| File name: | fleetdeck-agent-DBwjJrfSY8H1hxjbmuCPca.exe |
| Full analysis: | https://app.any.run/tasks/b16aba60-27cb-4ae8-aef1-740a53a9eba0 |
| Verdict: | Malicious activity |
| Analysis date: | July 30, 2024, 11:19:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5: | FB614079B3013C30AD9416181A41AF13 |
| SHA1: | CE1CCF866D578206391DCDC4BEFF8F2E60C819D4 |
| SHA256: | B2A2FB20EE5CA49704D07C20C8342F9A1808DA8B5A5308AFE1B0A863F2092788 |
| SSDEEP: | 98304:iU8j1T4bbO+91VDYJlMi0KB92qwG0WXdr0z/hXFP31xIjQICSF0kVlXBDYylp6pn:D2x/HQ5t |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | Executable, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 3 |
| CodeSize: | 830464 |
| InitializedDataSize: | 2326528 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5aae0 |
| OSVersion: | 6.1 |
| ImageVersion: | 1 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | ASCII |
| Comments: | FleetDeck Agent |
| CompanyName: | FleetDeck Inc. |
| FileDescription: | FleetDeck Agent |
| InternalName: | fleetdeck_installer |
| LegalCopyright: | © FleetDeck. All rights reservered |
| OriginalFileName: | fleetdeck_installer |
| ProductName: | FleetDeck Agent |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 720 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3168 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3620 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3704 | C:\WINDOWS\Sysnative\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden -Command " $s=Get-Service 'FleetDeck Agent Service' if($s.Status -eq 'Running') { $s.Stop() if ($?) { $s.WaitForStatus('Stopped') } } while('True') { Move-Item -Force 'C:\Program Files (x86)\FleetDeck Agent\20220420175353\fleetdeck_agent_svc.exe' -Destination 'C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent_svc.exe' -ErrorVariable err if(!$err) { break } Start-Sleep -s 1 } $s.Start() " | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | fleetdeck_agent_svc.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 3848 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4632 | "C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent_svc.exe" -deploymentID 62b4d470-59c8-4a00-8e2e-486b193b8c1f -askForName=0 | C:\Program Files (x86)\FleetDeck Agent\fleetdeck_agent_svc.exe | — | msiexec.exe | |||||||||||
User: admin Company: FleetDeck Inc. Integrity Level: HIGH Description: FleetDeck Agent Service Exit code: 0 Modules
| |||||||||||||||
| 5296 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5632 | C:\Windows\syswow64\MsiExec.exe -Embedding 4297AC3588E3C635D32675DA5CB98EFB | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5696 | "C:\Users\admin\AppData\Local\Temp\fleetdeck-agent-DBwjJrfSY8H1hxjbmuCPca.exe" | C:\Users\admin\AppData\Local\Temp\fleetdeck-agent-DBwjJrfSY8H1hxjbmuCPca.exe | explorer.exe | ||||||||||||
User: admin Company: FleetDeck Inc. Integrity Level: HIGH Description: FleetDeck Agent Exit code: 0 Modules
| |||||||||||||||
| 5864 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4800000000000000BBD8ED5472E2DA01080F000008060000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 4800000000000000BBD8ED5472E2DA01080F000008060000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000DFC7375572E2DA01080F000008060000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000532C3A5572E2DA01080F000008060000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 4800000000000000CC8F3C5572E2DA01080F000008060000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4800000000000000A156415572E2DA01080F000008060000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 11 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4800000000000000E525B65572E2DA01080F000008060000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3848) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000CC88B85572E2DA01080F000034150000E8030000010000000000000000000000D3908F19733DC44BA4E8FF2906AF783E00000000000000000000000000000000 | |||
| (PID) Process: | (5296) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000B1B3BF5572E2DA01B0140000880E0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3848 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 5696 | fleetdeck-agent-DBwjJrfSY8H1hxjbmuCPca.exe | C:\Users\admin\AppData\Local\Temp\344502223.msi | executable | |
MD5:04381CF1F12960AE2D748820670C4337 | SHA256:E82143029872C041297EC16187E17BB835504D8EE0E7BAAE9CDB413CD8480421 | |||
| 3848 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225F | der | |
MD5:C1657C09CBF653085FE5977265C03E1D | SHA256:3E9B4E775C00A2FD2B1DB9D5C7B4E83D6DF7F3683AABA7283A8137248DAD751A | |||
| 3848 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{198f90d3-3d73-4bc4-a4e8-ff2906af783e}_OnDiskSnapshotProp | binary | |
MD5:0CC1F8A4BB1D85B6D186EB39B0133B4D | SHA256:E08A83F9B828248B616326D201DAD708F8398E967A83FBDD3587198D08E68C2E | |||
| 3848 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:0CC1F8A4BB1D85B6D186EB39B0133B4D | SHA256:E08A83F9B828248B616326D201DAD708F8398E967A83FBDD3587198D08E68C2E | |||
| 3848 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_93702E680A5530C052C8D2BA33A2225F | binary | |
MD5:6E051F9ECD38E4F95284CA3CC7E1BE0A | SHA256:2AADB5DD305DA652848C274E64430FB5DD92086A56BAAEE9B904ED14FC238B14 | |||
| 3848 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3AA0DCD5A74331FBD6F344550EC48B87_99F3F28C2A0B034F2DC8026EDB069DB7 | binary | |
MD5:9E8F0B3298F3337AD41418882EE392DB | SHA256:4C30E59B87B7BEC0A4C722985B06F2C54787B3694AA857A90631CE6FC8541F2F | |||
| 3848 | msiexec.exe | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log | text | |
MD5:E8B37744D2A2299C5FFB52AB4DEA3B61 | SHA256:609881311DD67E254C0C1E8C3231EECD91F91B713596C51988CF048F666F2588 | |||
| 3848 | msiexec.exe | C:\Windows\Installer\MSI4CC0.tmp | binary | |
MD5:C98CB509FD72DCF1231CADA83FFF4FD1 | SHA256:E2787FBF899AD177C35A9BE8EAB86C5422FC636236F1F238BFAFC830C40E8B55 | |||
| 3848 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\18E6B4A57A6BC7EC9B861CDF2D6D0D02_EF52C1EC85F21F31CC0157A5C8803013 | binary | |
MD5:06EA6D8CE6D252D9BA790FC0E71C5800 | SHA256:1BA60ABD62E1A0469233002D3510A8A127794E6004015C2B8EC01E15CB270EB3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3848 | msiexec.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D | unknown | — | — | whitelisted |
4424 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3848 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEDPXCKiRQFMZ4qW70zm5rW4%3D | unknown | — | — | whitelisted |
3848 | msiexec.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRd0JozUYXMqqW4y4zJTrLcMCRSkAQUgTKSQSsozUbIxKLGKjkS7EipPxQCEHR28R9Rj%2FPAA8%2F86fZxtFs%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3676 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
5024 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4132 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 131.253.33.254:443 | a-ring-fallback.msedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.23.209.168:443 | www.bing.com | Akamai International B.V. | GB | unknown |
4376 | slui.exe | 40.91.76.224:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6012 | MoUsoCoreWorker.exe | 20.106.86.13:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4340 | svchost.exe | 20.106.86.13:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2592 | RUXIMICS.exe | 20.106.86.13:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2668 | slui.exe | 40.91.76.224:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
t-ring-fdv2.msedge.net |
| unknown |
a-ring-fallback.msedge.net |
| unknown |
www.bing.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2284 | svchost.exe | Misc activity | ET INFO Fleetdeck Remote Management Software Domain in DNS Lookup (fleetdeck .io) |
7952 | fleetdeck_agent_svc.exe | Misc activity | ET INFO Observed Fleetdeck Remote Management Software Domain in TLS SNI (fleetdeck .io) |
7952 | fleetdeck_agent_svc.exe | Misc activity | ET INFO Observed Fleetdeck Remote Management Software Domain in TLS SNI (fleetdeck .io) |