File name: | ManageEngineAssetExplorerAgent.msi |
Full analysis: | https://app.any.run/tasks/4e1bfc2f-f8d6-4770-ba35-b18e9093b80e |
Verdict: | Malicious activity |
Analysis date: | August 14, 2018, 03:39:05 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {B7E8074D-D742-44B1-8305-6EBDD55F6DD7}, Title: ManageEngine AssetExplorer, Author: ZOHO Corp, Number of Words: 2, Last Saved Time/Date: Fri Jan 5 12:28:55 2018, Last Printed: Fri Jan 5 12:28:55 2018 |
MD5: | B8D2995C8AA53949A35BB305A7448C76 |
SHA1: | 2CE89F8A6A63BA4302D36AABE45FC47970EFB0D3 |
SHA256: | EA6FF48DB7D61FD663BC2E5D579486759B774F1E325D0EF7241CDB01C399311C |
SSDEEP: | 98304:H6xw+Yp/F/Tcs7aPWfmnlgirBnvCR1qxJVTWHkYtPJak:H6KzSc6fmKV6HZJak |
.msi | | | Microsoft Windows Installer (98.5) |
---|---|---|
.msi | | | Microsoft Installer (100) |
CreateDate: | 1999:06:21 07:00:00 |
---|---|
Software: | Windows Installer |
Security: | Password protected |
CodePage: | Windows Latin 1 (Western European) |
Template: | Intel;1033 |
Pages: | 200 |
RevisionNumber: | {B7E8074D-D742-44B1-8305-6EBDD55F6DD7} |
Title: | ManageEngine AssetExplorer |
Subject: | - |
Author: | ZOHO Corp |
Keywords: | - |
Comments: | - |
Words: | 2 |
ModifyDate: | 2018:01:05 12:28:55 |
LastPrinted: | 2018:01:05 12:28:55 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
696 | WSCRIPT /B ae_scan.vbs agentdata | C:\Windows\system32\wscript.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
1336 | agentmonitor.exe /r | C:\Program Files\ManageEngine\AssetExplorer\bin\agentmonitor.exe | CustomActions.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
1460 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot19" "" "" "61530dda3" "00000000" "000004B0" "00000330" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2176 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2208 | cmd /c aeagent.bat scan | C:\Windows\system32\cmd.exe | — | aeagent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2416 | cmd /c aeagent.bat deltascan | C:\Windows\system32\cmd.exe | — | aeagent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2452 | cmd /c aeagent.bat scan | C:\Windows\system32\cmd.exe | — | aeagent.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2464 | WSCRIPT /B ae_scan.vbs agentdata | C:\Windows\system32\wscript.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
2468 | aeagent.exe POST_SCAN_DATA | C:\Program Files\ManageEngine\AssetExplorer\bin\aeagent.exe | agentmonitor.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
2492 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\ManageEngineAssetExplorerAgent.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2492) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2728) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000C06FBF6D8033D401A80A000050070000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2728) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000C06FBF6D8033D401A80A000050070000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000004CF6066E8033D401800800005C0E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000004CF6066E8033D40180080000180D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000004CF6066E8033D40180080000B80C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000004CF6066E8033D4018008000084020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000005A1D0E6E8033D40180080000180D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000005A1D0E6E8033D4018008000084020000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (2176) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000000EE2126E8033D401800800005C0E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2728 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFEDBAA464AB680816.TMP | — | |
MD5:— | SHA256:— | |||
2176 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{e7d53678-b090-4013-853b-a4e710187495}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
1460 | DrvInst.exe | C:\Windows\INF\setupapi.ev1 | binary | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\Windows\Installer\MSI829D.tmp | binary | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\Program Files\ManageEngine\AssetExplorer\bin\CustomActions.exe | executable | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\Program Files\ManageEngine\AssetExplorer\RemoteControl\Service.exe | executable | |
MD5:— | SHA256:— | |||
2728 | msiexec.exe | C:\Program Files\ManageEngine\AssetExplorer\bin\agentmonitor.exe | executable | |
MD5:— | SHA256:— |
Domain | IP | Reputation |
---|---|---|
hypsdprd01.tra.ae |
| unknown |