File name:

Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe

Full analysis: https://app.any.run/tasks/66b815d9-6692-4d4d-933c-eed14b380051
Verdict: Malicious activity
Analysis date: February 01, 2022, 14:04:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

961795E6F576C203ACF26756248B1061

SHA1:

2A1EBF419DE2B5B5E4B7F34BFB9C4FBEB2A060F2

SHA256:

FB7D9A5CF6AE1B52786827AB9357062EC5A7A9B49D1FAAAAEBC4B2E2B1C5F182

SSDEEP:

196608:BozgrggXBBj7QlBWIf+qivj62uKjMaaEusDCB3djS/YP0IAHIWyfuEZLNjdT1c/N:KgkgMMyXivjCKbavsDM3qqFAoW6uEZJ2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • MsiExec.exe (PID: 2808)
      • MsiExec.exe (PID: 2144)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • DrvInst.exe (PID: 2264)
    • Application was dropped or rewritten from another process

      • PreVerCheck.exe (PID: 2544)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • SWXDAgent.exe (PID: 1112)
      • SSUService.exe (PID: 2580)
    • Writes to a start menu file

      • MsiExec.exe (PID: 2144)
    • Loads dropped or rewritten executable

      • SWXDAgent.exe (PID: 1112)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • rundll32.exe (PID: 2228)
      • MsiExec.exe (PID: 2144)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • MsiExec.exe (PID: 2808)
      • MsiExec.exe (PID: 2144)
      • msiexec.exe (PID: 3688)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • rundll32.exe (PID: 2228)
      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Checks supported languages

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • cmd.exe (PID: 3460)
      • PreVerCheck.exe (PID: 2544)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • SWXDAgent.exe (PID: 1112)
      • cmd.exe (PID: 2472)
      • cmd.exe (PID: 3472)
      • SSUService.exe (PID: 2580)
      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Reads the computer name

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • PreVerCheck.exe (PID: 2544)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • SSUService.exe (PID: 2580)
      • SWXDAgent.exe (PID: 1112)
      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Drops a file that was compiled in debug mode

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • MsiExec.exe (PID: 2808)
      • msiexec.exe (PID: 3688)
      • Splashtop_Software_Updater.exe (PID: 3792)
      • MsiExec.exe (PID: 2144)
      • rundll32.exe (PID: 2228)
      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Starts CMD.EXE for commands execution

      • Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe (PID: 2404)
      • SWXDAgent.exe (PID: 1112)
      • cmd.exe (PID: 3472)
    • Executed as Windows Service

      • msiexec.exe (PID: 3688)
      • vssvc.exe (PID: 3496)
      • SSUService.exe (PID: 2580)
    • Reads Environment values

      • vssvc.exe (PID: 3496)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3688)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3688)
      • Splashtop_Software_Updater.exe (PID: 3792)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3688)
    • Application launched itself

      • msiexec.exe (PID: 3688)
      • cmd.exe (PID: 3472)
    • Drops a file with too old compile date

      • MsiExec.exe (PID: 2808)
      • msiexec.exe (PID: 3688)
      • Splashtop_Software_Updater.exe (PID: 3792)
    • Uses TASKKILL.EXE to kill process

      • MsiExec.exe (PID: 2144)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3688)
      • DrvInst.exe (PID: 2264)
      • SSUService.exe (PID: 2580)
      • DrvInst.exe (PID: 3208)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3688)
      • Splashtop_Software_Updater.exe (PID: 3792)
    • Creates files in the program directory

      • Splashtop_Software_Updater.exe (PID: 3792)
      • msiexec.exe (PID: 3688)
      • MsiExec.exe (PID: 2144)
      • SSUService.exe (PID: 2580)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 3472)
    • Searches for installed software

      • msiexec.exe (PID: 3688)
    • Creates or modifies windows services

      • Splashtop_Software_Updater.exe (PID: 3792)
    • Uses RUNDLL32.EXE to load library

      • cmd.exe (PID: 3472)
      • DrvInst.exe (PID: 2264)
    • Removes files from Windows directory

      • msiexec.exe (PID: 3688)
      • DrvInst.exe (PID: 2264)
      • SSUService.exe (PID: 2580)
      • DrvInst.exe (PID: 3208)
    • Executed via COM

      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 2476)
      • msiexec.exe (PID: 3688)
      • vssvc.exe (PID: 3496)
      • MsiExec.exe (PID: 2808)
      • MsiExec.exe (PID: 2144)
      • taskkill.exe (PID: 3380)
      • sc.exe (PID: 3372)
      • sc.exe (PID: 3508)
      • timeout.exe (PID: 852)
      • rundll32.exe (PID: 2228)
      • sc.exe (PID: 3812)
      • rundll32.exe (PID: 1300)
    • Reads the computer name

      • msiexec.exe (PID: 2476)
      • msiexec.exe (PID: 3688)
      • vssvc.exe (PID: 3496)
      • MsiExec.exe (PID: 2808)
      • MsiExec.exe (PID: 2144)
      • taskkill.exe (PID: 3380)
      • sc.exe (PID: 3812)
      • sc.exe (PID: 3508)
      • rundll32.exe (PID: 2228)
      • sc.exe (PID: 3372)
      • rundll32.exe (PID: 1300)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3688)
      • rundll32.exe (PID: 2228)
      • DrvInst.exe (PID: 2264)
      • rundll32.exe (PID: 1300)
      • DrvInst.exe (PID: 3208)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3688)
      • rundll32.exe (PID: 2228)
      • rundll32.exe (PID: 1300)
      • DrvInst.exe (PID: 2264)
      • DrvInst.exe (PID: 3208)
    • Searches for installed software

      • DrvInst.exe (PID: 2264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (61.2)
.ax | DirectShow filter (14.5)
.exe | Win32 EXE PECompact compressed (v2.x) (4.2)
.exe | InstallShield setup (3.1)

EXIF

EXE

ProductVersion: 1.5.8.3
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
FileVersion: 1.58.9.6924
FileDescription: Splashtop® Wired XDisplay Agent
CompanyName: Splashtop Inc.
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.5.8.3
FileVersionNumber: 1.58.9.6924
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x105b2
UninitializedDataSize: -
InitializedDataSize: 219136
CodeSize: 158720
LinkerVersion: 9
PEType: PE32
TimeStamp: 2020:12:14 16:13:03+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 14-Dec-2020 15:13:03
Detected languages:
  • Chinese - Taiwan
  • English - United States
Debug artifacts:
  • d:\slave\workspace\WiredXDisplay_Agent_Win\Source\wiredisplay\WiredDisplayTx\win\Release\SRUnPackFile.pdb
CompanyName: Splashtop Inc.
FileDescription: Splashtop® Wired XDisplay Agent
FileVersion: 1.58.9.6924
LegalCopyright: Copyright © Splashtop Inc. All Rights Reserved.
ProductName: Splashtop® Wired XDisplay - Extend & Mirror
ProductVersion: 1.5.8.3

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 14-Dec-2020 15:13:03
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00026B50
0x00026C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.59923
.rdata
0x00028000
0x00008F36
0x00009000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.88966
.data
0x00031000
0x00005E98
0x00002200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.79188
.rsrc
0x00037000
0x0002A4DC
0x0002A600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.62669

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.77792
357
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.01437
67624
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
3
5.26502
38056
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
4
5.3847
16936
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
5
5.64581
9640
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
6
5.62654
6760
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
7
5.7252
4264
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
8
4.54691
1128
Latin 1 / Western European
Chinese - Taiwan
RT_ICON
9
2.98844
376
Latin 1 / Western European
English - United States
RT_STRING
10
2.74274
180
Latin 1 / Western European
Chinese - Taiwan
RT_CURSOR

Imports

ADVAPI32.dll
COMDLG32.dll
GDI32.dll
KERNEL32.dll
OLEACC.dll (delay-loaded)
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
WINSPOOL.DRV
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
23
Malicious processes
9
Suspicious processes
3

Behavior graph

Click at the process to see the details
start splashtop_wired_xdisplay_agent_v1.5.8.3.exe cmd.exe no specs prevercheck.exe msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe msiexec.exe taskkill.exe no specs splashtop_software_updater.exe ssuservice.exe swxdagent.exe no specs cmd.exe no specs cmd.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs timeout.exe no specs rundll32.exe drvinst.exe rundll32.exe no specs drvinst.exe splashtop_wired_xdisplay_agent_v1.5.8.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
852timeout /t 2 /nobreakC:\Windows\system32\timeout.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1112"C:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exe" -dC:\Program Files\Splashtop\Splashtop Wired XDisplay\Agent\SWXDAgent.exeMsiExec.exe
User:
SYSTEM
Company:
Splashtop Inc.
Integrity Level:
SYSTEM
Description:
Splashtop� Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\program files\splashtop\splashtop wired xdisplay\agent\swxdagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
1300rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{67f8ad87-cd66-1c6e-2b92-436113abac2a} Global\{09b52b9f-7591-1229-0e0a-cd13cddc591f} C:\Windows\System32\DriverStore\Temp\{2aacab13-ae37-5aea-95a5-f2688d22ba1f}\lci_proxywddm.inf C:\Windows\System32\DriverStore\Temp\{2aacab13-ae37-5aea-95a5-f2688d22ba1f}\lci_proxywddm.catC:\Windows\system32\rundll32.exeDrvInst.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2144C:\Windows\system32\MsiExec.exe -Embedding 52F585A138ADE1F96EA408DDCEE92B29 E Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2228rundll32 x86\my_setup.dll do_install_lci_proxywddmC:\Windows\system32\rundll32.exe
cmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2264DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7ffb4d68-9043-1cfa-2058-bb2988b37336}\lci_proxywddm.inf" "0" "6a8a251e7" "00000580" "WinSta0\Default" "00000400" "208" "c:\program files\splashtop\splashtop wired xdisplay\agent\driver\win7"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2404"C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe" C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
Explorer.EXE
User:
admin
Company:
Splashtop Inc.
Integrity Level:
HIGH
Description:
Splashtop� Wired XDisplay Agent
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\users\admin\appdata\local\temp\splashtop_wired_xdisplay_agent_v1.5.8.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2472C:\Windows\system32\cmd.exe /c verC:\Windows\system32\cmd.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2476msiexec /norestart /i "setup.msi" /qb! /l*v "C:\Users\admin\AppData\Local\Temp\PreVerC.log.txt"C:\Windows\system32\msiexec.exePreVerCheck.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2544PreVerCheck.exeC:\Users\admin\AppData\Local\Temp\unpack\PreVerCheck.exe
cmd.exe
User:
admin
Company:
Splashtop Inc.
Integrity Level:
HIGH
Description:
Splashtop� Wired XDisplay Agent Installer
Exit code:
0
Version:
1.58.9.6924
Modules
Images
c:\users\admin\appdata\local\temp\unpack\prevercheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
22 612
Read events
21 985
Write events
619
Delete events
8

Modification events

(PID) Process:(2404) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2404) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2404) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2404) Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3688) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009ABED0AC7417D801680E0000EC090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3688) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F420D3AC7417D801680E0000EC090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3688) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
69
(PID) Process:(3688) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
400000000000000080A71AAD7417D801680E0000EC090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3688) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA091DAD7417D801680E000098040000E80300000100000000000000000000003C8C0DAC57D2F7478DB8D5E97A9219940000000000000000
(PID) Process:(3496) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000009CF528AD7417D801A80D0000680D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
76
Suspicious files
28
Text files
27
Unknown types
18

Dropped files

PID
Process
Filename
Type
2404Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\setup.msi
MD5:
SHA256:
3688msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3688msiexec.exeC:\Windows\Installer\140bf5.msi
MD5:
SHA256:
3688msiexec.exeC:\Windows\Installer\MSIFFD.tmp
MD5:
SHA256:
2404Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack.logini
MD5:48B2A8880BCD08DAC7D7CFE8628D300F
SHA256:44AAAA1D9858F1CF6787C521432C7679CA92DAA9F40F4F2A5131A02C196652A5
2544PreVerCheck.exeC:\Users\admin\AppData\Local\Temp\PreVerC.logini
MD5:302A9BC590E8A455ADD21298ABAB0B65
SHA256:BCC7050A5608C8A5B79289285C0775228382534C7DE185A2BD251495D06C724B
3688msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{ac0d8c3c-d257-47f7-8db8-d5e97a921994}_OnDiskSnapshotPropbinary
MD5:AFF92BD44792637BBC4089178E92BAE4
SHA256:0BFE5595EAED04056DEB682343B46DA318F7A59D5B0D401D4C2E53E8B9FCF6E9
3688msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:AFF92BD44792637BBC4089178E92BAE4
SHA256:0BFE5595EAED04056DEB682343B46DA318F7A59D5B0D401D4C2E53E8B9FCF6E9
2404Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exeC:\Users\admin\AppData\Local\Temp\unpack\setup.iniini
MD5:CE3FB3221DF283E1B86F1D6E448907F7
SHA256:253D4FECB0901274851EC461A555A5AB4CCB2718EFB1E4650AD8FAC63F4A3C1E
3688msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF53F3D26A89C4181A.TMPgmc
MD5:DA311F359543B082F7B3F79E7E70B995
SHA256:73EE1D6256F38E91C54B99793B3FA3117EFA8B678206373463C3E50571A05BCE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2580
SSUService.exe
GET
404
54.167.186.135:80
http://sn.splashtop.com/file_system/apt_repository/dists/ProtoSSU01/released/binary-i386/Packages.gz
US
xml
341 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2580
SSUService.exe
54.167.186.135:80
sn.splashtop.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.microsoft.com
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
sn.splashtop.com
  • 54.167.186.135
  • 34.200.72.34
  • 3.234.33.71
  • 34.194.228.52
  • 54.196.187.76
  • 54.208.25.2
unknown

Threats

No threats detected
Process
Message
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUtility::OSInfo] OS 6.1(7601) Service Pack 1 x64:0 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::FindHeader] Name:C:\Users\admin\AppData\Local\Temp\Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::FindHeader] Sign Size:6096 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::FindHeader] Header offset:378880 Err:183
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] FreeSpace:234439835648 FileSize:11297280 Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] (1/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\setup.msi (11297280) Err:2
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] UnPack count:1 len:11297280 File:(null) Err:0
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] FreeSpace:234428534784 FileSize:15 Err:183
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] (2/4)UnPack file name:C:\Users\admin\AppData\Local\Temp\unpack\run.bat (15) Err:122
Splashtop_Wired_XDisplay_Agent_v1.5.8.3.exe
[2404]2022-02-01 14:04:48 [CUnPack::UnPackFiles] UnPack count:2 len:15 File:(null) Err:0