File name:

Retrac.Launcher_1.0.13_x64_en-US.msi

Full analysis: https://app.any.run/tasks/b8ce65f3-beba-40ca-af8d-5d0599883752
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 02, 2024, 00:55:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
loader
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Retrac Launcher, Author: retrac, Keywords: Installer, Comments: This installer database contains the logic and data required to install Retrac Launcher., Template: x64;0, Revision Number: {96B6EFCC-925B-4F3C-B073-1B1E96E5D875}, Create Time/Date: Fri Aug 30 21:43:00 2024, Last Saved Time/Date: Fri Aug 30 21:43:00 2024, Number of Pages: 450, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

5F1EAA7C85D7589BFF98B064E521A8CF

SHA1:

FB4183909BFA7D8CCD056D15D3062A2343811B11

SHA256:

77F824CBC498DD3CA31197B8251C41B3F810F8FED50C5A9893552D42EE42FA65

SSDEEP:

98304:/mpbDmD4IPKBzzrvuziWwLuFHArMAfDZdf7zrPwOC+rGBIJql2phRPvqFAvn4i6s:/sDjn7fVv1Lue

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 7132)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 2252)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 1108)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5712)
    • Powershell scripting: start process

      • msiexec.exe (PID: 5712)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 5712)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 5712)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 5712)
      • powershell.exe (PID: 7132)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
    • Downloads file from URI

      • powershell.exe (PID: 7132)
    • Request a resource from the Internet using PowerShell's cmdlet

      • msiexec.exe (PID: 5712)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 7132)
    • Process drops legitimate windows executable

      • powershell.exe (PID: 7132)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • svchost.exe (PID: 1020)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 7132)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2252)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1048)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 3104)
      • MicrosoftEdgeUpdate.exe (PID: 1608)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5476)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdgeUpdate.exe (PID: 460)
    • Reads the date of Windows installation

      • MicrosoftEdgeUpdate.exe (PID: 2252)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 1020)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 460)
    • Application launched itself

      • setup.exe (PID: 4732)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 2580)
      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdgeUpdate.exe (PID: 1608)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1048)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 3104)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5476)
      • MicrosoftEdgeUpdate.exe (PID: 6320)
      • MicrosoftEdgeUpdate.exe (PID: 1076)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
      • MicrosoftEdgeUpdate.exe (PID: 460)
      • setup.exe (PID: 4732)
      • setup.exe (PID: 6248)
    • An automatically generated document

      • msiexec.exe (PID: 4980)
    • Reads the computer name

      • msiexec.exe (PID: 2580)
      • msiexec.exe (PID: 5712)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdgeUpdate.exe (PID: 1608)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1048)
      • MicrosoftEdgeUpdate.exe (PID: 1076)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5476)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 3104)
      • MicrosoftEdgeUpdate.exe (PID: 460)
      • MicrosoftEdgeUpdate.exe (PID: 6320)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
      • setup.exe (PID: 4732)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5712)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5712)
      • msiexec.exe (PID: 4980)
    • Disables trace logs

      • powershell.exe (PID: 7132)
    • Checks proxy server information

      • powershell.exe (PID: 7132)
      • MicrosoftEdgeUpdate.exe (PID: 1076)
      • MicrosoftEdgeUpdate.exe (PID: 460)
    • Create files in a temporary directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • svchost.exe (PID: 1020)
    • The executable file from the user directory is run by the Powershell process

      • MicrosoftEdgeWebview2Setup.exe (PID: 5544)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 2252)
      • MicrosoftEdgeUpdate.exe (PID: 460)
      • MicrosoftEdge_X64_128.0.2739.54.exe (PID: 6444)
      • setup.exe (PID: 4732)
      • setup.exe (PID: 6248)
    • The process uses the downloaded file

      • powershell.exe (PID: 7132)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 1076)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 2252)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 1076)
      • MicrosoftEdgeUpdate.exe (PID: 460)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 1076)
      • MicrosoftEdgeUpdate.exe (PID: 460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Retrac Launcher
Author: retrac
Keywords: Installer
Comments: This installer database contains the logic and data required to install Retrac Launcher.
Template: x64;0
RevisionNumber: {96B6EFCC-925B-4F3C-B073-1B1E96E5D875}
CreateDate: 2024:08:30 21:43:00
ModifyDate: 2024:08:30 21:43:00
Pages: 450
Words: 2
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
21
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe microsoftedge_x64_128.0.2739.54.exe setup.exe no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
460"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1020C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITSC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
1048"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.15\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1076"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMTUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMTUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7NTQ2MzJCRjAtMTdBNy00MDYyLUIyOUMtOUEwM0M1Q0FFNzJGfSIgdXNlcmlkPSJ7NDZFRUNCMUUtQzFGNC00QkM0LUFDOTMtQzc5RkIyRkQyRkE2fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0QUExRUZCQS1BQkZELTQxM0YtQTBERC00MjIzQjZGQzExMEZ9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE5NS4xNSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTI1NjIzNTIzNjAiIGluc3RhbGxfdGltZV9tcz0iNTQ3Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
1108C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1608"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
2252C:\Users\admin\AppData\Local\Temp\EU2415.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU2415.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\temp\eu2415.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
2580C:\Windows\syswow64\MsiExec.exe -Embedding F3D23C602C4020C52B9D17608651C56D CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3104"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.15
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.15\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4732"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{A662583A-AD7B-4084-A8BF-5F5F708106C6}\EDGEMITMP_FE9FE.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{A662583A-AD7B-4084-A8BF-5F5F708106C6}\MicrosoftEdge_X64_128.0.2739.54.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{A662583A-AD7B-4084-A8BF-5F5F708106C6}\EDGEMITMP_FE9FE.tmp\setup.exeMicrosoftEdge_X64_128.0.2739.54.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Version:
128.0.2739.54
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{a662583a-ad7b-4084-a8bf-5f5f708106c6}\edgemitmp_fe9fe.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
32 266
Read events
28 632
Write events
3 577
Delete events
57

Modification events

(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000072CABCE2D2FCDA0150160000481A0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000942DBFE2D2FCDA0150160000481A0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000A760F8E2D2FCDA0150160000481A0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000A760F8E2D2FCDA0150160000481A0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000023C4FAE2D2FCDA0150160000481A0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000BD27FDE2D2FCDA0150160000481A0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000965674E3D2FCDA0150160000481A0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5712) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000BBBC76E3D2FCDA0150160000AC090000E8030000010000000000000000000000F5EE8113B413CE41A429DA68B2F0C9AB00000000000000000000000000000000
(PID) Process:(1108) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000007FB282E3D2FCDA0154040000341B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
205
Suspicious files
18
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
5712msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
5712msiexec.exeC:\Windows\Installer\130013.msi
MD5:
SHA256:
5712msiexec.exeC:\Windows\Installer\130015.msi
MD5:
SHA256:
5712msiexec.exeC:\Windows\Temp\~DF127467B3DEFA0F55.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
5712msiexec.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Retrac Launcher\Retrac Launcher.lnklnk
MD5:1B9AE13F0A06983B38DC94D754D3504F
SHA256:DD714BD34B8BF9499CC0093693624BBAC55674438E6F6707FE754D1D2620D662
5712msiexec.exeC:\Program Files\Retrac Launcher\Retrac Launcher.exeexecutable
MD5:8EB3B4AE2BCF577A41B13E5AC0DEA44A
SHA256:8C6A9FB495E49421FD229513F33640F70E08737E61B1668B091B73450E76D2C7
5712msiexec.exeC:\Windows\Temp\~DF96292747E6650113.TMPbinary
MD5:427BD109234C7CE776472C4E49C607F8
SHA256:E8EC3FC5284CBC7F94E630DB0C2A71289C41F276C507E404D28BF2763D9AAD5E
5712msiexec.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Retrac Launcher\Retrac Launcher.lnk~RF1305c0.TMPbinary
MD5:1B9AE13F0A06983B38DC94D754D3504F
SHA256:DD714BD34B8BF9499CC0093693624BBAC55674438E6F6707FE754D1D2620D662
5712msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:427BD109234C7CE776472C4E49C607F8
SHA256:E8EC3FC5284CBC7F94E630DB0C2A71289C41F276C507E404D28BF2763D9AAD5E
4980msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIB81D.tmpexecutable
MD5:4FDD16752561CF585FED1506914D73E0
SHA256:AECD2D2FE766F6D439ACC2BBF1346930ECC535012CF5AD7B3273D2875237B7E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
19
DNS requests
10
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
13.107.42.16:443
https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.195.15?clientId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&appChannel_edgeupdate=6&appConsentState_edgeupdate=0&appDayOfInstall_edgeupdate=0&appInactivityBadgeApplied_edgeupdate=0&appInactivityBadgeCleared_edgeupdate=0&appInactivityBadgeDuration_edgeupdate=0&appInstallTimeDiffSec_edgeupdate=0&appIsPinnedSystem_edgeupdate=false&appLastLaunchCount_edgeupdate=0&appLastLaunchTime_edgeupdate=0&appLastLaunchTimeJson_edgeupdate=0&appLastLaunchTimeDaysAgo_edgeupdate=0&appVersion_edgeupdate=1.3.195.15&appUpdateCheckIsUpdateDisabled_edgeupdate=false&appUpdatesAllowedForMeteredNetworks_edgeupdate=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=4&hwPhysmemory=4&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=DELL&oemProductName=DELL&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.4046&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=otherinstallcmd&requestIsMachine=false&requestOmahaShellVersion=1.3.195.15&requestOmahaVersion=1.3.195.15
unknown
binary
439 b
POST
200
13.67.191.143:443
https://msedge.api.cdp.microsoft.com/api/v1.1/internal/contents/Browser/namespaces/Default/names/msedgewebview-stable-win-x64/versions/128.0.2739.54/files?action=GenerateDownloadInfo&foregroundPriority=true
unknown
text
6.70 Kb
GET
200
152.199.21.175:443
https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/bfbbeee6-130c-46b7-bf66-6b8eab0e894d/MicrosoftEdgeWebview2Setup.exe
unknown
executable
1.57 Mb
1020
svchost.exe
GET
200
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6e21df09-d909-4575-8e24-d945909e58df?P1=1725843392&P2=404&P3=2&P4=EPaWvYxI5Nt7anjhsKOvtMynCUqgOsqTkbw0kjRAzozzOT%2bY0yEP0kXz2X4siwuEvm0B5b1uQIPErUdV2RkNvQ%3d%3d
unknown
whitelisted
1020
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/6e21df09-d909-4575-8e24-d945909e58df?P1=1725843392&P2=404&P3=2&P4=EPaWvYxI5Nt7anjhsKOvtMynCUqgOsqTkbw0kjRAzozzOT%2bY0yEP0kXz2X4siwuEvm0B5b1uQIPErUdV2RkNvQ%3d%3d
unknown
whitelisted
POST
200
13.67.191.143:443
https://msedge.api.cdp.microsoft.com/api/v2/contents/Browser/namespaces/Default/names?action=batchupdates
unknown
text
103 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6232
svchost.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
6420
RUXIMICS.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
6232
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4324
svchost.exe
20.106.86.13:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7132
powershell.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
7132
powershell.exe
152.199.21.175:443
msedge.sf.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
1076
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 52.140.118.28
  • 20.73.194.208
  • 20.106.86.13
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedge.api.cdp.microsoft.com
  • 13.95.26.4
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Misc activity
ET INFO Request for EXE via Powershell
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1020
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info