File name: | TrellixSmartInstall.exe |
Full analysis: | https://app.any.run/tasks/d15eb316-cbf8-4f52-89ff-021f86010b0f |
Verdict: | Malicious activity |
Analysis date: | April 17, 2024, 15:18:37 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | 82E3BE96DDEFCD8DF1C2AAF71AEA430E |
SHA1: | 4185336B9E913B8F5DD4A2C4A9383E4198AD2A33 |
SHA256: | BB5C333E0611647C347EF79977216ED91C7D64891F1FBC85161E8E7614DEA1E9 |
SSDEEP: | 49152:7Pn0vzOdauelEjZRXuB42Ym+PmjOFD6Vw6W6peszMNY1Yp1FvZ+ua/BvuyLVWJHH:7Pn0xlEjZR+B3JimjW7YoPvAZ/dPR2HH |
.exe | | | UPX compressed Win32 Executable (43.5) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (42.7) |
.exe | | | Win32 Executable (generic) (7.2) |
.exe | | | Generic Win/DOS Executable (3.2) |
.exe | | | DOS Executable Generic (3.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2023:12:07 19:36:30+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.29 |
CodeSize: | 937984 |
InitializedDataSize: | 118784 |
UninitializedDataSize: | 1724416 |
EntryPoint: | 0x28a7c0 |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 5.8.1.313 |
ProductVersionNumber: | 5.8.1.313 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Dynamic link library |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Musarubra US LLC. |
FileDescription: | Trellix Smart Installer |
FileVersion: | 5.8.1.313 |
InternalName: | TrellixSmartInstall.exe |
LegalCopyright: | Copyright (C) 2024 Musarubra US LLC. All rights reserved |
OriginalFileName: | TrellixSmartInstall.exe |
ProductName: | Trellix Agent |
ProductVersion: | 5.8.1.313 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
548 | "C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe" | C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe | explorer.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: Trellix Smart Installer Version: 5.8.1.313 Modules
| |||||||||||||||
924 | "C:\Program Files\McAfee\Agent\masvc.exe" /ServiceStart | C:\Program Files\McAfee\Agent\masvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent Service Version: 5.8.1.313 Modules
| |||||||||||||||
1196 | "C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe" | C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe | — | explorer.exe | |||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: MEDIUM Description: Trellix Smart Installer Exit code: 3221226540 Version: 5.8.1.313 Modules
| |||||||||||||||
1340 | "C:\Program Files\McAfee\Agent\macmnsvc.exe" /ServiceStart | C:\Program Files\McAfee\Agent\macmnsvc.exe | services.exe | ||||||||||||
User: LOCAL SERVICE Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent Common Services Version: 5.8.1.313 Modules
| |||||||||||||||
1880 | "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe" -burn.unelevated BurnPipe.{DC7E9337-48D2-449B-9E2C-1B401C0F9CBF} {A79C8642-012C-4200-B6F8-63A4E78C79B0} 2632 /norestart /silent | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe | dxlsetup-ma.exe | ||||||||||||
User: admin Company: Trellix Integrity Level: HIGH Description: Trellix Data Exchange Layer for TA Version: 6.0.3.1021 Modules
| |||||||||||||||
2176 | -install -location "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall" -initiator 2880 | C:\Program Files\McAfee\Agent\mcupdater.exe | FrmInst.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: Trellix Agent Extension Updater Version: 5.8.1.313 Modules
| |||||||||||||||
2248 | /load | C:\Program Files\McAfee\Agent\mctray.exe | — | UpdaterUI.exe | |||||||||||
User: admin Company: Trellix Integrity Level: MEDIUM Description: Trellix Tray Application Version: 2.2.0.4696 Modules
| |||||||||||||||
2632 | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe /norestart /silent | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe | — | mcupdater.exe | |||||||||||
User: admin Company: Trellix Integrity Level: HIGH Description: Trellix Data Exchange Layer for TA Version: 6.0.3.1021 Modules
| |||||||||||||||
2844 | "C:\Program Files\McAfee\Agent\\mfemactl.exe" --msi 1 --log "C:\ProgramData\McAfee\Agent\logs" --ppid 924 --interface 4D454F57010000000000000000000000C000000000000046000000000500000027A2145BA31EE896C0D3668376F544E6011400009C039805DCEBE999E7B90ED700000000 | C:\Program Files\McAfee\Agent\mfemactl.exe | masvc.exe | ||||||||||||
User: SYSTEM Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent AAC Host Version: 5.8.1.313 Modules
| |||||||||||||||
2880 | "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe" /Install=Agent /Silent /FramePkg /EnforceEvents /TenantID="0B753CAA-282E-4143-AFAA-B6956A3E3861" /AgentGUID="{20f4bfaa-aeda-4ef8-8332-ce638297293d}" | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe | TrellixSmartInstall.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: MA Setup Program Version: 5.8.1.313 Modules
|
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_1 |
Value: Allow Agent HTTP Server,C:\Program Files\McAfee\Agent\macmnsvc.exe,0,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_2 |
Value: Allow Agent UDP Client,C:\Program Files\McAfee\Agent\macmnsvc.exe,1,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_5 |
Value: Allow Agent Compat Relay Discovery,C:\Program Files\McAfee\Agent\macmnsvc.exe,1,,,,8083,0 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_6 |
Value: Allow Agent TCP Traffic,C:\Program Files\McAfee\Agent\masvc.exe,0,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_7 |
Value: Allow Agent UDP Traffic,C:\Program Files\McAfee\Agent\masvc.exe,1,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_8 |
Value: Allow Agent Provisioning,C:\Program Files\McAfee\Agent\maconfig.exe,0,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_9 |
Value: Allow Agent Updater Engine TCP Traffic,C:\Program Files\McAfee\Agent\McScript_InUse.exe,0,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_10 |
Value: Allow Agent Updater Engine UDP Traffic,C:\Program Files\McAfee\Agent\McScript_InUse.exe,1,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_11 |
Value: Allow Agent Repository Mirror,C:\Program Files\McAfee\Agent\marepomirror.exe,0,,,,,1 | |||
(PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
Operation: | write | Name: | Rule_12 |
Value: Allow Agent Provisioning,C:\Program Files\McAfee\Agent\maconfigCmd.exe,0,,,,,1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\Shared.cab | — | |
MD5:— | SHA256:— | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\SiteList.xml | text | |
MD5:B445F36C3FA8DD919E7099BCD09E412A | SHA256:3C9C7966044B80500E3B9732B72255D673857C0721AD3A0DF619BD4A73201CCE | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\hashes.xml | xml | |
MD5:B48B0C1EDAA6C684DE3919928291BB00 | SHA256:8530BDB81DBFFD2E3231B5BCD2863DA02AEA80BB17319EF69EC90DBC58DF403F | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrameworkInstall.zip | compressed | |
MD5:41E5CDC2A7BF95EF6A465FC50356A557 | SHA256:5206D9FA9F89C7CA3729EF492AF868559DA99EA54D4D88C569773501C2CBE747 | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\req2048seckey.bin | binary | |
MD5:5191848515739AA65CDD97E3D2E283C8 | SHA256:8BA9397BDE9834209CE78BFBDED75C05B98924D1D16DE882A7E26C91EE2A2EAE | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\RepoKeys.ini | ini | |
MD5:4C9FA315DA6856C1BC0D74520167F519 | SHA256:EDC63E39BDA39C600E426D5380F0913C825C522F3EE14DBC6750000720D89712 | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\agent.ini | text | |
MD5:B742DE65F4A64355666B9A9C807BEC33 | SHA256:738E3D028C333CCF9D16EB3B1D366B2FD65E4B342B4175DB167576728A921DD7 | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe | executable | |
MD5:EF8D0352527B35E613BD4C37BFF66082 | SHA256:C497FDA2C61BCB718591B416EB0895B7C68E7D18D8446C6DAA7EFEB98F9E35A9 | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\BootstrapInfo.xml | xml | |
MD5:4491B8E18CEF975FDA9290FE816D6765 | SHA256:0DD5800FE2DC803C1601E0C4921EBEC837AFCD95732BCA155C3A3F49EE2EE69E | |||
548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\PackageInfo.xml | xml | |
MD5:F0F72C097C4D305FE169867D3BCD7012 | SHA256:560AEF1F9EFEE18D52A8358313F16A485871DF71F7D599969B7FBE5A3F93203D |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
548 | TrellixSmartInstall.exe | GET | 200 | 13.225.78.6:80 | http://cdn-usw004.mvision.mcafee.com/Software/Current/EPOAGENT3000/Install/0409/FrameworkInstall.zip | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
548 | TrellixSmartInstall.exe | 52.32.216.244:443 | ah-usw004.manage.trellix.com | AMAZON-02 | US | unknown |
548 | TrellixSmartInstall.exe | 192.168.100.255:8082 | — | — | — | unknown |
548 | TrellixSmartInstall.exe | 13.225.78.6:80 | cdn-usw004.mvision.mcafee.com | AMAZON-02 | US | unknown |
924 | masvc.exe | 52.32.216.244:443 | ah-usw004.manage.trellix.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
---|---|---|
ah-usw004.manage.trellix.com |
| unknown |
cdn-usw004.mvision.mcafee.com |
| unknown |
sw-usw004.mvision.mcafee.com |
| unknown |
ah-usw004.mvision.mcafee.com |
| unknown |
cdn-usw004.manage.trellix.com |
| unknown |
Process | Message |
---|---|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfevtpa.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|