrity Level:
SYSTEM
Description:
AteraAgent
Exit code:
0
Version:
1.8.0.10
Modules
Images
c:\program files\atera networks\ateraagent\ateraagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2080"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Dike_Infocert_upgrade.msi"C:\Windows\System32\msiexec.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2260"cmd.exe" /c "cscript ospp.vbs /dstatus"C:\Windows\system32\cmd.exeAgentPackageAgentInformation.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2276C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2312C:\Windows\system32\MsiExec.exe -Embedding 386E00DE15D0CE91C21BC051D9BB8EE4C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2828cscript ospp.vbs /dstatusC:\Windows\system32\cscript.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft � Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
2928"C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 9f4f4894-4365-4991-a237-2c95319a5772 "9b8d0020-5c0b-4410-915e-a6001d827609" agent-api.atera.com/Production 443 or8ixLi90Mf "initialIdentification"C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe
AteraAgent.exe
User:
SYSTEM
Company:
Atera Networks
Integrity Level:
SYSTEM
Description:
AgentPackageAgentInformation
Exit code:
0
Version:
28.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\atera networks\ateraagent\packages\agentpackageagentinformation\agentpackageagentinformation.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3440"C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000C:\Windows\System32\sc.exeAteraAgent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\sc.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
15 169
Read events
14 766
Write events
391
Delete events
12

Modification events

(PID) Process:(2080) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000E80F890DE573D701E4080000B00D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000E80F890DE573D701E4080000B00D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
67
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000CEF8D20DE573D701E4080000B00D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2276) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000CEF8D20DE573D701E4080000B80B0000E8030000010000000000000000000000440D5E134C73E84E963C7F224D37CEB10000000000000000
(PID) Process:(504) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DC1FDA0DE573D701F8010000F40B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(504) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DC1FDA0DE573D701F8010000D00A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(504) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DC1FDA0DE573D701F8010000F80B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(504) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DC1FDA0DE573D701F801000090010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
10
Suspicious files
8
Text files
7
Unknown types
4

Dropped files

PID
Process
Filename
Type
2276msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2276msiexec.exeC:\Windows\Installer\19a39a.ipibinary
MD5:
SHA256:
2276msiexec.exeC:\Windows\Installer\19a399.msiexecutable
MD5:
SHA256:
2276msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFA24EABBC6FED746F.TMPgmc
MD5:
SHA256:
2276msiexec.exeC:\Windows\Installer\MSIA781.tmpbinary
MD5:
SHA256:
2276msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
2276msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{135e0d44-734c-4ee8-963c-7f224d37ceb1}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2276msiexec.exeC:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exeexecutable
MD5:
SHA256:
2276msiexec.exeC:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe.configxml
MD5:7FF0AC77806AED9588B143CD0FAB552B
SHA256:730D85D5EF4F0939154278949C126A444ED859E7718BB175CA3153CA6ED9D142
2276msiexec.exeC:\Windows\Installer\MSIA791.tmpexecutable
MD5:A3AE5D86ECF38DB9427359EA37A5F646
SHA256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
31
DNS requests
11
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1408
AteraAgent.exe
GET
200
104.18.11.39:80
http://cacerts.thawte.com/ThawteRSACA2018.crt
US
der
1.14 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1408
AteraAgent.exe
40.119.152.241:443
agent-api.atera.com
Microsoft Corporation
US
suspicious
1408
AteraAgent.exe
54.93.254.236:443
ps.pndsn.com
Amazon.com, Inc.
DE
suspicious
1408
AteraAgent.exe
104.18.11.39:80
cacerts.thawte.com
Cloudflare Inc
US
shared
2928
AgentPackageAgentInformation.exe
40.119.152.241:443
agent-api.atera.com
Microsoft Corporation
US
suspicious
1408
AteraAgent.exe
191.239.203.0:443
packagesstore.blob.core.windows.net
Microsoft Corporation
NL
whitelisted
191.239.203.0:443
packagesstore.blob.core.windows.net
Microsoft Corporation
NL
whitelisted
152.199.23.209:443
api.nuget.org
MCI Communications Services, Inc. d/b/a Verizon Business
US
suspicious
40.119.152.241:443
agent-api.atera.com
Microsoft Corporation
US
suspicious
13.69.106.3:443
atera-agent-heartbeat.servicebus.windows.net
Microsoft Corporation
NL
unknown
54.183.7.53:443
my.splashtop.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
agent-api.atera.com
  • 40.119.152.241
suspicious
cacerts.thawte.com
  • 104.18.11.39
  • 104.18.10.39
whitelisted
ps.pndsn.com
  • 54.93.254.236
  • 54.93.254.235
suspicious
packagesstore.blob.core.windows.net
  • 191.239.203.0
unknown
api.nuget.org
  • 152.199.23.209
whitelisted
atera-agent-heartbeat.servicebus.windows.net
  • 13.69.106.3
unknown
my.splashtop.com
  • 54.183.7.53
  • 54.193.67.184
suspicious
download.splashtop.com
  • 143.204.98.62
  • 143.204.98.74
  • 143.204.98.8
  • 143.204.98.68
suspicious

Threats

Found threats are available for the paid subscriptions
14 ETPRO signatures available at the full report
No debug info