Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
installer64v3.2.4.msi

Overview

General Information

Sample name:installer64v3.2.4.msi
Analysis ID:1582952
MD5:bb83d19df2604a346e5275a6d61d6db6
SHA1:65a5347d433aac3a271c1834d3d3c80717248595
SHA256:eb268ee40c412ae770820df2046c2c8886c450eb11fed5b1ef4c7374c2a08720
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Hides threads from debuggers
PE file has nameless sections
Query firmware table information (likely to detect VMs)
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 420 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v3.2.4.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 1880 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 3636 cmdline: C:\Windows\System32\MsiExec.exe -Embedding EA6DBA2415DF7A10C1254E269A35BEF5 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Program Files (x86)\Windows NT\apo.bVirustotal: Detection: 14%Perma Link
Source: C:\Windows\Installer\MSIC6C4.tmpVirustotal: Detection: 14%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6ebdf9.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{73CBB24E-B997-47C9-BE1F-A1A6C8409475}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC00D.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6ebdfb.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6ebdfb.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C4.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\6ebdfb.msiJump to behavior
Source: apo.b.3.drStatic PE information: Number of sections : 12 > 10
Source: MSIC6C4.tmp.1.drStatic PE information: Number of sections : 12 > 10
Source: installer64v3.2.4.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs installer64v3.2.4.msi
Source: MSIC6C4.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0000990863624477
Source: MSIC6C4.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9962479440789473
Source: MSIC6C4.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0001531862745099
Source: apo.b.3.drStatic PE information: Section: ZLIB complexity 1.0000990863624477
Source: apo.b.3.drStatic PE information: Section: ZLIB complexity 0.9962479440789473
Source: apo.b.3.drStatic PE information: Section: ZLIB complexity 1.0001531862745099
Source: classification engineClassification label: mal60.evad.winMSI@4/22@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF89C3812B7077A117.TMPJump to behavior
Source: installer64v3.2.4.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v3.2.4.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding EA6DBA2415DF7A10C1254E269A35BEF5 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding EA6DBA2415DF7A10C1254E269A35BEF5 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: installer64v3.2.4.msiStatic file information: File size 9928704 > 1048576
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: apo.b.3.drStatic PE information: section name:
Source: MSIC6C4.tmp.1.drStatic PE information: section name: entropy: 7.999788402302652
Source: MSIC6C4.tmp.1.drStatic PE information: section name: entropy: 7.992230231087625
Source: MSIC6C4.tmp.1.drStatic PE information: section name: entropy: 7.999727221510779
Source: MSIC6C4.tmp.1.drStatic PE information: section name: entropy: 6.99975289143053
Source: apo.b.3.drStatic PE information: section name: entropy: 7.999788402302652
Source: apo.b.3.drStatic PE information: section name: entropy: 7.992230231087625
Source: apo.b.3.drStatic PE information: section name: entropy: 7.999727221510779
Source: apo.b.3.drStatic PE information: section name: entropy: 6.99975289143053
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\apo.bJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C4.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C4.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\apo.bJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\msiexec.exeSystem information queried: FirmwareTableInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Windows NT\apo.bJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC6C4.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 500Thread sleep count: 898 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior

Anti Debugging

barindex
Source: C:\Windows\System32\msiexec.exeThread information set: HideFromDebuggerJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess queried: DebugPortJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
31
Masquerading
OS Credential Dumping31
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
22
Virtualization/Sandbox Evasion
LSASS Memory22
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
installer64v3.2.4.msi7%VirustotalBrowse
installer64v3.2.4.msi8%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files (x86)\Windows NT\apo.b14%VirustotalBrowse
C:\Windows\Installer\MSIC6C4.tmp14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582952
Start date and time:2025-01-01 05:13:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:installer64v3.2.4.msi
Detection:MAL
Classification:mal60.evad.winMSI@4/22@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.109.210.53
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
No context
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):7961850
Entropy (8bit):7.990142575922296
Encrypted:true
SSDEEP:196608:plXfxH6nSnVJJjd82KwZnGYQ4rYfhDLO7PXdVd4Tz1:plJfCwZn9Q9hotVd431
MD5:EFA0A0F625E45A2969433A97F96A4D66
SHA1:60B77273601BD4C9BFDEDFEA6389697B670E9BEB
SHA-256:394B686651A42A6D82D9593A4E3E47DC038AD14808F2A0DF6D5561ADA6BD7CC4
SHA-512:3E90F4693D32D6B90D93B089B0566800C7A06FE4A12C3018B33293A83E05F7C8D5EBF886AA30757105028B48B8F86FE8510553ED653F6289DB3BDBF6AC5568FE
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@..Y.@.....@.....@.....@.....@.....@......&.{73CBB24E-B997-47C9-BE1F-A1A6C8409475}..Setup..installer64v3.2.4.msi.@.....@.....@.....@........&.{C75F28A0-2961-4AB2-AE06-DB2D7F6EE0F8}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{73CBB24E-B997-47C9-BE1F-A1A6C8409475}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......`y.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...29.S.........." ................p.2.......................................2.....8.y...`... ...... ........ ...... ..............`......P...\....P......8....}..........@...........................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:dropped
Size (bytes):7954432
Entropy (8bit):7.990447540200526
Encrypted:true
SSDEEP:196608:QlXfxH6nSnVJJjd82KwZnGYQ4rYfhDLO7PXdVd4Tz:QlJfCwZn9Q9hotVd43
MD5:CEC0F38323005B30CC129B66FD397799
SHA1:CE0554664CC77AE1B04F0FD06465823AA0F38D78
SHA-256:E2CA964D5171265B64B50201EB67E7302058B00AC797988F1D70299A7EB48C2C
SHA-512:2E9B7D22CAB4FF0DF7FCE4748C352A9403EA5B43F8D2D48EC003FCEB8691829E2996CCC7BB719A54F1F56B48F3C1750041D78D714E008F3C3F4C020DF31285D3
Malicious:true
Antivirus:
  • Antivirus: Virustotal, Detection: 14%, Browse
Reputation:low
Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...29.S.........." ................p.2.......................................2.....8.y...`... ...... ........ ...... ..............`......P...\....P......8....}..........@...................................(.......................................................................................@............0..........................@.......................................@............@....-.....................@.......................................@.......................................@................ ......................@................0......................@................@......................@....rsrc........P......................@..@.........`...`....+.................@............02......,2..4G.............@...........................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):1929904
Entropy (8bit):7.999907607209515
Encrypted:true
SSDEEP:49152:npOLQJWch+Jq6iqBhAM1qLDtfUv/BBqz5o2:gLQRr6hV0tf0q9B
MD5:551D95AFD4A79799D57D96910B0E7C9C
SHA1:D9ED259A0AC5FB8A2A4EA46316F3FED81A5A3738
SHA-256:944B28CD16FEA397326C596BFC26E2143E2FA2456C5E367F9269FAB0A189E3B4
SHA-512:1884C0B3619EA4A0CDC3367BE0D1974E1E41475053A59D56239F246181F4659BA48807B5808E3C28D938860EA3FFAB4F64263A78F66C956A9C860519962A195B
Malicious:false
Reputation:low
Preview:.@S.....oH.................p.r.....}.Q....M!..|.92..L.rn%..A.Po.v&.Z....m..t...!..5]w.3bZ.*....=.W.cDx-EUZ\L)9}'*y.l..... ..w.B..N..7.....]';...@..D.~.[...Z.{.7...[V.....1...8 1............Md.rbt..A..'.~.0..'.....k.'.. \I...Fl....|...>.m.}..4........gkS...=..?.$.....+...R.Ko.ae.......?..6........M\...`...o(.7>`q..W..<k.G..Y..[.)..-f .;..Cc.W.,..e....Y...Ip+..../=A&Xr.o.F'.MP7.....b.F...>..p.X.4.{4...../.:...m.}..w.yH._..D.X..Q..r......R..j..Q.........e~......F...IM.j.V..{...3Q....M..A..G....*6.}.....d+...9...91.X.P.[J.}..vw....Bk3J.._.vS%7.6..{.....`.Ntj?...(.q.;....F.c.!...<.O......h....}/..BY.6.Me.l.Gtr.h...........`..v+.`.>.;.....k.6........j.G..`~zA.9=....m......./..%...d0.@......%~.g%....TuR#.&|v......~...|)q......i...q.eW.(..S..P.2=1..G.rfX9. "...`.p%.n.`B.3p.]..A.)..b......U...p.k.....h.8Y.......O-`..bh.KXO|......+OCiP.=....hYe..9..Ir.'......v/..Q..............X....|..Y_q ..]./.sH{Vi.?W.<..D./.6f.Qo..`L..-4.1.7l....'m.....+....
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfgergfgj, Template: Intel;1033, Revision Number: {C75F28A0-2961-4AB2-AE06-DB2D7F6EE0F8}, Create Time/Date: Tue Dec 31 17:55:08 2024, Last Saved Time/Date: Tue Dec 31 17:55:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):9928704
Entropy (8bit):7.990114583543092
Encrypted:true
SSDEEP:196608:VL2izZPDUswlXfxH6nSnVJJjX82KwZnGYQ4rYfhDLO7P6dVd4Tz:lBhIswlJVCwZn9Q9ho0Vd43
MD5:BB83D19DF2604A346E5275A6D61D6DB6
SHA1:65A5347D433AAC3A271C1834D3D3C80717248595
SHA-256:EB268EE40C412AE770820DF2046C2C8886C450EB11FED5B1EF4C7374C2A08720
SHA-512:DD558A95DB2E5085A6FF0BA3DE5B45078CD9A97FAAFE8D3C4D88BEC9F69332DA7E7EA9178DCE7C8B93560A37817FC62696E94475354C4A2510ECE3FE6A2DC7DD
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfgergfgj, Template: Intel;1033, Revision Number: {C75F28A0-2961-4AB2-AE06-DB2D7F6EE0F8}, Create Time/Date: Tue Dec 31 17:55:08 2024, Last Saved Time/Date: Tue Dec 31 17:55:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):9928704
Entropy (8bit):7.990114583543092
Encrypted:true
SSDEEP:196608:VL2izZPDUswlXfxH6nSnVJJjX82KwZnGYQ4rYfhDLO7P6dVd4Tz:lBhIswlJVCwZn9Q9ho0Vd43
MD5:BB83D19DF2604A346E5275A6D61D6DB6
SHA1:65A5347D433AAC3A271C1834D3D3C80717248595
SHA-256:EB268EE40C412AE770820DF2046C2C8886C450EB11FED5B1EF4C7374C2A08720
SHA-512:DD558A95DB2E5085A6FF0BA3DE5B45078CD9A97FAAFE8D3C4D88BEC9F69332DA7E7EA9178DCE7C8B93560A37817FC62696E94475354C4A2510ECE3FE6A2DC7DD
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):7956150
Entropy (8bit):7.990386296850201
Encrypted:true
SSDEEP:196608:plXfxH6nSnVJJjd82KwZnGYQ4rYfhDLO7PXdVd4Tzm:plJfCwZn9Q9hotVd43m
MD5:8CAB340DD5B117ED6D3636DEAEEFE8EE
SHA1:319C037831F2265926AF3DD3C69615FCF5311F38
SHA-256:F34B32F73211C73C3CD5CD08C071B1052A24AE3ABDD4DF1ABAC8802BEC1090A1
SHA-512:9B5C80C226B4A1FB827F91FDE546A63A0AA67A5A23A0805D5247F121E7BBA1620100A5B573F84AE1289EEBB50421690F9B065586319796B8B44BC4CD5CC780B4
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@..Y.@.....@.....@.....@.....@.....@......&.{73CBB24E-B997-47C9-BE1F-A1A6C8409475}..Setup..installer64v3.2.4.msi.@.....@.....@.....@........&.{C75F28A0-2961-4AB2-AE06-DB2D7F6EE0F8}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.r...@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\6ebdf9.msi.........@........file.dat..l4d..file.dat.@.....@.r...@.......@.............@.........@.....@.....@U....@....@.}...@..|......._....J..._.@A......`y.MZx.....................@..........................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:modified
Size (bytes):7954432
Entropy (8bit):7.990447540200526
Encrypted:true
SSDEEP:196608:QlXfxH6nSnVJJjd82KwZnGYQ4rYfhDLO7PXdVd4Tz:QlJfCwZn9Q9hotVd43
MD5:CEC0F38323005B30CC129B66FD397799
SHA1:CE0554664CC77AE1B04F0FD06465823AA0F38D78
SHA-256:E2CA964D5171265B64B50201EB67E7302058B00AC797988F1D70299A7EB48C2C
SHA-512:2E9B7D22CAB4FF0DF7FCE4748C352A9403EA5B43F8D2D48EC003FCEB8691829E2996CCC7BB719A54F1F56B48F3C1750041D78D714E008F3C3F4C020DF31285D3
Malicious:true
Antivirus:
  • Antivirus: Virustotal, Detection: 14%, Browse
Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...29.S.........." ................p.2.......................................2.....8.y...`... ...... ........ ...... ..............`......P...\....P......8....}..........@...................................(.......................................................................................@............0..........................@.......................................@............@....-.....................@.......................................@.......................................@................ ......................@................0......................@................@......................@....rsrc........P......................@..@.........`...`....+.................@............02......,2..4G.............@...........................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.167403888432925
Encrypted:false
SSDEEP:12:JSbX72FjlAGiLIlHVRpwh/7777777777777777777777777vDHFef2DQecYEgXVf:JTQI5Ya2DFPoF
MD5:05B5478E66B3E89AD38FDA6EEF2F2AC6
SHA1:6AE5794294766F7DA1FE5794F1BA773C24ACBDBC
SHA-256:DC6EA9F722C796C13C7FFE9EEFE6DFC73FA74941EBB9E6E547FEF7399231ABE2
SHA-512:EFB5B13FCEFAA742B0D31D71189F8DDDB254AC1DF52CF2BC7A365BCEBD6F9BBF82E7F33C485BC647EC4302F9FFD7F38E79C0E957577B0D345BE3D9A5DBFD0A60
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4686287241589286
Encrypted:false
SSDEEP:48:X8PhMuRc06WXJAnT5IHdeS5KrSdeSIGK7:WhM1DnTmwdSK7
MD5:D2F9918AC518D2F83EA8D3499DD02113
SHA1:1818F8F470AA14417D2C90C1E2E440BC0AE43F6B
SHA-256:F1E69040097FD962D85BC3115B7F886D27F20D93004D452290292153A5D30D12
SHA-512:B9F1D236498A1B12E5311C01351D6ECB8E37D1BB6C9230CCF62E4FADDAE1A52FD03306947AF541E0E36F2C65C3586BE25CBD316D82F1943ED972462E756B1347
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):360001
Entropy (8bit):5.362996217796097
Encrypted:false
SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau+:zTtbmkExhMJCIpEb
MD5:D509B5C0C548BB05BEF5C8125031E38C
SHA1:AE6A4AE29C552A6B72E1CA63D42614440F32213F
SHA-256:AA79C11187C3A2131AB66958F8D9732376C9D27D2172273D105A189D1781AEEB
SHA-512:327A0515CA00A516A28423D1B3DC47E004A6BFEB49F578FF0919641135C46866EC257DA03724AD5EB83BC32E2BD72620ABF9C777AE9B841018D13CA3D99CFE86
Malicious:false
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1834382522785623
Encrypted:false
SSDEEP:48:T5qnku1NveFXJnT5SHdeS5KrSdeSIGK7:qklPT0wdSK7
MD5:0DB05F68CA2CF2D7B3239BCBB766077E
SHA1:AAC0CC2F7ED978833EA7D8558E8BEA2CE4CFF479
SHA-256:7AC0486B3AAD2C2CD5A4FA14A4C94D5358364CA400051A5091D29EC91608CFD4
SHA-512:396BE58EDF4DD51A0E880C19BD1D3FF17792A1F2434EED36E840CF29F3AF53BF7323CE748768CC796ADD5D80D93F3A46D2BAA7BDFCA2C74B2D55E62F18844A98
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4686287241589286
Encrypted:false
SSDEEP:48:X8PhMuRc06WXJAnT5IHdeS5KrSdeSIGK7:WhM1DnTmwdSK7
MD5:D2F9918AC518D2F83EA8D3499DD02113
SHA1:1818F8F470AA14417D2C90C1E2E440BC0AE43F6B
SHA-256:F1E69040097FD962D85BC3115B7F886D27F20D93004D452290292153A5D30D12
SHA-512:B9F1D236498A1B12E5311C01351D6ECB8E37D1BB6C9230CCF62E4FADDAE1A52FD03306947AF541E0E36F2C65C3586BE25CBD316D82F1943ED972462E756B1347
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1834382522785623
Encrypted:false
SSDEEP:48:T5qnku1NveFXJnT5SHdeS5KrSdeSIGK7:qklPT0wdSK7
MD5:0DB05F68CA2CF2D7B3239BCBB766077E
SHA1:AAC0CC2F7ED978833EA7D8558E8BEA2CE4CFF479
SHA-256:7AC0486B3AAD2C2CD5A4FA14A4C94D5358364CA400051A5091D29EC91608CFD4
SHA-512:396BE58EDF4DD51A0E880C19BD1D3FF17792A1F2434EED36E840CF29F3AF53BF7323CE748768CC796ADD5D80D93F3A46D2BAA7BDFCA2C74B2D55E62F18844A98
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07439974281909413
Encrypted:false
SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOef2bniltA/ROmSWEgXTRaICVky6ljX:2F0i8n0itFzDHFef2DQecYEgXVjX
MD5:0FFDCE605003BC5402A166D9C5F0364C
SHA1:C7F77DA63FA27A293EAF9608D0953AA2C85C78C1
SHA-256:C053F6E5D8926ED935EA7B27F45B5E4626DDCC877CBC9ECB2FE14B0C3C64E619
SHA-512:E3F0CDB775353F5FBA95A7547C2FD42B04F57FA95EC9CD1B1DCB39DBB7ED725F830C43A18160A3CB44CF34EB11EE63A676352E89D473A7C9901AFC6FB69FC453
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):69632
Entropy (8bit):0.10509862979157224
Encrypted:false
SSDEEP:24:hh2CQXZLdB5GipVGdB5GipV7VgwGxlrkgN+:h7QXldeScdeS5KrN
MD5:131469503B85BF0F94AB7CE0BB7024A0
SHA1:CA9790376F7D5D7E111D7716D1ADCEE586E84B28
SHA-256:DBCF710EF59F20E812748A277D0820BD7AC2B633100B0A096C9059599BB85F8B
SHA-512:94069B7D6BB53650DA1FEA35C10813685872792292D1819A33B34BC80204AE80B0B0A24A0C2C4461F7DBFF078DAF08B7517AEC3DA24BA38535E43AB348DDE45E
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1834382522785623
Encrypted:false
SSDEEP:48:T5qnku1NveFXJnT5SHdeS5KrSdeSIGK7:qklPT0wdSK7
MD5:0DB05F68CA2CF2D7B3239BCBB766077E
SHA1:AAC0CC2F7ED978833EA7D8558E8BEA2CE4CFF479
SHA-256:7AC0486B3AAD2C2CD5A4FA14A4C94D5358364CA400051A5091D29EC91608CFD4
SHA-512:396BE58EDF4DD51A0E880C19BD1D3FF17792A1F2434EED36E840CF29F3AF53BF7323CE748768CC796ADD5D80D93F3A46D2BAA7BDFCA2C74B2D55E62F18844A98
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4686287241589286
Encrypted:false
SSDEEP:48:X8PhMuRc06WXJAnT5IHdeS5KrSdeSIGK7:WhM1DnTmwdSK7
MD5:D2F9918AC518D2F83EA8D3499DD02113
SHA1:1818F8F470AA14417D2C90C1E2E440BC0AE43F6B
SHA-256:F1E69040097FD962D85BC3115B7F886D27F20D93004D452290292153A5D30D12
SHA-512:B9F1D236498A1B12E5311C01351D6ECB8E37D1BB6C9230CCF62E4FADDAE1A52FD03306947AF541E0E36F2C65C3586BE25CBD316D82F1943ED972462E756B1347
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfgergfgj, Template: Intel;1033, Revision Number: {C75F28A0-2961-4AB2-AE06-DB2D7F6EE0F8}, Create Time/Date: Tue Dec 31 17:55:08 2024, Last Saved Time/Date: Tue Dec 31 17:55:08 2024, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Entropy (8bit):7.990114583543092
TrID:
  • Microsoft Windows Installer (60509/1) 88.31%
  • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
File name:installer64v3.2.4.msi
File size:9'928'704 bytes
MD5:bb83d19df2604a346e5275a6d61d6db6
SHA1:65a5347d433aac3a271c1834d3d3c80717248595
SHA256:eb268ee40c412ae770820df2046c2c8886c450eb11fed5b1ef4c7374c2a08720
SHA512:dd558a95db2e5085a6ff0ba3de5b45078cd9a97faafe8d3c4d88bec9f69332da7e7ea9178dce7c8b93560a37817fc62696e94475354c4a2510ece3fe6a2dc7dd
SSDEEP:196608:VL2izZPDUswlXfxH6nSnVJJjX82KwZnGYQ4rYfhDLO7P6dVd4Tz:lBhIswlJVCwZn9Q9ho0Vd43
TLSH:50A63315912EC29EDB9F527F0C66995F0E09EF5349B0864D4B983BCCA633B23406F7A1
File Content Preview:........................>......................................................................................................................................................................................................................................
Icon Hash:2d2e3797b32b2b99
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:23:14:08
Start date:31/12/2024
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v3.2.4.msi"
Imagebase:0x7ff7cf040000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:1
Start time:23:14:09
Start date:31/12/2024
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\msiexec.exe /V
Imagebase:0x7ff7cf040000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:false

Target ID:3
Start time:23:14:11
Start date:31/12/2024
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\MsiExec.exe -Embedding EA6DBA2415DF7A10C1254E269A35BEF5 E Global\MSI0000
Imagebase:0x7ff7cf040000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

No disassembly