Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
81Fh0BEPAB.msi

Overview

General Information

Sample name:81Fh0BEPAB.msi
renamed because original name is a hash value
Original sample name:3bee8bebad8ebf99b10258827587ffd2b6d00efb9379605319ab0d7daab4a91e.msi
Analysis ID:1584059
MD5:f26e4e270751682a3e33c7f31d7afb6c
SHA1:0e18debb34e257c0d1862b876a4be833870f743c
SHA256:3bee8bebad8ebf99b10258827587ffd2b6d00efb9379605319ab0d7daab4a91e
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 1744 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\81Fh0BEPAB.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 3192 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 344 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 9FB9D22A6E075FDBF671107BB80C069D E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIE510.tmpReversingLabs: Detection: 13%
Source: C:\Windows\Installer\MSIE510.tmpVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\63dd00.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{AB18198C-EE97-4289-85C1-652DCE68E26E}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDEC5.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\63dd02.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\63dd02.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIE510.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\63dd02.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIE510.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSIE510.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: 81Fh0BEPAB.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs 81Fh0BEPAB.msi
Source: MSIE510.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSIE510.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSIE510.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal52.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF7502A57866FE146E.TMPJump to behavior
Source: 81Fh0BEPAB.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\81Fh0BEPAB.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 9FB9D22A6E075FDBF671107BB80C069D E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 9FB9D22A6E075FDBF671107BB80C069D E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: 81Fh0BEPAB.msiStatic file information: File size 8970240 > 1048576
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name:
Source: MSIE510.tmp.1.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSIE510.tmp.1.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSIE510.tmp.1.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSIE510.tmp.1.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIE510.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIE510.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIE510.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 5460Thread sleep count: 168 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584059 Sample: 81Fh0BEPAB.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 52 15 Multi AV Scanner detection for dropped file 2->15 17 PE file has nameless sections 2->17 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIE510.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
81Fh0BEPAB.msi5%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIE510.tmp13%ReversingLabs
C:\Windows\Installer\MSIE510.tmp14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584059
Start date and time:2025-01-04 05:23:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 25s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:81Fh0BEPAB.msi
renamed because original name is a hash value
Original Sample Name:3bee8bebad8ebf99b10258827587ffd2b6d00efb9379605319ab0d7daab4a91e.msi
Detection:MAL
Classification:mal52.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIE510.tmpT1#U52a9#U624b1.0.2.msiGet hashmaliciousUnknownBrowse
    installer64v9.5.7.msiGet hashmaliciousUnknownBrowse
      installer64v1.2.5.msiGet hashmaliciousUnknownBrowse
        installer64v3.2.6.msiGet hashmaliciousUnknownBrowse
          installer64v0.2.8.msiGet hashmaliciousUnknownBrowse
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):6910172
            Entropy (8bit):7.9884528992761386
            Encrypted:false
            SSDEEP:98304:7hwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdL:7Kph8v4drS9vBExWwIF4Z4GHpKnazdL
            MD5:8DC70C46AAA280ECB1F4587807CE0859
            SHA1:CA57EF86219E87019F2A3688B3C2F367E5CED94D
            SHA-256:38EA8A6F9D25E9F8055011ACF4F1DC60D10FE787615C139F39B89EED2052389D
            SHA-512:B388815867B0D28A5EDEE6614CDEF1B9BB5BBF2086FDEB8CCD3436B32A975F03E22C3E5C772F58F99AD9F2376761EC83803A65718E72EFFCAFA7F11D51826479
            Malicious:false
            Reputation:low
            Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{AB18198C-EE97-4289-85C1-652DCE68E26E}..Setup..81Fh0BEPAB.msi.@.....@.....@.....@........&.{796EDC47-45A2-47BD-8778-A9514A8C9F1F}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{AB18198C-EE97-4289-85C1-652DCE68E26E}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):2020704
            Entropy (8bit):7.999923294825689
            Encrypted:true
            SSDEEP:49152:jRJmq02EMDScUhO1Dv8fiLl5EbmcqhGPr:NJmq0f6PUYllCpXPr
            MD5:17F6A6744BB0748B7C178998C314BD24
            SHA1:0FF5F713C50F0B1BE658528FD289DDB44A54B09D
            SHA-256:6D1991D0B2F5C764C2BFEF873610B35AD4634984CD85B5ABC7B88E10DB1798B7
            SHA-512:8CEC68C99BCF58C1018BF38E3AF2A40CAA55718501769C3BA1F3B66B3BA1F8C7864906D53044556671BDC4F1B90919546E51A7990709A5DEE48D671D44DFEB3F
            Malicious:false
            Reputation:low
            Preview:.@S......'..)..............f._...JY...Z..m.Ae?.k.V.rngO..q/...&}..f .&O...i..p[.f.....0.........?...L.RHT.R.*.....T{..<1.Bk..-rB./.n..X......MR.....^.hh?.8..a5....|...s.j.{..:...........o..8.........-...f...."E..D.ju..%...[i).l....*..m..z.i."O.KP.p...*......y..(BT.h.&.fn.Y....&.Tm...F...../Ove..Y.8.|.(..L.u#...Z..........pS..<..:D...OKW.m.M.........]2.`...>.h...D.>KZ.^ .+`.........3S....K..u...1...;].6.=D.D..C.~J..'.........+.1`.....9.t._Q...?E..j.Gr.....I.-zt6"w. r}!..T.?.c.N..; 6.!...k|F%.@....r{h..%...4..2*...`.S..|o(~({..".../.s:r.\.*..+......a.O..M:.3w.y..............)..Ni/........_~....N.*.{..|.Q..{.^V.[.o."......>~+...I..".....{V<..p...8..b....\>x..Y.S.Q..LD...p.!.@.....?[.h...)....Kc..2.U....p..&h%.i..D.I..g.*p..!...k.e.`h..:...#..v.Us..q.+.A.7...C:..h.....tg.........UN..1...1..)B$V.O..E|...G1k.|.6..S%#.p...t\..Cc....F....w?..D.j...)N.......Qp.Ih.]f.,.*..:.1..{.O...IT.Pj.a...[.:.Y*.)!...Q@sBi6b..P.....x!.
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dxdfsgfdh, Template: Intel;1033, Revision Number: {796EDC47-45A2-47BD-8778-A9514A8C9F1F}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
            Category:dropped
            Size (bytes):8970240
            Entropy (8bit):7.988584873601474
            Encrypted:false
            SSDEEP:196608:lo4s2SrN11AqKph8v4drS9vvExWwIF4Z4GHpKnxzd:uOqF4VkG1Q4Z48Kxzd
            MD5:F26E4E270751682A3E33C7F31D7AFB6C
            SHA1:0E18DEBB34E257C0D1862B876A4BE833870F743C
            SHA-256:3BEE8BEBAD8EBF99B10258827587FFD2B6D00EFB9379605319AB0D7DAAB4A91E
            SHA-512:6808BCAD0AA9D60D82583104AA520AD110520E21CE87394FACA4F438A2F4F66F634350BC9E9B46ABA08F629DE8D83D2812D11B80E483AA2F66028EB15020951E
            Malicious:false
            Reputation:low
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dxdfsgfdh, Template: Intel;1033, Revision Number: {796EDC47-45A2-47BD-8778-A9514A8C9F1F}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
            Category:dropped
            Size (bytes):8970240
            Entropy (8bit):7.988584873601474
            Encrypted:false
            SSDEEP:196608:lo4s2SrN11AqKph8v4drS9vvExWwIF4Z4GHpKnxzd:uOqF4VkG1Q4Z48Kxzd
            MD5:F26E4E270751682A3E33C7F31D7AFB6C
            SHA1:0E18DEBB34E257C0D1862B876A4BE833870F743C
            SHA-256:3BEE8BEBAD8EBF99B10258827587FFD2B6D00EFB9379605319AB0D7DAAB4A91E
            SHA-512:6808BCAD0AA9D60D82583104AA520AD110520E21CE87394FACA4F438A2F4F66F634350BC9E9B46ABA08F629DE8D83D2812D11B80E483AA2F66028EB15020951E
            Malicious:false
            Reputation:low
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):6904482
            Entropy (8bit):7.988750947929791
            Encrypted:false
            SSDEEP:98304:EhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdD:EKph8v4drS9vBExWwIF4Z4GHpKnazdD
            MD5:A718809F0CFB75A685CFB4E14A274BF2
            SHA1:DC54D4FDDCDE719AB29EF34C4D457FC7953F37DA
            SHA-256:C5B3FA0283EB19707DCD80CB61408E4840B3938C9D2A5D061AE4AEEE17D683A8
            SHA-512:4C3C8073457F2F64D7CA5CF56A01C6BFA3346A518095EBEB55A7EDEEA5687A2CD1D8571B7F1BE4219CCB186E3DC13E2D3BBC0786BD2C8FC1B7110C31B2217C6A
            Malicious:false
            Reputation:low
            Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{AB18198C-EE97-4289-85C1-652DCE68E26E}..Setup..81Fh0BEPAB.msi.@.....@.....@.....@........&.{796EDC47-45A2-47BD-8778-A9514A8C9F1F}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@`....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\63dd00.msi.........@........file.dat..l4d..file.dat.@.....@`....@.......@.............@.........@.....@.....@...t.@K.t..@|....@...$......_....J..._.@A......Ti.MZx.....................@.................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
            Category:dropped
            Size (bytes):6902784
            Entropy (8bit):7.988828924696361
            Encrypted:false
            SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
            MD5:258FF5AB92030549125E08E161FD2E19
            SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
            SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
            SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
            Malicious:true
            Antivirus:
            • Antivirus: ReversingLabs, Detection: 13%
            • Antivirus: Virustotal, Detection: 14%, Browse
            Joe Sandbox View:
            • Filename: T1#U52a9#U624b1.0.2.msi, Detection: malicious, Browse
            • Filename: installer64v9.5.7.msi, Detection: malicious, Browse
            • Filename: installer64v1.2.5.msi, Detection: malicious, Browse
            • Filename: installer64v3.2.6.msi, Detection: malicious, Browse
            • Filename: installer64v0.2.8.msi, Detection: malicious, Browse
            Reputation:low
            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):20480
            Entropy (8bit):1.1643158660155812
            Encrypted:false
            SSDEEP:12:JSbX72FjYSAGiLIlHVRpZh/7777777777777777777777777vDHF45dqKit/l0i5:J2SQI5t2oiF
            MD5:FA7494407B0E338607E8B28EFBA1924C
            SHA1:AE5834C5A4CCE90461B249BAE20928BDDF26E600
            SHA-256:ACFDA33AFC21E01B2A9D51931B873434F6231102EC7933BC23FAA14EFF0927C4
            SHA-512:B185FB9665D0F6B5354535C78A41A7E4CE63D8827F0BB4CC903DD6B4F8DAEC2FADD07D744C7112A17126F5E16FAAAA35AA484F1B557D3DA43F6A3E37F6C5DF33
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):20480
            Entropy (8bit):1.4620502674451403
            Encrypted:false
            SSDEEP:48:X8Ph2uRc06WXJ0nT5a1281deS5o1rydeSIy:Wh213nTZxZG
            MD5:6E64D77CAB7CB7466420F05E7F54B649
            SHA1:C278C45CDC4709187AEAF460C7616994A2A1D9BC
            SHA-256:50C42793B9ADB2632EEF910C8C561280DEF2EEC179A681693EF88E907F3F80A8
            SHA-512:586A16F19288A48B782826DA01BA984D6CA22E49126F24422A7C851C08DA5A6F72CF44CC782782ED8F8072DB0507F9B18D70F4F024CD82C62B041F029BDD4FF5
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
            Category:dropped
            Size (bytes):432221
            Entropy (8bit):5.375168899898069
            Encrypted:false
            SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau+:zTtbmkExhMJCIpEr3
            MD5:A2B810F61D6CF8D0BF1C9FB1E0EED674
            SHA1:E7954BC49F0166EB06763DA48DD62788B8C0ECBC
            SHA-256:429FF5278E517B3828FA03211FC798D589349E3F9C9D6726D5F6E73F06184C72
            SHA-512:20E5872B2919CE95D242F45C595A5EC921743D129EDA66B247CA549F0EBEF101669DB45ABC11C33CBB93B09B31E57FDBEDA5641030F9AF20C67CD8A07C094FFD
            Malicious:false
            Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):512
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3::
            MD5:BF619EAC0CDF3F68D496EA9344137E8B
            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
            Malicious:false
            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):32768
            Entropy (8bit):1.1788838622146978
            Encrypted:false
            SSDEEP:48:kneuxNveFXJLT581281deS5o1rydeSIy:KexzTLxZG
            MD5:56E575A526238C962B345C1EC3A1DF61
            SHA1:C8ABD77902525B37CEE82E91103D303A0AC35B72
            SHA-256:CB13CAC3C3FB6729369FB6341A25A30D71F6F274C4513E282494BD62265E6DD2
            SHA-512:D7716C94A9E59B310F96095BACC8FE593864FDABBC18C66C842C0FA3E8129B3423A3D54780EE2F62772C0E1DB61FDB31B3FA5E4AFD2F7CEE232A307C387C2469
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):512
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3::
            MD5:BF619EAC0CDF3F68D496EA9344137E8B
            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
            Malicious:false
            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):32768
            Entropy (8bit):0.07160875675695981
            Encrypted:false
            SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOP7kKyw8R8hgVky6lit/:2F0i8n0itFzDHF45dqdit/
            MD5:154A266C79769E9ADCD699B7B244EA82
            SHA1:EBF110469D846E4D77970D39A2913B01C4F38745
            SHA-256:93B9828794158C54B7678FD9F6C42D1B1992968A0EC4B93290EEA78C6A67D7DF
            SHA-512:0252C54BBA4FF84DA79D23F7158BCD3FD5E1F4D316712BDB7614B6554FB589EE674780080263F8AC73936B673A4A678D4D600CF3BD82D4F316B1DD5542BAFE41
            Malicious:false
            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):512
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3::
            MD5:BF619EAC0CDF3F68D496EA9344137E8B
            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
            Malicious:false
            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):69632
            Entropy (8bit):0.102148335898991
            Encrypted:false
            SSDEEP:24:TzZLdB5GipVGdB5GipV7V2BwGRlrkgF1R+fI3:TzldeScdeS5o1r3Ruo
            MD5:24401E8F6A87123128E7E3EF48F39C1C
            SHA1:0DFB1C6682C5DB10292125CD811FAECBC361EC07
            SHA-256:9B0178A27964F6127503147B91A95F50ADFF12B96DA1FC5427D026D979E91EDA
            SHA-512:76BE21E852C6591259979FDC3ACAFD45440523384BB13CDB40CA151B692BB8108AEA9F644E8E1EC45538891D457DF209685BD167785AF13C773066D4F66150BD
            Malicious:false
            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):32768
            Entropy (8bit):1.1788838622146978
            Encrypted:false
            SSDEEP:48:kneuxNveFXJLT581281deS5o1rydeSIy:KexzTLxZG
            MD5:56E575A526238C962B345C1EC3A1DF61
            SHA1:C8ABD77902525B37CEE82E91103D303A0AC35B72
            SHA-256:CB13CAC3C3FB6729369FB6341A25A30D71F6F274C4513E282494BD62265E6DD2
            SHA-512:D7716C94A9E59B310F96095BACC8FE593864FDABBC18C66C842C0FA3E8129B3423A3D54780EE2F62772C0E1DB61FDB31B3FA5E4AFD2F7CEE232A307C387C2469
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):20480
            Entropy (8bit):1.4620502674451403
            Encrypted:false
            SSDEEP:48:X8Ph2uRc06WXJ0nT5a1281deS5o1rydeSIy:Wh213nTZxZG
            MD5:6E64D77CAB7CB7466420F05E7F54B649
            SHA1:C278C45CDC4709187AEAF460C7616994A2A1D9BC
            SHA-256:50C42793B9ADB2632EEF910C8C561280DEF2EEC179A681693EF88E907F3F80A8
            SHA-512:586A16F19288A48B782826DA01BA984D6CA22E49126F24422A7C851C08DA5A6F72CF44CC782782ED8F8072DB0507F9B18D70F4F024CD82C62B041F029BDD4FF5
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:modified
            Size (bytes):512
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3::
            MD5:BF619EAC0CDF3F68D496EA9344137E8B
            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
            Malicious:false
            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):32768
            Entropy (8bit):1.1788838622146978
            Encrypted:false
            SSDEEP:48:kneuxNveFXJLT581281deS5o1rydeSIy:KexzTLxZG
            MD5:56E575A526238C962B345C1EC3A1DF61
            SHA1:C8ABD77902525B37CEE82E91103D303A0AC35B72
            SHA-256:CB13CAC3C3FB6729369FB6341A25A30D71F6F274C4513E282494BD62265E6DD2
            SHA-512:D7716C94A9E59B310F96095BACC8FE593864FDABBC18C66C842C0FA3E8129B3423A3D54780EE2F62772C0E1DB61FDB31B3FA5E4AFD2F7CEE232A307C387C2469
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:Composite Document File V2 Document, Cannot read section info
            Category:dropped
            Size (bytes):20480
            Entropy (8bit):1.4620502674451403
            Encrypted:false
            SSDEEP:48:X8Ph2uRc06WXJ0nT5a1281deS5o1rydeSIy:Wh213nTZxZG
            MD5:6E64D77CAB7CB7466420F05E7F54B649
            SHA1:C278C45CDC4709187AEAF460C7616994A2A1D9BC
            SHA-256:50C42793B9ADB2632EEF910C8C561280DEF2EEC179A681693EF88E907F3F80A8
            SHA-512:586A16F19288A48B782826DA01BA984D6CA22E49126F24422A7C851C08DA5A6F72CF44CC782782ED8F8072DB0507F9B18D70F4F024CD82C62B041F029BDD4FF5
            Malicious:false
            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            Process:C:\Windows\System32\msiexec.exe
            File Type:data
            Category:dropped
            Size (bytes):512
            Entropy (8bit):0.0
            Encrypted:false
            SSDEEP:3::
            MD5:BF619EAC0CDF3F68D496EA9344137E8B
            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
            Malicious:false
            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
            File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dxdfsgfdh, Template: Intel;1033, Revision Number: {796EDC47-45A2-47BD-8778-A9514A8C9F1F}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
            Entropy (8bit):7.988584873601474
            TrID:
            • Microsoft Windows Installer (60509/1) 88.31%
            • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
            File name:81Fh0BEPAB.msi
            File size:8'970'240 bytes
            MD5:f26e4e270751682a3e33c7f31d7afb6c
            SHA1:0e18debb34e257c0d1862b876a4be833870f743c
            SHA256:3bee8bebad8ebf99b10258827587ffd2b6d00efb9379605319ab0d7daab4a91e
            SHA512:6808bcad0aa9d60d82583104aa520ad110520e21ce87394faca4f438a2f4f66f634350bc9e9b46aba08f629de8d83d2812d11b80e483aa2f66028eb15020951e
            SSDEEP:196608:lo4s2SrN11AqKph8v4drS9vvExWwIF4Z4GHpKnxzd:uOqF4VkG1Q4Z48Kxzd
            TLSH:BC963312B43FC6ACF65174F19DB5A754C0063EA2A97086175B883B8C6376F1827733EA
            File Content Preview:........................>......................................................................................................................................................................................................................................
            Icon Hash:2d2e3797b32b2b99
            No network behavior found

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:23:24:01
            Start date:03/01/2025
            Path:C:\Windows\System32\msiexec.exe
            Wow64 process (32bit):false
            Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\81Fh0BEPAB.msi"
            Imagebase:0x7ff7ca790000
            File size:69'632 bytes
            MD5 hash:E5DA170027542E25EDE42FC54C929077
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high
            Has exited:true

            Target ID:1
            Start time:23:24:01
            Start date:03/01/2025
            Path:C:\Windows\System32\msiexec.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\system32\msiexec.exe /V
            Imagebase:0x7ff7ca790000
            File size:69'632 bytes
            MD5 hash:E5DA170027542E25EDE42FC54C929077
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high
            Has exited:false

            Target ID:2
            Start time:23:24:04
            Start date:03/01/2025
            Path:C:\Windows\System32\msiexec.exe
            Wow64 process (32bit):false
            Commandline:C:\Windows\System32\MsiExec.exe -Embedding 9FB9D22A6E075FDBF671107BB80C069D E Global\MSI0000
            Imagebase:0x7ff7ca790000
            File size:69'632 bytes
            MD5 hash:E5DA170027542E25EDE42FC54C929077
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:high
            Has exited:true

            No disassembly