| File name: | TrellixSmartInstall.exe |
| Full analysis: | https://app.any.run/tasks/d15eb316-cbf8-4f52-89ff-021f86010b0f |
| Verdict: | Malicious activity |
| Analysis date: | April 17, 2024, 15:18:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 82E3BE96DDEFCD8DF1C2AAF71AEA430E |
| SHA1: | 4185336B9E913B8F5DD4A2C4A9383E4198AD2A33 |
| SHA256: | BB5C333E0611647C347EF79977216ED91C7D64891F1FBC85161E8E7614DEA1E9 |
| SSDEEP: | 49152:7Pn0vzOdauelEjZRXuB42Ym+PmjOFD6Vw6W6peszMNY1Yp1FvZ+ua/BvuyLVWJHH:7Pn0xlEjZR+B3JimjW7YoPvAZ/dPR2HH |
| .exe | | | UPX compressed Win32 Executable (43.5) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (42.7) |
| .exe | | | Win32 Executable (generic) (7.2) |
| .exe | | | Generic Win/DOS Executable (3.2) |
| .exe | | | DOS Executable Generic (3.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:12:07 19:36:30+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 937984 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1724416 |
| EntryPoint: | 0x28a7c0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.8.1.313 |
| ProductVersionNumber: | 5.8.1.313 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Musarubra US LLC. |
| FileDescription: | Trellix Smart Installer |
| FileVersion: | 5.8.1.313 |
| InternalName: | TrellixSmartInstall.exe |
| LegalCopyright: | Copyright (C) 2024 Musarubra US LLC. All rights reserved |
| OriginalFileName: | TrellixSmartInstall.exe |
| ProductName: | Trellix Agent |
| ProductVersion: | 5.8.1.313 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 548 | "C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe" | C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe | explorer.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: Trellix Smart Installer Version: 5.8.1.313 Modules
| |||||||||||||||
| 924 | "C:\Program Files\McAfee\Agent\masvc.exe" /ServiceStart | C:\Program Files\McAfee\Agent\masvc.exe | services.exe | ||||||||||||
User: SYSTEM Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent Service Version: 5.8.1.313 Modules
| |||||||||||||||
| 1196 | "C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe" | C:\Users\admin\AppData\Local\Temp\TrellixSmartInstall.exe | — | explorer.exe | |||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: MEDIUM Description: Trellix Smart Installer Exit code: 3221226540 Version: 5.8.1.313 Modules
| |||||||||||||||
| 1340 | "C:\Program Files\McAfee\Agent\macmnsvc.exe" /ServiceStart | C:\Program Files\McAfee\Agent\macmnsvc.exe | services.exe | ||||||||||||
User: LOCAL SERVICE Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent Common Services Version: 5.8.1.313 Modules
| |||||||||||||||
| 1880 | "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe" -burn.unelevated BurnPipe.{DC7E9337-48D2-449B-9E2C-1B401C0F9CBF} {A79C8642-012C-4200-B6F8-63A4E78C79B0} 2632 /norestart /silent | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe | dxlsetup-ma.exe | ||||||||||||
User: admin Company: Trellix Integrity Level: HIGH Description: Trellix Data Exchange Layer for TA Version: 6.0.3.1021 Modules
| |||||||||||||||
| 2176 | -install -location "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall" -initiator 2880 | C:\Program Files\McAfee\Agent\mcupdater.exe | FrmInst.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: Trellix Agent Extension Updater Version: 5.8.1.313 Modules
| |||||||||||||||
| 2248 | /load | C:\Program Files\McAfee\Agent\mctray.exe | — | UpdaterUI.exe | |||||||||||
User: admin Company: Trellix Integrity Level: MEDIUM Description: Trellix Tray Application Version: 2.2.0.4696 Modules
| |||||||||||||||
| 2632 | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe /norestart /silent | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\DXL\dxlsetup-ma.exe | — | mcupdater.exe | |||||||||||
User: admin Company: Trellix Integrity Level: HIGH Description: Trellix Data Exchange Layer for TA Version: 6.0.3.1021 Modules
| |||||||||||||||
| 2844 | "C:\Program Files\McAfee\Agent\\mfemactl.exe" --msi 1 --log "C:\ProgramData\McAfee\Agent\logs" --ppid 924 --interface 4D454F57010000000000000000000000C000000000000046000000000500000027A2145BA31EE896C0D3668376F544E6011400009C039805DCEBE999E7B90ED700000000 | C:\Program Files\McAfee\Agent\mfemactl.exe | masvc.exe | ||||||||||||
User: SYSTEM Company: Musarubra US LLC. Integrity Level: SYSTEM Description: Trellix Agent AAC Host Version: 5.8.1.313 Modules
| |||||||||||||||
| 2880 | "C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe" /Install=Agent /Silent /FramePkg /EnforceEvents /TenantID="0B753CAA-282E-4143-AFAA-B6956A3E3861" /AgentGUID="{20f4bfaa-aeda-4ef8-8332-ce638297293d}" | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe | TrellixSmartInstall.exe | ||||||||||||
User: admin Company: Musarubra US LLC. Integrity Level: HIGH Description: MA Setup Program Version: 5.8.1.313 Modules
| |||||||||||||||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_1 |
Value: Allow Agent HTTP Server,C:\Program Files\McAfee\Agent\macmnsvc.exe,0,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_2 |
Value: Allow Agent UDP Client,C:\Program Files\McAfee\Agent\macmnsvc.exe,1,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_5 |
Value: Allow Agent Compat Relay Discovery,C:\Program Files\McAfee\Agent\macmnsvc.exe,1,,,,8083,0 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_6 |
Value: Allow Agent TCP Traffic,C:\Program Files\McAfee\Agent\masvc.exe,0,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_7 |
Value: Allow Agent UDP Traffic,C:\Program Files\McAfee\Agent\masvc.exe,1,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_8 |
Value: Allow Agent Provisioning,C:\Program Files\McAfee\Agent\maconfig.exe,0,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_9 |
Value: Allow Agent Updater Engine TCP Traffic,C:\Program Files\McAfee\Agent\McScript_InUse.exe,0,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_10 |
Value: Allow Agent Updater Engine UDP Traffic,C:\Program Files\McAfee\Agent\McScript_InUse.exe,1,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_11 |
Value: Allow Agent Repository Mirror,C:\Program Files\McAfee\Agent\marepomirror.exe,0,,,,,1 | |||
| (PID) Process: | (924) masvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\Agent\FirewallRules |
| Operation: | write | Name: | Rule_12 |
Value: Allow Agent Provisioning,C:\Program Files\McAfee\Agent\maconfigCmd.exe,0,,,,,1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\Shared.cab | — | |
MD5:— | SHA256:— | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\coninfo.xml | xml | |
MD5:391800A21D66F706C08908BA7200EF4F | SHA256:15B3EEDD2F795FADD68B5965B224580678D3E1C29A4AD1F34EBAFF77211A1A48 | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\cabundle.cer | text | |
MD5:38CEDA6F94EB434B4F04F27D3124FA07 | SHA256:F78F0BCB3EAB2536B785A744019698B9F09CD450514D9542EB39507C351945E8 | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrameworkConfig.zip | compressed | |
MD5:0D4181994F34F65FECF3A0E69D3236C9 | SHA256:4CB4754D2937FA5239FC4A6382640276C3FCF10FC5DA53A14CA8A3AA50F782CA | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\agent.ini | text | |
MD5:B742DE65F4A64355666B9A9C807BEC33 | SHA256:738E3D028C333CCF9D16EB3B1D366B2FD65E4B342B4175DB167576728A921DD7 | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\agentfipsmode | — | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\sr2048pubkey.bin | binary | |
MD5:FB599B28155C00E05882C33FE06E5DF8 | SHA256:B8F6AB4BBD8FE6C6BE3456BAA668945F71BA156D8D1D51C4BF335BFE98718642 | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\req2048seckey.bin | binary | |
MD5:5191848515739AA65CDD97E3D2E283C8 | SHA256:8BA9397BDE9834209CE78BFBDED75C05B98924D1D16DE882A7E26C91EE2A2EAE | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\RepoKeys.ini | ini | |
MD5:4C9FA315DA6856C1BC0D74520167F519 | SHA256:EDC63E39BDA39C600E426D5380F0913C825C522F3EE14DBC6750000720D89712 | |||
| 548 | TrellixSmartInstall.exe | C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\cleanup.exe | executable | |
MD5:A5C24E977890D96977A859723298AB1D | SHA256:44691F79E82E30B73CE208677CF8AB2B02021E903311841FE819AA69C6CF30A1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
548 | TrellixSmartInstall.exe | GET | 200 | 13.225.78.6:80 | http://cdn-usw004.mvision.mcafee.com/Software/Current/EPOAGENT3000/Install/0409/FrameworkInstall.zip | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
548 | TrellixSmartInstall.exe | 52.32.216.244:443 | ah-usw004.manage.trellix.com | AMAZON-02 | US | unknown |
548 | TrellixSmartInstall.exe | 192.168.100.255:8082 | — | — | — | whitelisted |
548 | TrellixSmartInstall.exe | 13.225.78.6:80 | cdn-usw004.mvision.mcafee.com | AMAZON-02 | US | whitelisted |
924 | masvc.exe | 52.32.216.244:443 | ah-usw004.manage.trellix.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ah-usw004.manage.trellix.com |
| unknown |
cdn-usw004.mvision.mcafee.com |
| unknown |
sw-usw004.mvision.mcafee.com |
| unknown |
ah-usw004.mvision.mcafee.com |
| unknown |
cdn-usw004.manage.trellix.com |
| unknown |
Process | Message |
|---|---|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfevtpa.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: DLL not found in install location, looking in current directory
|
FrmInst.exe | NotComDllGetInterface: C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\FrmInst.exe loading C:\Users\admin\AppData\Local\Temp\McAfeeSmartInstall\mfeaaca.dll, WinVerifyTrust failed with 80092003
|