| File name: | vsstrace.dll |
| Full analysis: | https://app.any.run/tasks/d0d14b21-f2ae-4690-900f-8adf325625bf |
| Verdict: | Malicious activity |
| Analysis date: | August 20, 2024, 13:04:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (DLL) (GUI) x86-64, for MS Windows |
| MD5: | 1EA063DFAEFF28CD360D3994C1BB78A3 |
| SHA1: | 4CC4A0C7C9DB2218AE78A21D185A81783150758B |
| SHA256: | CC48C0C10D3F7489F9126FD03144A6A015C3374268CB75FA699FC3B215924CE7 |
| SSDEEP: | 1536:8c4oRT9VwJJjhNXCV44XuWk+ZzrZf2wUsnk+:qgVwhMuWk+JBUQb |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 1975:11:30 01:06:30+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, DLL |
| PEType: | PE32+ |
| LinkerVersion: | 14.3 |
| CodeSize: | 40960 |
| InitializedDataSize: | 53248 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1fd0 |
| OSVersion: | 10 |
| ImageVersion: | 10 |
| SubsystemVersion: | 10 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.0.22621.1 |
| ProductVersionNumber: | 10.0.22621.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft® Volume Shadow Copy Service Tracing Library |
| FileVersion: | 10.0.22621.1 (WinBuild.160101.0800) |
| InternalName: | vsstrace.dll |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | vsstrace.dll |
| ProductName: | Microsoft® Windows® Operating System |
| ProductVersion: | 10.0.22621.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | DrvInst.exe "5" "2" "C:\WINDOWS\System32\DriverStore\FileRepository\prnms006.inf_amd64_2f92130612032712\prnms006.inf" "0" "449f30e93" "00000000000001D8" "WinSta0\Default" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2816 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3840 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\wedinterface.png" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3980 | C:\Users\admin\AppData\Local\Temp\B56D35EF-4C90-4A76-A9FB-8AB28454408E\dismhost.exe {B5EC8B33-7F4C-410D-9493-6B2BEF32344C} | C:\Users\admin\AppData\Local\Temp\B56D35EF-4C90-4A76-A9FB-8AB28454408E\DismHost.exe | — | cleanmgr.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Dism Host Servicing Process Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6180 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\electricman.png" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6728 | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -Embedding | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Worker Version: 10.0.19041.3989 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6804 | "C:\WINDOWS\System32\rundll32.exe" C:\Users\admin\AppData\Local\Temp\vsstrace.dll, #1 | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6832 | "C:\WINDOWS\system32\cleanmgr.exe" | C:\Windows\System32\cleanmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Disk Space Cleanup Manager for Windows Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7124 | "C:\WINDOWS\system32\cleanmgr.exe" | C:\Windows\System32\cleanmgr.exe | cleanmgr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Disk Space Cleanup Manager for Windows Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%systemroot%\system32\domgmt.dll,-103 |
Value: Delivery Optimization Files | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%systemroot%\system32\domgmt.dll,-104 |
Value: Delivery Optimization files are files that were previously downloaded to your computer and can be deleted if currently unused by the Delivery Optimization service. | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1070 |
Value: Downloaded Program Files | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1071 |
Value: Downloaded Program Files are ActiveX controls and Java applets downloaded automatically from the Internet when you view certain pages. They are temporarily stored in the Downloaded Program Files folder on your hard disk. | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1072 |
Value: &View Files | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\DATACLEN.DLL,-1010 |
Value: Setup Log Files | |||
| (PID) Process: | (6832) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\DATACLEN.DLL,-1011 |
Value: Files created by Windows | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6832 | cleanmgr.exe | C:\Windows\System32\LogFiles\setupcln\setupact.log | — | |
MD5:— | SHA256:— | |||
| 6832 | cleanmgr.exe | C:\Windows\System32\LogFiles\setupcln\diagwrn.xml | text | |
MD5:120A5813D24065B9212B5842190FEB08 | SHA256:18CCF640E3AD27215E88E709AECED5FD9A57E3D19C1DE8DAA1AB79BDEBE80D20 | |||
| 6832 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\d3fe7cdcb51a5ef5\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 6832 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 7124 | cleanmgr.exe | C:\Windows\Logs\DISM\dism.log | text | |
MD5:36C450759A94664D6417937482982909 | SHA256:3F8982AF3CF925144C9BD3241654523177C4FC287A39BB4CEEFC0FF55613692A | |||
| 6832 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\f4d41c5d09ae781\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 6832 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\ecbf0d5a3a180bb\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 7124 | cleanmgr.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:FB64A9EBEDF48D3895381D5B7D80743D | SHA256:EA21D495930AD76F267A33A0F593DBF0C7EA75E457FCAE49A29DAAD8BD920F42 | |||
| 6832 | cleanmgr.exe | C:\Users\admin\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 7124 | cleanmgr.exe | C:\Users\admin\AppData\Local\Temp\B56D35EF-4C90-4A76-A9FB-8AB28454408E\AssocProvider.dll | executable | |
MD5:B7DB592706D3EEFBCF0D5A166D462E56 | SHA256:DE21321272862E7C332E1724DC315F06F3ABE7A0340E61D351CAB208D6BBF059 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
4084 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7152 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6452 | SIHClient.exe | GET | 200 | 23.218.209.163:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2096 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3800 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4084 | svchost.exe | 40.126.32.138:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4084 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
7152 | backgroundTaskHost.exe | 20.223.36.55:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
7152 | backgroundTaskHost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fp.msedge.net |
| whitelisted |
www.bing.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: <----- Starting DismApi.dll session -----> - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: Host machine information: OS Version=10.0.19045, Running architecture=amd64, Number of processors=4 - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: API Version 10.0.19041.3758 - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 DismApi.dll: Parent process command line: "C:\WINDOWS\system32\cleanmgr.exe" - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 Enter DismInitializeInternal - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 Input parameters: LogLevel: 2, LogFilePath: (null), ScratchDirectory: (null) - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 Initialized GlobalConfig - DismInitializeInternal
|
cleanmgr.exe | PID=7124 TID=6884 Initialized SessionTable - DismInitializeInternal
|