File name:

hamachi.msi

Full analysis: https://app.any.run/tasks/37c24912-574f-44e1-ac28-1af5cc23fe4b
Verdict: Malicious activity
Analysis date: January 23, 2024, 13:02:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Hamachi Installer, Author: LogMeIn, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Hamachi., Template: ;1033, Number of Pages: 200, Number of Words: 2, Security: 2, Revision Number: {6B7DAA44-747B-45EB-9E86-0EF63D3D8A2D}, Create Time/Date: Mon Nov 6 11:52:41 2023, Last Saved Time/Date: Mon Nov 6 11:52:41 2023, Name of Creating Application: Windows Installer XML v2.0.5805.0 (candle/light)
MD5:

A44011365AB1EEE08BC055879967058C

SHA1:

17EB9E944AD9CF0FFD68BD3FA61E43F4FB14A88D

SHA256:

9D933EFB6C74180A8BE55C42F7FE9B58BC9F92E2B3217750796D547803DCACC3

SSDEEP:

98304:+u8eueXuHc5VLHlGoFJahcc2qCHdlrHmtscQLGtaF9qEH2Dr9h7LSH3j90IdKSFW:W0uqyhfgM2R14FTQPbT2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2568)
    • Creates a writable file in the system directory

      • LMIGuardianSvc.exe (PID: 292)
  • SUSPICIOUS

    • Executes as Windows Service

      • hamachi-2.exe (PID: 3968)
      • LMIGuardianSvc.exe (PID: 292)
      • hamachi-2.exe (PID: 3936)
    • Suspicious use of NETSH.EXE

      • hamachi-2.exe (PID: 3936)
    • Connects to unusual port

      • hamachi-2.exe (PID: 3936)
  • INFO

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2568)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2568)
    • Checks supported languages

      • LMIGuardianSvc.exe (PID: 3644)
      • hamachi-2.exe (PID: 3968)
      • LMIGuardianSvc.exe (PID: 3868)
      • LMIGuardianSvc.exe (PID: 292)
      • hamachi-2.exe (PID: 3936)
      • LMIGuardianSvc.exe (PID: 3960)
      • LMIGuardianSvc.exe (PID: 1392)
      • wmpnscfg.exe (PID: 3284)
      • wmpnscfg.exe (PID: 2900)
      • wmpnscfg.exe (PID: 2904)
      • wmpnscfg.exe (PID: 2768)
      • wmpnscfg.exe (PID: 3376)
      • wmpnscfg.exe (PID: 3588)
      • wmpnscfg.exe (PID: 3596)
      • wmpnscfg.exe (PID: 3612)
      • hamachi-2-ui.exe (PID: 3752)
      • LMIGuardianSvc.exe (PID: 3644)
    • Reads the computer name

      • LMIGuardianSvc.exe (PID: 3644)
      • hamachi-2.exe (PID: 3968)
      • LMIGuardianSvc.exe (PID: 3868)
      • LMIGuardianSvc.exe (PID: 292)
      • hamachi-2.exe (PID: 3936)
      • LMIGuardianSvc.exe (PID: 1392)
      • wmpnscfg.exe (PID: 3284)
      • wmpnscfg.exe (PID: 2900)
      • LMIGuardianSvc.exe (PID: 3960)
      • wmpnscfg.exe (PID: 3376)
      • wmpnscfg.exe (PID: 2768)
      • wmpnscfg.exe (PID: 3588)
      • wmpnscfg.exe (PID: 3596)
      • wmpnscfg.exe (PID: 3612)
      • wmpnscfg.exe (PID: 2904)
      • hamachi-2-ui.exe (PID: 3752)
      • LMIGuardianSvc.exe (PID: 3644)
    • Reads the machine GUID from the registry

      • LMIGuardianSvc.exe (PID: 3868)
      • hamachi-2.exe (PID: 3968)
      • LMIGuardianSvc.exe (PID: 292)
      • hamachi-2.exe (PID: 3936)
      • LMIGuardianSvc.exe (PID: 1392)
      • LMIGuardianSvc.exe (PID: 3960)
      • LMIGuardianSvc.exe (PID: 3644)
    • Creates files or folders in the user directory

      • LMIGuardianSvc.exe (PID: 1392)
      • hamachi-2-ui.exe (PID: 3752)
      • LMIGuardianSvc.exe (PID: 3644)
    • Creates files in the program directory

      • LMIGuardianSvc.exe (PID: 1392)
      • LMIGuardianSvc.exe (PID: 292)
      • LMIGuardianSvc.exe (PID: 3644)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3284)
      • wmpnscfg.exe (PID: 2900)
      • wmpnscfg.exe (PID: 3376)
      • wmpnscfg.exe (PID: 2768)
      • wmpnscfg.exe (PID: 3588)
      • wmpnscfg.exe (PID: 3596)
      • wmpnscfg.exe (PID: 3612)
      • hamachi-2-ui.exe (PID: 3752)
      • wmpnscfg.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Hamachi Installer
Author: LogMeIn, Inc.
Keywords: Installer
Comments: This installer database contains the logic and data required to install Hamachi.
Template: ;1033
Pages: 200
Words: 2
Security: Read-only recommended
RevisionNumber: {6B7DAA44-747B-45EB-9E86-0EF63D3D8A2D}
CreateDate: 2023:11:06 11:52:41
ModifyDate: 2023:11:06 11:52:41
Software: Windows Installer XML v2.0.5805.0 (candle/light)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
83
Monitored processes
25
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe netsh.exe no specs netsh.exe no specs rundll32.exe no specs lmiguardiansvc.exe no specs hamachi-2.exe no specs lmiguardiansvc.exe no specs lmiguardiansvc.exe no specs hamachi-2.exe lmiguardiansvc.exe no specs lmiguardiansvc.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs netsh.exe no specs wmpnscfg.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs hamachi-2-ui.exe no specs lmiguardiansvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe"C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exeservices.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LMIGuardianSvc
Exit code:
0
Version:
10.1.1742
Modules
Images
c:\program files\logmein hamachi\lmiguardiansvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\logmein hamachi\lmiguardiandll.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
476netsh interface ipv6 delete route ::/0 "18"C:\Windows\System32\netsh.exehamachi-2.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1392"C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe" /escort 1040 /CUSTOM Hamachi C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exehamachi-2-ui.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LMIGuardianSvc
Exit code:
0
Version:
10.1.1742
Modules
Images
c:\program files\logmein hamachi\lmiguardiansvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\logmein hamachi\lmiguardiandll.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
2568"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\hamachi.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2768netsh.exe interface set interface name="Local Area Connection" newname="Hamachi"C:\Windows\System32\netsh.exehamachi-2.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2768"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2900"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2904"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3096netsh interface ipv4 set subinterface "Local Area Connection" mtu=1404 store=persistentC:\Windows\System32\netsh.exehamachi-2.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3284"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 431
Read events
10 060
Write events
364
Delete events
7

Modification events

(PID) Process:(2568) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3096) netsh.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2768) netsh.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2768) netsh.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\Interfaces
Operation:writeName:Stamp
Value:
0
(PID) Process:(3968) hamachi-2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\LogMeIn Hamachi
Operation:writeName:EngineConfigDir
Value:
C:\Windows\ServiceProfiles\LocalService\AppData\Local\LogMeIn Hamachi
(PID) Process:(3936) hamachi-2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\LogMeIn Hamachi
Operation:delete valueName:NoLaunchUi
Value:
1
(PID) Process:(3936) hamachi-2.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3936) hamachi-2.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network
Operation:writeName:Config
Value:
00000000290000009ACF75E4CD603944A75F0079CE0E18A104000000280004006D0073005F006E006100740069007600650077006900660069007000000000006CCD24EA7AD14843919009F0D5BE83DD04000000380004006D0073005F006E006400690073006300610070000000000059D6F4B5AA7D65458E41BE220ED6054204000000000004006D0073005F007000610063006500720000000000ADDBF00363C9B44E8510DD8D23454D8504000000000000006D0073005F0073006500720076006500720000000000424A88E44D401E44B92D87ACC91B423A04000000280000006D0073005F006E0065007400620069006F0073000000000060640DB73536424DB866B8AB1A24454C04000000280004006D0073005F007700660070006C00770066000000000080DA583DBFC6E743BADFF8507CE87E6F04000000280000006D0073005F0073007400650065006C00680065006100640000000000D76E3ECCD1ADFE4F854F3B251964AB4104000000380000006D0073005F007200610073007300720076000000000087D008DF079564429B6AD0241B9C64F204000000280000006D0073005F007200610073006D0061006E00000000002D41A29FBB41DC47BE2AC2EE75DD6C9303000000800000006D0073005F006D00730063006C00690065006E0074000000000099E0C8DD2CEA82498D51E673D8E7AC5402000000380000006D0073005F006100670069006C006500760070006E00000000000E3E686B05158C4880533C130192424602000000280000006D0073005F007400630070006900700036005F00740075006E006E0065006C0000000000560047BF3A28A040A1C836E8D5E72A7602000000280000006D0073005F00740063007000690070005F00740075006E006E0065006C0000000000D32BDFDFCEED944D91E731408881A23D02000000280000006D0073005F0073006D006200000000006394CBA6C935C34594DD42006E3C9A8002000000280000006D0073005F00770061006E006100720070000000000071633A19E2DD57478153A3C2C55EFF3602000000380000006D0073005F006E0065007400620074005F0073006D006200000000000163140A8BC6C04D84F6A02EDF12ED4602000000280000006D0073005F006E006500740062007400000000006DC6A7C577B02944973E090595A1542002000000A00000006D0073005F0074006300700069007000360000000000AE9BFAEC1E9559418A498069BE7A432902000000A00000006D0073005F0074006300700069007000000000008B20975E78ADEF46A34A26B63A516CE202000000000000006D0073005F006C006C007400640069006F000000000094F95C1AE12A554DA5BAC17A8E87BACD02000000000000006D0073005F007200730070006E006400720000000000453EE841D97264448C8112DC566D8B6D02000000280000006D0073005F00770061006E006100720070007600360000000000E34A0E147D8C2342A0B703DB211BD01102000000280000006D0073005F007000700070006F00650000000000D32EE90C8768A84E896A9B2ACE69803E02000000380000006D0073005F0070007000740070000000000080278ED9898B6349A89825C4BFF052AE02000000380000006D0073005F006C00320074007000000000009E7545D2D4324C48B5F725AC540AEDBE02000000280000006D0073005F006E00640069007300770061006E0000000000BB1F72F960D91B4B864A13FCD9F21DA502000000380000006D0073005F00730073007400700000000000169AE61FB92EA6479174119B884BD11002000000280000006D0073005F006E00640069007300750069006F00000000000DBE8087DA3E464D8D4BEF6DCC7373D100000000090000002A00690073006100740061007000000052004F004F0054005C002A004900530041005400410050005C00300030003000310000006011B34F7A8BA242A889EB54300CD4A20000000001000000680061006D006100630068006900000052004F004F0054005C004E00450054005C0030003000300030000000B12F4A710F11E9488FF6BF268E6EED0600000000090000002A00690073006100740061007000000052004F004F0054005C002A004900530041005400410050005C003000300030003000000000CF40403E1B6A48B407FA14C56B6FC000000000840000007000630069005C00760065006E005F00380030003800360026006400650076005F00310030003000650000005000430049005C00560045004E005F00380030003800360026004400450056005F00310030003000450026005300550042005300590053005F003100310030003000310041004600340026005200450056005F00300033005C003300260031003300430030004200300043003500260030002600310038000000614CB1DC0D69F7468A89150432FA5C4400000000290000006D0073005F006100670069006C006500760070006E006D0069006E00690070006F0072007400000052004F004F0054005C004D0053005F004100470049004C004500560050004E004D0049004E00490050004F00520054005C003000300030003000000020A2F8E288AF6C449A55453E58DD3A33000000002A000000730077005C007B00650065006100620037003700390030002D0063003500310034002D0031003100640031002D0062003400320062002D003000300038003000350066006300310032003700300065007D000000530057005C007B00450045004100420037003700390030002D0043003500310034002D0031003100440031002D0042003400320042002D003000300038003000350046004300310032003700300045007D005C004100530059004E0043004D00410043000000F053567C4A1434459E3428AC99CBA85E00000000290000006D0073005F006E00640069007300770061006E0069007000000052004F004F0054005C004D0053005F004E00440049005300570041004E00490050005C0030003000300030000000A997DD7244E5154988D844E829C34F6800000000290000006D0073005F006E00640069007300770061006E0062006800000052004F004F0054005C004D0053005F004E00440049005300570041004E00420048005C0030003000300030000000059822F39E869E47BA76DD643F1D1B8000000000290000006D0073005F006E00640069007300770061006E006900700076003600000052004F004F0054005C004D0053005F004E00440049005300570041004E0049005000560036005C003000300030003000000079422BDBCFB526469DBA32D0ECE44C8700000000290000006D0073005F007000700070006F0065006D0069006E00690070006F0072007400000052004F004F0054005C004D0053005F005000500050004F0045004D0049004E00490050004F00520054005C0030003000300030000000383EDEC0A78B9F478B75833F294C5AA800000000290000006D0073005F0070007000740070006D0069006E00690070006F0072007400000052004F004F0054005C004D0053005F0050005000540050004D0049004E00490050004F00520054005C0030003000300030000000F89F3C483D504B41B402E4C1F1F568CB00000000290000006D0073005F006C003200740070006D0069006E00690070006F0072007400000052004F004F0054005C004D0053005F004C003200540050004D0049004E00490050004F00520054005C00300030003000300000006F898DE2A89E3A439C1066C97C19A92100000000290000006D0073005F0073007300740070006D0069006E00690070006F0072007400000052004F004F0054005C004D0053005F0053005300540050004D0049004E00490050004F00520054005C00300030003000300000000000000030000000050000001D000000050000001F000000010000001D000000010000001F000000020000001D000000020000001F000000020000002200000002000000230000000200000024000000030000000D00000003000000120000000300000011000000030000000F00000003000000100000000400000010000000090000000D00000009000000120000000900000011000000090000000F00000009000000100000000B0000001C0000000B0000001E0000001B0000001D0000001B0000001F000000160000001D000000160000001F000000140000001D000000140000001F000000130000001D000000130000001F000000120000001F000000120000001D000000110000001C000000110000001D000000110000001E000000110000001F0000000D000000120000000D000000110000000E000000220000001000000012000000100000001100000015000000240000001900000020000000190000002100000019000000250000001900000026000000190000002700000019000000280000000400000002000000010000001F00000002000000010000001D00000002000000110000001D00000002000000020000001D0000001C000000000000000100000000000000000000000100000001000000000000000000000002000000010000000000000000000000030000000100000000000000000000000400000001000000010000000900000000000000050000000100000000000000000000000600000001000000010000000700000000000000070000000100000000000000000000000800000001000000010000001900000000000000090000000100000000000000000000000A0000000100000000000000000000000B0000000100000000000000000000000C0000000100000000000000000000000D0000000100000000000000000000000E000000000000000100000022000000000000000F0000000000000001000000120000000000000010000000000000000100000012000000000000001100000001000000010000001200000000000000120000000100000000000000000000001300000001000000000000000000000014000000010000000000000000000000150000000000000001000000240000000000000016000000010000000000000000000000170000000100000000000000000000001800000001000000000000000000000019000000010000000100000006000000000000001A0000000100000000000000000000001B000000010000000000000000000000
(PID) Process:(3936) hamachi-2.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Linkage
Operation:writeName:Bind
Value:
\Device\{4040CF00-1B3E-486A-B407-FA14C56B6FC0}
(PID) Process:(3936) hamachi-2.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Linkage
Operation:writeName:Route
Value:
"{4040CF00-1B3E-486A-B407-FA14C56B6FC0}"
Executable files
6
Suspicious files
5
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
2568msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIBDE2.tmpexecutable
MD5:571C9E902F85252BC7A1B2CFB7A7BD27
SHA256:79252837D553EDD9DF816D3959D48E127740D6C21D24B0ADE6605EDC31639830
2568msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC8B0.tmpexecutable
MD5:571C9E902F85252BC7A1B2CFB7A7BD27
SHA256:79252837D553EDD9DF816D3959D48E127740D6C21D24B0ADE6605EDC31639830
2568msiexec.exeC:\Users\admin\AppData\Local\Temp\MSID0DF.tmpexecutable
MD5:571C9E902F85252BC7A1B2CFB7A7BD27
SHA256:79252837D553EDD9DF816D3959D48E127740D6C21D24B0ADE6605EDC31639830
2568msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI9837.tmpexecutable
MD5:571C9E902F85252BC7A1B2CFB7A7BD27
SHA256:79252837D553EDD9DF816D3959D48E127740D6C21D24B0ADE6605EDC31639830
2568msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI9886.tmpexecutable
MD5:571C9E902F85252BC7A1B2CFB7A7BD27
SHA256:79252837D553EDD9DF816D3959D48E127740D6C21D24B0ADE6605EDC31639830
3936hamachi-2.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\LogMeIn Hamachi\h2-engine.cfg.updatingtext
MD5:0F81D52E06CAAA4860887488D18271C7
SHA256:27EB5E51506C911F6FC4BB345C0D9DB6F60415FCEAB7C18E1E9B862637415777
3968hamachi-2.exeC:\Windows\TEMP\HamachiSetup.logtext
MD5:535871CCDF79828AF5E34051485E508D
SHA256:77978D55EEB2B104C3016E35BEDA0E17C6A443FA0AA48B286CCE992043C98AFC
3936hamachi-2.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\LogMeIn Hamachi\h2-engine.ini.baktext
MD5:E723DFE4E5BF655B6586CD4BE8937BC1
SHA256:1C89F654F433102B00A9D74C203FC228D016D7A3A2F864F6517FA43806AF4913
3936hamachi-2.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\LogMeIn Hamachi\h2-engine.id.baktext
MD5:C9216E1F7835ED67FEB70D8A52655556
SHA256:94EECE9A4942A47EB72CAF2210119EA899D3F6DE5F4668C4925CDA8CFA8F864C
3936hamachi-2.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\LogMeIn Hamachi\h2-engine.cfg.baktext
MD5:5919A4242A1FB169C68317D18ADF2746
SHA256:7E5ADB2F62EB88481057A6E469ED552B15BEEA681C3CC4AB37C96B458D1969BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
58
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1040
hamachi-2-ui.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbd7b2fbd4bac8f1
unknown
unknown
1040
hamachi-2-ui.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f8b33b8966d033f9
unknown
unknown
1040
hamachi-2-ui.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1040
hamachi-2-ui.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
1040
hamachi-2-ui.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
1040
hamachi-2-ui.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
1040
hamachi-2-ui.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
1040
hamachi-2-ui.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD7vSzSbK8Z0QnHSrEZ7mPf
unknown
binary
472 b
unknown
1080
svchost.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?663a78a3b1d15987
unknown
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?aab46216fbac899d
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3936
hamachi-2.exe
158.120.16.67:12975
ORACLE-BMC-31898
DE
unknown
3936
hamachi-2.exe
239.255.255.250:1900
whitelisted
1040
hamachi-2-ui.exe
158.120.16.74:443
secure.logmein.com
ORACLE-BMC-31898
DE
unknown
1040
hamachi-2-ui.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1040
hamachi-2-ui.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1040
hamachi-2-ui.exe
23.45.104.48:443
accounts.logme.in
AKAMAI-AS
DE
unknown
1040
hamachi-2-ui.exe
152.199.19.161:443
az416426.vo.msecnd.net
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
hamachi-data-center.logmein-gateway.com
  • 216.219.114.24
unknown
hamachi-list.24.logmein-gateway.com
unknown
secure.logmein.com
  • 158.120.16.74
unknown
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
accounts.logme.in
  • 23.45.104.48
unknown
az416426.vo.msecnd.net
  • 152.199.19.161
whitelisted
ssl.google-analytics.com
  • 142.250.185.168
whitelisted
www.googletagmanager.com
  • 142.250.186.104
whitelisted
ocsp.pki.goog
  • 142.250.186.163
whitelisted

Threats

No threats detected
No debug info