File name: | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver |
Full analysis: | https://app.any.run/tasks/2ca1ec97-5355-44ca-9ff6-2c8d34ecde27 |
Verdict: | Malicious activity |
Analysis date: | January 10, 2025, 21:36:01 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32+ executable (console) x86-64, for MS Windows, 7 sections |
MD5: | 98FEDF655C52D5B8B84537B35987456A |
SHA1: | 0A8FDAAF376CC520C29CBC2C2BBC20FFA50F147E |
SHA256: | 7EBCE1AC5339B3163A6E323639424BDE8F385259F5E4FE6E41DB29D74A96E3BA |
SSDEEP: | 98304:b/NkRdEtqLdOvOSWHO2mSxzbOep2irTPjz1:x+dJh |
.exe | | | Generic Win/DOS Executable (50) |
---|---|---|
.exe | | | DOS Executable Generic (49.9) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2022:12:09 20:12:49+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 14 |
CodeSize: | 2122240 |
InitializedDataSize: | 1475072 |
UninitializedDataSize: | - |
EntryPoint: | 0x1d9d8c |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows command line |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x0017 |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
FileDescription: | MeshCentral Background Service Agent |
FileVersion: | 2022-Dec-2 11:42:16-0800 |
LegalCopyright: | Apache 2.0 License |
ProductName: | MeshCentral Agent |
ProductVersion: | Commit: 2022-Dec-2 11:42:16-0800 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2324 | "C:\Users\admin\Desktop\2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe" | C:\Users\admin\Desktop\2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: MeshCentral Background Service Agent Exit code: 0 Version: 2022-Dec-2 11:42:16-0800 Modules
| |||||||||||||||
5696 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2788 | wmic os get oslanguage /FORMAT:LIST | C:\Windows\System32\wbem\WMIC.exe | — | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1544 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2736 | "C:\Users\admin\Desktop\2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe" -fullinstall | C:\Users\admin\Desktop\2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: MeshCentral Background Service Agent Exit code: 0 Version: 2022-Dec-2 11:42:16-0800 Modules
| |||||||||||||||
1612 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5308 | "C:\Program Files\Mesh Agent\MeshAgent.exe" --installedByUser="S-1-5-21-1693682860-607145093-2874071422-1001" | C:\Program Files\Mesh Agent\MeshAgent.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: MeshCentral Background Service Agent Version: 2022-Dec-2 11:42:16-0800 Modules
|
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mesh Agent |
Operation: | write | Name: | ImagePath |
Value: "C:\Program Files\Mesh Agent\MeshAgent.exe" --installedByUser="S-1-5-21-1693682860-607145093-2874071422-1001" | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mesh Agent |
Operation: | write | Name: | _InstalledBy |
Value: S-1-5-21-1693682860-607145093-2874071422-1001 | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | DisplayName |
Value: Mesh Agent | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Mesh Agent\MeshAgent.exe | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Mesh Agent\ | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | EstimatedSize |
Value: 3358 | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | NoModify |
Value: 1 | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | NoRepair |
Value: 1 | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | UninstallString |
Value: C:\Program Files\Mesh Agent\MeshAgent.exe -funinstall --meshServiceName="Mesh Agent" | |||
(PID) Process: | (2736) 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mesh Agent |
Operation: | write | Name: | DisplayVersion |
Value: 2022-12-02 19:42:16.000+00:00 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2736 | 2025-01-10_98fedf655c52d5b8b84537b35987456a_ismagent_ryuk_sliver.exe | C:\Program Files\Mesh Agent\MeshAgent.exe | executable | |
MD5:98FEDF655C52D5B8B84537B35987456A | SHA256:7EBCE1AC5339B3163A6E323639424BDE8F385259F5E4FE6E41DB29D74A96E3BA | |||
5308 | MeshAgent.exe | C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\A04E215925FA505F40D1BC29E4063289A31F680B | binary | |
MD5:E5E3F616AE3CACA3BC0995E3C7A02E72 | SHA256:56A5B4EFDE2B336C99DF681584E7BB47332263C88380AEC93520C00A03FF58EA | |||
5308 | MeshAgent.exe | C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\80858169C3FA1FF9DAFDA0AC128014422FA6C66F | binary | |
MD5:05B66B479FAA2423210EFB07D68469A2 | SHA256:9C9AD4B578EDFC1D792D2E213A0D01F024273C8E433972A3E35DC0B84DF99E5C | |||
5308 | MeshAgent.exe | C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\00056C324F1A689F8FAF03A9727DD31E6A9CC481 | binary | |
MD5:E09FC0328979636AF7B2DCC4E6BD3568 | SHA256:7467E31E384B1793356C3376153B6F2BF81A6473AE03E3C0B02BDED8BB608873 | |||
5308 | MeshAgent.exe | C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\164FEF8315B70A36A1509D97CE930DDC74134E66 | binary | |
MD5:D842B64B79947CF8D260B7A1DFBA15FB | SHA256:06822735B37723A83C4FE6378E314D360624A8E7F2FC2F78E44198A9AA5D4166 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4428 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.173:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4428 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4712 | MoUsoCoreWorker.exe | 23.48.23.173:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
4428 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
4428 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3976 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| unknown |
google.com |
| unknown |
crl.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
self.events.data.microsoft.com |
| unknown |