File name:

CargoWise Application.exe

Full analysis: https://app.any.run/tasks/555e505d-858b-41da-953e-185301562db3
Verdict: Malicious activity
Analysis date: December 20, 2024, 19:30:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

B9AFA480896BB115EEC8D79623DFC8B4

SHA1:

97FEAB10FD33580F34D1C3AC159C614C5321FD25

SHA256:

A3FBC2710D8AFFC3AD3AD7A983F07A0C97619701A01C33D22F17277B47A67F12

SSDEEP:

98304:48Memvl171kM2ZuMChPMJDlDhG16YRVVOkaNbHLU4GzoMZ8Memvl171/SnyaKtMX:gSnyaKtM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
    • Reads security settings of Internet Explorer

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
    • Process drops legitimate windows executable

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
    • Executes as Windows Service

      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6604)
    • Restarts service on failure

      • sc.exe (PID: 6852)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6604)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 6604)
    • Reads the history of recent RDP connections

      • msiexec.exe (PID: 6604)
  • INFO

    • Reads Environment values

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • msiexec.exe (PID: 7156)
    • Create files in a temporary directory

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
    • Creates files or folders in the user directory

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • msiexec.exe (PID: 6604)
    • The process uses the downloaded file

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
    • The sample compiled with english language support

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • msiexec.exe (PID: 6604)
    • Checks supported languages

      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • CargoWise Application.exe (PID: 6392)
      • msiexec.exe (PID: 6604)
      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
      • msiexec.exe (PID: 7156)
      • MSI87D3.tmp (PID: 6164)
      • MSI896B.tmp (PID: 6248)
      • msiexec.exe (PID: 1156)
    • Reads the computer name

      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
      • CargoWise Application.exe (PID: 6392)
      • msiexec.exe (PID: 6604)
      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
      • msiexec.exe (PID: 7156)
      • MSI87D3.tmp (PID: 6164)
      • MSI896B.tmp (PID: 6248)
      • msiexec.exe (PID: 1156)
    • Process checks computer location settings

      • CargoWise Application.exe (PID: 6392)
      • CargoWiseOneRemoteDesktopServicesSetup.exe (PID: 6484)
    • Reads the software policy settings

      • msiexec.exe (PID: 6604)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6604)
      • CargoWise.ApplicationManager.Service.exe (PID: 6724)
      • MSI87D3.tmp (PID: 6164)
      • MSI896B.tmp (PID: 6248)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6604)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 6604)
    • Sends debugging messages

      • msiexec.exe (PID: 7156)
      • msiexec.exe (PID: 1156)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (83)
.exe | Win32 Executable (generic) (9)
.exe | Generic Win/DOS Executable (3.9)
.exe | DOS Executable Generic (3.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:03:23 09:39:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 300032
InitializedDataSize: 280576
UninitializedDataSize: -
EntryPoint: 0x3218c
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.2.0
ProductVersionNumber: 1.4.2.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: WiseTech Global
FileDescription: WiseCloud Client.
FileVersion: 1.4.2
InternalName: WiseCloudClientSetup
LegalCopyright: Copyright (C) 2016 WiseTech Global
OriginalFileName: WiseCloudClientSetup.exe
ProductName: WiseCloud Client
ProductVersion: 1.4.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
14
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start cargowise application.exe cargowiseoneremotedesktopservicessetup.exe msiexec.exe no specs msiexec.exe cargowise.applicationmanager.service.exe no specs sc.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe msi87d3.tmp no specs msi896b.tmp no specs msiexec.exe msiexec.exe no specs cargowise application.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1156C:\Windows\syswow64\MsiExec.exe -Embedding 622E9E4C9E8F4EF50A412A8CBDF071B9 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2744 /i "C:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client 1.4.2\install\WiseCloud Client.RELEASE.msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\CargoWise Application.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\" EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs " AI_FOUND_PREREQS=".NET Framework 4.0" AI_MISSING_PREREQS="CargoWise One Remote Desktop Services"C:\Windows\System32\msiexec.exeCargoWise Application.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6164"C:\WINDOWS\Installer\MSI87D3.tmp" 2C:\Windows\Installer\MSI87D3.tmpmsiexec.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
Remote Desktop Services Session Killer
Exit code:
0
Version:
16.6.20.122
Modules
Images
c:\windows\installer\msi87d3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6232"C:\Users\admin\AppData\Local\Temp\CargoWise Application.exe" C:\Users\admin\AppData\Local\Temp\CargoWise Application.exeexplorer.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
MEDIUM
Description:
WiseCloud Client.
Exit code:
3221226540
Version:
1.4.2
Modules
Images
c:\users\admin\appdata\local\temp\cargowise application.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6248"C:\WINDOWS\Installer\MSI896B.tmp"C:\Windows\Installer\MSI896B.tmpmsiexec.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
GacUtilUninstall
Exit code:
0
Version:
16.6.20.122
Modules
Images
c:\windows\installer\msi896b.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6392"C:\Users\admin\AppData\Local\Temp\CargoWise Application.exe" C:\Users\admin\AppData\Local\Temp\CargoWise Application.exe
explorer.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
WiseCloud Client.
Version:
1.4.2
Modules
Images
c:\users\admin\appdata\local\temp\cargowise application.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6484"C:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\CargoWiseOneRemoteDesktopServicesSetup.exe" /qnC:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\CargoWiseOneRemoteDesktopServicesSetup.exe
CargoWise Application.exe
User:
admin
Company:
WiseTech Global
Integrity Level:
HIGH
Description:
CargoWise One Remote Desktop Services Installer
Exit code:
0
Version:
4.4.0
Modules
Images
c:\users\admin\appdata\roaming\wisetech global\wisecloud client\prerequisites\cargowiseoneremotedesktopservicessetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6568"C:\WINDOWS\System32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\WiseTech Global\CargoWise One Remote Desktop Services\prerequisites\CargoWiseOneAppManagerSetup.msi" /qnC:\Windows\SysWOW64\msiexec.exeCargoWiseOneRemoteDesktopServicesSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6604C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6724"C:\Program Files (x86)\WiseTech Global\CargoWise One Application Manager\CargoWise.ApplicationManager.Service.exe"C:\Program Files (x86)\WiseTech Global\CargoWise One Application Manager\CargoWise.ApplicationManager.Service.exeservices.exe
User:
SYSTEM
Company:
WiseTech Global
Integrity Level:
SYSTEM
Description:
CargoWise Application Manager
Version:
16.6.20.122
Modules
Images
c:\program files (x86)\wisetech global\cargowise one application manager\cargowise.applicationmanager.service.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
Total events
8 239
Read events
7 972
Write events
249
Delete events
18

Modification events

(PID) Process:(6484) CargoWiseOneRemoteDesktopServicesSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi\OpenWithProgids
Operation:writeName:Msi.Package
Value:
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\136ce8.rbs
Value:
31150869
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\136ce8.rbsLow
Value:
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1797CE9468DD12439B1CAD8AFF2E517
Operation:writeName:2E1BD3036A3B4EE42B58B4ED6B9D3D7E
Value:
C:\Program Files (x86)\WiseTech Global\CargoWise One Application Manager\CargoWise.ApplicationManager.Service.exe
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E4F8ECB0CB541944906B9F31F14FAF5
Operation:writeName:2E1BD3036A3B4EE42B58B4ED6B9D3D7E
Value:
02:\SOFTWARE\CargoWise edi\ediAppMgr\CurrentVersion
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files (x86)\WiseTech Global\CargoWise One Application Manager\
Value:
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files (x86)\WiseTech Global\
Value:
(PID) Process:(6604) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CargoWise edi\ediAppMgr
Operation:writeName:CurrentVersion
Value:
2.0.3
(PID) Process:(6604) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
CC190000FC90AAAA1553DB01
Executable files
35
Suspicious files
43
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
6484CargoWiseOneRemoteDesktopServicesSetup.exeC:\Windows\Tasks\C__Users_admin_AppData_Roaming_WiseTech Global_WiseCloud Client_prerequisites_CargoWiseOneRemoteDesktopServicesSetup.exe.jobbinary
MD5:079C995E5C9031FC50DBFF8D8976B68F
SHA256:C010556F8F0F95436836301694401677FF8A15D727F089ED9EBDC11B520F88E5
6484CargoWiseOneRemoteDesktopServicesSetup.exeC:\Users\admin\AppData\Roaming\WiseTech Global\CargoWise One Remote Desktop Services\prerequisites\CargoWiseOneAppManagerSetup.msiexecutable
MD5:00381A876D20040C19FCAAADED592500
SHA256:5553EE24DE4E86BD3FBF2BA3E461EA4CA15AF63A955A00F534EB1B79860BAF10
6392CargoWise Application.exeC:\Windows\Tasks\C__Users_admin_AppData_Local_Temp_CargoWise Application.exe.jobbinary
MD5:DED351492906A3680EF0541F5FC482E0
SHA256:12A386586192E64B3596D97EB77118593AE1497BE0AAAD1F1AC57B32A69E56EA
6484CargoWiseOneRemoteDesktopServicesSetup.exeC:\Users\admin\AppData\Local\Temp\shi69F8.tmpexecutable
MD5:CE85F5D941EBCA72DA2A55835B303EB9
SHA256:6CF60B8101CBB475F3803E18617172CC180AFA4BC0CA8CA261C2AB6ED1C93EA1
6604msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_6043FC604A395E1485AF7AC16D16B7CEbinary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
6392CargoWise Application.exeC:\Users\admin\AppData\Roaming\WiseTech Global\WiseCloud Client\prerequisites\CargoWiseOneRemoteDesktopServicesSetup.exeexecutable
MD5:9C6EB6B37017B2901DD40B01933E3AD1
SHA256:60DAE9A95D25CBE17586A69EFC4CA8050AC50AB08C2880274C250E85802132B7
6604msiexec.exeC:\Windows\Installer\136ce6.msiexecutable
MD5:00381A876D20040C19FCAAADED592500
SHA256:5553EE24DE4E86BD3FBF2BA3E461EA4CA15AF63A955A00F534EB1B79860BAF10
6392CargoWise Application.exeC:\Users\admin\AppData\Local\Temp\shi6768.tmpexecutable
MD5:CE85F5D941EBCA72DA2A55835B303EB9
SHA256:6CF60B8101CBB475F3803E18617172CC180AFA4BC0CA8CA261C2AB6ED1C93EA1
6604msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EA618097E393409AFA316F0F87E2C202_4DADA7D3B8757C46C18D6B5A76450BB1binary
MD5:5BFA51F3A417B98E7443ECA90FC94703
SHA256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
6604msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_6043FC604A395E1485AF7AC16D16B7CEbinary
MD5:9EEEA8FF86A985D18589121961B4A960
SHA256:550131F1CF0F4D7EBE42A39621ECCAB0D26DC42A0CFBB322CF104C8C287B3A18
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
28
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6604
msiexec.exe
GET
200
152.199.19.74:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEE2PudmHJOFyLPyqYMyRi1w%3D
unknown
unknown
6604
msiexec.exe
GET
200
152.199.19.74:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
unknown
whitelisted
6604
msiexec.exe
GET
200
152.199.19.74:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
unknown
whitelisted
6604
msiexec.exe
GET
200
192.229.221.95:80
http://s1.symcb.com/pca3-g5.crl
unknown
whitelisted
6604
msiexec.exe
GET
200
192.229.221.95:80
http://sv.symcb.com/sv.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6604
msiexec.exe
GET
200
152.199.19.74:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEE2PudmHJOFyLPyqYMyRi1w%3D
unknown
unknown
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6604
msiexec.exe
152.199.19.74:80
s2.symcb.com
EDGECAST
US
unknown
6604
msiexec.exe
192.229.221.95:80
s1.symcb.com
EDGECAST
US
whitelisted
4128
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1176
svchost.exe
192.229.221.95:80
s1.symcb.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
unknown
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
unknown
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
s2.symcb.com
  • 152.199.19.74
whitelisted
s1.symcb.com
  • 192.229.221.95
whitelisted
sv.symcd.com
  • 152.199.19.74
shared
sv.symcb.com
  • 192.229.221.95
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
login.live.com
  • 40.126.32.68
  • 40.126.32.133
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.72
  • 20.190.160.22
  • 40.126.32.140
  • 40.126.32.138
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
Process
Message
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | Build JOINed tables CustomActionData string...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | SELECT Join Query: [SELECT * FROM `RemoveRegistry`, `AI_RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry` = `AI_RemoveRegistry`.`RemoveReg`].
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader: Getting the active MSI database for this installation session...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader::ExecuteQuery [SELECT * FROM `RemoveRegistry`, `AI_RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry` = `AI_RemoveRegistry`.`RemoveReg`]...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | OnAiRemoveRegsImmediate start.
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader::ExecuteQuery [SELECT * FROM `RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry`='EdiEnterprise']...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader::ExecuteQuery [SELECT * FROM `RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry`='__3']...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | Commit scheduled.
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader::ExecuteQuery [SELECT * FROM `RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry`='_']...
msiexec.exe
# 2024-12-20 @19:30:54 [PID=7156|Thread=5720] | MsiTableReader::ExecuteQuery [SELECT * FROM `RemoveRegistry` WHERE `RemoveRegistry`.`RemoveRegistry`='__6']...