File name:

Agent-Core-Windows-10.0.0-3240.i386.msi

Full analysis: https://app.any.run/tasks/b0ab23a4-eff2-404e-a939-e9fc64c431f1
Verdict: Malicious activity
Analysis date: January 08, 2020, 15:09:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 950, Title: Installation Database, Subject: Trend Micro Deep Security Agent, Author: q, Keywords: Installer Firewall DPI IDS IPS Integrity-Monitoring Log-Inspection, Comments: w{w]t Deep Security Agent wM, Create Time/Date: Tue Jan 29 02:44:46 2019, Name of Creating Application: Windows Installer XML Toolset (3.10.3.3007), Security: 2, Template: Intel;1033, Last Saved By: Intel;1028, Revision Number: {40B647BE-5F0F-42F3-A862-78870786F8F0}127.127.32767;{9E9C33D7-CCD2-4BDC-A540-1417E3880CEB}127.127.32767;{7D80D986-A5B6-4A74-BF95-9DD7C2B43980}, Number of Pages: 300, Number of Characters: 0
MD5:

48762C47EEDB201A56847D31C91BA071

SHA1:

69E2B946A7DEFF5F3E5C6D237801759BCE7CF3B6

SHA256:

CD48312182843B0FB94A41E36EE0E4F5A94A264888F9A12C68001684B351603C

SSDEEP:

98304:gjlHGBzETDJcUtkF2zNCAaaWGvCaLv+PDz29MIsZXSfT2TQue03USgVdLi:g5HOzETttkFx7c2HDfS0Q3Vw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ds_monitor.exe (PID: 2620)
      • dsa.exe (PID: 2372)
      • Notifier.exe (PID: 1648)
      • Notifier.exe (PID: 2960)
    • Loads dropped or rewritten executable

      • ds_monitor.exe (PID: 2620)
  • SUSPICIOUS

    • Executed as Windows Service

      • ds_monitor.exe (PID: 2620)
      • dsa.exe (PID: 2372)
      • Notifier.exe (PID: 2960)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4064)
      • msiexec.exe (PID: 2716)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 2716)
    • Creates files in the program directory

      • Notifier.exe (PID: 2960)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1948)
      • MsiExec.exe (PID: 3944)
      • MsiExec.exe (PID: 2428)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2716)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 2716)
    • Application launched itself

      • msiexec.exe (PID: 2716)
    • Creates files in the program directory

      • msiexec.exe (PID: 2716)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Trend Micro Deep Security Agent
Author: Trend Micro Inc.
Keywords: Installer Firewall DPI IDS IPS Integrity-Monitoring Log-Inspection
Comments: This installer database contains the logic and data required to install Deep Security Agent
RevisionNumber: {E893E793-8705-4AA7-9ADC-D06C2A1661AC}
CreateDate: 2019:01:29 02:43:00
ModifyDate: 2019:01:29 02:43:00
Pages: 300
Words: 2
Software: Windows Installer XML Toolset (3.10.3.3007)
Security: Read-only recommended
Template: Intel;1033,1031,3082,1036,1040,1041,1042,1049,2052,1028
LastModifiedBy: Intel;1031
Characters: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs notifier.exe no specs notifier.exe no specs ds_monitor.exe dsa.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1648"C:\Program Files\Trend Micro\Deep Security Agent\Notifier.exe"C:\Program Files\Trend Micro\Deep Security Agent\Notifier.exeNotifier.exe
User:
admin
Company:
Trend Micro Inc.
Integrity Level:
MEDIUM
Description:
Deep Security Notifier
Exit code:
0
Version:
10.0.0.3240
Modules
Images
c:\program files\trend micro\deep security agent\notifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1948C:\Windows\system32\MsiExec.exe -Embedding A41B17B2815F81A03124B6C1325259DC CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2372"C:\Program Files\Trend Micro\Deep Security Agent\dsa.exe" -a "ds_agent" -b -i -w "HKLM\Software\TrendMicro\Deep Security Agent\DataFolder" -e "C:\Program Files\Trend Micro\Deep Security Agent\ext\."C:\Program Files\Trend Micro\Deep Security Agent\dsa.exeservices.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Deep Security Agent
Exit code:
0
Version:
10.0.0.3240
2428C:\Windows\system32\MsiExec.exe -Embedding 5EA71CDEC4C00E8EA12429F8D95C180E M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2620"C:\Program Files\Trend Micro\Deep Security Agent\ds_monitor.exe"C:\Program Files\Trend Micro\Deep Security Agent\ds_monitor.exe
services.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Deep Security Monitor
Exit code:
0
Version:
10.0.0.3240
Modules
Images
c:\program files\trend micro\deep security agent\ds_monitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\trend micro\deep security agent\msvcp110.dll
c:\program files\trend micro\deep security agent\msvcr110.dll
2716C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2960"C:\Program Files\Trend Micro\Deep Security Agent\Notifier.exe" -serviceC:\Program Files\Trend Micro\Deep Security Agent\Notifier.exeservices.exe
User:
SYSTEM
Company:
Trend Micro Inc.
Integrity Level:
SYSTEM
Description:
Deep Security Notifier
Exit code:
0
Version:
10.0.0.3240
Modules
Images
c:\program files\trend micro\deep security agent\notifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3944C:\Windows\system32\MsiExec.exe -Embedding 79B6315400D0B14D05DCD786D9A52096C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4064"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Agent-Core-Windows-10.0.0-3240.i386.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
787
Read events
586
Write events
199
Delete events
2

Modification events

(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
(PID) Process:(4064) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-844
Value:
BitLocker Data Recovery Agent
(PID) Process:(2716) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2716) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
9C0A0000CCFD30AF35C6D501
(PID) Process:(2716) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
2FC0CA2667B9C777818E06367749388D8A3077B8560E65C8E3F1A9AD8332433B
(PID) Process:(2716) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
Executable files
40
Suspicious files
16
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\CabBD5F.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\TarBD60.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\CabBD70.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\TarBD71.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\CabBE3E.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\TarBE3F.tmp
MD5:
SHA256:
4064msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI5428.tmp
MD5:
SHA256:
2716msiexec.exeC:\Windows\Installer\3a5b06.msi
MD5:
SHA256:
2716msiexec.exeC:\Users\admin\AppData\Local\Temp\Cab5BD1.tmp
MD5:
SHA256:
2716msiexec.exeC:\Users\admin\AppData\Local\Temp\Tar5BD2.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4064
msiexec.exe
GET
200
92.122.213.201:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
57.4 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4064
msiexec.exe
92.122.213.201:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
www.download.windowsupdate.com
  • 92.122.213.201
  • 92.122.213.217
whitelisted

Threats

No threats detected
Process
Message
ds_monitor.exe
ds_monitor
ds_monitor.exe
Setting ds_monitor state to 2
ds_monitor.exe
ServiceMain_
ds_monitor.exe
Setting ds_monitor state to 4