File name:

WiseCloudClientSetup.exe

Full analysis: https://app.any.run/tasks/a0521970-c1ff-4d77-85b4-e03da9d3abfd
Verdict: Malicious activity
Analysis date: March 09, 2021, 00:01:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

64D66E7AE07EDDC8842D2BBB7FAE98E5

SHA1:

62A0F834DF46A520E85F2BD0FF8CCC7249614A03

SHA256:

A0401C8FA7D274E9693C7A25F7A90D4BDAEB9742AD0971BEE2AD39019C19DEAE

SSDEEP:

98304:6EThIF1XrwzMtmq1YMnAOPdmlHGSyDEThIF1XrwzMtm2H8KoFWEr9aPdjHAKoFW/:C8qxIlHGSS8uoZ9afoZ9Lp+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • msiexec.exe (PID: 3372)
      • WiseCloudClient.exe (PID: 2500)
    • Loads the Task Scheduler DLL interface

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
    • Loads dropped or rewritten executable

      • CargoWise.ApplicationManager.Service.exe (PID: 3888)
      • WiseCloudClient.exe (PID: 2816)
      • WiseCloudClient.exe (PID: 2980)
      • WiseCloudClient.exe (PID: 2500)
    • Application was dropped or rewritten from another process

      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • CargoWise.ApplicationManager.Service.exe (PID: 3888)
      • WiseCloudClient.exe (PID: 2500)
      • WiseCloudClient.exe (PID: 2816)
      • WiseCloudClient.exe (PID: 2980)
    • Drops executable file immediately after starts

      • msiexec.exe (PID: 3372)
    • Writes to a start menu file

      • msiexec.exe (PID: 3372)
    • Loads the Task Scheduler COM API

      • ngen.exe (PID: 1344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • msiexec.exe (PID: 3372)
    • Adds / modifies Windows certificates

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • msiexec.exe (PID: 3372)
      • WiseCloudClient.exe (PID: 2500)
    • Drops a file that was compiled in debug mode

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • msiexec.exe (PID: 3372)
    • Creates files in the user directory

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • WiseCloudClient.exe (PID: 2816)
      • WiseCloudClient.exe (PID: 2500)
      • WiseCloudClient.exe (PID: 2980)
    • Creates files in the Windows directory

      • WiseCloudClientSetup.exe (PID: 2568)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • msiexec.exe (PID: 3372)
      • MSI238B.tmp (PID: 2944)
      • ngen.exe (PID: 1344)
    • Starts Microsoft Installer

      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • WiseCloudClientSetup.exe (PID: 2568)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3372)
    • Executed as Windows Service

      • CargoWise.ApplicationManager.Service.exe (PID: 3888)
    • Starts SC.EXE for service management

      • CargoWise.ApplicationManager.Service.exe (PID: 3888)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 3372)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 3372)
    • Changes default file association

      • msiexec.exe (PID: 3372)
    • Removes files from Windows directory

      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 2684)
      • WiseCloudClientSetup.exe (PID: 2568)
    • Reads Environment values

      • WiseCloudClient.exe (PID: 2500)
      • WiseCloudClient.exe (PID: 2816)
      • WiseCloudClient.exe (PID: 2980)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1216)
      • MsiExec.exe (PID: 1756)
      • MsiExec.exe (PID: 3716)
      • MsiExec.exe (PID: 3860)
      • msiexec.exe (PID: 3372)
      • MsiExec.exe (PID: 2812)
      • MsiExec.exe (PID: 1908)
      • MsiExec.exe (PID: 4068)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3372)
      • WiseCloudClientSetup.exe (PID: 2568)
    • Creates files in the program directory

      • msiexec.exe (PID: 3372)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 3372)
    • Application was dropped or rewritten from another process

      • MSI238B.tmp (PID: 2944)
      • MSI22BF.tmp (PID: 1504)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3372)
    • Application launched itself

      • msiexec.exe (PID: 3372)
    • Searches for installed software

      • msiexec.exe (PID: 3372)
    • Manual execution by user

      • WiseCloudClient.exe (PID: 2816)
      • WiseCloudClient.exe (PID: 2980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (21.4)
.exe | Win64 Executable (generic) (14.2)
.exe | Win32 Executable (generic) (2.3)
.exe | Generic Win/DOS Executable (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:10:26 17:31:42+02:00
PEType: PE32
LinkerVersion: 14.15
CodeSize: 1505792
InitializedDataSize: 703488
UninitializedDataSize: -
EntryPoint: 0x122273
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.5.1.0
ProductVersionNumber: 5.5.1.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: WiseTech Global
FileDescription: WiseCloud Client Installer
FileVersion: 5.5.1
InternalName: WiseCloudClientSetup
LegalCopyright: Copyright (C) 2020 WiseTech Global
OriginalFileName: WiseCloudClientSetup.exe
ProductName: WiseCloud Client
ProductVersion: 5.5.1

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 26-Oct-2018 15:31:42
Detected languages:
  • English - United States
Debug artifacts:
  • C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb
CompanyName: WiseTech Global
FileDescription: WiseCloud Client Installer
FileVersion: 5.5.1
InternalName: WiseCloudClientSetup
LegalCopyright: Copyright (C) 2020 WiseTech Global
OriginalFileName: WiseCloudClientSetup.exe
ProductName: WiseCloud Client
ProductVersion: 5.5.1

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000120

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 26-Oct-2018 15:31:42
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0016F9BF
0x0016FA00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.44031
.rdata
0x00171000
0x0005E736
0x0005E800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.55758
.data
0x001D0000
0x0000707C
0x00005400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.08035
.rsrc
0x001D8000
0x0002EE48
0x0002F000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.95848
.reloc
0x00207000
0x00018FB8
0x00019000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.57539

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.18998
1909
Latin 1 / Western European
English - United States
RT_MANIFEST
2
3.41628
67624
Latin 1 / Western European
English - United States
RT_ICON
3
2.48523
16936
Latin 1 / Western European
English - United States
RT_ICON
4
2.50251
9640
Latin 1 / Western European
English - United States
RT_ICON
5
2.58913
4264
Latin 1 / Western European
English - United States
RT_ICON
6
2.75612
1128
Latin 1 / Western European
English - United States
RT_ICON
9
3.37783
1116
Latin 1 / Western European
English - United States
RT_STRING
10
3.35254
1888
Latin 1 / Western European
English - United States
RT_STRING
11
3.31743
760
Latin 1 / Western European
English - United States
RT_STRING
12
3.23118
1432
Latin 1 / Western European
English - United States
RT_STRING

Imports

KERNEL32.dll
msi.dll (delay-loaded)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
22
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start wisecloudclientsetup.exe msiexec.exe no specs cargowiseoneremotedesktopservicessetup.exe msiexec.exe no specs msiexec.exe no specs cargowise.applicationmanager.service.exe no specs sc.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msi22bf.tmp no specs msi238b.tmp no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs ngen.exe no specs wisecloudclient.exe wisecloudclient.exe wisecloudclient.exe wisecloudclientsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1216C:\Windows\system32\MsiExec.exe -Embedding A1867DC177DD51B64ED6DE8E29A4CCD9 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1344C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "C:\Program Files\WiseTech Global\WiseCloud Client\WiseCloudClient.exe" /queue:3C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
1504"C:\Windows\Installer\MSI22BF.tmp" 2C:\Windows\Installer\MSI22BF.tmpmsiexec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\installer\msi22bf.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1756C:\Windows\system32\MsiExec.exe -Embedding 382E241717C21CD081A8F3D0F64254EA CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1908C:\Windows\system32\MsiExec.exe -Embedding C9D007C73E16F518348EFC33DC27A84CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2500"C:\Program Files\WiseTech Global\WiseCloud Client\WiseCloudClient.exe"C:\Program Files\WiseTech Global\WiseCloud Client\WiseCloudClient.exe
msiexec.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
WiseCloud Client
Exit code:
0
Version:
5.5.1
Modules
Images
c:\program files\wisetech global\wisecloud client\wisecloudclient.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2508"C:\Windows\System32\sc.exe" failure ediAppMgr reset= 0 actions= restart/180000/restart/180000/restart/180000C:\Windows\System32\sc.exeCargoWise.ApplicationManager.Service.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2532"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\WiseTech Global\CargoWise One Remote Desktop Services\install\CargoWiseOneRemoteDesktopServicesSetup.msi" /qn AI_SETUPEXEPATH="C:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\CargoWiseOneRemoteDesktopServicesSetup.exe" SETUPEXEDIR="C:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\" EXE_CMD_LINE="/exenoupdates /forcecleanup /qn " AI_EUIMSI=""C:\Windows\system32\msiexec.exeCargoWiseOneRemoteDesktopServicesSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2568"C:\Users\admin\AppData\Local\Temp\WiseCloudClientSetup.exe" C:\Users\admin\AppData\Local\Temp\WiseCloudClientSetup.exe
explorer.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
WiseCloud Client Installer
Exit code:
0
Version:
5.5.1
Modules
Images
c:\users\admin\appdata\local\temp\wisecloudclientsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2640"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\WiseTech Global\CargoWise One Remote Desktop Services\prerequisites\CargoWiseOneAppManagerSetup.msi" /qnC:\Windows\System32\msiexec.exeCargoWiseOneRemoteDesktopServicesSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 502
Read events
1 923
Write events
543
Delete events
36

Modification events

(PID) Process:(2568) WiseCloudClientSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2568) WiseCloudClientSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
Operation:writeName:Blob
Value:
040000000100000010000000CB17E431673EE209FE455793F30AFA1C0F0000000100000014000000E91E1E972B8F467AB4E0598FA92285387DEE94C90300000001000000140000004EB6D578499B1CCF5F581EAD56BE3D9B6744A5E57E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703011D0000000100000010000000C6CBCAFA17955C4CFD41ECA0C654C3610B000000010000001200000056006500720069005300690067006E0000001400000001000000140000007FD365A7C2DDECBBF03009F34339FA02AF3331336200000001000000200000009ACFAB7E43C8D880D06B262A94DEEEE4B4659989C3D0CAF19BAF6405E41AB7DF09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000004600000030443021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0190000000100000010000000D8B5FB368468620275D142FFD2AADE372000000001000000D7040000308204D3308203BBA003020102021018DAD19E267DE8BB4A2158CDCC6B3B4A300D06092A864886F70D01010505003081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D204735301E170D3036313130383030303030305A170D3336303731363233353935395A3081CA310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303620566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79314530430603550403133C566572695369676E20436C6173732033205075626C6963205072696D6172792043657274696669636174696F6E20417574686F72697479202D20473530820122300D06092A864886F70D01010105000382010F003082010A0282010100AF240808297A359E600CAAE74B3B4EDC7CBC3C451CBB2BE0FE2902F95708A364851527F5F1ADC831895D22E82AAAA642B38FF8B955B7B1B74BB3FE8F7E0757ECEF43DB66621561CF600DA4D8DEF8E0C362083D5413EB49CA59548526E52B8F1B9FEBF5A191C23349D843636A524BD28FE870514DD189697BC770F6B3DC1274DB7B5D4B56D396BF1577A1B0F4A225F2AF1C926718E5F40604EF90B9E400E4DD3AB519FF02BAF43CEEE08BEB378BECF4D7ACF2F6F03DAFDD759133191D1C40CB7424192193D914FEAC2A52C78FD50449E48D6347883C6983CBFE47BD2B7E4FC595AE0E9DD4D143C06773E314087EE53F9F73B8330ACF5D3F3487968AEE53E825150203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E041604147FD365A7C2DDECBBF03009F34339FA02AF333133300D06092A864886F70D0101050500038201010093244A305F62CFD81A982F3DEADC992DBD77F6A5792238ECC4A7A07812AD620E457064C5E797662D98097E5FAFD6CC2865F201AA081A47DEF9F97C925A0869200DD93E6D6E3C0D6ED8E606914018B9F8C1EDDFDB41AAE09620C9CD64153881C994EEA284290B136F8EDB0CDD2502DBA48B1944D2417A05694A584F60CA7E826A0B02AA251739B5DB7FE784652A958ABD86DE5E8116832D10CCDEFDA8822A6D281F0D0BC4E5E71A2619E1F4116F10B595FCE7420532DBCE9D515E28B69E85D35BEFA57D4540728EB70E6B0E06FB33354871B89D278BC4655F0D86769C447AF6955CF65D320833A454B6183F685CF2424A853854835FD1E82CF2AC11D6A8ED636A
(PID) Process:(2568) WiseCloudClientSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
Operation:writeName:Blob
Value:
0400000001000000100000007F667A71D3EB6978209A51149D83DA200F0000000100000010000000E8A598BE84828EFEAE701115013576B2030000000100000014000000BE36A4562FB2EE05DBB3D32323ADF445084ED65609000000010000000C000000300A06082B060105050703080B000000010000000E00000074006800610077007400650000001D00000001000000100000006454A4AA36F9B5CC8338E5A67FABFF17140000000100000014000000DDBCBD869C3F07ED40E31B08EFCEC4D188CD3B156200000001000000200000006B6C1E01F590F5AFC5FCF85CD0B9396884048659FC2C6D1170D68B045216C3FD190000000100000010000000181C2BE05851F96993E196F279954B232000000001000000A5020000308202A13082020AA003020102020100300D06092A864886F70D010104050030818B310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311430120603550407130B44757262616E76696C6C65310F300D060355040A1306546861777465311D301B060355040B13145468617774652043657274696669636174696F6E311F301D060355040313165468617774652054696D657374616D70696E67204341301E170D3937303130313030303030305A170D3230313233313233353935395A30818B310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311430120603550407130B44757262616E76696C6C65310F300D060355040A1306546861777465311D301B060355040B13145468617774652043657274696669636174696F6E311F301D060355040313165468617774652054696D657374616D70696E6720434130819F300D06092A864886F70D010101050003818D0030818902818100D62B587861458653EA347B519CEDB0E62E180EFEE05FA827D3B4C9E07C594E160E735460C17FF69F2EE93A8524153CDB470463C39EC4941A5ADF4C7AF3D9431D3C107A7925DB90FEF051E730D64100FD9F28DF79BE94BB9DB614E32385D7A941E04CA479B02B1A8BF2F83B8A3E45AC719200B4904198FB5FEDFAB72E8AF888370203010001A3133011300F0603551D130101FF040530030101FF300D06092A864886F70D01010405000381810067DBE2C2E6873D40838637357D1FCE9AC30C6620A8BAAA048986C2F510080DBFCBA2058AD04D363EF4D7EF69C65EE4B0946F4AB9E7DE5B88B67BDBE327E576C3F035C1CBB5279B3379DC90A6009E77FAFCCD279442169CD31C68ECBF5CDDE5A97B100A32745413318B85038491B75801301438AF28CAFCB150191909AC8949D3
(PID) Process:(2568) WiseCloudClientSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2568) WiseCloudClientSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2684) CargoWiseOneRemoteDesktopServicesSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2684) CargoWiseOneRemoteDesktopServicesSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
0400000001000000100000001BFE69D191B71933A372A80FE155E5B50F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD9796254830300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0B00000001000000100000005300650063007400690067006F0000001D0000000100000010000000885010358D29A38F059B028559C95F901400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD253000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B06010505070307190000000100000010000000EA6089055218053DD01E37E1D806EEDF2000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(2684) CargoWiseOneRemoteDesktopServicesSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2684) CargoWiseOneRemoteDesktopServicesSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3372) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
49
Suspicious files
14
Text files
51
Unknown types
5

Dropped files

PID
Process
Filename
Type
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\MSIFF9C.tmp
MD5:
SHA256:
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client 5.5.1\install\WiseCloud Client.RELEASE.msiexecutable
MD5:
SHA256:
2568WiseCloudClientSetup.exeC:\Windows\Tasks\C__Users_admin_AppData_Local_Temp_WiseCloudClientSetup.exe.jobbinary
MD5:
SHA256:
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\CargoWiseOneRemoteDesktopServicesSetup.exeexecutable
MD5:
SHA256:
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\exclamicimage
MD5:3DBA38E7A6085876E79F162F9985618C
SHA256:593F94EF1405422B3E453F4422B22C990D84303668D60344C6FD257318E92428
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\repairicimage
MD5:D234CA0358B21BDCFC5E3F9B2E7C7A22
SHA256:99D490C2BDEF5115F306A595964663540370141F65A25C5052352155F2603F68
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\cmdlinkarrowimage
MD5:983358CE03817F1CA404BEFBE1E4D96A
SHA256:7F0121322785C107BFDFE343E49F06C604C719BAFF849D07B6E099675D173961
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\removicoimage
MD5:20D25E871A244B94574C47726DE745D6
SHA256:88DD7EE9FA22ECDBDC6B3D47DB83BC3D72360AEB43588E6A9A008B224389CB1C
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\infoimage
MD5:554FF4C199562515D758C9ABFF5C2943
SHA256:9AE4A96BF2A349667E844ACC1E2AC4F89361A6182268438F4D063DF3A6FC47BC
2568WiseCloudClientSetup.exeC:\Users\admin\AppData\Local\Temp\AI_EXTUI_BIN_2568\Newimage
MD5:C23CBF002D82192481B61ED7EC0890F4
SHA256:4F92E804A11453382EBFF7FB0958879BAE88FE3366306911DEC9D811CD306EED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2500
WiseCloudClient.exe
203.62.212.23:443
chiwca.wisegrid.net
WiseTechGlobal Pty Ltd
US
unknown
2816
WiseCloudClient.exe
203.62.212.23:443
chiwca.wisegrid.net
WiseTechGlobal Pty Ltd
US
unknown
2980
WiseCloudClient.exe
203.62.212.23:443
chiwca.wisegrid.net
WiseTechGlobal Pty Ltd
US
unknown

DNS requests

Domain
IP
Reputation
chiwca.wisegrid.net
  • 203.62.212.23
unknown

Threats

No threats detected
No debug info