| File name: | neoTermServSetup.exe |
| Full analysis: | https://app.any.run/tasks/b3baec1f-64b4-4f48-a9f8-75e2568b072d |
| Verdict: | Malicious activity |
| Analysis date: | January 22, 2025, 12:34:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 9980AFA1FCADABC96312DA46AA8B0AC6 |
| SHA1: | 12D4E9D858CD260CC81314BC61DA985364C49643 |
| SHA256: | F3E9E9497ABD12AB005362B21C41D8C9852970050B8CC62ABBABC215896B9FC3 |
| SSDEEP: | 98304:byR5i6CSDsR++nGBYoYB/3jKaMNM4B0Tgqz0ZuZ8ftXbmcl8cKGYg4FbG6EJE1Ma:Xnh8U5x |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 22:27:36+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 123904 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x366e |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2996 | "C:\Users\admin\AppData\Local\Temp\neoTermServSetup.exe" | C:\Users\admin\AppData\Local\Temp\neoTermServSetup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Pulse Secure\Pulse Terminal Services Client |
| Operation: | write | Name: | Language |
Value: | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | DisplayName |
Value: Pulse Secure Terminal Services Client | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\uninstall.exe" | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\uninstall.exe" /S | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | StartupApp |
Value: "C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServ.exe" | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | StopApp |
Value: "C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServ.exe" -stop | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | DisplayVersion |
Value: 9.1.18.25581 | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | Publisher |
Value: Pulse Secure, LLC | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services |
| Operation: | write | Name: | URLInfoAbout |
Value: http://www.pulsesecure.net | |||
| (PID) Process: | (2996) neoTermServSetup.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pulse_Term_Services\Commands |
| Operation: | write | Name: | RegisterOCX |
Value: "C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\msrdp.ocx",DllRegisterServer | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServ.exe | executable | |
MD5:D00465AF94C4316589EDEA9AAC9F691B | SHA256:3952D940BC414A1719D20C5F346261D2F757E470767C6F287B6D0514A0D4FA65 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServResource_JA.dll | executable | |
MD5:F82B394805599B6AC4C98BBF5C1C300F | SHA256:5C35F0F9877254E578520955D7825677FBF8B39528E6FD4E2D30F3BAFBB1F1F6 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsWinClient.dll | executable | |
MD5:B6D96032A6BD8E5FC0407C17EEE76C2B | SHA256:E70CC980C5609BD9D102384840CE8B5C65CE525F8B60F5C5F2A10D05D381883D | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServResource_DE.dll | executable | |
MD5:14EF04E874454EBAF9D8BCEF8201B49B | SHA256:790A4F20613A79E65FD59EB31EA82C87A7FCCDDBE6536E0FB68E3A3F46741C73 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServResource_ZH_CN.dll | executable | |
MD5:E76CFCFB72B80BDC371DFC380ED9A842 | SHA256:7180BDC8F732C5C20A70D24BEB00A185F8E5DAB2DB56459F8C99B4CD911DE704 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServResource_FR.dll | executable | |
MD5:B36CB6A93CD3838794AD8800FF5B0A27 | SHA256:E56A789A3F5AE99DAADBC3BD691B143D30338929168F2266845C6C32168ED00D | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsTermServResource_ES.dll | executable | |
MD5:4124DB22667FA00CB24149FA4B35E68E | SHA256:6B4C6819DA6DD7277DAFE113E4203871C9ED146775E0304A55204F34A962460D | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\dsOpenSSL.dll | executable | |
MD5:FF5D08FAEC1579078A6670D0E85A2397 | SHA256:06039470A2BB31C35844BD6C66006C04240B167AFD1A13F36A1A00905481D777 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\libcrypto-1_1.dll | executable | |
MD5:973932FDFD0E0B58870CB93CC9F35212 | SHA256:DB9FD3C18EB5C47624EF1192AA1F29DF39E3FB039109865906E36D5AF712E300 | |||
| 2996 | neoTermServSetup.exe | C:\Users\admin\AppData\Roaming\Pulse Secure\Pulse Terminal Services Client\wolfEngine.dll | executable | |
MD5:6A7318570AB6283082AF43BD4ECEA528 | SHA256:9A448560A795527ABBD3A4E042572C4A8779F3B5EF0E6822DEE4E5AC64634A46 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6972 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6972 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6292 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
876 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
1176 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4536 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |