File name:

mesh.exe

Full analysis: https://app.any.run/tasks/f35d7a75-b754-48e1-b177-3ba341cc0045
Verdict: Malicious activity
Analysis date: April 02, 2024, 09:13:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

61B9DC1683B88077BF00E7357CB034EB

SHA1:

4378C43AB111C8CBB9CD0D41E4F91CA377890ED7

SHA256:

B6E9011BA04C174D1A30E8DBC6BBD1504CC2C46CE6A34C1B908F281FD8CB0B12

SSDEEP:

98304:th7Jc09d/1Xn0R7PRD+9KWFn1O6Al0QFUv6Azk7prpSPynGRter9t2oEhaI0vZRS:KtO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • mesh.exe (PID: 1692)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 1780)
  • SUSPICIOUS

    • Uses WMIC.EXE to obtain operating system information

      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
    • Reads the Internet Settings

      • WMIC.exe (PID: 2572)
      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
      • WMIC.exe (PID: 1556)
      • WMIC.exe (PID: 3800)
      • WMIC.exe (PID: 1544)
      • WMIC.exe (PID: 2060)
      • WMIC.exe (PID: 2592)
      • WMIC.exe (PID: 1864)
      • powershell.exe (PID: 3900)
      • powershell.exe (PID: 2808)
      • powershell.exe (PID: 3260)
    • Reads security settings of Internet Explorer

      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
    • Application launched itself

      • mesh.exe (PID: 1692)
    • Uses WMIC.EXE to obtain computer system information

      • mesh.exe (PID: 1560)
    • The process hides Powershell's copyright startup banner

      • mesh.exe (PID: 1560)
    • Starts POWERSHELL.EXE for commands execution

      • mesh.exe (PID: 1560)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 2808)
      • powershell.exe (PID: 3900)
      • powershell.exe (PID: 3260)
    • Uses WMIC.EXE to obtain system information

      • mesh.exe (PID: 1560)
    • Creates a software uninstall entry

      • mesh.exe (PID: 1560)
    • The process bypasses the loading of PowerShell profile settings

      • mesh.exe (PID: 1560)
  • INFO

    • Reads the machine GUID from the registry

      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
    • Checks supported languages

      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
    • Reads the computer name

      • mesh.exe (PID: 1692)
      • mesh.exe (PID: 1560)
    • Create files in a temporary directory

      • mesh.exe (PID: 1560)
    • Creates files or folders in the user directory

      • mesh.exe (PID: 1560)
    • Checks proxy server information

      • mesh.exe (PID: 1560)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 3260)
      • powershell.exe (PID: 3900)
      • powershell.exe (PID: 2808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:12:09 20:13:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2458112
InitializedDataSize: 1511936
UninitializedDataSize: -
EntryPoint: 0x1c1570
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: MeshCentral Background Service Agent
FileVersion: 2022-Dec-2 11:42:16-0800
LegalCopyright: Apache 2.0 License
ProductName: MeshCentral Agent
ProductVersion: Commit: 2022-Dec-2 11:42:16-0800
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
13
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mesh.exe no specs wmic.exe no specs mesh.exe wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs wmic.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1544wmic ComputerSystem get PCSystemType /FORMAT:"C:\Windows\system32\wbem\en-US\csv"C:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1556wmic ComputerSystem get PCSystemType /FORMAT:"C:\Windows\system32\wbem\en-US\csv"C:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1560"C:\Users\admin\AppData\Local\Temp\mesh.exe" connect --disableUpdate=1 --hideConsole=1 --exitPID=1692 C:\Users\admin\AppData\Local\Temp\mesh.exe
mesh.exe
User:
admin
Integrity Level:
HIGH
Description:
MeshCentral Background Service Agent
Version:
2022-Dec-2 11:42:16-0800
Modules
Images
c:\users\admin\appdata\local\temp\mesh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1692"C:\Users\admin\AppData\Local\Temp\mesh.exe" C:\Users\admin\AppData\Local\Temp\mesh.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MeshCentral Background Service Agent
Version:
2022-Dec-2 11:42:16-0800
Modules
Images
c:\users\admin\appdata\local\temp\mesh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1780powershell -noprofile -nologo -command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1864wmic os get oslanguage /FORMAT:LISTC:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2060wmic SystemEnclosure get ChassisTypesC:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2572wmic os get oslanguage /FORMAT:LISTC:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2592wmic os get oslanguage /FORMAT:LISTC:\Windows\System32\wbem\WMIC.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2808powershell -noprofile -nologo -command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exemesh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
12 319
Read events
12 242
Write events
77
Delete events
0

Modification events

(PID) Process:(1692) mesh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1692) mesh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1692) mesh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1692) mesh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1692) mesh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1560) mesh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1560) mesh.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Open Source\MeshAgent2
Operation:writeName:KeyStore
Value:
Microsoft Software Key Storage Provider
(PID) Process:(1560) mesh.exeKey:HKEY_CURRENT_USER\Software\Open Source\Mesh Agent
Operation:writeName:NodeId
Value:
a4b74nMjoXMH1pfEN@HoNPgce4zoMy0x0U9pljwP8mIsisVp0Ytr4bI5cQsaMipI
(PID) Process:(1560) mesh.exeKey:HKEY_CURRENT_USER\Software\Open Source\Mesh Agent
Operation:writeName:AgentHash
Value:
A6FCA84280C769A8009769B44908FB78D81EA4020EF2381BE45AD9EFD7866DC4AC787B1AA4133B35D30F48362A4C2DBD
(PID) Process:(1560) mesh.exeKey:HKEY_CURRENT_USER\Software\Open Source\Mesh Agent
Operation:writeName:MeshId
Value:
8bpxI20zNyaN0vmNoT9l10isyFbWTd7T7xDwCyrZEo3WbVVQTb4CLmWZKCUaSsFM
Executable files
0
Suspicious files
3
Text files
1
Unknown types
12

Dropped files

PID
Process
Filename
Type
1560mesh.exeC:\Users\admin\AppData\Local\Temp\mesh.mshtext
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\AD48D04E1E8E60E082077A4499B99CB9E2D23CC5binary
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\D0BE8303877AC5F5E465C151D6D05C7D7D61EF3Abinary
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\C86E596BF8178478FAFB1D811B1E28C890145C80binary
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\62514A1334CD6FE38BF6AADDAD9C34B37A6B7408binary
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Local\Temp\mesh.dbbinary
MD5:
SHA256:
1780powershell.exeC:\Users\admin\AppData\Local\Temp\zta5upsa.3zz.ps1binary
MD5:
SHA256:
1780powershell.exeC:\Users\admin\AppData\Local\Temp\spveeca5.1d0.psm1binary
MD5:
SHA256:
1780powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactivebinary
MD5:
SHA256:
1560mesh.exeC:\Users\admin\AppData\Local\Temp\mesh.db.tmpbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1560
mesh.exe
159.100.22.162:443
support.myftp.org
diva-e Datacenters GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
support.myftp.org
  • 159.100.22.162
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.myftp .org
No debug info