Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
T1#U52a9#U624b1.0.2.msi

Overview

General Information

Sample name:T1#U52a9#U624b1.0.2.msi
renamed because original name is a hash value
Original sample name:T11.0.2.msi
Analysis ID:1584045
MD5:c5c8d24b317f75a9781f32b5e1a6cb3a
SHA1:01fda6145fcece4cce326152d66b18d6e4d18fe9
SHA256:254fb5e9b88c97494475e55bf157fc6fd062b245a671b5a002fa1bba20c10f72
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 6784 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U52a9#U624b1.0.2.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 6884 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 5516 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 07F42B025C4FEC44143FF3A440D45D90 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIEA3E.tmpVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3ce480.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{3454CF84-2CCD-43A3-8A42-55EF28138F9E}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIE616.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3ce482.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3ce482.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEA3E.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\3ce482.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIEA3E.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSIEA3E.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: T1#U52a9#U624b1.0.2.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs T1#U52a9#U624b1.0.2.msi
Source: MSIEA3E.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSIEA3E.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSIEA3E.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal52.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF5505625DB464CC97.TMPJump to behavior
Source: T1#U52a9#U624b1.0.2.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U52a9#U624b1.0.2.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 07F42B025C4FEC44143FF3A440D45D90 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 07F42B025C4FEC44143FF3A440D45D90 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: T1#U52a9#U624b1.0.2.msiStatic file information: File size 8511488 > 1048576
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name:
Source: MSIEA3E.tmp.1.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSIEA3E.tmp.1.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSIEA3E.tmp.1.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSIEA3E.tmp.1.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEA3E.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEA3E.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIEA3E.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 2368Thread sleep count: 224 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584045 Sample: T1#U52a9#U624b1.0.2.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 52 15 Multi AV Scanner detection for dropped file 2->15 17 PE file has nameless sections 2->17 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIEA3E.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
T1#U52a9#U624b1.0.2.msi5%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIEA3E.tmp14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584045
Start date and time:2025-01-04 04:23:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 20s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:T1#U52a9#U624b1.0.2.msi
renamed because original name is a hash value
Original Sample Name:T11.0.2.msi
Detection:MAL
Classification:mal52.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIEA3E.tmpinstaller64v9.5.7.msiGet hashmaliciousUnknownBrowse
    installer64v1.2.5.msiGet hashmaliciousUnknownBrowse
      installer64v3.2.6.msiGet hashmaliciousUnknownBrowse
        installer64v0.2.8.msiGet hashmaliciousUnknownBrowse
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):6910190
          Entropy (8bit):7.9884554891637105
          Encrypted:false
          SSDEEP:98304:4hwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdm:4Kph8v4drS9vBExWwIF4Z4GHpKnazdm
          MD5:F009E40176B24FC389FBA195C4AE6379
          SHA1:5FA0DF35DE28D521F0A61E5F3E14F17FC1E4D209
          SHA-256:0AB81996EB873FF9642FE3B3A05975F998CC76AEBFBFFF49F8D8AD5592B2A778
          SHA-512:5A1EB63C799AA8022EB4B62B9B2F761CF313847A135D79E942E5658F82637372024653ED00EA3400928DBFED801CFBACFF413F47582B6F5EBFC9985B93FFBE42
          Malicious:false
          Reputation:low
          Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{3454CF84-2CCD-43A3-8A42-55EF28138F9E}..Setup..T1#U52a9#U624b1.0.2.msi.@.....@.....@.....@........&.{8481C31B-FE4B-4547-B498-63A22CE9DB7F}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{3454CF84-2CCD-43A3-8A42-55EF28138F9E}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q.......................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):1563120
          Entropy (8bit):7.999893691380633
          Encrypted:true
          SSDEEP:24576:WT8s+HH9paDrF330bnZOTNjuk91Z/VnzMgjEY7a29lP7MbcG165vcaUOD9JHfoW8:WTV+HdpaDr5CnZOTVtZtYgYoa2DMbcGJ
          MD5:DCFC3AD496F4BF5A9F05EFC235D770B6
          SHA1:009927BB8D6D74B739E561F7C2ED43B817B4D845
          SHA-256:E9A6B42700B9AB30C63E116C1F02815D0D9220AF8C1447E6C4DCED25115CD5D4
          SHA-512:96841C240BEDE4CED10D848D3AB8CF285DFE0BF5A82BE4EF22D43E41BADF0DFF61AD6C0D8B78490B57ED3FFDB6D8C5FB56C02D9DFE0F9384BA2EA70FC58F62DF
          Malicious:false
          Reputation:low
          Preview:.@S.....Cgl%...............h.,t.......j...8.(~.6.]...?.n^"5.k. Q.../A.. .!.,.Yx6i..a-4rF....y....}..H.\|...P.#..#{3.......x....#N6....m...B.A...:.'..N.).Z....iD...&,(...p.n..J..F.[.....9..E....`G.e.Pmj..qbi.-x2d0v..~.I3.YRN..Y@.6/.._.....f.....D.r.r.._b...K6..zd....Q..9.,.......R..!..&..Q..f.7..L0...!..M3W.TB...p...?.]..'.._......\......F.......d0.?....rH.8K.)c.;FXeP..a.......8....N.^.S....m..I..T{.wW...BYdh.d.8\qo._.R1})..v..=*P.}... 9...eL.w.f.n.3=9..?...W,..l.'.l(....z.....b..........|.|........&.=(.5..B...T..nj+..t...@*W..`..:..u...$.1..r....T..R.Y7.Z.>'.n.XY....<.~.....v..W..J..1.x.#s<d.s?..q0.v.-..<.Z..XLo.LTh.8B;9.N....e...ogi<U.-.:.g..S..b.k7........{.*....s-o]..-..@..Y].I.nQ...3..\..>o.9.I....f.*..e..K,.4....d...N......G{.Ea.g.....lJ@.M....0.(..yJ~W..\....5H.p/.v=~.......X.&..G....w...Z.-..>o.y.+z..].$..8D0N..!...;w#.Q..Oc...h.'.TeL..+.u`ec8@.d..X.z.$.U.X.*..S..^.e........k...t){.?.r....|.DS\D....s\...qd.).....O..w8.?XD....7..a..$w..6..X..3.
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {8481C31B-FE4B-4547-B498-63A22CE9DB7F}, Create Time/Date: Fri Jan 3 16:02:48 2025, Last Saved Time/Date: Fri Jan 3 16:02:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
          Category:dropped
          Size (bytes):8511488
          Entropy (8bit):7.987726427409731
          Encrypted:false
          SSDEEP:196608:8UrndlmHm5yGKph8v4drS9vBE3WwIF4Z4GHpKnaz6:JnjBsGF4VkG1Q4Z48Kaz6
          MD5:C5C8D24B317F75A9781F32B5E1A6CB3A
          SHA1:01FDA6145FCECE4CCE326152D66B18D6E4D18FE9
          SHA-256:254FB5E9B88C97494475E55BF157FC6FD062B245A671B5A002FA1BBA20C10F72
          SHA-512:BE428917C209B75F2164CFFCCA43A6B61633DEC723D9FA78EB5FF2097F2C16E3889F5A6DEE8467AD6DD7D7246EC875D119088B9E2ECA0DDEAB07C5B9A27759BB
          Malicious:false
          Reputation:low
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {8481C31B-FE4B-4547-B498-63A22CE9DB7F}, Create Time/Date: Fri Jan 3 16:02:48 2025, Last Saved Time/Date: Fri Jan 3 16:02:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
          Category:dropped
          Size (bytes):8511488
          Entropy (8bit):7.987726427409731
          Encrypted:false
          SSDEEP:196608:8UrndlmHm5yGKph8v4drS9vBE3WwIF4Z4GHpKnaz6:JnjBsGF4VkG1Q4Z48Kaz6
          MD5:C5C8D24B317F75A9781F32B5E1A6CB3A
          SHA1:01FDA6145FCECE4CCE326152D66B18D6E4D18FE9
          SHA-256:254FB5E9B88C97494475E55BF157FC6FD062B245A671B5A002FA1BBA20C10F72
          SHA-512:BE428917C209B75F2164CFFCCA43A6B61633DEC723D9FA78EB5FF2097F2C16E3889F5A6DEE8467AD6DD7D7246EC875D119088B9E2ECA0DDEAB07C5B9A27759BB
          Malicious:false
          Reputation:low
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):6904491
          Entropy (8bit):7.988751100239969
          Encrypted:false
          SSDEEP:98304:ehwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd8:eKph8v4drS9vBExWwIF4Z4GHpKnazd8
          MD5:2C8B833BF1AB2CC7CF011D88296AD579
          SHA1:B3714B1B19A9BE7B72312D1BCF0B84F2F01DAEDF
          SHA-256:23E3C17322242BE911B6C6C7BA60706D94EE429235F401A1C4390D1AFD4764DD
          SHA-512:D7B27BC98004C67958F6CF65D664A1942D4AD21C6DA9BF43DDC55AC29D2411942DC05741F9EFAC3F26E01F7A2706076B9D2423196F94C65657111A21922EBC71
          Malicious:false
          Reputation:low
          Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{3454CF84-2CCD-43A3-8A42-55EF28138F9E}..Setup..T1#U52a9#U624b1.0.2.msi.@.....@.....@.....@........&.{8481C31B-FE4B-4547-B498-63A22CE9DB7F}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\3ce480.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@..:..@...Z.@.....@5.p......._....J..._.@A......Ti.MZx.....................@........................
          Process:C:\Windows\System32\msiexec.exe
          File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
          Category:dropped
          Size (bytes):6902784
          Entropy (8bit):7.988828924696361
          Encrypted:false
          SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
          MD5:258FF5AB92030549125E08E161FD2E19
          SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
          SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
          SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
          Malicious:true
          Antivirus:
          • Antivirus: Virustotal, Detection: 14%, Browse
          Joe Sandbox View:
          • Filename: installer64v9.5.7.msi, Detection: malicious, Browse
          • Filename: installer64v1.2.5.msi, Detection: malicious, Browse
          • Filename: installer64v3.2.6.msi, Detection: malicious, Browse
          • Filename: installer64v0.2.8.msi, Detection: malicious, Browse
          Reputation:low
          Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):1.168947079897312
          Encrypted:false
          SSDEEP:12:JSbX72FjOAGiLIlHVRpU5h/7777777777777777777777777vDHFS2KnncYJl0i5:JsQI5GnbsQF
          MD5:F6C4FFC41A57010289DB63123BAF0101
          SHA1:B9DEA7186CF4C1B7F6EB78EAEAEB5C2A87798A3A
          SHA-256:9E344757DF3202BC0725FFB8B898617B65ABF4B9566EB96FE4B8327C0A309E12
          SHA-512:046CC99C69CD8A92D3A15800C1E9732FCB970313B3FD61063BE41BBBC356B49A3F5FD39F47AA3006FF736292972941494B0FC194CC66C3A75D4B92B0415709BA
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):1.4654476767574676
          Encrypted:false
          SSDEEP:48:88Ph2uRc06WXJmjT55eWdeS5osrydeSIyr:Th219jTODQGr
          MD5:D609FF78BA962617791ED9FD00F9ACAF
          SHA1:34B7A0A6AB8C1C773116E235C03EBD9202FF53B4
          SHA-256:4C377EE443076DEAC38B469A8BDA823681D63558AEDF32E85C9C1D13F90CB3B0
          SHA-512:82E2D83D54FFF08D8E7278EE6721FA3835AAED59EBC5ABA214C3A1D3B472D8B4A5E8BCC24E114F260D8B13F75722A99C37C2D9B34800F7C9B4C8BB5D4D629E58
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
          Category:dropped
          Size (bytes):432221
          Entropy (8bit):5.375174177168666
          Encrypted:false
          SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgaue:zTtbmkExhMJCIpErj
          MD5:2E021058B7FD7694217EF3D4046C500F
          SHA1:4F7070A652BAB95210FE5586589E582DBA31B961
          SHA-256:1F4ED1FCD125528D92BA8E2BFABCC869A49C73C4CFD9741E54AF3C7DBC2B85D7
          SHA-512:992AECB29F2E3C52EEDE5175B9531A241E400436D64724473063D3B21A3E20AF63C266B4DB0DAE6D84AC0174B56583EADCCFA1992C9CBD2F52702E30F267582A
          Malicious:false
          Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):32768
          Entropy (8bit):1.1809604458660332
          Encrypted:false
          SSDEEP:24:JzhC3neuxPiEipKP2xza2tzhA7ZZagUMClXtd85y1U+kAdB5GipV7V2BwGalrkga:UneuxJveFXJBT5beWdeS5osrydeSIyr
          MD5:82534DA9D6028B2E331D6743EBCA0141
          SHA1:D432D7897D4944F783282D27E52737E4B7381111
          SHA-256:69DB426B0FCDBB568F66BC3C61067A62EAE010CBCA2F233C5162646FF56D2BF2
          SHA-512:D05C6CF3C96B65EA39CADCE758288F5365EA1A05C9CB0431562BC243FC4CFCDCA0F05885F4D00ABB9636351D302E7AA740067ECA575E57542EA42E4624F8FB85
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):512
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:3::
          MD5:BF619EAC0CDF3F68D496EA9344137E8B
          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
          Malicious:false
          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):69632
          Entropy (8bit):0.10329628999939439
          Encrypted:false
          SSDEEP:24:kRAzZLdB5GipVGdB5GipV7V2BwGalrkgn+kA1:oAzldeScdeS5osrnS
          MD5:C627B42DFF4DD2A42AB773E38E386EBA
          SHA1:238E7566E4C7EFB6D1B5AB32E65CCD855CBDBB16
          SHA-256:A97B1F89DDAAA4CAB232ED2C13B61D7C63077651DB2FA44EE33965538155E403
          SHA-512:736BE0C4BB93E187084A3B5A20405FE37D9F000EE2C2EBE2DE151B13E0FAB4EA3EC02391AA4648720C1E264DCF0FCE4C9E8059B97E1798B83EA0AD830FC280C2
          Malicious:false
          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):512
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:3::
          MD5:BF619EAC0CDF3F68D496EA9344137E8B
          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
          Malicious:false
          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):512
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:3::
          MD5:BF619EAC0CDF3F68D496EA9344137E8B
          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
          Malicious:false
          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):32768
          Entropy (8bit):1.1809604458660332
          Encrypted:false
          SSDEEP:24:JzhC3neuxPiEipKP2xza2tzhA7ZZagUMClXtd85y1U+kAdB5GipV7V2BwGalrkga:UneuxJveFXJBT5beWdeS5osrydeSIyr
          MD5:82534DA9D6028B2E331D6743EBCA0141
          SHA1:D432D7897D4944F783282D27E52737E4B7381111
          SHA-256:69DB426B0FCDBB568F66BC3C61067A62EAE010CBCA2F233C5162646FF56D2BF2
          SHA-512:D05C6CF3C96B65EA39CADCE758288F5365EA1A05C9CB0431562BC243FC4CFCDCA0F05885F4D00ABB9636351D302E7AA740067ECA575E57542EA42E4624F8FB85
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):32768
          Entropy (8bit):1.1809604458660332
          Encrypted:false
          SSDEEP:24:JzhC3neuxPiEipKP2xza2tzhA7ZZagUMClXtd85y1U+kAdB5GipV7V2BwGalrkga:UneuxJveFXJBT5beWdeS5osrydeSIyr
          MD5:82534DA9D6028B2E331D6743EBCA0141
          SHA1:D432D7897D4944F783282D27E52737E4B7381111
          SHA-256:69DB426B0FCDBB568F66BC3C61067A62EAE010CBCA2F233C5162646FF56D2BF2
          SHA-512:D05C6CF3C96B65EA39CADCE758288F5365EA1A05C9CB0431562BC243FC4CFCDCA0F05885F4D00ABB9636351D302E7AA740067ECA575E57542EA42E4624F8FB85
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):32768
          Entropy (8bit):0.07505458882068111
          Encrypted:false
          SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOolpoKnncGwHi6Vky6lD1:2F0i8n0itFzDHFS2KnncYJ
          MD5:CEB83930F65A95E6E5A8C03C9AD39303
          SHA1:B16953C5CEAB1CA10B7782C5F16086CF86B5B940
          SHA-256:9A69B05536E63A3697023D123CCDC431764CE0450DAF6C76F9590986BCD506F8
          SHA-512:45E498F6BE1F864FEA6A32590763E248AE667DB7CBF84B2092483A97753FF3583F9D3E60350EA8AD7A5F7E7836B54F20558EE04C6B6783FF00F85D04F97A54D2
          Malicious:false
          Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:modified
          Size (bytes):512
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:3::
          MD5:BF619EAC0CDF3F68D496EA9344137E8B
          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
          Malicious:false
          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):1.4654476767574676
          Encrypted:false
          SSDEEP:48:88Ph2uRc06WXJmjT55eWdeS5osrydeSIyr:Th219jTODQGr
          MD5:D609FF78BA962617791ED9FD00F9ACAF
          SHA1:34B7A0A6AB8C1C773116E235C03EBD9202FF53B4
          SHA-256:4C377EE443076DEAC38B469A8BDA823681D63558AEDF32E85C9C1D13F90CB3B0
          SHA-512:82E2D83D54FFF08D8E7278EE6721FA3835AAED59EBC5ABA214C3A1D3B472D8B4A5E8BCC24E114F260D8B13F75722A99C37C2D9B34800F7C9B4C8BB5D4D629E58
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:data
          Category:dropped
          Size (bytes):512
          Entropy (8bit):0.0
          Encrypted:false
          SSDEEP:3::
          MD5:BF619EAC0CDF3F68D496EA9344137E8B
          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
          Malicious:false
          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          Process:C:\Windows\System32\msiexec.exe
          File Type:Composite Document File V2 Document, Cannot read section info
          Category:dropped
          Size (bytes):20480
          Entropy (8bit):1.4654476767574676
          Encrypted:false
          SSDEEP:48:88Ph2uRc06WXJmjT55eWdeS5osrydeSIyr:Th219jTODQGr
          MD5:D609FF78BA962617791ED9FD00F9ACAF
          SHA1:34B7A0A6AB8C1C773116E235C03EBD9202FF53B4
          SHA-256:4C377EE443076DEAC38B469A8BDA823681D63558AEDF32E85C9C1D13F90CB3B0
          SHA-512:82E2D83D54FFF08D8E7278EE6721FA3835AAED59EBC5ABA214C3A1D3B472D8B4A5E8BCC24E114F260D8B13F75722A99C37C2D9B34800F7C9B4C8BB5D4D629E58
          Malicious:false
          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {8481C31B-FE4B-4547-B498-63A22CE9DB7F}, Create Time/Date: Fri Jan 3 16:02:48 2025, Last Saved Time/Date: Fri Jan 3 16:02:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
          Entropy (8bit):7.987726427409731
          TrID:
          • Microsoft Windows Installer (60509/1) 88.31%
          • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
          File name:T1#U52a9#U624b1.0.2.msi
          File size:8'511'488 bytes
          MD5:c5c8d24b317f75a9781f32b5e1a6cb3a
          SHA1:01fda6145fcece4cce326152d66b18d6e4d18fe9
          SHA256:254fb5e9b88c97494475e55bf157fc6fd062b245a671b5a002fa1bba20c10f72
          SHA512:be428917c209b75f2164cffcca43a6b61633dec723d9fa78eb5ff2097f2c16e3889f5a6dee8467ad6dd7d7246ec875d119088b9e2eca0ddeab07c5b9a27759bb
          SSDEEP:196608:8UrndlmHm5yGKph8v4drS9vBE3WwIF4Z4GHpKnaz6:JnjBsGF4VkG1Q4Z48Kaz6
          TLSH:7B863312B53FD6ECF46275B28EF6A354D0062E91A5B0891797883F8C1B30F2457B73A9
          File Content Preview:........................>......................................................................................................................................................................................................................................
          Icon Hash:2d2e3797b32b2b99
          No network behavior found

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:22:23:58
          Start date:03/01/2025
          Path:C:\Windows\System32\msiexec.exe
          Wow64 process (32bit):false
          Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U52a9#U624b1.0.2.msi"
          Imagebase:0x7ff7eed70000
          File size:69'632 bytes
          MD5 hash:E5DA170027542E25EDE42FC54C929077
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:high
          Has exited:true

          Target ID:1
          Start time:22:23:58
          Start date:03/01/2025
          Path:C:\Windows\System32\msiexec.exe
          Wow64 process (32bit):false
          Commandline:C:\Windows\system32\msiexec.exe /V
          Imagebase:0x7ff7eed70000
          File size:69'632 bytes
          MD5 hash:E5DA170027542E25EDE42FC54C929077
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:high
          Has exited:false

          Target ID:2
          Start time:22:24:01
          Start date:03/01/2025
          Path:C:\Windows\System32\msiexec.exe
          Wow64 process (32bit):false
          Commandline:C:\Windows\System32\MsiExec.exe -Embedding 07F42B025C4FEC44143FF3A440D45D90 E Global\MSI0000
          Imagebase:0x7ff7eed70000
          File size:69'632 bytes
          MD5 hash:E5DA170027542E25EDE42FC54C929077
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:high
          Has exited:true

          No disassembly