File name:

MSTeamsSetup_c_l_.exe

Full analysis: https://app.any.run/tasks/1a2e8b1b-330b-48a8-817f-dea43ed8b676
Verdict: Malicious activity
Analysis date: April 17, 2024, 09:32:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CF0E0F57B68A11D099EC944200A6069D

SHA1:

1DDC31265D8DDDBA4F82FE34A66A1BC4000F93AD

SHA256:

73354811E3109E265821124A18B1B7D9FD3DD1207BB46C18937D250C6AB46DEC

SSDEEP:

49152:PZhIlVmOquOk1fNDsYtlqZh0MTQDNB40te+DRKL0CqO0K1c3+FVbmw/DxrbFRLtV:PZhIlGItdlqZhY40U+DgLhqO0KkMVqwl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MSTeamsSetup_c_l_.exe (PID: 1288)
      • Update.exe (PID: 2032)
    • The DLL Hijacking

      • Teams.exe (PID: 3324)
      • Teams.exe (PID: 3116)
      • Teams.exe (PID: 3028)
      • Teams.exe (PID: 3232)
    • Changes the autorun value in the registry

      • Teams.exe (PID: 2944)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Update.exe (PID: 2032)
    • Actions looks like stealing of personal data

      • Update.exe (PID: 2032)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MSTeamsSetup_c_l_.exe (PID: 1288)
    • Executable content was dropped or overwritten

      • MSTeamsSetup_c_l_.exe (PID: 1288)
      • Update.exe (PID: 2032)
    • Process drops legitimate windows executable

      • MSTeamsSetup_c_l_.exe (PID: 1288)
      • Update.exe (PID: 2032)
    • Reads the Internet Settings

      • Update.exe (PID: 2032)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 2944)
      • Squirrel.exe (PID: 3576)
    • Reads settings of System Certificates

      • Update.exe (PID: 2032)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
      • Squirrel.exe (PID: 3576)
    • Reads security settings of Internet Explorer

      • Update.exe (PID: 2032)
    • The process drops C-runtime libraries

      • Update.exe (PID: 2032)
    • Application launched itself

      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 2944)
    • Checks Windows Trust Settings

      • Update.exe (PID: 2032)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2848)
    • Searches for installed software

      • Update.exe (PID: 2032)
    • Creates a software uninstall entry

      • Update.exe (PID: 2032)
  • INFO

    • Checks supported languages

      • MSTeamsSetup_c_l_.exe (PID: 1288)
      • Update.exe (PID: 2032)
      • Teams.exe (PID: 3324)
      • Squirrel.exe (PID: 3576)
      • Teams.exe (PID: 1900)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 1844)
      • Teams.exe (PID: 3116)
      • Teams.exe (PID: 2944)
      • Teams.exe (PID: 3028)
      • Teams.exe (PID: 2120)
      • Teams.exe (PID: 1692)
      • Teams.exe (PID: 3656)
      • Teams.exe (PID: 2692)
      • Teams.exe (PID: 4084)
      • Teams.exe (PID: 3232)
    • Creates files or folders in the user directory

      • MSTeamsSetup_c_l_.exe (PID: 1288)
      • Update.exe (PID: 2032)
      • Squirrel.exe (PID: 3576)
      • Teams.exe (PID: 1900)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
      • Teams.exe (PID: 2120)
    • Reads the computer name

      • Update.exe (PID: 2032)
      • Squirrel.exe (PID: 3576)
      • Teams.exe (PID: 1900)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 3324)
      • Teams.exe (PID: 3116)
      • Teams.exe (PID: 1844)
      • Teams.exe (PID: 2944)
      • Teams.exe (PID: 3028)
      • Teams.exe (PID: 2120)
      • Teams.exe (PID: 3232)
      • Teams.exe (PID: 4084)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 2032)
      • Squirrel.exe (PID: 3576)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
    • Reads Environment values

      • Update.exe (PID: 2032)
      • Squirrel.exe (PID: 3576)
      • Teams.exe (PID: 1900)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
    • Reads Microsoft Office registry keys

      • Update.exe (PID: 2032)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
      • Squirrel.exe (PID: 3576)
    • Reads the software policy settings

      • Update.exe (PID: 2032)
      • Update.exe (PID: 1644)
      • Teams.exe (PID: 2944)
      • Squirrel.exe (PID: 3576)
    • Create files in a temporary directory

      • Update.exe (PID: 2032)
      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 2944)
    • Reads product name

      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 2944)
    • Process checks computer location settings

      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 3656)
      • Teams.exe (PID: 2944)
      • Teams.exe (PID: 1692)
      • Teams.exe (PID: 2692)
    • Reads CPU info

      • Teams.exe (PID: 1900)
      • Teams.exe (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:26 06:41:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 215040
InitializedDataSize: 1211904
UninitializedDataSize: -
EntryPoint: 0x14510
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.7.0.3315
ProductVersionNumber: 1.7.0.3315
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Microsoft Teams
FileVersion: 1.7.00.3315
InternalName: Setup.exe
LegalCopyright: Copyright (C) 2016 Microsoft. All rights reserved.
OriginalFileName: Setup.exe
ProductName: Microsoft Teams
ProductVersion: 1.7.00.3315
SquirrelAwareVersion: 1
CompanyName: Microsoft Corporation
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
17
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msteamssetup_c_l_.exe update.exe squirrel.exe teams.exe no specs update.exe teams.exe no specs teams.exe no specs teams.exe no specs teams.exe teams.exe no specs teams.exe teams.exe no specs teams.exe no specs regsvr32.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1288"C:\Users\admin\AppData\Local\Temp\MSTeamsSetup_c_l_.exe" C:\Users\admin\AppData\Local\Temp\MSTeamsSetup_c_l_.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Exit code:
0
Version:
1.7.00.3315
Modules
Images
c:\users\admin\appdata\local\temp\msteamssetup_c_l_.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1644C:\Users\admin\AppData\Local\Microsoft\Teams\Update.exe --createShortcut=Teams.exe -l=StartMenuC:\Users\admin\AppData\Local\Microsoft\Teams\Update.exe
Teams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams classic
Exit code:
0
Version:
3.3.15.0
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1692"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --enable-wer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --enable-sandbox --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=1644 --field-trial-handle=1116,i,361135994144382996,4574649792004050651,131072 --enable-features=ContextBridgeMutability,SharedArrayBuffer,WinUseBrowserSpellChecker,WinUseHybridSpellChecker --disable-features=CalculateNativeWinOcclusion,ExtraCookieValidityChecks,ForcedColors,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --msteams-process-type=loadingWindow /prefetch:1C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeTeams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Teams
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1844"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --mojo-platform-channel-handle=1504 --field-trial-handle=1148,i,5038364000064256386,11240098210421483770,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeTeams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Exit code:
0
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1900"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --squirrel-install 1.7.00.7956C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Exit code:
0
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2032"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . --exeName=MSTeamsSetup_c_l_.exe --bootstrapperModeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
MSTeamsSetup_c_l_.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams classic
Exit code:
0
Version:
3.3.15.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2120"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --enable-wer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --mojo-platform-channel-handle=1416 --field-trial-handle=1116,i,361135994144382996,4574649792004050651,131072 --enable-features=ContextBridgeMutability,SharedArrayBuffer,WinUseBrowserSpellChecker,WinUseHybridSpellChecker --disable-features=CalculateNativeWinOcclusion,ExtraCookieValidityChecks,ForcedColors,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Teams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2692"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=renderer --enable-wer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --app-user-model-id=com.squirrel.Teams.Teams --app-path="C:\Users\admin\AppData\Local\Microsoft\Teams\current\resources\app.asar" --enable-sandbox --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2752 --field-trial-handle=1116,i,361135994144382996,4574649792004050651,131072 --enable-features=ContextBridgeMutability,SharedArrayBuffer,WinUseBrowserSpellChecker,WinUseHybridSpellChecker --disable-features=CalculateNativeWinOcclusion,ExtraCookieValidityChecks,ForcedColors,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --msteams-process-type=accountSelectWindow /prefetch:1C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeTeams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Teams
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2848"C:\Windows\system32\regsvr32.exe" /s /n /i:user "C:\Users\admin\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.24022.3\x86\Microsoft.Teams.AddinLoader.dll"C:\Windows\System32\regsvr32.exeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2944"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --squirrel-firstrunC:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe
Update.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Version:
1.7.00.7956
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
31 632
Read events
31 492
Write events
139
Delete events
1

Modification events

(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2032) Update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Update_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
346
Suspicious files
92
Text files
155
Unknown types
60

Dropped files

PID
Process
Filename
Type
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\packages\Teams-1.7.00.7956-full.nupkg
MD5:
SHA256:
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\setup.jsonbinary
MD5:F57CCF6F5B9C1E2AAC3C144605B53AA5
SHA256:A92CCAA545B4AF7A81AC10C260291C3C33FB68197D150F8A42D1FBF74EB27648
1288MSTeamsSetup_c_l_.exeC:\Users\admin\AppData\Local\SquirrelTemp\background.gifimage
MD5:FF1F29DCA0451246C3CA6CB7B023434F
SHA256:753D7D351E427246E2B6CC86C45E21F952939E306C3EB2FDB1BD7D67842C64B8
1288MSTeamsSetup_c_l_.exeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exeexecutable
MD5:8F0E958D7EF57D727ADCDA1C67C24C2B
SHA256:4955CC6E58049EF1E274F340C8425CC55B324278199C92AC0DE87DF05BFAD35D
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\current\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:45BE29E949E609DA5D322A67D7FF9EA8
SHA256:57A4A65F7F5074EE3B78D6D0EF54941F8BB471103275829C8805623F2B82672D
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\Update.exeexecutable
MD5:8F0E958D7EF57D727ADCDA1C67C24C2B
SHA256:4955CC6E58049EF1E274F340C8425CC55B324278199C92AC0DE87DF05BFAD35D
2032Update.exeC:\Users\admin\AppData\Roaming\Microsoft\Teams\teams_install_session.jsonbinary
MD5:2DAFAC7EF60A4E17BC69ED99FEB65C30
SHA256:FCE20524A90E5EFFFBCD209BF8AC2ECC0D0CC7797F4BB008049AEA8AA7B54E04
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\current\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:D7C53B48A52916C7439D61810FB07A81
SHA256:0C57B5E3D1A8C5D8683F23BF21B5C6345AD6560931F3090AE801271B0A4EFF94
2032Update.exeC:\Users\admin\AppData\Local\SquirrelTemp\setup.jsonbinary
MD5:F57CCF6F5B9C1E2AAC3C144605B53AA5
SHA256:A92CCAA545B4AF7A81AC10C260291C3C33FB68197D150F8A42D1FBF74EB27648
2032Update.exeC:\Users\admin\AppData\Local\Microsoft\Teams\current\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:A71DADBB909A1F9EC012B6D9F62093C1
SHA256:54D851FDDA042803C37D342203E355D53ED49F13B81274FE761BBF815A43C804
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2032
Update.exe
52.123.128.14:443
teams.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2032
Update.exe
2.16.164.67:443
statics.teams.cdn.office.net
Akamai International B.V.
NL
unknown
2032
Update.exe
20.50.80.210:443
mobile.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1644
Update.exe
20.42.65.89:443
mobile.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2120
Teams.exe
88.221.110.81:443
statics.teams.cdn.office.net
Akamai International B.V.
DE
unknown
2120
Teams.exe
52.123.128.14:443
teams.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
teams.microsoft.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
statics.teams.cdn.office.net
  • 2.16.164.67
  • 2.16.164.105
  • 88.221.110.81
  • 2.16.100.168
whitelisted
mobile.pipe.aria.microsoft.com
  • 20.50.80.210
  • 20.42.65.89
whitelisted
teams.events.data.microsoft.com
  • 104.208.16.92
whitelisted

Threats

No threats detected
Process
Message
Update.exe
TelemetryManagerImpl creation started
Update.exe
Starting TelemetryManager constructor
Update.exe
Update.exe Information: 0 :
Update.exe
Update.exe Information: 0 :
Update.exe
Performance counters are disabled. Skipping creation of counters category.
Update.exe
Update.exe Information: 0 :
Update.exe
RecordBatcherTask with ID 4 started.
Update.exe
Update.exe Information: 0 :
Update.exe
DataPackageSender with UserAgent name: AST-exe-C#, version: 3.3.15.0, [Ast_Default_Source]
Update.exe
Update.exe Information: 0 :