File name:

a.msi

Full analysis: https://app.any.run/tasks/892919c3-d33f-486c-8de4-ac899d909f0d
Verdict: Malicious activity
Analysis date: October 26, 2021, 03:22:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: AteraAgent, Author: Atera networks, Keywords: Installer, Comments: This installer database contains the logic and data required to install AteraAgent., Template: Intel;1033, Revision Number: {9DEB3F55-79C3-4C80-BCDC-D8B5B53D0787}, Create Time/Date: Wed Jul 14 10:04:10 2021, Last Saved Time/Date: Wed Jul 14 10:04:10 2021, Number of Pages: 200, Number of Words: 6, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

31B8BB512A0F8C74461B4C6AE28CC5EF

SHA1:

F36BE96E0F28EDFCC5A232E9C4DFCDAD0E94C151

SHA256:

7FF41B06CA3F24829BAF4F67BC669BE8421F70895DC1734B24948BD5F74BEAF4

SSDEEP:

12288:0s+WC8R/Mn4c6b3Diy95fP701DpHyNRAX7PaeAkCP437+8jOZy2KsGU6a4Ks:WWrBMnsO85fP701DhyHreAzgLhOE2Z39

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • msiexec.exe (PID: 3744)
    • Executed as Windows Service

      • msiexec.exe (PID: 3744)
      • vssvc.exe (PID: 1036)
      • AteraAgent.exe (PID: 2872)
    • Reads Environment values

      • vssvc.exe (PID: 1036)
      • AteraAgent.exe (PID: 2872)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3744)
      • msiexec.exe (PID: 1388)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3744)
      • msiexec.exe (PID: 1388)
    • Application launched itself

      • msiexec.exe (PID: 3744)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3744)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3744)
    • Creates files in the program directory

      • msiexec.exe (PID: 3744)
      • AteraAgent.exe (PID: 2940)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3744)
    • Checks supported languages

      • AteraAgent.exe (PID: 2940)
      • AteraAgent.exe (PID: 2872)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 3744)
    • Reads the computer name

      • AteraAgent.exe (PID: 2872)
      • AteraAgent.exe (PID: 2940)
    • Creates files in the Windows directory

      • AteraAgent.exe (PID: 2940)
    • Starts SC.EXE for service management

      • AteraAgent.exe (PID: 2872)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 1388)
      • msiexec.exe (PID: 3744)
      • vssvc.exe (PID: 1036)
      • MsiExec.exe (PID: 2372)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1388)
      • msiexec.exe (PID: 3744)
    • Checks supported languages

      • msiexec.exe (PID: 1388)
      • msiexec.exe (PID: 3744)
      • MsiExec.exe (PID: 2372)
      • vssvc.exe (PID: 1036)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 1388)
      • msiexec.exe (PID: 3744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: AteraAgent
Author: Atera networks
Keywords: Installer
Comments: This installer database contains the logic and data required to install AteraAgent.
Template: Intel;1033
RevisionNumber: {9DEB3F55-79C3-4C80-BCDC-D8B5B53D0787}
CreateDate: 2021:07:14 09:04:10
ModifyDate: 2021:07:14 09:04:10
Pages: 200
Words: 6
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs ateraagent.exe no specs ateraagent.exe sc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1036C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft� Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1388"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\a.msi"C:\Windows\System32\msiexec.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1876"C:\Windows\System32\sc.exe" failure AteraAgent reset= 600 actions= restart/25000C:\Windows\System32\sc.exeAteraAgent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2372C:\Windows\system32\MsiExec.exe -Embedding 8112B7DCF396F8893422A75C2952A3C0C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2872"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe
services.exe
User:
SYSTEM
Company:
ATERA Networks Ltd.
Integrity Level:
SYSTEM
Description:
AteraAgent
Exit code:
0
Version:
1.8.0.14
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\program files\atera networks\ateraagent\ateraagent.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2940"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe" /i /IntegratorLogin="andreyar5ye@yahoo.com" /CompanyId="1" /IntegratorLoginUI="" /CompanyIdUI="" /FolderId="" /AccountId="0013z00002jA9QEAA0"C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exemsiexec.exe
User:
admin
Company:
ATERA Networks Ltd.
Integrity Level:
MEDIUM
Description:
AteraAgent
Exit code:
0
Version:
1.8.0.14
Modules
Images
c:\program files\atera networks\ateraagent\ateraagent.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
3744C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 668
Read events
6 406
Write events
250
Delete events
12

Modification events

(PID) Process:(1388) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3744) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000E040D5BB18CAD701A00E000098090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3744) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000003AA3D7BB18CAD701A00E000098090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3744) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
67
(PID) Process:(3744) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000007AEE23BC18CAD701A00E000098090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3744) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D45026BC18CAD701A00E000074010000E803000001000000000000000000000033CC43ECE9C39244AE642E9CA306FBFA0000000000000000
(PID) Process:(1036) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000088152BBC18CAD7010C040000380C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1036) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000E2772DBC18CAD7010C040000700B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1036) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000E2772DBC18CAD7010C040000600D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1036) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000E2772DBC18CAD7010C040000380D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
4
Suspicious files
6
Text files
1
Unknown types
3

Dropped files

PID
Process
Filename
Type
3744msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3744msiexec.exeC:\Program Files\ATERA Networks\AteraAgent\PubNub-Messaging.dll
MD5:
SHA256:
3744msiexec.exeC:\Windows\Installer\97032.msiexecutable
MD5:
SHA256:
3744msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFCB2D225C092D10CA.TMPgmc
MD5:
SHA256:
3744msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{ec43cc33-c3e9-4492-ae64-2e9ca306fbfa}_OnDiskSnapshotPropbinary
MD5:
SHA256:
3744msiexec.exeC:\Windows\Installer\97033.ipibinary
MD5:
SHA256:
3744msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
3744msiexec.exeC:\Windows\Installer\MSI763D.tmpbinary
MD5:
SHA256:
3744msiexec.exeC:\Windows\Installer\MSI764E.tmpexecutable
MD5:A3AE5D86ECF38DB9427359EA37A5F646
SHA256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
3744msiexec.exeC:\Windows\Installer\SourceHash{91854F72-27A1-40DA-A725-D3517E127C0D}binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
49
DNS requests
36
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.37.43.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEHhvSYT5N0gvTTb3x7RJTGs%3D
NL
der
1.47 Kb
shared
POST
107.22.247.100:80
http://ds1.devicevm.com/
US
suspicious
2872
AteraAgent.exe
GET
200
104.18.10.39:80
http://cacerts.thawte.com/ThawteRSACA2018.crt
US
der
1.14 Kb
whitelisted
GET
200
13.107.4.50:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7f48e875eb14dd80
US
compressed
4.70 Kb
whitelisted
GET
301
3.211.32.119:80
http://sn.splashtop.com/file_system/apt_repository/dists/ProtoSSU01/released/binary-i386/Packages.gz
US
html
134 b
unknown
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.52 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
Microsoft Corporation
GB
whitelisted
2872
AteraAgent.exe
40.119.152.241:443
agent-api.atera.com
Microsoft Corporation
US
suspicious
2872
AteraAgent.exe
54.93.254.236:443
ps.pndsn.com
Amazon.com, Inc.
DE
suspicious
54.93.254.235:443
ps.pndsn.com
Amazon.com, Inc.
DE
unknown
13.107.246.45:443
ps.atera.com
Microsoft Corporation
US
malicious
54.93.254.236:443
ps.pndsn.com
Amazon.com, Inc.
DE
suspicious
40.119.152.241:443
agent-api.atera.com
Microsoft Corporation
US
suspicious
2872
AteraAgent.exe
104.18.10.39:80
cacerts.thawte.com
Cloudflare Inc
US
shared
13.69.106.3:443
atera-agent-heartbeat.servicebus.windows.net
Microsoft Corporation
NL
unknown
152.199.23.209:443
api.nuget.org
MCI Communications Services, Inc. d/b/a Verizon Business
US
suspicious

DNS requests

Domain
IP
Reputation
agent-api.atera.com
  • 40.119.152.241
suspicious
cacerts.thawte.com
  • 104.18.10.39
  • 104.18.11.39
whitelisted
ps.pndsn.com
  • 54.93.254.236
  • 54.93.254.235
suspicious
ps.atera.com
  • 13.107.246.45
  • 13.107.213.45
suspicious
my.splashtop.com
  • 13.57.80.176
  • 54.176.213.229
suspicious
atera-agent-heartbeat.servicebus.windows.net
  • 13.69.106.3
  • 52.236.186.4
  • 13.69.64.4
unknown
api.nuget.org
  • 152.199.23.209
whitelisted
download.splashtop.com
  • 18.66.112.54
  • 18.66.112.114
  • 18.66.112.86
  • 18.66.112.4
suspicious
ctldl.windowsupdate.com
  • 13.107.4.50
whitelisted
s2.symcb.com
  • 23.37.43.27
whitelisted

Threats

Found threats are available for the paid subscriptions
11 ETPRO signatures available at the full report
No debug info