File name: | anyconnect-win-4.8.03052-core-vpn-webdeploy-k9.exe |
Full analysis: | https://app.any.run/tasks/0f738b47-1b07-4930-87a4-5c89aa86de0e |
Verdict: | Malicious activity |
Analysis date: | June 04, 2024, 07:58:06 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 7E09B9489041A94DD9BF0288FA30A321 |
SHA1: | 7B1A4AF7BAF8B72DBD6DF7DB00B64995073DD08E |
SHA256: | B79C480CAEB6433E0E17BC4D1AE2D3F690ACF9967EC3D9506A744D5FDD6C6600 |
SSDEEP: | 98304:iI8ZyFjWPAdlTbfm4je9PG2+/fWO2h5s/qI7SU+0/4i5lviRA3ptHgJtXUe8YNA9:7JEX7pLBk12JI/bj |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2019:01:08 11:52:26+00:00 |
ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.16 |
CodeSize: | 1504768 |
InitializedDataSize: | 598016 |
UninitializedDataSize: | - |
EntryPoint: | 0x121b07 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 4.8.3052.0 |
ProductVersionNumber: | 4.8.3052.0 |
FileFlagsMask: | 0x003f |
FileFlags: | Debug |
FileOS: | Win32 |
ObjectFileType: | Dynamic link library |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Cisco Systems, Inc. |
FileDescription: | Cisco AnyConnect Secure Mobility Client Installer |
FileVersion: | 4.8.03052 |
InternalName: | WinSetup-Release-web-deploy |
LegalCopyright: | Copyright (C) 2020 Cisco Systems, Inc. |
OriginalFileName: | WinSetup-Release-web-deploy.exe |
ProductName: | Cisco AnyConnect Secure Mobility Client |
ProductVersion: | 4.8.03052 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
188 | /C "C:\Users\admin\AppData\Local\Temp\{E97FA8CB-3670-4E83-84D8-C9D68AD23DF9}.bat" | C:\Windows\System32\cmd.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
1072 | C:\Windows\system32\MsiExec.exe -Embedding 49CEA77DDD1555961B5C8664C1C033AD E Global\MSI0000 | C:\Windows\System32\msiexec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1248 | "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -createLink "C:\ProgramData\Cisco\Cisco AnyConnect VPN Client\update.txt" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\update.txt" | C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe | — | msiexec.exe | |||||||||||
User: admin Company: Cisco Systems, Inc. Integrity Level: MEDIUM Description: AnyConnect Secure Mobility Client Install Helper Exit code: 0 Version: 4, 8, 03052 Modules
| |||||||||||||||
1408 | "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -registerdll "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnapi.dll" | C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe | — | msiexec.exe | |||||||||||
User: admin Company: Cisco Systems, Inc. Integrity Level: MEDIUM Description: AnyConnect Secure Mobility Client Install Helper Exit code: 0 Version: 4, 8, 03052 Modules
| |||||||||||||||
1612 | "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveIfExist "C:\Users\admin\AppData\Local\\Cisco\Cisco AnyConnect VPN Client\preferences.xml" "C:\Users\admin\AppData\Local\Cisco\Cisco AnyConnect Secure Mobility Client\\preferences.xml" | C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe | — | msiexec.exe | |||||||||||
User: admin Company: Cisco Systems, Inc. Integrity Level: MEDIUM Description: AnyConnect Secure Mobility Client Install Helper Exit code: 0 Version: 4, 8, 03052 Modules
| |||||||||||||||
1680 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1980 | /C "C:\Users\admin\AppData\Local\Temp\{E97FA8CB-3670-4E83-84D8-C9D68AD23DF9}.bat" | C:\Windows\System32\cmd.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
1996 | "C:\Windows\System32\grpconv.exe" -o | C:\Windows\System32\grpconv.exe | — | runonce.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Progman Group Converter Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2032 | C:\Windows\system32\MsiExec.exe -Embedding AAC1E900D015B68651B6C7E112322824 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2076 | "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe" -moveFiles "C:\ProgramData\\Cisco\Cisco AnyConnect VPN Client\l10n\\" "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\\l10n\\" "*.*" | C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\InstallHelper.exe | — | msiexec.exe | |||||||||||
User: admin Company: Cisco Systems, Inc. Integrity Level: MEDIUM Description: AnyConnect Secure Mobility Client Install Helper Exit code: 1 Version: 4, 8, 03052 Modules
|
(PID) Process: | (3976) anyconnect-win-4.8.03052-core-vpn-webdeploy-k9.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2108) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (4048) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000745526FB54B6DA01D00F0000A0050000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (4048) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000745526FB54B6DA01D00F0000A0050000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (4048) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 75 | |||
(PID) Process: | (4048) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000D225D9FB54B6DA01D00F0000A0050000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (4048) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000002C88DBFB54B6DA01D00F0000D8020000E803000001000000000000000000000028FBBB8F62D61A4F96BB169973AAC1440000000000000000 | |||
(PID) Process: | (1680) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EE73E7FB54B6DA019006000058040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1680) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EE73E7FB54B6DA019006000024040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1680) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EE73E7FB54B6DA019006000058080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3976 | anyconnect-win-4.8.03052-core-vpn-webdeploy-k9.exe | C:\Users\admin\AppData\Local\Temp\Cisco\Installer\holder0.aiph | — | |
MD5:— | SHA256:— | |||
4048 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
4048 | msiexec.exe | C:\Windows\Installer\MSI7E5B.tmp | — | |
MD5:— | SHA256:— | |||
2108 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI3D5A.tmp | executable | |
MD5:09979FE43E7417C747CA0F71D811B5C1 | SHA256:D3AB8B009C45EA39791A8179EC1EC8C649281D7AF3C8E975991085A25D4757A9 | |||
3976 | anyconnect-win-4.8.03052-core-vpn-webdeploy-k9.exe | C:\Users\admin\AppData\Local\Temp\MSI3BA3.tmp | executable | |
MD5:09979FE43E7417C747CA0F71D811B5C1 | SHA256:D3AB8B009C45EA39791A8179EC1EC8C649281D7AF3C8E975991085A25D4757A9 | |||
4048 | msiexec.exe | C:\Windows\Installer\1077a3.msi | executable | |
MD5:B920F0B741926B3393693ED4FDF58152 | SHA256:5FED384F0FEA5495C2462E23E16709B4C2D3C5CA72C622C130FE0F55C0D1A027 | |||
3976 | anyconnect-win-4.8.03052-core-vpn-webdeploy-k9.exe | C:\Users\admin\AppData\Local\Temp\Cisco\Installer\decoder.dll | executable | |
MD5:77298CD7E6D855F8EC8B093B6E0CF85D | SHA256:A9B2E1DFCFA819B730DBE099F39A19068A4D04979B1CFABCCDAD1260145F89FC | |||
4048 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:9A1AEF33F0AC380EC9F369BE54234CAA | SHA256:41B1B2D4235DFCFC2FF5796C4BC3294D281F9D8FA57E936A7628D2DD29661901 | |||
4048 | msiexec.exe | C:\Windows\Installer\MSI7CD4.tmp | executable | |
MD5:AC2E623B82226DBD9E703E1F36DBDE0B | SHA256:355E1A68F0287F64C8C03BEC59D350C1DBA13BF51F0A22B5F0B23F03CBA795D1 | |||
4048 | msiexec.exe | C:\Windows\Installer\1077a4.ipi | binary | |
MD5:1DADBA8DEA7006F0FB25E452868D9F9A | SHA256:11E304E4B42C2441E07EB8301129CCE494BEB150C5543471C2E06223CDD07947 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2800 | vpnagent.exe | 72.163.1.80:80 | mus.cisco.com | CISCOSYSTEMS | US | unknown |
3092 | vpnui.exe | 31.194.163.178:443 | vpn.almag.it | Telecom Italia | IT | unknown |
2800 | vpnagent.exe | 31.194.163.178:443 | vpn.almag.it | Telecom Italia | IT | unknown |
Domain | IP | Reputation |
---|---|---|
mus.cisco.com |
| unknown |
vpn.almag.it |
| unknown |
Process | Message |
---|---|
msiexec.exe | DBGHELP: Symbol Search Path: .
|
msiexec.exe | DBGHELP: Symbol Search Path: C:\Windows\system32
|
msiexec.exe | DBGHELP: C:\Windows\system32\ntdll.pdb - file not found
|
msiexec.exe | DBGHELP: ntdll.pdb - file not found
|
msiexec.exe | DBGHELP: ntdll - export symbols
|
msiexec.exe | DBGHELP: SymSrv load failure: symsrv.dll
|
msiexec.exe | DBGHELP: C:\Windows\system32\dll\ntdll.pdb - file not found
|
msiexec.exe | DBGHELP: C:\Windows\system32\symbols\dll\ntdll.pdb - file not found
|
VACon.exe | VACON: -install
|
msiexec.exe | DBGHELP: Symbol Search Path: .
|