URL:

https://www.citrix.com/downloads/workspace-app/windows/workspace-app-for-windows-latest.html?srsltid=AfmBOoqOjTW0sz0K2Y-e5vUoc0JJooZDcuQwFnwG_0OPty9SwG-zxRPk

Full analysis: https://app.any.run/tasks/b98e78b5-0515-43bf-a40b-c8f7111cc5bc
Verdict: Malicious activity
Analysis date: January 15, 2025, 12:54:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MD5:

95A9477FA68DC108BA6562F930D20626

SHA1:

B9B08AA5F94001D66EBDFA220516415FF9F240A3

SHA256:

C4EA0B67BC06FA458316D26CB901C73EF4559F7B9AFC052E03ACA2D473095987

SSDEEP:

3:N8DSL1qGTKBKXK5bl/L0KXLnW/aKSSAMRqXzMU0NusIOdHhUeS+QR+31O:2OLYKK8aP/wMDLKSSjRqXzXpOdHhUNnB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CitrixWorkspaceApp.exe (PID: 2744)
      • bootstrapperhelper.exe (PID: 2728)
      • DotNetCoreInstaller.exe (PID: 2676)
      • DotNetCoreInstaller.exe (PID: 4816)
      • dotnetcoreinstaller.exe (PID: 6288)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 372)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • DotNetCoreInstaller.exe (PID: 7456)
      • DotNetCoreInstaller.exe (PID: 7480)
      • vc_redist.x86.exe (PID: 7656)
      • vc_redist.x86.exe (PID: 7632)
      • vc_redist.x64.exe (PID: 7976)
      • VC_redist.x86.exe (PID: 7912)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 6584)
      • VC_redist.x86.exe (PID: 7704)
      • VC_redist.x86.exe (PID: 7864)
      • vc_redist.x64.exe (PID: 8040)
      • VC_redist.x64.exe (PID: 8088)
      • VC_redist.x64.exe (PID: 4544)
      • VC_redist.x64.exe (PID: 7268)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7352)
      • DXSETUP.exe (PID: 6148)
    • Reads security settings of Internet Explorer

      • CitrixWorkspaceApp.exe (PID: 2744)
      • bootstrapperhelper.exe (PID: 2728)
      • DotNetCoreInstaller.exe (PID: 2676)
      • dotnetcoreinstaller.exe (PID: 6288)
      • CWAInstaller.exe (PID: 6192)
    • The process drops C-runtime libraries

      • bootstrapperhelper.exe (PID: 2728)
      • msiexec.exe (PID: 2456)
    • Process drops legitimate windows executable

      • bootstrapperhelper.exe (PID: 2728)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 372)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 6584)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • msiexec.exe (PID: 2456)
      • vc_redist.x86.exe (PID: 7632)
      • vc_redist.x86.exe (PID: 7656)
      • VC_redist.x86.exe (PID: 7912)
      • vc_redist.x64.exe (PID: 7976)
      • VC_redist.x86.exe (PID: 7704)
      • vc_redist.x64.exe (PID: 8040)
      • VC_redist.x64.exe (PID: 8088)
      • VC_redist.x64.exe (PID: 7268)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7352)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
      • DXSETUP.exe (PID: 6148)
    • Starts itself from another location

      • DotNetCoreInstaller.exe (PID: 4816)
      • DotNetCoreInstaller.exe (PID: 2676)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 6584)
      • DotNetCoreInstaller.exe (PID: 7480)
      • vc_redist.x86.exe (PID: 7656)
      • vc_redist.x64.exe (PID: 8040)
      • DotNetCoreInstaller.exe (PID: 7456)
    • Searches for installed software

      • dllhost.exe (PID: 4360)
      • DotNetCoreInstaller.exe (PID: 7480)
      • VC_redist.x86.exe (PID: 7864)
      • VC_redist.x64.exe (PID: 7268)
      • VC_redist.x64.exe (PID: 4544)
    • Checks Windows Trust Settings

      • DotNetCoreInstaller.exe (PID: 2676)
      • dotnetcoreinstaller.exe (PID: 6288)
      • msiexec.exe (PID: 2456)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3824)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 6584)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • vc_redist.x86.exe (PID: 7656)
      • VC_redist.x86.exe (PID: 7704)
      • vc_redist.x64.exe (PID: 8040)
      • VC_redist.x64.exe (PID: 8088)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • VC_redist.x64.exe (PID: 8088)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 2456)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2456)
      • CWAInstaller.exe (PID: 6192)
    • Creates file in the systems drive root

      • explorer.exe (PID: 4488)
    • Application launched itself

      • VC_redist.x86.exe (PID: 7840)
      • VC_redist.x86.exe (PID: 7864)
      • VC_redist.x64.exe (PID: 7220)
      • VC_redist.x64.exe (PID: 4544)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 1868)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 6392)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 6392)
      • chrome.exe (PID: 4724)
      • msiexec.exe (PID: 2456)
    • The process uses the downloaded file

      • chrome.exe (PID: 1796)
      • DotNetCoreInstaller.exe (PID: 2676)
    • The sample compiled with english language support

      • chrome.exe (PID: 4724)
      • DotNetCoreInstaller.exe (PID: 2676)
      • bootstrapperhelper.exe (PID: 2728)
      • CitrixWorkspaceApp.exe (PID: 2744)
      • dotnetcoreinstaller.exe (PID: 6288)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 372)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 6584)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • DotNetCoreInstaller.exe (PID: 4816)
      • msiexec.exe (PID: 2456)
      • DotNetCoreInstaller.exe (PID: 7456)
      • DotNetCoreInstaller.exe (PID: 7480)
      • vc_redist.x86.exe (PID: 7632)
      • vc_redist.x86.exe (PID: 7656)
      • VC_redist.x86.exe (PID: 7704)
      • VC_redist.x86.exe (PID: 7864)
      • VC_redist.x86.exe (PID: 7912)
      • vc_redist.x64.exe (PID: 7976)
      • vc_redist.x64.exe (PID: 8040)
      • VC_redist.x64.exe (PID: 8088)
      • VC_redist.x64.exe (PID: 4544)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7352)
      • VC_redist.x64.exe (PID: 7268)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
      • DXSETUP.exe (PID: 6148)
    • Reads the software policy settings

      • explorer.exe (PID: 4488)
      • DotNetCoreInstaller.exe (PID: 2676)
      • msiexec.exe (PID: 2456)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
      • CWAInstaller.exe (PID: 6192)
    • Checks proxy server information

      • explorer.exe (PID: 4488)
      • dotnetcoreinstaller.exe (PID: 6288)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
      • CWAInstaller.exe (PID: 6192)
      • DXSETUP.exe (PID: 6148)
    • Checks supported languages

      • CitrixWorkspaceApp.exe (PID: 2744)
      • bootstrapperhelper.exe (PID: 2728)
      • PreRequisiteInstaller.exe (PID: 4556)
      • dotnetcoreinstaller.exe (PID: 6288)
      • msiexec.exe (PID: 2456)
      • msiexec.exe (PID: 7320)
      • vc_redist.x64.exe (PID: 8040)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
      • CWAInstaller.exe (PID: 6192)
    • Sends debugging messages

      • CitrixWorkspaceApp.exe (PID: 2744)
      • bootstrapperhelper.exe (PID: 2728)
      • PreRequisiteInstaller.exe (PID: 4556)
      • msiexec.exe (PID: 2456)
      • CWAInstaller.exe (PID: 6192)
      • DXSETUP.exe (PID: 6148)
    • Reads the computer name

      • CitrixWorkspaceApp.exe (PID: 2744)
      • PreRequisiteInstaller.exe (PID: 4556)
      • DotNetCoreInstaller.exe (PID: 2676)
      • dotnetcoreinstaller.exe (PID: 6288)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • dotnetcoreinstaller.exe (PID: 7528)
      • DotNetCoreInstaller.exe (PID: 7480)
      • vc_redist.x86.exe (PID: 7656)
      • VC_redist.x86.exe (PID: 7864)
      • VC_redist.x64.exe (PID: 4544)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4488)
    • Creates files in the program directory

      • bootstrapperhelper.exe (PID: 2728)
      • PreRequisiteInstaller.exe (PID: 4556)
      • dotnetcoreinstaller.exe (PID: 6288)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
    • Process checks computer location settings

      • CitrixWorkspaceApp.exe (PID: 2744)
      • MicrosoftEdgeUpdate.exe (PID: 1868)
    • Creates files or folders in the user directory

      • PreRequisiteInstaller.exe (PID: 4556)
      • explorer.exe (PID: 4488)
      • dotnetcoreinstaller.exe (PID: 6288)
    • Manages system restore points

      • SrTasks.exe (PID: 5880)
    • Reads the machine GUID from the registry

      • DotNetCoreInstaller.exe (PID: 2676)
      • dotnetcoreinstaller.exe (PID: 6288)
      • windowsdesktop-runtime-8.0.4-win-x86.exe (PID: 3420)
      • msiexec.exe (PID: 2456)
      • VC_redist.x86.exe (PID: 7704)
      • CWAInstaller.exe (PID: 6192)
    • Create files in a temporary directory

      • DotNetCoreInstaller.exe (PID: 2676)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2456)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 1868)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
207
Monitored processes
70
Malicious processes
15
Suspicious processes
12

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs rundll32.exe no specs explorer.exe citrixworkspaceapp.exe chrome.exe no specs chrome.exe no specs bootstrapperhelper.exe no specs bootstrapperhelper.exe prerequisiteinstaller.exe dotnetcoreinstaller.exe dotnetcoreinstaller.exe dotnetcoreinstaller.exe SPPSurrogate no specs vssvc.exe no specs chrome.exe no specs srtasks.exe no specs conhost.exe no specs chrome.exe no specs windowsdesktop-runtime-8.0.4-win-x86.exe windowsdesktop-runtime-8.0.4-win-x86.exe windowsdesktop-runtime-8.0.4-win-x86.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs dotnetcoreinstaller.exe dotnetcoreinstaller.exe dotnetcoreinstaller.exe no specs SPPSurrogate no specs vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe no specs vc_redist.x86.exe vc_redist.x86.exe vc_redist.x64.exe chrome.exe no specs vc_redist.x64.exe vc_redist.x64.exe SPPSurrogate no specs vc_redist.x64.exe no specs vc_redist.x64.exe vc_redist.x64.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe cwainstaller.exe chrome.exe no specs dxsetup.exe SPPSurrogate no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\ProgramData\Package Cache\003DB9CAF01060799F32A5CA1B98355AE305DC24\redist\windowsdesktop-runtime-8.0.4-win-x86.exe" /q /norestart /ChainingPackage "dotnetcoreinstaller" /log "C:\Program Files (x86)\Citrix\Logs\CTXPreRequisiteInstallLogs-20250115-125643\CtxInstall-DotNetCoreInstaller-20250115-125643_000_NetCoreDesktopRuntime_x86.log.log" /pipe NetFxSection.{B91F82D5-0A7A-4AEA-9AA6-5C403F59B4CC}C:\ProgramData\Package Cache\003DB9CAF01060799F32A5CA1B98355AE305DC24\redist\windowsdesktop-runtime-8.0.4-win-x86.exe
dotnetcoreinstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Desktop Runtime - 8.0.4 (x86)
Exit code:
0
Version:
8.0.4.33519
Modules
Images
c:\programdata\package cache\003db9caf01060799f32a5ca1b98355ae305dc24\redist\windowsdesktop-runtime-8.0.4-win-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
628"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4280 --field-trial-handle=1928,i,970888239465356562,1238080228040947495,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
644"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=4400 --field-trial-handle=1928,i,970888239465356562,1238080228040947495,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=3568 --field-trial-handle=1928,i,970888239465356562,1238080228040947495,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1480"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6040 --field-trial-handle=1928,i,970888239465356562,1238080228040947495,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1796"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=6052 --field-trial-handle=1928,i,970888239465356562,1238080228040947495,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1868"C:\Program Files (x86)\Microsoft\Temp\EUD100.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EUD100.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.181.5
Modules
Images
c:\program files (x86)\microsoft\temp\eud100.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2456C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2676"C:\Users\admin\AppData\Local\Temp\{A4B87E76-A006-40F6-AAF7-B620A956402E}\.cr\DotNetCoreInstaller.exe" -burn.clean.room="C:\Program Files (x86)\Citrix\Ctx-4D04A53B-3609-4008-8BD0-319827489AB8\DotNetCoreInstaller.exe" -burn.filehandle.attached=712 -burn.filehandle.self=716 /silent /norestart /l "C:\Program Files (x86)\Citrix\Logs\CTXPreRequisiteInstallLogs-20250115-125643\CtxInstall-DotNetCoreInstaller-20250115-125643.log"C:\Users\admin\AppData\Local\Temp\{A4B87E76-A006-40F6-AAF7-B620A956402E}\.cr\DotNetCoreInstaller.exe
DotNetCoreInstaller.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
HIGH
Description:
dotnetcoreinstaller
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\{a4b87e76-a006-40f6-aaf7-b620a956402e}\.cr\dotnetcoreinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2728"C:\Users\admin\AppData\Local\Ctx-528512E6-1941-4737-BFB7-FC21AFF35D1D\Extract\bootstrapperhelper.exe" C:\Users\admin\AppData\Local\Ctx-528512E6-1941-4737-BFB7-FC21AFF35D1D\Extract\bootstrapperhelper.exe
CitrixWorkspaceApp.exe
User:
admin
Company:
Citrix Systems, Inc.
Integrity Level:
HIGH
Description:
Citrix Workspace
Version:
24.9.1.207
Modules
Images
c:\users\admin\appdata\local\ctx-528512e6-1941-4737-bfb7-fc21aff35d1d\extract\bootstrapperhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
Total events
65 609
Read events
62 520
Write events
2 398
Delete events
691

Modification events

(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(6392) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(4488) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppBadgeUpdated
Operation:writeName:Chrome
Value:
6
(PID) Process:(4488) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000602E4
Operation:writeName:VirtualDesktop
Value:
1000000030304456A48A294F7A40804AB924005FF030B61F
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\StatefulEvents\C
Operation:writeName:C7I
Value:
1
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C1I
Value:
1
(PID) Process:(6392) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C2I
Value:
1
Executable files
1 146
Suspicious files
612
Text files
257
Unknown types
17

Dropped files

PID
Process
Filename
Type
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF136a85.TMP
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF136a85.TMP
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF136a85.TMP
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF136a85.TMP
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF136aa4.TMP
MD5:
SHA256:
6392chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
48
TCP/UDP connections
174
DNS requests
195
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4504
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6628
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
5732
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/imoffpf67hel7kbknqflao2oo4_1.0.2738.0/neifaoindggfcjicffkgpmnlppeffabd_1.0.2738.0_win64_kj4dp5kifwxbdodqls7e5nzhtm.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6076
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.21.65.132:443
www.bing.com
Akamai International B.V.
NL
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
6392
chrome.exe
239.255.255.250:1900
whitelisted
6796
chrome.exe
104.102.45.64:443
www.citrix.com
AKAMAI-AS
DE
whitelisted
6796
chrome.exe
108.177.127.84:443
accounts.google.com
GOOGLE
US
whitelisted
6796
chrome.exe
184.28.89.29:443
assets.adobedtm.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.21.65.132
  • 2.21.65.154
  • 2.23.227.221
  • 2.23.227.215
  • 2.23.227.199
  • 2.23.227.198
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
www.citrix.com
  • 104.102.45.64
whitelisted
accounts.google.com
  • 108.177.127.84
whitelisted
assets.adobedtm.com
  • 184.28.89.29
whitelisted
s7.addthis.com
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.32.138
whitelisted
consent.trustarc.com
  • 18.66.122.49
  • 18.66.122.97
  • 18.66.122.116
  • 18.66.122.78
shared
tag.demandbase.com
  • 18.245.46.89
  • 18.245.46.25
  • 18.245.46.44
  • 18.245.46.22
whitelisted
www.googletagmanager.com
  • 142.250.185.168
whitelisted

Threats

No threats detected
Process
Message
CitrixWorkspaceApp.exe
CUpdatePackage::Run: Temp Path is C:\Users\admin\AppData\Local
CitrixWorkspaceApp.exe
RunPackage: bootstrap install started
CitrixWorkspaceApp.exe
Extracting files to folder with index -1
bootstrapperhelper.exe
Installing PreRequisite from path C:\Program Files (x86)\Citrix\Ctx-4D04A53B-3609-4008-8BD0-319827489AB8
bootstrapperhelper.exe
CreateFolderAndExtactBinary::dualpk does not exist...C:\Program Files (x86)\Citrix\Ctx-4D04A53B-3609-4008-8BD0-319827489AB8\dualpk.cab
bootstrapperhelper.exe
CreateFolderAndExtactBinary: User`is an Admin
bootstrapperhelper.exe
[C:\tc\work\b1ab78357dece3ec\Utility\src\Windows\Source\CustomerSpecificBrandingHelper.cpp:154] CustomerSpecificBrandingHelper : Unable to find any BrandPersonalization install info.
bootstrapperhelper.exe
[C:\tc\work\b1ab78357dece3ec\Utility\src\Windows\Source\CustomerSpecificBrandingHelper.cpp:91] CustomerSpecificBrandingHelper : There is no Admin install.
bootstrapperhelper.exe
Launching process from path : C:\Program Files (x86)\Citrix\Ctx-4D04A53B-3609-4008-8BD0-319827489AB8\PreRequisiteInstaller.exe with cmdline
PreRequisiteInstaller.exe
Information - CRebrandingHelper::Initialize(24) - Branded Name is : Citrix Workspace