| File name: | setup.msi |
| Full analysis: | https://app.any.run/tasks/573debb2-f716-4599-90df-4957e108422d |
| Verdict: | Malicious activity |
| Analysis date: | March 29, 2024, 08:39:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: AteraAgent, Author: Atera networks, Keywords: Installer, Comments: This installer database contains the logic and data required to install AteraAgent., Template: Intel;1033, Revision Number: {721AD955-79FD-4019-BBF5-9DCC4C1175BB}, Create Time/Date: Wed Feb 28 10:52:02 2024, Last Saved Time/Date: Wed Feb 28 10:52:02 2024, Number of Pages: 200, Number of Words: 6, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2 |
| MD5: | CE1F52A3BC7007D5B7AF096B89B39252 |
| SHA1: | A575CAFD73FC9AB5E5D0D6AECA3341E5D05F7EFF |
| SHA256: | 91C4F308AEDBD3C2DD1B21C40A3393DE0BB5F0C6C28BA56F64F6BE8BDCCBF6D2 |
| SSDEEP: | 98304:4IZTffzvns6eLKLdpRwznfsJb+7J7ERXndiWaKzPtSjXmbABY/lT8vjkZBvrePVv:93XP9No |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | AteraAgent |
| Author: | Atera networks |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install AteraAgent. |
| Template: | Intel;1033 |
| RevisionNumber: | {721AD955-79FD-4019-BBF5-9DCC4C1175BB} |
| CreateDate: | 2024:02:28 10:52:02 |
| ModifyDate: | 2024:02:28 10:52:02 |
| Pages: | 200 |
| Words: | 6 |
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\AgentPackageMarketplace.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "dc459b92-576b-474e-9787-61cb31041b34" agent-api.atera.com/Production 443 or8ixLi90Mf "agentprovision" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMarketplace\AgentPackageMarketplace.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: AgentPackageMarketplace Exit code: 0 Version: 1.4.0.0 Modules
| |||||||||||||||
| 316 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\IdleTimeFinder.exe" | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageSystemTools\IdleTimeFinder.exe | — | AgentPackageSystemTools.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApp1 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 896 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "de26c503-58f1-4470-89b9-170817c13823" agent-api.atera.com/Production 443 or8ixLi90Mf "heartbeat" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageHeartbeat Exit code: 0 Version: 17.14.0.0 Modules
| |||||||||||||||
| 900 | "C:\Program Files\Splashtop\Splashtop Remote\Server\SRUtility.exe" -a "st-streamer://com.splashtop.streamer/?rmm_session_pwd=0253780d69c3859475ba972f16573df3&rmm_session_pwd_ttl=86400" | C:\Program Files\Splashtop\Splashtop Remote\Server\SRUtility.exe | — | AgentPackageSTRemote.exe | |||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop® Streamer Utility Exit code: 0 Version: 3.64.1.122 Modules
| |||||||||||||||
| 908 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "2aad265d-7143-4f81-b52e-34c02c89f0b5" agent-api.atera.com/Production 443 or8ixLi90Mf "minimalIdentification" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageAgentInformation Exit code: 0 Version: 36.3.0.0 Modules
| |||||||||||||||
| 908 | "C:\Program Files\Splashtop\Splashtop Remote\Server\SRManager.exe" | C:\Program Files\Splashtop\Splashtop Remote\Server\SRManager.exe | SRService.exe | ||||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop® Streamer SRManager Version: 3.64.1.122 Modules
| |||||||||||||||
| 912 | "C:\Program Files\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe" | C:\Program Files\Splashtop\Splashtop Remote\Server\SRVirtualDisplay.exe | — | SRManager.exe | |||||||||||
User: SYSTEM Company: Splashtop Inc. Integrity Level: SYSTEM Description: Splashtop Streamer Virtual Monitor Utility Version: 3.64.1.122 Modules
| |||||||||||||||
| 916 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "c886d556-165b-4d35-879d-38ba1ce59672" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: AgentPackageMonitoring Exit code: 0 Version: 36.4.0.0 Modules
| |||||||||||||||
| 992 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "6df87ade-9cdc-4cf5-bcf8-b62da233787f" agent-api.atera.com/Production 443 or8ixLi90Mf "syncprofile" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: AgentPackageMonitoring Exit code: 0 Version: 36.4.0.0 Modules
| |||||||||||||||
| 1028 | "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageServicesCommands\AgentPackageServicesCommands.exe" 211260b7-b550-4dfb-9f30-265314e81f24 "bc06f741-1428-4552-9738-acfc393459f8" agent-api.atera.com/Production 443 or8ixLi90Mf "query_services" 001Q300000AHAJlIAP | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageServicesCommands\AgentPackageServicesCommands.exe | AteraAgent.exe | ||||||||||||
User: SYSTEM Company: Atera Networks Integrity Level: SYSTEM Description: AgentPackageServicesCommands Exit code: 0 Version: 16.1.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4008) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005A2C81A4B481DA010C0A000074090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005A2C81A4B481DA010C0A0000840A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005A2C81A4B481DA010C0A0000A00D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005A2C81A4B481DA010C0A0000C40A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000B48E83A4B481DA010C0A0000840A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000000EF185A4B481DA010C0A000074090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000000EF185A4B481DA010C0A0000A00D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000000EF185A4B481DA010C0A0000C40A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2572) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Enter) |
Value: 4000000000000000D47773A6B481DA010C0A0000C40A000001040000010000000000000000000000F527F2C889F54D4083AAB092D1797F6B0000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation.zip | compressed | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe | executable | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe.config | xml | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.ini | text | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Atera.AgentPackage.Common.dll | executable | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\Newtonsoft.Json.dll | executable | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C56C4404C4DEF0DC88E5FCD9F09CB2F1 | binary | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Windows\system32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C56C4404C4DEF0DC88E5FCD9F09CB2F1 | binary | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring.zip | compressed | |
MD5:— | SHA256:— | |||
| 2640 | AteraAgent.exe | C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2760 | AteraAgent.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c42953dd5e0c3a4f | unknown | — | — | unknown |
2760 | AteraAgent.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | unknown |
2760 | AteraAgent.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | unknown |
2640 | AteraAgent.exe | GET | 200 | 192.229.221.95:80 | http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt | unknown | — | — | unknown |
2760 | AteraAgent.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAooSZl45YmN9AojjrilUug%3D | unknown | — | — | unknown |
3872 | AteraAgent.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAZ%2FYEeVZiSnFZlhdD2BlJM%3D | unknown | — | — | unknown |
908 | SRManager.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAx%2B7MjF4dH7UpJWotMQ8HE%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2488 | rundll32.exe | 40.119.152.241:443 | agent-api.atera.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
2760 | AteraAgent.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2760 | AteraAgent.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2640 | AteraAgent.exe | 40.119.152.241:443 | agent-api.atera.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
2956 | rundll32.exe | 40.119.152.241:443 | agent-api.atera.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
2640 | AteraAgent.exe | 35.157.63.227:443 | ps.pndsn.com | AMAZON-02 | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
agent-api.atera.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ps.pndsn.com |
| unknown |
ps.atera.com |
| unknown |
cacerts.digicert.com |
| whitelisted |
my.splashtop.com |
| unknown |
download.splashtop.com |
| unknown |
api.nuget.org |
| whitelisted |
atera-agent-heartbeat-cus.servicebus.windows.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
2904 | AgentPackageSTRemote.exe | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
2904 | AgentPackageSTRemote.exe | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
908 | SRManager.exe | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
908 | SRManager.exe | Misc activity | ET INFO Splashtop Domain (splashtop .com) in TLS SNI |
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
1080 | svchost.exe | Misc activity | ET INFO Splashtop Domain in DNS Lookup (splashtop .com) |
Process | Message |
|---|---|
AgentPackageMonitoring.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll"...
|
AgentPackageMonitoring.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll"...
|
AgentPackageMonitoring.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\x86\SQLite.Interop.dll"...
|
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUnPack::UnPackFiles] (1/5)UnPack file name:C:\Windows\TEMP\unpack\setup.msi (51506176) (Last=0) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUnPack::UnPackFiles] FreeSpace:233162358784 FileSize:51506176 (Last=0) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUnPack::FindHeader] Sign Size:10248 (Last=0) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUnPack::FindHeader] Header offset:434176 (Last=183) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUnPack::FindHeader] Name:C:\Windows\TEMP\SplashtopStreamer.exe (Last=0) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:51 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 (Last=0) |
SplashtopStreamer.exe | [3912]2024-03-29 08:41:52 [CUnPack::UnPackFiles] FreeSpace:233110847488 FileSize:1528 (Last=183) |