Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
BBEYH73ThQ.msi

Overview

General Information

Sample name:BBEYH73ThQ.msi
renamed because original name is a hash value
Original sample name:e4293872c79e70f9de46de4a6196e6de8d5c662f912056e6e65b8d9bd290617f.msi
Analysis ID:1584062
MD5:012a2e128172c4be72f5b5a90980b2eb
SHA1:df79013e59f132f28a355b6cc6543d01a29d03c3
SHA256:e4293872c79e70f9de46de4a6196e6de8d5c662f912056e6e65b8d9bd290617f
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)

Classification

  • System is w10x64
  • msiexec.exe (PID: 6372 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\BBEYH73ThQ.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 6536 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 3172 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 856A84CED78D3640C5733385B6C615C9 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI1D8B.tmpReversingLabs: Detection: 13%
Source: C:\Windows\Installer\MSI1D8B.tmpVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: global trafficTCP traffic: 192.168.2.7:54353 -> 162.159.36.2:53
Source: unknownDNS traffic detected: query: 171.39.242.20.in-addr.arpa replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa

System Summary

barindex
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\66132a.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{F24F4CB8-1C5F-4258-A565-F326F70BA51B}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI14FE.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\66132c.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\66132c.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI1D8B.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\66132c.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI1D8B.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSI1D8B.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: BBEYH73ThQ.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs BBEYH73ThQ.msi
Source: MSI1D8B.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSI1D8B.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSI1D8B.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal52.winMSI@4/21@1/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFC2C7B05123FBE157.TMPJump to behavior
Source: BBEYH73ThQ.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\BBEYH73ThQ.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 856A84CED78D3640C5733385B6C615C9 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 856A84CED78D3640C5733385B6C615C9 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: BBEYH73ThQ.msiStatic file information: File size 8478720 > 1048576
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name:
Source: MSI1D8B.tmp.1.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSI1D8B.tmp.1.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSI1D8B.tmp.1.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSI1D8B.tmp.1.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI1D8B.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI1D8B.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI1D8B.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 792Thread sleep count: 131 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
Software Packing
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1584062 Sample: BBEYH73ThQ.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 52 16 171.39.242.20.in-addr.arpa 2->16 18 Multi AV Scanner detection for dropped file 2->18 20 PE file has nameless sections 2->20 7 msiexec.exe 75 29 2->7         started        10 msiexec.exe 5 2->10         started        signatures3 process4 file5 14 C:\Windows\Installer\MSI1D8B.tmp, PE32+ 7->14 dropped 12 msiexec.exe 7->12         started        process6

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
BBEYH73ThQ.msi5%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI1D8B.tmp13%ReversingLabs
C:\Windows\Installer\MSI1D8B.tmp14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
171.39.242.20.in-addr.arpa
unknown
unknownfalse
    high
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1584062
    Start date and time:2025-01-04 05:24:10 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 4m 36s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:15
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:BBEYH73ThQ.msi
    renamed because original name is a hash value
    Original Sample Name:e4293872c79e70f9de46de4a6196e6de8d5c662f912056e6e65b8d9bd290617f.msi
    Detection:MAL
    Classification:mal52.winMSI@4/21@1/0
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • Found application associated with file extension: .msi
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.109.210.53, 20.242.39.171, 20.12.23.50
    • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    No simulations
    No context
    No context
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    C:\Windows\Installer\MSI1D8B.tmpxkUUkjILS6.msiGet hashmaliciousUnknownBrowse
      81Fh0BEPAB.msiGet hashmaliciousUnknownBrowse
        T1#U52a9#U624b1.0.2.msiGet hashmaliciousUnknownBrowse
          installer64v9.5.7.msiGet hashmaliciousUnknownBrowse
            installer64v1.2.5.msiGet hashmaliciousUnknownBrowse
              installer64v3.2.6.msiGet hashmaliciousUnknownBrowse
                installer64v0.2.8.msiGet hashmaliciousUnknownBrowse
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):6910188
                  Entropy (8bit):7.988451337922987
                  Encrypted:false
                  SSDEEP:98304:KhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdl:KKph8v4drS9vBExWwIF4Z4GHpKnazdl
                  MD5:DA39B09DDE114CBF94AA048360794128
                  SHA1:4544F9C8FDDB7F3C90041D226D624EECBD49F6E7
                  SHA-256:7B4BA72AA312A47DB57EAD1D4B2746B14B0B47A31B82BE8C789B9CC2603B9527
                  SHA-512:CB416CE7021F38977435CB7891267F60843E59DAE623ED68CC9600CFD23264DAD479AB76EC43CB73A8A912B507CA3F56AAE8DB4A1A5D839BE436A1F6D53F54F1
                  Malicious:false
                  Reputation:low
                  Preview:...@IXOS.@.....@$.#Z.@.....@.....@.....@.....@.....@......&.{F24F4CB8-1C5F-4258-A565-F326F70BA51B}..Setup..BBEYH73ThQ.msi.@.....@.....@.....@........&.{0EDEF991-300A-44FE-919E-AAF24CBFC3B4}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{F24F4CB8-1C5F-4258-A565-F326F70BA51B}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1527248
                  Entropy (8bit):7.999893673893284
                  Encrypted:true
                  SSDEEP:24576:B2ktOixUBb/TKtkaHEcmODWWcKM0fCRCjbWY+NFFiRz/NY70Z:UktOixU1bK2OHyUMOCRAbWLNq/GAZ
                  MD5:1A7B936CE187EF3D468F25067BEB29B3
                  SHA1:56348974048B8DEF1DC1B299D7AB8E623CBCE457
                  SHA-256:365E574D4309785677B0EC0357E1621CA36352B05D12BB0FD36C054B41670274
                  SHA-512:FABE9896AC659FC64DAB6F82A4B275546A6D9AEB1A014993FE89CE21D25B1474D61487B88CBC9C41A6E2099DC66755C557F25939482F9FC826200B0BE363992F
                  Malicious:false
                  Reputation:low
                  Preview:.@S......E....................2m.0....[(v...c&6..Y.G`.V..7JN...B......r@ .7.)D R+.......P...P...t.jg.....!..~M..%r........+.J.G....a[...;p..5~`...%oI..b)*A%.{K.l........bn...J?4.@3R.7...`.\.].7P.].dY...!..k.M..c..i6...%3.^&.."E.?....EZ.u.;.....u..fb...@..<.......1c.............M"...~<x.qO.*]s...$...F...h)o..?..N%_...V?.....*....}.rn......@..?..:.~...D...?S(.......N..L...?u.../....}Y....i..."E=`....I..u...>..}7.K.K.{.LP1.t.@....@7Z..>v.F.P.....(...i.......1.,.&.3+...C.6.R.c.4JH.c.....v.....~.JX.f..^`..Z.....f\H.3..*....s.".aj...F........K..H.".a...~8s. .........~p.=.R.3F..Y<.>.....2.vM....G...Y.....h.1..g....+A<.a..XIK.).mG.L.&.h..J..5.r..G........n..-.~3..h$..|Dr.6..T..YIb....5.:o.t.&.g.?O.!G.e.......P.........'.`.N..lk....K...fx..MW..B&Tj.8....7.<..UY..>..t.N.cm..*...E..Fca..S>...i.o2.U........T..I.."..*....<.C..:......x.z.)....i.L..(3b....BZ=g....7.r.o...`3..M,...v.!&.8..,.h.-...d../.B....C-Y......~..-..........^.....N]7#P.~.......
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdtserhygj, Template: Intel;1033, Revision Number: {0EDEF991-300A-44FE-919E-AAF24CBFC3B4}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Category:dropped
                  Size (bytes):8478720
                  Entropy (8bit):7.987008819361772
                  Encrypted:false
                  SSDEEP:196608:yZt99GsKph8v4drS9vBEnWwIF4Z4GHpKnazS:qtLF4Vku1Q4Z48KazS
                  MD5:012A2E128172C4BE72F5B5A90980B2EB
                  SHA1:DF79013E59F132F28A355B6CC6543D01A29D03C3
                  SHA-256:E4293872C79E70F9DE46DE4A6196E6DE8D5C662F912056E6E65B8D9BD290617F
                  SHA-512:0BC95CFE086DE1C514E2B42D6FF0B96B46FE16C595C6F5345A9288A134B309F8FA902F24B4424DC44BE10A103C12F313F0370B5C5CECD7FA04D3348966ACA82B
                  Malicious:false
                  Reputation:low
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdtserhygj, Template: Intel;1033, Revision Number: {0EDEF991-300A-44FE-919E-AAF24CBFC3B4}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Category:dropped
                  Size (bytes):8478720
                  Entropy (8bit):7.987008819361772
                  Encrypted:false
                  SSDEEP:196608:yZt99GsKph8v4drS9vBEnWwIF4Z4GHpKnazS:qtLF4Vku1Q4Z48KazS
                  MD5:012A2E128172C4BE72F5B5A90980B2EB
                  SHA1:DF79013E59F132F28A355B6CC6543D01A29D03C3
                  SHA-256:E4293872C79E70F9DE46DE4A6196E6DE8D5C662F912056E6E65B8D9BD290617F
                  SHA-512:0BC95CFE086DE1C514E2B42D6FF0B96B46FE16C595C6F5345A9288A134B309F8FA902F24B4424DC44BE10A103C12F313F0370B5C5CECD7FA04D3348966ACA82B
                  Malicious:false
                  Reputation:low
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):6904494
                  Entropy (8bit):7.988750351004292
                  Encrypted:false
                  SSDEEP:98304:ihwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEde:iKph8v4drS9vBExWwIF4Z4GHpKnazde
                  MD5:2C5903ADC18250BD064B16FA92A36F62
                  SHA1:B22ED985686A198AAD42C264ED4457885F39518F
                  SHA-256:AD3E4356163B9EF7C89D82C10B766F6D03FCEC6742730CF36544E028B7B080BC
                  SHA-512:9CE4C0205FF1911AF0C7CD5A782123A1017A7544BB6C1270A30B7ED67793335D71F80197AF2B818AD2904F6E8DA90ED46AF629293D117B6D285446038B973521
                  Malicious:false
                  Reputation:low
                  Preview:...@IXOS.@.....@#.#Z.@.....@.....@.....@.....@.....@......&.{F24F4CB8-1C5F-4258-A565-F326F70BA51B}..Setup..BBEYH73ThQ.msi.@.....@.....@.....@........&.{0EDEF991-300A-44FE-919E-AAF24CBFC3B4}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.M...@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\66132a.msi.........@........file.dat..l4d..file.dat.@.....@.M...@.......@.............@.........@.....@.....@.{.l.@..=.@F.%..@{.)......._....J..._.@A......Ti.MZx.....................@.................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                  Category:modified
                  Size (bytes):6902784
                  Entropy (8bit):7.988828924696361
                  Encrypted:false
                  SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
                  MD5:258FF5AB92030549125E08E161FD2E19
                  SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
                  SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
                  SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
                  Malicious:true
                  Antivirus:
                  • Antivirus: ReversingLabs, Detection: 13%
                  • Antivirus: Virustotal, Detection: 14%, Browse
                  Joe Sandbox View:
                  • Filename: xkUUkjILS6.msi, Detection: malicious, Browse
                  • Filename: 81Fh0BEPAB.msi, Detection: malicious, Browse
                  • Filename: T1#U52a9#U624b1.0.2.msi, Detection: malicious, Browse
                  • Filename: installer64v9.5.7.msi, Detection: malicious, Browse
                  • Filename: installer64v1.2.5.msi, Detection: malicious, Browse
                  • Filename: installer64v3.2.6.msi, Detection: malicious, Browse
                  • Filename: installer64v0.2.8.msi, Detection: malicious, Browse
                  Reputation:low
                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.1638108381780439
                  Encrypted:false
                  SSDEEP:12:JSbX72Fj6SAGiLIlHVRpZh/7777777777777777777777777vDHFAOAsInscit/z:J4SQI5tuRsIsZiF
                  MD5:8744A529B4BF84035AF58BFA1B757F87
                  SHA1:D14E00D93CB3CBA27F892235DD325CE4A2128F64
                  SHA-256:599925EE5F70768B9428E8B2016D823F8D2797EA48770161722104A32D857D16
                  SHA-512:AD1C314B11F7AE8F1C7828989167929DBF084A3E638B0EEB3D42B7FA56CBB359583AFB7A4AD2F5BE93CA4EBBD2ED2387854757C97E44A66B267E7FFF04B55B92
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4685642244023143
                  Encrypted:false
                  SSDEEP:48:H08PheuRc06WXJMnT51prVSU1deS5MgrydeSIACxZ8d:HLhe1vnTlrVwTUcCxZU
                  MD5:121C73C3123D4A10FD4DF656CDB2EBBB
                  SHA1:4D4D4DDD6D1C8ADE9A4ADD5CB3B665D112F68F2D
                  SHA-256:6472952BAEC71FFDBC0BBCAB7EC842EAE32A3334878085B1868C0CC144EBC3D7
                  SHA-512:21F5BACDE2430CB5D2695621EF8ECD024BE18B84B21B7A2D084EA18E99632D7C022F370FD0875B54B400230A0222B2C349539E91D8F246DA792DE6FB0F3EB0B7
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):360001
                  Entropy (8bit):5.362957380507103
                  Encrypted:false
                  SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauZ:zTtbmkExhMJCIpEI
                  MD5:9EE1973ABA11432E81A08143ADA6ADE3
                  SHA1:777269265EFA9DD4BDAEDBEB044395E3D687FDF3
                  SHA-256:A073C27DA00F0F111B014C44BA67DD549BA3B4FF86498BE345D387B293D3D0EC
                  SHA-512:15ED2D7FD7D19CA4BAFB00430BE980C56C37F7D073AB3C904E37CFA11138EAEC5F116184AF7740430460DBA1B84B18614FCD1697C5A5D453EC9899B8B1E90EED
                  Malicious:false
                  Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.1829984563103126
                  Encrypted:false
                  SSDEEP:48:Ln2uZNveFXJjT5HprVSU1deS5MgrydeSIACxZ8d:j2p7T/rVwTUcCxZU
                  MD5:E4397BC98B3F8A517A9D1B722A63E5A1
                  SHA1:825E1086C5DD582FF3AB865AF1C2CCD00A7A25FA
                  SHA-256:023D9FCEDCD1C3083868C115E14E64F230DB612E92C6BD8507D36EF15A25C2AA
                  SHA-512:1BF7BEBFA44A7BEC437597B3AE72BE074C41A04012270A24D79710FBF2C3443801D44FA28573222C03E18718E7BAAEA8B41A104AE9FC2C6FEFF6F7A798FE8855
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.1829984563103126
                  Encrypted:false
                  SSDEEP:48:Ln2uZNveFXJjT5HprVSU1deS5MgrydeSIACxZ8d:j2p7T/rVwTUcCxZU
                  MD5:E4397BC98B3F8A517A9D1B722A63E5A1
                  SHA1:825E1086C5DD582FF3AB865AF1C2CCD00A7A25FA
                  SHA-256:023D9FCEDCD1C3083868C115E14E64F230DB612E92C6BD8507D36EF15A25C2AA
                  SHA-512:1BF7BEBFA44A7BEC437597B3AE72BE074C41A04012270A24D79710FBF2C3443801D44FA28573222C03E18718E7BAAEA8B41A104AE9FC2C6FEFF6F7A798FE8855
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4685642244023143
                  Encrypted:false
                  SSDEEP:48:H08PheuRc06WXJMnT51prVSU1deS5MgrydeSIACxZ8d:HLhe1vnTlrVwTUcCxZU
                  MD5:121C73C3123D4A10FD4DF656CDB2EBBB
                  SHA1:4D4D4DDD6D1C8ADE9A4ADD5CB3B665D112F68F2D
                  SHA-256:6472952BAEC71FFDBC0BBCAB7EC842EAE32A3334878085B1868C0CC144EBC3D7
                  SHA-512:21F5BACDE2430CB5D2695621EF8ECD024BE18B84B21B7A2D084EA18E99632D7C022F370FD0875B54B400230A0222B2C349539E91D8F246DA792DE6FB0F3EB0B7
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):0.07124906791942463
                  Encrypted:false
                  SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOiPhwPoMtInsLXgVky6lit/:2F0i8n0itFzDHFAOAsInsPit/
                  MD5:784C75021BAEFF7BDD2D31C6522682CF
                  SHA1:2ADF6164145EDF4DFD108DB0F6D0FB29A7417914
                  SHA-256:6CBC1322250E8A014F4934279551BF5A1760450EB391E06AAB250C71F01A3E8E
                  SHA-512:0A1D52A8359BF7F559756CA6AD95C2A775DB4A70990B382A4BF38DF3089A1FCCF96465C8FE7582DC0AB0239A1B73161B417ACBCDF9DEB4651E13AC879A682458
                  Malicious:false
                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.1829984563103126
                  Encrypted:false
                  SSDEEP:48:Ln2uZNveFXJjT5HprVSU1deS5MgrydeSIACxZ8d:j2p7T/rVwTUcCxZU
                  MD5:E4397BC98B3F8A517A9D1B722A63E5A1
                  SHA1:825E1086C5DD582FF3AB865AF1C2CCD00A7A25FA
                  SHA-256:023D9FCEDCD1C3083868C115E14E64F230DB612E92C6BD8507D36EF15A25C2AA
                  SHA-512:1BF7BEBFA44A7BEC437597B3AE72BE074C41A04012270A24D79710FBF2C3443801D44FA28573222C03E18718E7BAAEA8B41A104AE9FC2C6FEFF6F7A798FE8855
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4685642244023143
                  Encrypted:false
                  SSDEEP:48:H08PheuRc06WXJMnT51prVSU1deS5MgrydeSIACxZ8d:HLhe1vnTlrVwTUcCxZU
                  MD5:121C73C3123D4A10FD4DF656CDB2EBBB
                  SHA1:4D4D4DDD6D1C8ADE9A4ADD5CB3B665D112F68F2D
                  SHA-256:6472952BAEC71FFDBC0BBCAB7EC842EAE32A3334878085B1868C0CC144EBC3D7
                  SHA-512:21F5BACDE2430CB5D2695621EF8ECD024BE18B84B21B7A2D084EA18E99632D7C022F370FD0875B54B400230A0222B2C349539E91D8F246DA792DE6FB0F3EB0B7
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):69632
                  Entropy (8bit):0.10479699751847799
                  Encrypted:false
                  SSDEEP:24:gZ8doL1EZLdB5GipVGdB5GipV7VqewGnlrkgRUR+3r+:gZ8dG1EldeScdeS5MgrRUROr+
                  MD5:0E6D2B8F6590CE0FAC498502CF3B9580
                  SHA1:B2DAB01CD71BB844F9710823D2B80B80EC919D9C
                  SHA-256:C2B177B1877AD34CFAB20DD57B074536E06375620F931193E6E5A1F7AF01BCBC
                  SHA-512:47C3D00F26F895B149AC9A3A42B1905E77F8C1F1708E3D04E9D651DEFAEBED692BB6C4694F925D55C41F0EC2E2F51D5604B48AFF9FDE796810D3BE8F6D2C0491
                  Malicious:false
                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdtserhygj, Template: Intel;1033, Revision Number: {0EDEF991-300A-44FE-919E-AAF24CBFC3B4}, Create Time/Date: Sat Jan 4 01:58:50 2025, Last Saved Time/Date: Sat Jan 4 01:58:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Entropy (8bit):7.987008819361772
                  TrID:
                  • Microsoft Windows Installer (60509/1) 88.31%
                  • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                  File name:BBEYH73ThQ.msi
                  File size:8'478'720 bytes
                  MD5:012a2e128172c4be72f5b5a90980b2eb
                  SHA1:df79013e59f132f28a355b6cc6543d01a29d03c3
                  SHA256:e4293872c79e70f9de46de4a6196e6de8d5c662f912056e6e65b8d9bd290617f
                  SHA512:0bc95cfe086de1c514e2b42d6ff0b96b46fe16c595c6f5345a9288a134b309f8fa902f24b4424dc44be10a103c12f313f0370b5c5cecd7fa04d3348966aca82b
                  SSDEEP:196608:yZt99GsKph8v4drS9vBEnWwIF4Z4GHpKnazS:qtLF4Vku1Q4Z48KazS
                  TLSH:0E863313B53FD6BCF5A234B25CF5A754C01A6D92A9B088538B843E8C1772F246B7335A
                  File Content Preview:........................>......................................................................................................................................................................................................................................
                  Icon Hash:2d2e3797b32b2b99
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 4, 2025 05:25:38.369811058 CET5435353192.168.2.7162.159.36.2
                  Jan 4, 2025 05:25:38.374599934 CET5354353162.159.36.2192.168.2.7
                  Jan 4, 2025 05:25:38.375842094 CET5435353192.168.2.7162.159.36.2
                  Jan 4, 2025 05:25:38.380748034 CET5354353162.159.36.2192.168.2.7
                  Jan 4, 2025 05:25:38.866270065 CET5435353192.168.2.7162.159.36.2
                  Jan 4, 2025 05:25:38.871292114 CET5354353162.159.36.2192.168.2.7
                  Jan 4, 2025 05:25:38.871356964 CET5435353192.168.2.7162.159.36.2
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 4, 2025 05:25:38.367063046 CET5364175162.159.36.2192.168.2.7
                  Jan 4, 2025 05:25:38.884746075 CET5512953192.168.2.71.1.1.1
                  Jan 4, 2025 05:25:38.891601086 CET53551291.1.1.1192.168.2.7
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Jan 4, 2025 05:25:38.884746075 CET192.168.2.71.1.1.10xa963Standard query (0)171.39.242.20.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Jan 4, 2025 05:25:38.891601086 CET1.1.1.1192.168.2.70xa963Name error (3)171.39.242.20.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false

                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:23:25:04
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\BBEYH73ThQ.msi"
                  Imagebase:0x7ff742130000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:1
                  Start time:23:25:05
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\msiexec.exe /V
                  Imagebase:0x7ff742130000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:false

                  Target ID:7
                  Start time:23:25:08
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\System32\MsiExec.exe -Embedding 856A84CED78D3640C5733385B6C615C9 E Global\MSI0000
                  Imagebase:0x7ff742130000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  No disassembly