| File name: | DumpFiles.7z |
| Full analysis: | https://app.any.run/tasks/592e4490-b41b-4496-9999-e2ffad678471 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2022, 16:23:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | EA4D39FDAD743C29853EA6353613DC6E |
| SHA1: | 716C78914ACA71C23131D81880EBCE1309C1C998 |
| SHA256: | 6B2B3B4E45991E913CF6464D467BAAE5FEA604DD9C2289A4F2E93175775BF85B |
| SSDEEP: | 49152:rcijqdOvZVCdqF2lTXzZJW7RE6m9KgJveBhe0Dx6:rcIqMVCdq23F6m90B1g |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | regedit.exe /s "C:\Windows\TEMP\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\InstRegExp.reg" | C:\Windows\regedit.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 316 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 320 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe" ebfacb49-64ce-4228-8744-397b6d001845 "68f8d0a5-6704-4249-8ed2-a1a61ea2b200" agent-api.atera.com/Production 443 or8ixLi90Mf "syncdevices" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageInternalPoller\AgentPackageInternalPoller.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: AgentPackageInternalPoller Exit code: 0 Version: 21.6.0.0 Modules
| |||||||||||||||
| 460 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe" ebfacb49-64ce-4228-8744-397b6d001845 "04982b1a-7b76-4a80-a1f5-26ed8db9fea1" agent-api.atera.com/Production 443 or8ixLi90Mf "eyJBZENvbW1hbmRUeXBlIjo1LCJJbnN0YWxsYXRpb25GaWxlVXJsIjpudWxsfQ==" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageADRemote\AgentPackageADRemote.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: AgentPackageADRemote Exit code: 0 Version: 4.4.0.0 Modules
| |||||||||||||||
| 484 | C:\Windows\System32\cmd.exe /C "taskkill.exe /F /IM SRApp.exe /T" | C:\Windows\System32\cmd.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 128 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 556 | C:\Windows\Temp\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\Splashtop_Software_Updater.exe /S /Caller=SVR | C:\Windows\Temp\{B7C5EA94-B96A-41F5-BE95-25D78B486678}\Splashtop_Software_Updater.exe | MsiExec.exe | ||||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop software updater enables updates and enhancements to the SmartView browser extension. Exit code: 0 Version: 1.5.6.19 Modules
| |||||||||||||||
| 632 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe" ebfacb49-64ce-4228-8744-397b6d001845 "da03519c-4a8f-4a70-a3eb-935a86f99018" agent-api.atera.com/Production 443 or8ixLi90Mf "syncinstalledapps" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageProgramManagement\AgentPackageProgramManagement.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageProgramManagement Exit code: 0 Version: 20.6.0.0 Modules
| |||||||||||||||
| 656 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe" ebfacb49-64ce-4228-8744-397b6d001845 "50dca861-006f-4a80-a51f-f8cdfc4dd8f5" agent-api.atera.com/Production 443 or8ixLi90Mf "checkforupdates" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageUpgradeAgent\AgentPackageUpgradeAgent.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks LTD Integrity Level: SYSTEM Description: AgentPackageUpgradeAgent Exit code: 0 Version: 23.6.0.0 Modules
| |||||||||||||||
| 676 | C:\Windows\system32\MsiExec.exe -Embedding B6D0B25F91DB254D545ED72A7D3BF5DC E Global\MSI0000 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 676 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe" ebfacb49-64ce-4228-8744-397b6d001845 "8464ac7f-95c3-4444-9997-031207abaf87" agent-api.atera.com/Production 443 or8ixLi90Mf "downloadifneeded" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe | — | AteraAgent.exe | |||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageSTRemote Exit code: 0 Version: 18.12.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\DumpFiles.7z | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2300) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 316 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2300 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2300.38350\DumpFiles\gmd.exe | executable | |
MD5:— | SHA256:— | |||
| 2300 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2300.38350\DumpFiles\GET_YOUR_FILES_BACK.txt | text | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{ff02fb7e-d6da-47f2-b03b-88cccc0d13e9}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\Windows\Installer\MSI8AD6.tmp | binary | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\Windows\Installer\e846e.msi | executable | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\Windows\Installer\e846f.ipi | binary | |
MD5:— | SHA256:— | |||
| 1068 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\log.txt | text | |
MD5:— | SHA256:— | |||
| 316 | msiexec.exe | C:\Windows\Installer\e8471.msi | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3636 | AteraAgent.exe | GET | — | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0ff66268f039194e | US | — | — | whitelisted |
3780 | SRManager.exe | GET | 200 | 23.37.43.27:80 | http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D | NL | der | 1.52 Kb | whitelisted |
3780 | SRManager.exe | GET | 200 | 23.37.43.27:80 | http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEHhvSYT5N0gvTTb3x7RJTGs%3D | NL | der | 1.47 Kb | shared |
2444 | SSUService.exe | POST | — | 107.22.247.100:80 | http://ds1.devicevm.com/ | US | — | — | suspicious |
3636 | AteraAgent.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA9Pb936OTbfiKMzmkd4EHs%3D | US | der | 471 b | whitelisted |
2444 | SSUService.exe | GET | 301 | 34.200.72.34:80 | http://sn.splashtop.com/file_system/apt_repository/dists/ProtoSSU01/released/binary-i386/Packages.gz | US | html | 134 b | suspicious |
3636 | AteraAgent.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D | US | der | 471 b | whitelisted |
3636 | AteraAgent.exe | GET | 200 | 104.18.11.39:80 | http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt | US | der | 1.69 Kb | whitelisted |
3636 | AteraAgent.exe | GET | 200 | 104.18.11.39:80 | http://cacerts.thawte.com/ThawteRSACA2018.crt | US | der | 1.14 Kb | whitelisted |
3636 | AteraAgent.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0ddb956bfdb9c6b2 | US | compressed | 4.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3636 | AteraAgent.exe | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
3636 | AteraAgent.exe | 104.18.11.39:80 | cacerts.thawte.com | Cloudflare Inc | US | shared |
3636 | AteraAgent.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
3636 | AteraAgent.exe | 35.157.63.229:443 | ps.pndsn.com | Amazon.com, Inc. | DE | suspicious |
— | — | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
3636 | AteraAgent.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3636 | AteraAgent.exe | 13.107.246.44:443 | ps.atera.com | Microsoft Corporation | US | suspicious |
3636 | AteraAgent.exe | 104.18.10.39:80 | cacerts.thawte.com | Cloudflare Inc | US | shared |
3172 | AgentPackageMonitoring.exe | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
956 | AgentPackageSTRemote.exe | 40.119.152.241:443 | agent-api.atera.com | Microsoft Corporation | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
agent-api.atera.com |
| suspicious |
cacerts.thawte.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ps.pndsn.com |
| suspicious |
ps.atera.com |
| suspicious |
cacerts.digicert.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
my.splashtop.com |
| suspicious |
api.nuget.org |
| whitelisted |
download.splashtop.com |
| suspicious |
Process | Message |
|---|---|
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::FindHeader] Name:C:\Windows\TEMP\SplashtopStreamer3360.exe (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::FindHeader] Sign Size:7776 (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::FindHeader] Header offset:429568 (Last=183) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] FreeSpace:234124738560 FileSize:34159616 (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] (1/5)UnPack file name:C:\Windows\TEMP\unpack\setup.msi (34159616) (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] UnPack count:1 len:34159616 File:(null) (Last=0) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] FreeSpace:234090573824 FileSize:15 (Last=183) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] (2/5)UnPack file name:C:\Windows\TEMP\unpack\run.bat (15) (Last=122) |
SplashtopStreamer3360.exe | [2536]2022-02-10 16:27:28 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) (Last=0) |