Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
installer64v5.6.9.msi

Overview

General Information

Sample name:installer64v5.6.9.msi
Analysis ID:1581855
MD5:73c55c50b25cffa80af0e926f9d7339b
SHA1:244ffa6838248cc882fd4ea1bfeefe1f7ef1ddbb
SHA256:cbf1da6b059e49a132df5a70ef816d08216fe30757984deedbf8c1675cfb3ce8
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Hides threads from debuggers
PE file contains section with special chars
Query firmware table information (likely to detect VMs)
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 3380 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v5.6.9.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 2432 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6948 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 5C6EE983EC4EF83FAEB98F9C2B254C34 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Program Files (x86)\Windows NT\hrsv.tacReversingLabs: Detection: 18%
Source: C:\Program Files (x86)\Windows NT\hrsv.tacVirustotal: Detection: 25%Perma Link
Source: C:\Windows\Installer\MSIA50.tmpReversingLabs: Detection: 18%
Source: installer64v5.6.9.msiVirustotal: Detection: 20%Perma Link
Source: installer64v5.6.9.msiReversingLabs: Detection: 13%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIA50.tmp.1.drStatic PE information: section name: .cE%
Source: hrsv.tac.3.drStatic PE information: section name: .cE%
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\420212.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{836C0019-EFBF-4F79-8C1F-5269FDA1AD48}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3C7.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\420214.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\420214.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIA50.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\420214.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\Windows NT\hrsv.tac C719EC19E1E00A334D48760CB39609C69FDD0AC7458700A6255DDF41FEB43BEE
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIA50.tmp C719EC19E1E00A334D48760CB39609C69FDD0AC7458700A6255DDF41FEB43BEE
Source: installer64v5.6.9.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs installer64v5.6.9.msi
Source: classification engineClassification label: mal68.evad.winMSI@4/22@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFCB62487DA300DFA1.TMPJump to behavior
Source: installer64v5.6.9.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: installer64v5.6.9.msiVirustotal: Detection: 20%
Source: installer64v5.6.9.msiReversingLabs: Detection: 13%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v5.6.9.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 5C6EE983EC4EF83FAEB98F9C2B254C34 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 5C6EE983EC4EF83FAEB98F9C2B254C34 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: installer64v5.6.9.msiStatic file information: File size 7655424 > 1048576
Source: MSIA50.tmp.1.drStatic PE information: section name: .00cfg
Source: MSIA50.tmp.1.drStatic PE information: section name: _RDATA
Source: MSIA50.tmp.1.drStatic PE information: section name: .cE%
Source: hrsv.tac.3.drStatic PE information: section name: .00cfg
Source: hrsv.tac.3.drStatic PE information: section name: _RDATA
Source: hrsv.tac.3.drStatic PE information: section name: .cE%
Source: MSIA50.tmp.1.drStatic PE information: section name: .text entropy: 7.08800768947479
Source: hrsv.tac.3.drStatic PE information: section name: .text entropy: 7.08800768947479
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIA50.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\hrsv.tacJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIA50.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\hrsv.tacJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\msiexec.exeSystem information queried: FirmwareTableInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIA50.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Windows NT\hrsv.tacJump to dropped file
Source: C:\Windows\System32\msiexec.exeLast function: Thread delayed
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior

Anti Debugging

barindex
Source: C:\Windows\System32\msiexec.exeThread information set: HideFromDebuggerJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess queried: DebugPortJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
31
Masquerading
OS Credential Dumping31
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
21
Virtualization/Sandbox Evasion
LSASS Memory21
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
installer64v5.6.9.msi20%VirustotalBrowse
installer64v5.6.9.msi13%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files (x86)\Windows NT\hrsv.tac18%ReversingLabs
C:\Program Files (x86)\Windows NT\hrsv.tac25%VirustotalBrowse
C:\Windows\Installer\MSIA50.tmp18%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581855
Start date and time:2024-12-29 06:50:20 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 24s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:installer64v5.6.9.msi
Detection:MAL
Classification:mal68.evad.winMSI@4/22@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.63, 52.149.20.212
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIA50.tmpinstaller64v3.2.9.msiGet hashmaliciousUnknownBrowse
    yzwnoob.msiGet hashmaliciousUnknownBrowse
      sbfwyinhu.msiGet hashmaliciousUnknownBrowse
        caonimayinhu.msiGet hashmaliciousUnknownBrowse
          installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
            C:\Program Files (x86)\Windows NT\hrsv.tacinstaller64v3.2.9.msiGet hashmaliciousUnknownBrowse
              yzwnoob.msiGet hashmaliciousUnknownBrowse
                sbfwyinhu.msiGet hashmaliciousUnknownBrowse
                  caonimayinhu.msiGet hashmaliciousUnknownBrowse
                    installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6078190
                      Entropy (8bit):7.3911471808869145
                      Encrypted:false
                      SSDEEP:98304:rguaE99X1NNBNUpVzglP/szL6lD6E97b1ScJFhs9kwfgdvC3OiXpNm0:UA5ZvUp5g+KQE9319vExJXpNm0
                      MD5:5C08DEF47E40E709B20B5E59E17C89DF
                      SHA1:5E702E90A3557ACF1972A019A87CB701EEC69A6E
                      SHA-256:C52B8D0D126ADB4C3B1C1C1BA34BFE4BAAAF6828010F1F4621BC3D3A4823EDBC
                      SHA-512:A39A19BD06931744AD06B8F2A8F364F0BE30891D931BCD061BADCC94C9ADDC99747BA3FC54A0CA1B674914E7DAA01CFD2CDD8D7813941B44B1CBF027D63F814D
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@f..Y.@.....@.....@.....@.....@.....@......&.{836C0019-EFBF-4F79-8C1F-5269FDA1AD48}..Setup..installer64v5.6.9.msi.@.....@.....@.....@........&.{AD42D2CA-D67A-4BB6-96C7-F32097180263}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{836C0019-EFBF-4F79-8C1F-5269FDA1AD48}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......\.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d.....og.........." ........................................................0]......]...`.............................................`...0...(.....].......\.,7........... ].x.......................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1543184
                      Entropy (8bit):7.999877543801716
                      Encrypted:true
                      SSDEEP:24576:rHGVMKs+MT/GRGABjbyMk7EmJBZLpZ3ejRZLzxXSxJwUDSZ3y78xfAvsGC:rmVRsLe7yMk7Ei7phej/hiOpf9GC
                      MD5:79CE273611906292517A1ADD8AAD65EB
                      SHA1:3704837E5F3E2B10E7714C718C6F56E4FE97398D
                      SHA-256:1131485DDF06B777333594A2FB38CA4B45DF0D9A095B0F366EEE7E6F0D4454D4
                      SHA-512:B75055E8572F7C32D3C8466617FFB17C49B159F8F37C0AF5040CE538F0D31ACFAD5DD540E48EE0DF98EB36E57B96F47165B4D99BE08AE53094BF6EC6E4A12557
                      Malicious:false
                      Reputation:low
                      Preview:.@S.......Lw................9...$.7....E.._...v9U...S.%....R.==PB....M.$!85._g..C...d.....c>P*sk...i.'r5'v|z.K@K..>..0.+..8.j...........i...V.k!....O`......9..+.F....7=jg~.;J>......:....!e.aI.GrXE'0,.yJ.........z.m@....W..._}~.t..GA..@....N.F..z"5..y..1...~.;..0b65.5k.h.K"..."H...N}...w..dL/..p...=.b<.sS..8v...2.Yy.....K.4......;....R.<]._...J5!.q...:r._..{..d@..]...W.Xv...+.x.6v."_.uf.C....%....g.b....0.. jE.%..1YTGT4..0.!.O..-.....S.............4v.Q...X...m....n.#..1DQ.E..u..,H{'6.......'.c....%6.l..^o.;.d...T.~p.l..V8O@.2f....h.o.xI..i.9.%D.-.....o.7f..L..I.."..h...........+m......Y-.i._`.P#...2^.y;BR.2T.......K.. ..k#.c.K.y{u*#:.O...^.{..2.!Xu.L.!.*....t...?...1..x.yD.09....v.v.b.l=..z\.LL..9..I.)..8)"...F.....D.x...$.......7.....!6.e.If..}...Z..(y.(.l._...T.6.*k&.....dS.(..P.......I...W..n,....3.l.>...O.....,|p..~.F...&:cb.-.....}"...I......&Nt:..g.Gi..d.h..4.z.(.,.i..=..W...5....LI2.u.#.2T.h.$...i..m.}Tp...l..u&..T.$.F...f...w.-..!..
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:dropped
                      Size (bytes):6070784
                      Entropy (8bit):7.391209406124013
                      Encrypted:false
                      SSDEEP:98304:KguaE99X1NNBNUpVzglP/szL6lD6E97b1ScJFhs9kwfgdvC3OiXpNm:jA5ZvUp5g+KQE9319vExJXpNm
                      MD5:F2667D49F895F5A458B245725B8B8E06
                      SHA1:0B9B0375BBDDD7A8049C69AC8894350FA742D374
                      SHA-256:C719EC19E1E00A334D48760CB39609C69FDD0AC7458700A6255DDF41FEB43BEE
                      SHA-512:89126FCED8A2E49DE22ACD27D5D29BB1A0ED726120813D0179094CAA90BAC5725A7978606BB68EDA25A8E1ECDB1D86730AB87069957144A1C8B1D8525B00167D
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 18%
                      • Antivirus: Virustotal, Detection: 25%, Browse
                      Joe Sandbox View:
                      • Filename: installer64v3.2.9.msi, Detection: malicious, Browse
                      • Filename: yzwnoob.msi, Detection: malicious, Browse
                      • Filename: sbfwyinhu.msi, Detection: malicious, Browse
                      • Filename: caonimayinhu.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      Reputation:low
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d.....og.........." ........................................................0]......]...`.............................................`...0...(.....].......\.,7........... ].x...............................(....)..@...............0............................text...n........................... ..`.rdata...k.......l..................@..@.data...Tg...`...F...B..............@....pdata...6....2..8....2.............@..@.00cfg..8.....3.......2.............@..@.tls......... 3.......2.............@..._RDATA.......03.......2.............@..@.cE%......)..@3...)...2............. ..h.rsrc.........].......\.............@..@.reloc..x.... ].......\.............@..B........................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfgeah, Template: Intel;1033, Revision Number: {AD42D2CA-D67A-4BB6-96C7-F32097180263}, Create Time/Date: Sun Dec 29 03:35:08 2024, Last Saved Time/Date: Sun Dec 29 03:35:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):7655424
                      Entropy (8bit):7.574414199657463
                      Encrypted:false
                      SSDEEP:196608:+zgsBitCVA5ZvUp+g+KQE9319vExJXpNm:+UtQKZsFHavXm
                      MD5:73C55C50B25CFFA80AF0E926F9D7339B
                      SHA1:244FFA6838248CC882FD4EA1BFEEFE1F7EF1DDBB
                      SHA-256:CBF1DA6B059E49A132DF5A70EF816D08216FE30757984DEEDBF8C1675CFB3CE8
                      SHA-512:4E7E9675C8052D6A3EDBD9FEE8585ED1F0CE6316B9A38CFFD847D1AF3CA0B9E0866B5E1499B6B9D8B9AA2E580E7BA9A9EDB534E382C01B8BFFE3E087CB9EF67B
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfgeah, Template: Intel;1033, Revision Number: {AD42D2CA-D67A-4BB6-96C7-F32097180263}, Create Time/Date: Sun Dec 29 03:35:08 2024, Last Saved Time/Date: Sun Dec 29 03:35:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):7655424
                      Entropy (8bit):7.574414199657463
                      Encrypted:false
                      SSDEEP:196608:+zgsBitCVA5ZvUp+g+KQE9319vExJXpNm:+UtQKZsFHavXm
                      MD5:73C55C50B25CFFA80AF0E926F9D7339B
                      SHA1:244FFA6838248CC882FD4EA1BFEEFE1F7EF1DDBB
                      SHA-256:CBF1DA6B059E49A132DF5A70EF816D08216FE30757984DEEDBF8C1675CFB3CE8
                      SHA-512:4E7E9675C8052D6A3EDBD9FEE8585ED1F0CE6316B9A38CFFD847D1AF3CA0B9E0866B5E1499B6B9D8B9AA2E580E7BA9A9EDB534E382C01B8BFFE3E087CB9EF67B
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6072490
                      Entropy (8bit):7.391233498098227
                      Encrypted:false
                      SSDEEP:98304:RguaE99X1NNBNUpVzglP/szL6lD6E97b1ScJFhs9kwfgdvC3OiXpNmh:yA5ZvUp5g+KQE9319vExJXpNmh
                      MD5:7495E19518178239E31C0E903EE826A8
                      SHA1:BBC491A23643F345572A871DD7A4B5111DF0259D
                      SHA-256:E6811A42D431E5060DAEFACBC6A556805C834D6AB6B4CF82C3861AC04B5B2398
                      SHA-512:7F8B27B8B32886C275D59FB3A62B30AD0A5DE22C6C1B731ECD0354D8CE20B02A22B403E3DB74FBE2FA14441E4B002BC61F7D12D7536CC4A063813B28F0648F60
                      Malicious:false
                      Preview:...@IXOS.@.....@f..Y.@.....@.....@.....@.....@.....@......&.{836C0019-EFBF-4F79-8C1F-5269FDA1AD48}..Setup..installer64v5.6.9.msi.@.....@.....@.....@........&.{AD42D2CA-D67A-4BB6-96C7-F32097180263}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\420212.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@y.'6.@..b..@Qz...@..e......_....J..._.@A.......\.MZx.....................@..........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6070784
                      Entropy (8bit):7.391209406124013
                      Encrypted:false
                      SSDEEP:98304:KguaE99X1NNBNUpVzglP/szL6lD6E97b1ScJFhs9kwfgdvC3OiXpNm:jA5ZvUp5g+KQE9319vExJXpNm
                      MD5:F2667D49F895F5A458B245725B8B8E06
                      SHA1:0B9B0375BBDDD7A8049C69AC8894350FA742D374
                      SHA-256:C719EC19E1E00A334D48760CB39609C69FDD0AC7458700A6255DDF41FEB43BEE
                      SHA-512:89126FCED8A2E49DE22ACD27D5D29BB1A0ED726120813D0179094CAA90BAC5725A7978606BB68EDA25A8E1ECDB1D86730AB87069957144A1C8B1D8525B00167D
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 18%
                      Joe Sandbox View:
                      • Filename: installer64v3.2.9.msi, Detection: malicious, Browse
                      • Filename: yzwnoob.msi, Detection: malicious, Browse
                      • Filename: sbfwyinhu.msi, Detection: malicious, Browse
                      • Filename: caonimayinhu.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d.....og.........." ........................................................0]......]...`.............................................`...0...(.....].......\.,7........... ].x...............................(....)..@...............0............................text...n........................... ..`.rdata...k.......l..................@..@.data...Tg...`...F...B..............@....pdata...6....2..8....2.............@..@.00cfg..8.....3.......2.............@..@.tls......... 3.......2.............@..._RDATA.......03.......2.............@..@.cE%......)..@3...)...2............. ..h.rsrc.........].......\.............@..@.reloc..x.... ].......\.............@..B........................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1673159099767603
                      Encrypted:false
                      SSDEEP:12:JSbX72FjnAGiLIlHVRpwh/7777777777777777777777777vDHFqjQEgXanjXl0G:J5QI5YjaWF
                      MD5:D04387566F41D29FA5FCDFC232D731A1
                      SHA1:5F4E1CF8936D15E9BA847A36FC9350B73B56D157
                      SHA-256:21CA2B1269CBAB58A07C8576B6116CFF4C4DA77AB8EDD19091CF1BAD8DF769FB
                      SHA-512:130713A332DA01C9119375622A5D2A2AAAD7B873FD0B7820C0D5FA5D306F1655DBCC4A7DFA96323C2FAC2EA9909B46C92DCF95BBA31C4445E598C6A0A788121A
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4692066912606188
                      Encrypted:false
                      SSDEEP:48:98PhMuRc06WXJAnT5xW4UZdeS5ezrCdeSIG6brO:ghM1DnT+4V7HS6vO
                      MD5:CB1A2EE4DEAD44F0C895B8CDF7DF59B3
                      SHA1:7845EE0B337BE1675E8C5BE72A1A6B37B0ED075B
                      SHA-256:A952A4B8BE0AE6F438BE7B94943E65BC25DF292EE4E5A591732220B7589050F6
                      SHA-512:162C3C5D7C95B9FFCA0E077818FE14951376DAAFE9B47326253E588623D52871B7FBE0465DAD0DF829EA0881C47A8121EB043469A02386D896B33CF3738D9CEA
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):360001
                      Entropy (8bit):5.362986533662231
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauJ:zTtbmkExhMJCIpEw
                      MD5:493B9DC5A19D11DBFC8862F7DD245005
                      SHA1:B05854F62B65ABCB8C02F790D6EAB4241993F89D
                      SHA-256:CE21DD6AA2DA2E22B4925F01BE36BA966A00F4C70381C2949C8C38582CB166F9
                      SHA-512:C3E78AD827A93448C654F9A9B7BE340DF7AA860DB29F4E1F5D90D5AE756BC4510708720250FA51AFFFB7D3BAA51BC3E5BD8D035BFA1FE884E203D088547D1B29
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07431098241939675
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOq7nc6CEgXTRGjRXCVky6ljX:2F0i8n0itFzDHFqjQEgXanjX
                      MD5:9E67838635079D12E9A8458B77E7B1B5
                      SHA1:55B2265EDEDFCAF6321ACD21361EC1576EAB21B9
                      SHA-256:B3C5CA26F26C77EAA685F40CC045AA6066B2F41E7E5CEAE66D8E78E790AC4827
                      SHA-512:91FB34CF662A4E5614A77C40AA65B6618B4E59B855BD0ED4EF839BA88BC3748A40B7E5F07E55E4D8843D682B06D6F89EE986EBBCAF1CEE687E1E57D77121D0C6
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1835697975316695
                      Encrypted:false
                      SSDEEP:48:nnkunNveFXJnT5jW4UZdeS5ezrCdeSIG6brO:nkDPTo4V7HS6vO
                      MD5:FADAC64B106B1511CE4080EE296F7DE1
                      SHA1:F6E582542D64C7E939C7DAF2F2DF7CB0948E0EBA
                      SHA-256:17538739DA85D1306DA137263D465197A343849061FA447CDD20AD7C8663999E
                      SHA-512:1AD45C1B18677C71CEF4E39D5829F040625C73EF46FC18B9A1DFD0AE2D263B90BB7D08BECFD3B07BB96FBF3AC577B9FD7C2A42F9CD59C5A416979378A7496180
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4692066912606188
                      Encrypted:false
                      SSDEEP:48:98PhMuRc06WXJAnT5xW4UZdeS5ezrCdeSIG6brO:ghM1DnT+4V7HS6vO
                      MD5:CB1A2EE4DEAD44F0C895B8CDF7DF59B3
                      SHA1:7845EE0B337BE1675E8C5BE72A1A6B37B0ED075B
                      SHA-256:A952A4B8BE0AE6F438BE7B94943E65BC25DF292EE4E5A591732220B7589050F6
                      SHA-512:162C3C5D7C95B9FFCA0E077818FE14951376DAAFE9B47326253E588623D52871B7FBE0465DAD0DF829EA0881C47A8121EB043469A02386D896B33CF3738D9CEA
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1835697975316695
                      Encrypted:false
                      SSDEEP:48:nnkunNveFXJnT5jW4UZdeS5ezrCdeSIG6brO:nkDPTo4V7HS6vO
                      MD5:FADAC64B106B1511CE4080EE296F7DE1
                      SHA1:F6E582542D64C7E939C7DAF2F2DF7CB0948E0EBA
                      SHA-256:17538739DA85D1306DA137263D465197A343849061FA447CDD20AD7C8663999E
                      SHA-512:1AD45C1B18677C71CEF4E39D5829F040625C73EF46FC18B9A1DFD0AE2D263B90BB7D08BECFD3B07BB96FBF3AC577B9FD7C2A42F9CD59C5A416979378A7496180
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4692066912606188
                      Encrypted:false
                      SSDEEP:48:98PhMuRc06WXJAnT5xW4UZdeS5ezrCdeSIG6brO:ghM1DnT+4V7HS6vO
                      MD5:CB1A2EE4DEAD44F0C895B8CDF7DF59B3
                      SHA1:7845EE0B337BE1675E8C5BE72A1A6B37B0ED075B
                      SHA-256:A952A4B8BE0AE6F438BE7B94943E65BC25DF292EE4E5A591732220B7589050F6
                      SHA-512:162C3C5D7C95B9FFCA0E077818FE14951376DAAFE9B47326253E588623D52871B7FBE0465DAD0DF829EA0881C47A8121EB043469A02386D896B33CF3738D9CEA
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10512895534055823
                      Encrypted:false
                      SSDEEP:24:VzbrOGXZLdB5GipVGdB5GipV7VgwG1tlrkgs++hQA:RbrOGXldeScdeS5ezrs+LA
                      MD5:8F46F57B763F713E56A52D2D5059E51D
                      SHA1:F86DFEF2AF3E25F47FCE5A374C62C7A7BAF3003E
                      SHA-256:4DFCC630F5326CFFA691E571A23E04E3E55B0A3C839DED0AA1404BD14789C475
                      SHA-512:A37A1DEB58356588316204056E108AF70972F37B71B50860B1C609FAC9312B4DF933094F67C850FB758A99F63D22595774F981D0A693D44BF18ABE90D1A95E54
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1835697975316695
                      Encrypted:false
                      SSDEEP:48:nnkunNveFXJnT5jW4UZdeS5ezrCdeSIG6brO:nkDPTo4V7HS6vO
                      MD5:FADAC64B106B1511CE4080EE296F7DE1
                      SHA1:F6E582542D64C7E939C7DAF2F2DF7CB0948E0EBA
                      SHA-256:17538739DA85D1306DA137263D465197A343849061FA447CDD20AD7C8663999E
                      SHA-512:1AD45C1B18677C71CEF4E39D5829F040625C73EF46FC18B9A1DFD0AE2D263B90BB7D08BECFD3B07BB96FBF3AC577B9FD7C2A42F9CD59C5A416979378A7496180
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfgeah, Template: Intel;1033, Revision Number: {AD42D2CA-D67A-4BB6-96C7-F32097180263}, Create Time/Date: Sun Dec 29 03:35:08 2024, Last Saved Time/Date: Sun Dec 29 03:35:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.574414199657463
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:installer64v5.6.9.msi
                      File size:7'655'424 bytes
                      MD5:73c55c50b25cffa80af0e926f9d7339b
                      SHA1:244ffa6838248cc882fd4ea1bfeefe1f7ef1ddbb
                      SHA256:cbf1da6b059e49a132df5a70ef816d08216fe30757984deedbf8c1675cfb3ce8
                      SHA512:4e7e9675c8052d6a3edbd9fee8585ed1f0ce6316b9a38cffd847d1af3ca0b9e0866b5e1499b6b9d8b9aa2e580e7ba9a9edb534e382c01b8bffe3e087cb9ef67b
                      SSDEEP:196608:+zgsBitCVA5ZvUp+g+KQE9319vExJXpNm:+UtQKZsFHavXm
                      TLSH:9376013659B7B0BCF693D6B58AB78777A037379117265CBF00A5E3301A32A104B46B72
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:00:51:10
                      Start date:29/12/2024
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v5.6.9.msi"
                      Imagebase:0x7ff78ef50000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:00:51:10
                      Start date:29/12/2024
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff78ef50000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:00:51:13
                      Start date:29/12/2024
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 5C6EE983EC4EF83FAEB98F9C2B254C34 E Global\MSI0000
                      Imagebase:0x7ff78ef50000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly