File name:

microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe

Full analysis: https://app.any.run/tasks/54e2d08d-c888-4403-9c00-f03d4f5888b6
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 01, 2024, 03:31:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
netreactor
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7D0AC5C013C5860386A1DAC2C692AD4E

SHA1:

E4AB24EA96C8052F26C19594CACB6CC4016D5A5C

SHA256:

83F651888F23C36B152ABFEDE10EABD693D02E6638FB20EA2E783A7007B0F900

SSDEEP:

98304:T+cD4dn4W33TWpPoDaO9Uus0tGL5sFhkLnehWJEVfltjtYedsvCIDoUdAyviV3lg:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • UnifiedStub-installer.exe (PID: 5880)
    • The DLL Hijacking

      • Teams.exe (PID: 3292)
      • Teams.exe (PID: 4008)
    • Changes the autorun value in the registry

      • Teams.exe (PID: 4448)
      • rundll32.exe (PID: 608)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Update.exe (PID: 4132)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 3316)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 6172)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • gyhr4liz.exe (PID: 5712)
      • UnifiedStub-installer.exe (PID: 5880)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
      • Update.exe (PID: 4132)
    • Reads security settings of Internet Explorer

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 6804)
      • component0.exe (PID: 488)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • Update.exe (PID: 4132)
      • Teams.exe (PID: 4448)
      • rsWSC.exe (PID: 2040)
      • UnifiedStub-installer.exe (PID: 5880)
      • rsEngineSvc.exe (PID: 6736)
    • Reads the date of Windows installation

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 6804)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • Update.exe (PID: 4132)
    • Drops the executable file immediately after the start

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 3316)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 6172)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • gyhr4liz.exe (PID: 5712)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
      • Update.exe (PID: 4132)
    • Reads the Windows owner or organization settings

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
    • Process drops legitimate windows executable

      • gyhr4liz.exe (PID: 5712)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
      • Update.exe (PID: 4132)
      • UnifiedStub-installer.exe (PID: 5880)
    • Searches for installed software

      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 4132)
    • Creates a software uninstall entry

      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 4132)
    • Executes as Windows Service

      • rsSyncSvc.exe (PID: 1812)
      • rsWSC.exe (PID: 6688)
      • rsClientSvc.exe (PID: 6816)
    • The process drops C-runtime libraries

      • Update.exe (PID: 4132)
      • UnifiedStub-installer.exe (PID: 5880)
    • Executes application which crashes

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
    • Application launched itself

      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 4448)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5656)
      • regsvr32.exe (PID: 1752)
    • The process creates files with name similar to system file names

      • UnifiedStub-installer.exe (PID: 5880)
    • Drops a system driver (possible attempt to evade defenses)

      • UnifiedStub-installer.exe (PID: 5880)
    • Drops 7-zip archiver for unpacking

      • UnifiedStub-installer.exe (PID: 5880)
    • Checks Windows Trust Settings

      • UnifiedStub-installer.exe (PID: 5880)
      • rsWSC.exe (PID: 2040)
      • rsEngineSvc.exe (PID: 6736)
    • Adds/modifies Windows certificates

      • UnifiedStub-installer.exe (PID: 5880)
    • Uses RUNDLL32.EXE to load library

      • UnifiedStub-installer.exe (PID: 5880)
    • Creates files in the driver directory

      • UnifiedStub-installer.exe (PID: 5880)
    • Creates or modifies Windows services

      • rundll32.exe (PID: 608)
      • UnifiedStub-installer.exe (PID: 5880)
    • Uses WEVTUTIL.EXE to install publishers and event logs from the manifest

      • UnifiedStub-installer.exe (PID: 5880)
  • INFO

    • Checks supported languages

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 3316)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 6804)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 6172)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • gyhr4liz.exe (PID: 5712)
      • UnifiedStub-installer.exe (PID: 5880)
      • rsSyncSvc.exe (PID: 1812)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 1060)
      • Update.exe (PID: 4132)
      • rsSyncSvc.exe (PID: 5768)
      • Squirrel.exe (PID: 4604)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 3292)
      • Teams.exe (PID: 4448)
      • Teams.exe (PID: 4008)
      • Teams.exe (PID: 1556)
      • Teams.exe (PID: 7092)
      • Teams.exe (PID: 6416)
      • Teams.exe (PID: 5124)
      • Teams.exe (PID: 448)
      • Teams.exe (PID: 4084)
      • Teams.exe (PID: 6724)
      • rsWSC.exe (PID: 2040)
      • rsWSC.exe (PID: 6688)
      • rsClientSvc.exe (PID: 7132)
      • rsClientSvc.exe (PID: 6816)
      • rsEngineSvc.exe (PID: 6736)
    • Create files in a temporary directory

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 3316)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.exe (PID: 6172)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • gyhr4liz.exe (PID: 5712)
      • Update.exe (PID: 4132)
      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 4448)
      • UnifiedStub-installer.exe (PID: 5880)
    • Process checks computer location settings

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 6804)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • Update.exe (PID: 4132)
      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 4448)
      • Teams.exe (PID: 6416)
      • Teams.exe (PID: 5124)
      • Teams.exe (PID: 6724)
      • Teams.exe (PID: 4084)
    • Reads the computer name

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 6804)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • rsSyncSvc.exe (PID: 1812)
      • microsoft-teams-1.7.00.21751-installer.exe (PID: 1060)
      • Update.exe (PID: 4132)
      • rsSyncSvc.exe (PID: 5768)
      • Squirrel.exe (PID: 4604)
      • Teams.exe (PID: 6620)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 3292)
      • Teams.exe (PID: 4448)
      • Teams.exe (PID: 1556)
      • Teams.exe (PID: 4008)
      • Teams.exe (PID: 7092)
      • Teams.exe (PID: 448)
      • rsWSC.exe (PID: 2040)
      • rsWSC.exe (PID: 6688)
      • rsClientSvc.exe (PID: 7132)
      • rsClientSvc.exe (PID: 6816)
      • rsEngineSvc.exe (PID: 6736)
    • Reads the software policy settings

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • slui.exe (PID: 3140)
      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • WerFault.exe (PID: 7140)
      • WerFault.exe (PID: 6056)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 4448)
      • Update.exe (PID: 4132)
      • Squirrel.exe (PID: 4604)
      • slui.exe (PID: 6768)
      • rsWSC.exe (PID: 2040)
      • rsEngineSvc.exe (PID: 6736)
    • The process uses the downloaded file

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 4132)
      • runonce.exe (PID: 2724)
      • rsWSC.exe (PID: 2040)
      • rsEngineSvc.exe (PID: 6736)
    • Disables trace logs

      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 8)
      • Update.exe (PID: 4132)
      • Squirrel.exe (PID: 4604)
    • Reads Environment values

      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 4132)
      • Squirrel.exe (PID: 4604)
      • Teams.exe (PID: 6620)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 4448)
    • Checks proxy server information

      • component0.exe (PID: 488)
      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • UnifiedStub-installer.exe (PID: 5880)
      • WerFault.exe (PID: 6056)
      • WerFault.exe (PID: 7140)
      • Teams.exe (PID: 6620)
      • Update.exe (PID: 8)
      • Update.exe (PID: 4132)
      • Teams.exe (PID: 4448)
      • Squirrel.exe (PID: 4604)
      • slui.exe (PID: 6768)
      • rsWSC.exe (PID: 2040)
    • Reads the machine GUID from the registry

      • microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp (PID: 4980)
      • component0.exe (PID: 488)
      • UnifiedStub-installer.exe (PID: 5880)
      • Update.exe (PID: 4132)
      • Squirrel.exe (PID: 4604)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 4448)
      • rsWSC.exe (PID: 2040)
      • rsWSC.exe (PID: 6688)
      • rsEngineSvc.exe (PID: 6736)
    • Creates files in the program directory

      • UnifiedStub-installer.exe (PID: 5880)
      • rsWSC.exe (PID: 2040)
      • rsEngineSvc.exe (PID: 6736)
    • Manual execution by a user

      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
    • Creates files or folders in the user directory

      • microsoft-teams-1.7.00.21751-installer.exe (PID: 2016)
      • Update.exe (PID: 4132)
      • WerFault.exe (PID: 6056)
      • WerFault.exe (PID: 7140)
      • Squirrel.exe (PID: 4604)
      • Teams.exe (PID: 6620)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 4448)
      • Teams.exe (PID: 7092)
      • UnifiedStub-installer.exe (PID: 5880)
      • rsWSC.exe (PID: 2040)
    • Reads Microsoft Office registry keys

      • Update.exe (PID: 4132)
      • Squirrel.exe (PID: 4604)
      • Teams.exe (PID: 6620)
      • Update.exe (PID: 8)
      • Teams.exe (PID: 4448)
    • Reads CPU info

      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 4448)
    • Reads product name

      • Teams.exe (PID: 6620)
      • Teams.exe (PID: 4448)
    • .NET Reactor protector has been detected

      • UnifiedStub-installer.exe (PID: 5880)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 2724)
    • Reads the time zone

      • runonce.exe (PID: 2724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.40.1.8969
ProductVersionNumber: 2.40.1.8969
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 2.40.1.8969
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 3.1.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
191
Monitored processes
49
Malicious processes
12
Suspicious processes
2

Behavior graph

Click at the process to see the details
start microsoft-teams-1.7.00.21751-installer_xe-vk81.exe microsoft-teams-1.7.00.21751-installer_xe-vk81.tmp no specs microsoft-teams-1.7.00.21751-installer_xe-vk81.exe microsoft-teams-1.7.00.21751-installer_xe-vk81.tmp sppextcomobj.exe no specs slui.exe slui.exe component0.exe gyhr4liz.exe THREAT unifiedstub-installer.exe microsoft-teams-1.7.00.21751-installer.exe no specs rssyncsvc.exe no specs conhost.exe no specs rssyncsvc.exe no specs microsoft-teams-1.7.00.21751-installer.exe update.exe werfault.exe werfault.exe squirrel.exe teams.exe no specs update.exe teams.exe no specs teams.exe no specs teams.exe teams.exe no specs teams.exe teams.exe no specs teams.exe no specs teams.exe no specs teams.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs teams.exe no specs rundll32.exe runonce.exe no specs grpconv.exe no specs wevtutil.exe no specs conhost.exe no specs fltmc.exe no specs conhost.exe no specs wevtutil.exe no specs conhost.exe no specs rswsc.exe rswsc.exe no specs rsclientsvc.exe no specs conhost.exe no specs rsclientsvc.exe no specs rsenginesvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
8C:\Users\admin\AppData\Local\Microsoft\Teams\Update.exe --createShortcut=Teams.exe -l=StartMenuC:\Users\admin\AppData\Local\Microsoft\Teams\Update.exe
Teams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams classic
Exit code:
0
Version:
3.3.13.0
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
236C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
448"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --enable-wer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --mojo-platform-channel-handle=2784 --field-trial-handle=1496,i,11260290050542756122,870479897604509635,131072 --enable-features=ContextBridgeMutability,SharedArrayBuffer,WinUseBrowserSpellChecker,WinUseHybridSpellChecker --disable-features=CalculateNativeWinOcclusion,ExtraCookieValidityChecks,ForcedColors,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeTeams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Teams
Version:
1.7.00.21751
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
488"C:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\component0.exe" -ip:"dui=bb926e54-e3ca-40fd-ae90-2764341e7792&dit=20240901033129&is_silent=true&oc=ZB_RAV_Cross_Solo_Soft&p=fa70&a=100&b=&se=true" -iC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\component0.exe
microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
rsStubActivator
Version:
1.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9c6fm.tmp\component0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
608"C:\WINDOWS\system32\rundll32.exe" setupapi.dll,InstallHinfSection DefaultInstall 128 C:\Program Files\ReasonLabs\EPP\x64\rsKernelEngine.infC:\Windows\System32\rundll32.exe
UnifiedStub-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
1060"C:\Users\admin\Downloads\microsoft-teams-1.7.00.21751-installer.exe" C:\Users\admin\Downloads\microsoft-teams-1.7.00.21751-installer.exemicrosoft-teams-1.7.00.21751-installer_Xe-VK81.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Teams
Exit code:
0
Version:
1.7.00.21751
Modules
Images
c:\users\admin\downloads\microsoft-teams-1.7.00.21751-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1556"C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Teams" --mojo-platform-channel-handle=2184 --field-trial-handle=1832,i,7912423019529456999,6072863308246169849,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\Microsoft\Teams\current\Teams.exeTeams.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Teams
Exit code:
0
Version:
1.7.00.21751
Modules
Images
c:\users\admin\appdata\local\microsoft\teams\current\teams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\users\admin\appdata\local\microsoft\teams\current\ffmpeg.dll
1640"C:\WINDOWS\system32\wevtutil.exe" im C:\Program Files\ReasonLabs\EPP\x64\rsKernelEngineEvents.xmlC:\Windows\System32\wevtutil.exeUnifiedStub-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
87
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
1752"C:\WINDOWS\SysWOW64\regsvr32.exe" /s /n /i:user "C:\Users\admin\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.24192.2\x86\Microsoft.Teams.AddinLoader.dll"C:\Windows\SysWOW64\regsvr32.exeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1812"C:\Program Files\ReasonLabs\Common\rsSyncSvc.exe" -pn:EPP -lpn:rav_antivirus -url:https://update.reasonsecurity.com/v2/live -bn:ReasonLabs -dt:10C:\Program Files\ReasonLabs\Common\rsSyncSvc.exeservices.exe
User:
SYSTEM
Company:
Reason Software Company Inc.
Integrity Level:
SYSTEM
Description:
Reason Security Synchronize Service
Version:
1.8.5.0
Modules
Images
c:\program files\reasonlabs\common\rssyncsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
61 319
Read events
60 450
Write events
803
Delete events
66

Modification events

(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
7413000028BD0B671FFCDA01
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4332EE31470C39F7DE73E70FE945E0A03FE0A7CCE9292D031A71E5E874AFF124
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4980) microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(488) component0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(488) component0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(488) component0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\component0_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
738
Suspicious files
260
Text files
179
Unknown types
27

Dropped files

PID
Process
Filename
Type
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\is-LMOG1.tmp
MD5:
SHA256:
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\microsoft-teams-1.7.00.21751-installer.exe
MD5:
SHA256:
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\Downloads\microsoft-teams-1.7.00.21751-installer.exe
MD5:
SHA256:
3316microsoft-teams-1.7.00.21751-installer_Xe-VK81.exeC:\Users\admin\AppData\Local\Temp\is-0QBNP.tmp\microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpexecutable
MD5:AA3F5C7E680FC85A57710828D7359296
SHA256:95B43E16FEF63605D3EBF8E1161502923BF151E7AD4B0CFFD16D46B406D434E7
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\image.jpgimage
MD5:1D92925F59FD6DCD37606F69AE28C640
SHA256:CC904833699D9851A3CA7E1C739855BFDD7AC6CFA9442BC4CA3BA53818FD917D
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\is-PQPN4.tmpimage
MD5:1D92925F59FD6DCD37606F69AE28C640
SHA256:CC904833699D9851A3CA7E1C739855BFDD7AC6CFA9442BC4CA3BA53818FD917D
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\N.pngimage
MD5:1A01027365500D86730A737EB32CBF2A
SHA256:D79A97538B93179012A5EBEBDE873EDC18E30A0287953800F7AA7EA4F25724E1
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4980microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpC:\Users\admin\AppData\Local\Temp\is-9C6FM.tmp\100.pngimage
MD5:4167C79312B27C8002CBEEA023FE8CB5
SHA256:C3BF350627B842BED55E6A72AB53DA15719B4F33C267A6A132CB99FF6AFE3CD8
6172microsoft-teams-1.7.00.21751-installer_Xe-VK81.exeC:\Users\admin\AppData\Local\Temp\is-LS3M8.tmp\microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmpexecutable
MD5:AA3F5C7E680FC85A57710828D7359296
SHA256:95B43E16FEF63605D3EBF8E1161502923BF151E7AD4B0CFFD16D46B406D434E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
77
DNS requests
40
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3652
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7008
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7008
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2700
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBTDHsfuqfubd3pihvq4mgQVWgHWNwQUyH7SaoUqG8oZmAQHJ89QEE9oqKICEzMAAAAHh6M0o3uljhwAAAAAAAc%3D
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBTOQYLFSE5GO%2FpaRVfYu7d9gZEbQAQU2UEpsA8PY2zvadf1zSmepEhqMOYCEzMAAAAHN4xbodlbjNQAAAAAAAc%3D
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRBq81UG1MnDOVNKqff0SSEz6JuZwQU6IPEM9fcnwycdpoKptTfh6ZeWO4CEzMAAWTujc16eayoCZIAAAABZO4%3D
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRBq81UG1MnDOVNKqff0SSEz6JuZwQU6IPEM9fcnwycdpoKptTfh6ZeWO4CEzMAAWTujc16eayoCZIAAAABZO4%3D
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2001.crl
unknown
whitelisted
5880
UnifiedStub-installer.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6864
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3352
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6864
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4980
microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp
18.245.78.22:443
d25qho5rs4tpl0.cloudfront.net
US
whitelisted
4980
microsoft-teams-1.7.00.21751-installer_Xe-VK81.tmp
151.101.65.91:443
images.sftcdn.net
FASTLY
US
whitelisted
2120
MoUsoCoreWorker.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 52.140.118.28
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.14
whitelisted
d25qho5rs4tpl0.cloudfront.net
  • 18.245.78.22
  • 18.245.78.128
  • 18.245.78.68
  • 18.245.78.70
whitelisted
images.sftcdn.net
  • 151.101.65.91
  • 151.101.193.91
  • 151.101.129.91
  • 151.101.1.91
whitelisted
client.wns.windows.com
  • 40.115.3.253
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.20
  • 40.126.32.76
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.133
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
gsf-fl.softonic.com
  • 199.232.194.133
  • 199.232.198.133
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

No threats detected
Process
Message
Update.exe
Update.exe Information: 0 :
Update.exe
Starting TelemetryManager constructor
Update.exe
Update.exe Information: 0 :
Update.exe
TelemetryManagerImpl creation started
Update.exe
Update.exe Information: 0 :
Update.exe
Performance counters are disabled. Skipping creation of counters category.
Update.exe
Update.exe Information: 0 :
Update.exe
RecordBatcherTask with ID 4 started.
Update.exe
Update.exe Information: 0 :
Update.exe
DataPackageSender with UserAgent name: AST-exe-C#, version: 3.3.13.0, [Ast_Default_Source]