File name:

Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe

Full analysis: https://app.any.run/tasks/47e9640a-ed0a-48e0-a688-8b726fa7728f
Verdict: Malicious activity
Analysis date: May 21, 2021, 14:23:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

961795E6F576C203ACF26756248B1061

SHA1:

2A1EBF419DE2B5B5E4B7F34BFB9C4FBEB2A060F2

SHA256:

FB7D9A5CF6AE1B52786827AB9357062EC5A7A9B49D1FAAAAEBC4B2E2B1C5F182

SSDEEP:

196608:BozgrggXBBj7QlBWIf+qivj62uKjMaaEusDCB3djS/YP0IAHIWyfuEZLNjdT1c/N:KgkgMMyXivjCKbavsDM3qqFAoW6uEZJ2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 3792)
      • Splashtop_Software_Updater.exe (PID: 2844)
      • DrvInst.exe (PID: 2248)
    • Application was dropped or rewritten from another process

      • PreVerCheck.exe (PID: 3684)
      • Splashtop_Software_Updater.exe (PID: 2844)
      • SSUService.exe (PID: 2324)
      • SWXDAgent.exe (PID: 1140)
    • Loads dropped or rewritten executable

      • Splashtop_Software_Updater.exe (PID: 2844)
      • SWXDAgent.exe (PID: 1140)
      • rundll32.exe (PID: 1832)
    • Writes to a start menu file

      • MsiExec.exe (PID: 2108)
    • Changes settings of System certificates

      • rundll32.exe (PID: 1832)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 3792)
      • MsiExec.exe (PID: 2108)
      • Splashtop_Software_Updater.exe (PID: 2844)
      • rundll32.exe (PID: 1832)
      • DrvInst.exe (PID: 2248)
    • Starts CMD.EXE for commands execution

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 3792)
      • cmd.exe (PID: 2260)
      • SWXDAgent.exe (PID: 1140)
    • Drops a file that was compiled in debug mode

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 3792)
      • MsiExec.exe (PID: 2556)
      • MsiExec.exe (PID: 2108)
      • Splashtop_Software_Updater.exe (PID: 2844)
      • rundll32.exe (PID: 1832)
      • DrvInst.exe (PID: 2248)
    • Drops a file with too old compile date

      • MsiExec.exe (PID: 2556)
      • Splashtop_Software_Updater.exe (PID: 2844)
    • Uses TASKKILL.EXE to kill process

      • MsiExec.exe (PID: 2108)
    • Creates a software uninstall entry

      • Splashtop_Software_Updater.exe (PID: 2844)
    • Creates a directory in Program Files

      • Splashtop_Software_Updater.exe (PID: 2844)
    • Creates files in the program directory

      • Splashtop_Software_Updater.exe (PID: 2844)
      • SSUService.exe (PID: 2324)
      • rundll32.exe (PID: 1832)
    • Creates files in the Windows directory

      • SSUService.exe (PID: 2324)
      • rundll32.exe (PID: 576)
      • DrvInst.exe (PID: 2248)
    • Executed as Windows Service

      • SSUService.exe (PID: 2324)
    • Creates or modifies windows services

      • Splashtop_Software_Updater.exe (PID: 2844)
    • Removes files from Windows directory

      • SSUService.exe (PID: 2324)
      • DrvInst.exe (PID: 2248)
      • rundll32.exe (PID: 576)
    • Application launched itself

      • cmd.exe (PID: 2260)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 2260)
    • Uses RUNDLL32.EXE to load library

      • cmd.exe (PID: 2260)
      • DrvInst.exe (PID: 2248)
    • Adds / modifies Windows certificates

      • rundll32.exe (PID: 1832)
    • Executed via COM

      • DrvInst.exe (PID: 2248)
      • rundll32.exe (PID: 2540)
      • DrvInst.exe (PID: 1052)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2248)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2556)
      • MsiExec.exe (PID: 2108)
    • Creates files in the program directory

      • MsiExec.exe (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (61.2)
.ax | DirectShow filter (14.5)
.exe | Win32 EXE PECompact compressed (v2.x) (4.2)
.exe | InstallShield setup (3.1)

EXIF

EXE

ProductVersion: 1.5.8.3
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
FileVersion: 1.58.9.6924
FileDescription: Splashtop® Wired XDisplay Agent
CompanyName: Splashtop Inc.
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.5.8.3
FileVersionNumber: 1.58.9.6924
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x105b2
UninitializedDataSize: -
InitializedDataSize: 219136
CodeSize: 158720
LinkerVersion: 9
PEType: PE32
TimeStamp: 2020:12:14 16:13:03+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 14-Dec-2020 15:13:03
Detected languages:
  • Chinese - Taiwan
  • English - United States
Debug artifacts:
  • d:\slave\workspace\WiredXDisplay_Agent_Win\Source\wiredisplay\WiredDisplayTx\win\Release\SRUnPackFile.pdb
CompanyName: Splashtop Inc.
FileDescription: Splashtop® Wired XDisplay Agent
FileVersion: 1.58.9.6924
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
ProductVersion: 1.5.8.3

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 14-Dec-2020 15:13:03
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00026B50
0x00026C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.59923
.rdata
0x00028000
0x00008F36
0x00009000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.88966
.data
0x00031000
0x00005E98
0x00002200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.79188
.rsrc
0x00037000
0x0002A4DC
0x0002A600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.62669

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.77792
357
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.01437
67624
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
3
5.26502
38056
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
4
5.3847
16936
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
5
5.64581
9640
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
6
5.62654
6760
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
7
5.7252
4264
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
8
4.54691
1128
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
9
2.98844
376
Latin 1 / Western European
English - United States
RT_STRING
10
2.74274
180
Latin 1 / Western European
Chinese - Taiwan
RT_CURSOR

Imports

ADVAPI32.dll
COMDLG32.dll
GDI32.dll
KERNEL32.dll
OLEACC.dll (delay-loaded)
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
WINSPOOL.DRV
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
21
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start splashtop_wired_xdisplay_agent_v1.5.8.3.exe cmd.exe no specs prevercheck.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe splashtop_software_updater.exe ssuservice.exe swxdagent.exe cmd.exe no specs cmd.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs rundll32.exe drvinst.exe rundll32.exe no specs drvinst.exe no specs rundll32.exe no specs splashtop_wired_xdisplay_agent_v1.5.8.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
576rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{35909091-8fe8-627e-1017-4d3b2bbf303a} Global\{2043897b-8fe8-627e-f49a-b26c65e25a57} C:\Windows\System32\DriverStore\Temp\{597ca218-1b97-718a-66e1-191365e25a57}\lci_proxywddm.inf C:\Windows\System32\DriverStore\Temp\{597ca218-1b97-718a-66e1-191365e25a57}\lci_proxywddm.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1012"C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe" C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeexplorer.exe
User:
admin
Company:
Splashtop Inc.
Integrity Level:
MEDIUM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
3221226540
Version:
1.58.9.6924
Modules
Images
c:\users\admin\appdata\local\temp\splashtop_wired_xdisplay_agent_v1.5.8.3.exe
c:\systemroot\system32\ntdll.dll
1012sc query ddmgrC:\Windows\system32\sc.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\users\admin\appdata\local\temp\splashtop_wired_xdisplay_agent_v1.5.8.3.exe
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1052DrvInst.exe "3" "201" "ROOT\SYSTEM\0001" "" "" "6a8a251e7" "000005D0" "000005F0" "000005F8"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096921
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1140"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" -dC:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe
MsiExec.exe
User:
SYSTEM
Company:
Splashtop Inc.
Integrity Level:
SYSTEM
Description:
Splashtop® Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1832rundll32 x86\my_setup.dll do_install_lci_proxywddmC:\Windows\system32\rundll32.exe
cmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2108C:\Windows\system32\MsiExec.exe -Embedding D98CC0B427C4DD64C2DCA1687DD90F29 M Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2120msiexec /norestart /i "setup.msi" /qb! /l*v "C:\Users\admin\AppData\Local\Temp\PreVerC.log.txt"C:\Windows\system32\msiexec.exePreVerCheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2248DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5074fe0a-93ce-76b9-9704-b62ab1735f75}\lci_proxywddm.inf" "0" "6a8a251e7" "000005D0" "WinSta0\Default" "000005D8" "208" "c:\program files\splashtop\splashtop wired xdisplay\agent\driver\win7"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096963
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2260"C:\Windows\System32\cmd.exe" /c "C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\Driver\install.bat" C:\Windows\System32\cmd.exeSWXDAgent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
548
Read events
438
Write events
110
Delete events
0

Modification events

(PID) Process:(3792) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3792) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Splashtop Software Updater\InstallRefCount
Operation:writeName:WXD
Value:
1
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:InstallPath
Value:
C:\Program Files\Splashtop\Splashtop Software Updater
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:Version
Value:
1.5.6.17
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:LogTarget
Value:
0
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:LogFile
Value:
%Temp%\SSU_New.log
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:EnablePreInstallUI
Value:
1
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:PreInstallUI
Value:
C:\Program Files\Splashtop\Splashtop Software Updater\DefaultUI.dll
(PID) Process:(2844) Splashtop_Software_Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Splashtop Inc.\Splashtop Software Updater
Operation:writeName:PlatformsTobeDeleted
Value:
Executable files
21
Suspicious files
9
Text files
105
Unknown types
4

Dropped files

PID
Process
Filename
Type
3792Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\setup.msi
MD5:
SHA256:
3684PreVerCheck.exeC:\Users\admin\AppData\Local\Temp\PreVerC.logini
MD5:
SHA256:
3792Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack.logini
MD5:
SHA256:
3792Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\PreVerCheck.exeexecutable
MD5:950C5BB6CBB6F2C23A0D40297BF05C74
SHA256:A2792F3E3839877EF48469E6E2B52363CF31E4BFF322933DEB73B9E4046636D1
3792Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\run.battext
MD5:56884732C1B8ABCBA0A31746DF533D97
SHA256:A6212DAAA9A377B202A9436D80AB97BC9B0050DC7E174FCD35F255B34500CFAB
2108MsiExec.exeC:\Users\admin\AppData\Local\Temp\{2BA7A0A5-BEB4-4709-9BE0-2029BB20A934}\IsConfig.initext
MD5:1A130FB17CAD6B57D1F2F38C860BD1DF
SHA256:5F1D5D55A41F38343997F9772F7476EE134FF66FDB3B280E8FF3F01DD486B7C4
2108MsiExec.exeC:\Users\admin\AppData\Local\Temp\{8D3AA617-9FCB-4097-A8CF-9BE355EA6314}\IsConfig.initext
MD5:1A130FB17CAD6B57D1F2F38C860BD1DF
SHA256:5F1D5D55A41F38343997F9772F7476EE134FF66FDB3B280E8FF3F01DD486B7C4
2108MsiExec.exeC:\Users\admin\AppData\Local\Temp\{8D3AA617-9FCB-4097-A8CF-9BE355EA6314}\setup.inxbinary
MD5:81102AF209480F879E223018D01B39E0
SHA256:9AE23C42C709EF1437E29320F36923B60EA254FA8883689481C48010B82BEEA9
3792Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\setup.initext
MD5:CE3FB3221DF283E1B86F1D6E448907F7
SHA256:253D4FECB0901274851EC461A555A5AB4CCB2718EFB1E4650AD8FAC63F4A3C1E
2844Splashtop_Software_Updater.exeC:\Users\admin\AppData\Local\Temp\nsv87F5.tmp\SSUDesc.xml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2324
SSUService.exe
POST
107.22.247.100:80
http://ds1.devicevm.com/
US
suspicious
2324
SSUService.exe
GET
200
54.90.0.51:80
http://sn.splashtop.com/file_system/apt_repository/dists/ProtoSSU01/released/binary-i386/Packages.gz
US
compressed
830 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2324
SSUService.exe
54.90.0.51:80
sn.splashtop.com
Amazon.com, Inc.
US
unknown
2324
SSUService.exe
107.22.247.100:80
ds1.devicevm.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
sn.splashtop.com
  • 54.90.0.51
  • 34.198.76.23
unknown
ds1.devicevm.com
  • 107.22.247.100
suspicious

Threats

No threats detected
No debug info