Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
wlTYtdNJP8.msi

Overview

General Information

Sample name:wlTYtdNJP8.msi
renamed because original name is a hash value
Original sample name:1b3b04875b79904236403b95c742641c1686d72308a364eacb49a7269566100d.msi
Analysis ID:1584063
MD5:1ff22b0e2277abe37a89bca5a4d9f5d8
SHA1:124e473d3858061ba3c93ff1fdc8e6db51f2067d
SHA256:1b3b04875b79904236403b95c742641c1686d72308a364eacb49a7269566100d
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7784 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\wlTYtdNJP8.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7856 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7960 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 0A2686AEF5EA0F8D89DF9E5C53215DB9 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSICB76.tmpReversingLabs: Detection: 13%
Source: C:\Windows\Installer\MSICB76.tmpVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\54c3e3.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{30A77E35-B878-4FF8-91E6-7B863992B417}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC5D7.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\54c3e5.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\54c3e5.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB76.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\54c3e5.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSICB76.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSICB76.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: wlTYtdNJP8.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs wlTYtdNJP8.msi
Source: MSICB76.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSICB76.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSICB76.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal52.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF310BE35D3CF0E406.TMPJump to behavior
Source: wlTYtdNJP8.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\wlTYtdNJP8.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 0A2686AEF5EA0F8D89DF9E5C53215DB9 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 0A2686AEF5EA0F8D89DF9E5C53215DB9 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: wlTYtdNJP8.msiStatic file information: File size 8761344 > 1048576
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name:
Source: MSICB76.tmp.2.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSICB76.tmp.2.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSICB76.tmp.2.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSICB76.tmp.2.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB76.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB76.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICB76.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 8000Thread sleep count: 331 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584063 Sample: wlTYtdNJP8.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 52 15 Multi AV Scanner detection for dropped file 2->15 17 PE file has nameless sections 2->17 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSICB76.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
wlTYtdNJP8.msi5%VirustotalBrowse
wlTYtdNJP8.msi8%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSICB76.tmp13%ReversingLabs
C:\Windows\Installer\MSICB76.tmp14%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584063
Start date and time:2025-01-04 05:25:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:wlTYtdNJP8.msi
renamed because original name is a hash value
Original Sample Name:1b3b04875b79904236403b95c742641c1686d72308a364eacb49a7269566100d.msi
Detection:MAL
Classification:mal52.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 172.202.163.200, 20.109.210.53
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSICB76.tmpBBEYH73ThQ.msiGet hashmaliciousUnknownBrowse
    xkUUkjILS6.msiGet hashmaliciousUnknownBrowse
      81Fh0BEPAB.msiGet hashmaliciousUnknownBrowse
        T1#U52a9#U624b1.0.2.msiGet hashmaliciousUnknownBrowse
          installer64v9.5.7.msiGet hashmaliciousUnknownBrowse
            installer64v1.2.5.msiGet hashmaliciousUnknownBrowse
              installer64v3.2.6.msiGet hashmaliciousUnknownBrowse
                installer64v0.2.8.msiGet hashmaliciousUnknownBrowse
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):6910176
                  Entropy (8bit):7.98845413724879
                  Encrypted:false
                  SSDEEP:98304:thwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdq:tKph8v4drS9vBExWwIF4Z4GHpKnazdq
                  MD5:0A78ACA6EE7CE3682F945C1192C07131
                  SHA1:D42D2800D3DA13C932068CAD9A58C79848C99C9F
                  SHA-256:978DD8E2E8C2BB4AFBB3CA712B72623EBF61F056D1BB3727392A110EF2F38980
                  SHA-512:731E4440E2DAE9C2FA8C6CEBCDF81C971FE0C2262C6E160857BC7E8FE4344F10E20FFCCF02B9A695894EFA65A3773C5FC483D18748B7F9108B1920CAA2EF04D4
                  Malicious:false
                  Reputation:low
                  Preview:...@IXOS.@.....@D.#Z.@.....@.....@.....@.....@.....@......&.{30A77E35-B878-4FF8-91E6-7B863992B417}..Setup..wlTYtdNJP8.msi.@.....@.....@.....@........&.{BA060549-6155-46DD-ADDA-6E6F0FA6469D}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{30A77E35-B878-4FF8-91E6-7B863992B417}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):1812192
                  Entropy (8bit):7.99988754539387
                  Encrypted:true
                  SSDEEP:24576:lnov0StBHp2/l7Z8MBu3/NfnBOY2HYaVgorhNoE0vI1dDCyHaOVf+413o:l3b/ZAlfnBrbaV/oESod28P2g3o
                  MD5:F2C7DF849D1B44A515ACA3515CCF4256
                  SHA1:B0E0D4B752902A13981E48A265E279E6C6272CE9
                  SHA-256:D083699042ED4722327B83667015F702F7F318ED5E910E3A28D653E4C16042BE
                  SHA-512:FD66AB5F4D1BED1DDEBC14E94B19BD9C563DAA5F85561E00DBE0895326307F495D1FDB6378DA23FFCFF61EC5C5A8D3C717772EE3F854E82B1DBF1BA572647989
                  Malicious:false
                  Reputation:low
                  Preview:.@S.....2."|Z...............@..I.#....m[...KX.....\..m...g.V.g...QS)..x..U:oIR...5...`..uD....G=.t...#..9~.dq5....^...C}./.g.X.ee^.l......=...(.*8..7@..Q.{..."G.d.b<n.....4U....H..9..ppC].'.......G/n.a...^....h.....l...w.,. z..,...(.&.J.@..,".....T..~.l..j.i.~~!'.....M@1...P'N,.4..1..g..:.i......MFI.J...~lw.?h...3..[%OR...y..J.......-K'..~...V.i.M....0R_/.4..3.'p..u.Esyq.b{..........f../.9.lh+?z.7E.g!.;...sZcC.....Y.5`...{...(o.T....`...l..U..T..... .&5.~.....8.....<.m.....N.T.......K..}.....f+%.E.3.....s..*.s?.../=r..r.....]....-.L(&.E./3.&S..=.g..*"...F....d.U.s.r.y.....H./[..Q}......Y.U.....0.f..+8..]....`......y.o........&.h..B.,..[.......Y.I.%&pl.... ..J!xx..8.}...}..{.{3.........T<..0.~mnBw ..<.U~.'......@ .............3...P....5>..7.\Y....u".4.D3....C%|..j......w@%0.;..%>".....:....PG......9.X.w2..s........0..Y9..;.d.'.....r.e.......Y..t..bZ.$q.f.N.:....._.-Pm...H....d.....091N.G.bg?.....e.noG.^L.%.yUFwKQ....%.9k._^.
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {BA060549-6155-46DD-ADDA-6E6F0FA6469D}, Create Time/Date: Sat Jan 4 01:58:42 2025, Last Saved Time/Date: Sat Jan 4 01:58:42 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Category:dropped
                  Size (bytes):8761344
                  Entropy (8bit):7.988174785666731
                  Encrypted:false
                  SSDEEP:196608:XogU+BpUzdKph8v4drS9vBuxWwIF4Z4GHpKnAzd:4gU+BpMdF4VkW1Q4Z48KAzd
                  MD5:1FF22B0E2277ABE37A89BCA5A4D9F5D8
                  SHA1:124E473D3858061BA3C93FF1FDC8E6DB51F2067D
                  SHA-256:1B3B04875B79904236403B95C742641C1686D72308A364EACB49A7269566100D
                  SHA-512:2BCB74885911D3121020AE1113BD328A0232828EAB2432DDE77845F99BB7DABE4CD404345DD7DFE372E908A32D0DC792F35BA39B84E814E1061047B5DE502225
                  Malicious:false
                  Reputation:low
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {BA060549-6155-46DD-ADDA-6E6F0FA6469D}, Create Time/Date: Sat Jan 4 01:58:42 2025, Last Saved Time/Date: Sat Jan 4 01:58:42 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Category:dropped
                  Size (bytes):8761344
                  Entropy (8bit):7.988174785666731
                  Encrypted:false
                  SSDEEP:196608:XogU+BpUzdKph8v4drS9vBuxWwIF4Z4GHpKnAzd:4gU+BpMdF4VkW1Q4Z48KAzd
                  MD5:1FF22B0E2277ABE37A89BCA5A4D9F5D8
                  SHA1:124E473D3858061BA3C93FF1FDC8E6DB51F2067D
                  SHA-256:1B3B04875B79904236403B95C742641C1686D72308A364EACB49A7269566100D
                  SHA-512:2BCB74885911D3121020AE1113BD328A0232828EAB2432DDE77845F99BB7DABE4CD404345DD7DFE372E908A32D0DC792F35BA39B84E814E1061047B5DE502225
                  Malicious:false
                  Reputation:low
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):6904485
                  Entropy (8bit):7.988750809873906
                  Encrypted:false
                  SSDEEP:98304:xhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdh:xKph8v4drS9vBExWwIF4Z4GHpKnazdh
                  MD5:49A32F886E0E3617410B0821D1F4F938
                  SHA1:E84BEBA67D0E869701E3D9ED9B2B8020FD9CB856
                  SHA-256:F932EBC89BCF2385CA793C265889610E92FFF4C060C5D04FF6891DBCF04D088A
                  SHA-512:4F8928C5773AD70296D3BAF360FE037FD8EE8749AB8208E351FBB49C0104524A25207AA1F2FED1D8CFF534587697612D1D920CDC0052F28E78A787C230EDC928
                  Malicious:false
                  Reputation:low
                  Preview:...@IXOS.@.....@D.#Z.@.....@.....@.....@.....@.....@......&.{30A77E35-B878-4FF8-91E6-7B863992B417}..Setup..wlTYtdNJP8.msi.@.....@.....@.....@........&.{BA060549-6155-46DD-ADDA-6E6F0FA6469D}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\54c3e3.msi.........@........file.dat..l4d..file.dat.@.....@....@.......@.............@.........@.....@.....@....@..D..@...Q.@\.BV......_....J..._.@A......Ti.MZx.....................@.................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                  Category:modified
                  Size (bytes):6902784
                  Entropy (8bit):7.988828924696361
                  Encrypted:false
                  SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
                  MD5:258FF5AB92030549125E08E161FD2E19
                  SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
                  SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
                  SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
                  Malicious:true
                  Antivirus:
                  • Antivirus: ReversingLabs, Detection: 13%
                  • Antivirus: Virustotal, Detection: 14%, Browse
                  Joe Sandbox View:
                  • Filename: BBEYH73ThQ.msi, Detection: malicious, Browse
                  • Filename: xkUUkjILS6.msi, Detection: malicious, Browse
                  • Filename: 81Fh0BEPAB.msi, Detection: malicious, Browse
                  • Filename: T1#U52a9#U624b1.0.2.msi, Detection: malicious, Browse
                  • Filename: installer64v9.5.7.msi, Detection: malicious, Browse
                  • Filename: installer64v1.2.5.msi, Detection: malicious, Browse
                  • Filename: installer64v3.2.6.msi, Detection: malicious, Browse
                  • Filename: installer64v0.2.8.msi, Detection: malicious, Browse
                  Reputation:moderate, very likely benign file
                  Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.1642647473007335
                  Encrypted:false
                  SSDEEP:12:JSbX72FjHAGiLIlHVRpZh/7777777777777777777777777vDHF9JQXGit/l0i8Q:JFQI5tnJQiF
                  MD5:C9F248FA93D66853B6C05A363B2F5FD0
                  SHA1:1B1460974FDF84F91857DDA9CD3E2683D2AB8BA8
                  SHA-256:67B2D402BCD619C0281F941AD5596F44BF9AB1AC8C29C3560F067C26F4AC95A8
                  SHA-512:0290D354C088E5D64154B282CFB79D48E0D8F384168BCDAC6FBB17F59E62DCD10422C306D2667CF57BC94964FC7C9728FB2A77EBBF5299E0AC552F71645066B7
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4634883478789376
                  Encrypted:false
                  SSDEEP:48:y8PhAuRc06WXJWFT5YUEddeS5rrideSI7cn:dhA1tFTfJ4Pc
                  MD5:ADEC21BC3D6A7E00C9744A2413D1032D
                  SHA1:237B6FFF2350FF532DAF46508B80EBC559151645
                  SHA-256:481876676B672F74ED54838CEB6404EC2134A99CB91F628179E0160A27BC27FB
                  SHA-512:DF4491A1758F3C75B4EFD768A80BE4FF8B29199191AD669FCEF24093058FE3ADA45311B09E062176B8A9112DAAD8690B5887028DECCF09A122A2E7C2C4C97AED
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):360001
                  Entropy (8bit):5.362973076712661
                  Encrypted:false
                  SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauX:zTtbmkExhMJCIpES
                  MD5:CAB76CCD1286A7448CD6FEEFAA02AB40
                  SHA1:EBB7ADD07062D3F5869EE6C7F53E006D58D7C99D
                  SHA-256:9FB4F038DFE461E3EC053A600CA3A08FC3F32B3E4D05DBC411401D48E5A4C9A4
                  SHA-512:0B191B0E414C6BCFE943801293DC5422472AA69AA33F4635DE6F6A4926CA588C8EFB9270E902F24FDE0D22FA7108713FC2745080AC769FBC9D1D6B4FDEF6D88E
                  Malicious:false
                  Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):0.07166666052182893
                  Encrypted:false
                  SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOmgcWQX0GDtgVky6lit/:2F0i8n0itFzDHF9JQXHZit/
                  MD5:53F935DC3F15D52FCAF89607FCBD3328
                  SHA1:EA9850D6274BDEF25133DADC862B495489E5F3B1
                  SHA-256:08AFA7F18F2E06AFB16B425A513CD42D1914E18B32DBE1409DB26DDF06DCB182
                  SHA-512:AEBB3A5B885839A7993758958ED479E780033436D361A87BC57322329A982FEA903EBD9547F550AD40B22D793F3245C4D43B5674D086C82A44D744D5D79F8161
                  Malicious:false
                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):69632
                  Entropy (8bit):0.10278513018382245
                  Encrypted:false
                  SSDEEP:24:8C+Q+CZLdB5GipVGdB5GipV7VPwGrlrkg1Z+Y7:1n+CldeScdeS5rr1Z5
                  MD5:14196782B898F7B85AF94FF4F534CDD2
                  SHA1:66AE03DF6466B4DB0EB2B1FB7C6B40E9FAD40AC6
                  SHA-256:9C0C9849B8C34EF93E1CBE6D58D72E45797B01F7771319A59D34A38968B42F15
                  SHA-512:7376C894FD2E623DFB71EC6ECDBC04035F16C9823A3D23939F9964E118046DDD75C9C19FD87E128FB2DAFC09DD2A0A56BE1AFBA503B9D8BEDB10FDACE6DD7D9A
                  Malicious:false
                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4634883478789376
                  Encrypted:false
                  SSDEEP:48:y8PhAuRc06WXJWFT5YUEddeS5rrideSI7cn:dhA1tFTfJ4Pc
                  MD5:ADEC21BC3D6A7E00C9744A2413D1032D
                  SHA1:237B6FFF2350FF532DAF46508B80EBC559151645
                  SHA-256:481876676B672F74ED54838CEB6404EC2134A99CB91F628179E0160A27BC27FB
                  SHA-512:DF4491A1758F3C75B4EFD768A80BE4FF8B29199191AD669FCEF24093058FE3ADA45311B09E062176B8A9112DAAD8690B5887028DECCF09A122A2E7C2C4C97AED
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.179735950648221
                  Encrypted:false
                  SSDEEP:48:xnoujPveFXJXT52UEddeS5rrideSI7cn:toZ/TNJ4Pc
                  MD5:39E3A6BBB5547D639F681C019C15A00E
                  SHA1:A03A52A61B7333E3C98BA412F0A54A777B65D9A8
                  SHA-256:48BE4E50B5A7929F3377DA965BE59EB94BCC9B970623567CF4920052258B60DA
                  SHA-512:50B9A2F2755E886C1991173ACBE51BE6FB330A10311F054AF1193F9B73FD2D7EF2CACF0320C36C02485CE23C9A5A339FE37B9D1B81AD6FEC42B094853E7AE84E
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.179735950648221
                  Encrypted:false
                  SSDEEP:48:xnoujPveFXJXT52UEddeS5rrideSI7cn:toZ/TNJ4Pc
                  MD5:39E3A6BBB5547D639F681C019C15A00E
                  SHA1:A03A52A61B7333E3C98BA412F0A54A777B65D9A8
                  SHA-256:48BE4E50B5A7929F3377DA965BE59EB94BCC9B970623567CF4920052258B60DA
                  SHA-512:50B9A2F2755E886C1991173ACBE51BE6FB330A10311F054AF1193F9B73FD2D7EF2CACF0320C36C02485CE23C9A5A339FE37B9D1B81AD6FEC42B094853E7AE84E
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):32768
                  Entropy (8bit):1.179735950648221
                  Encrypted:false
                  SSDEEP:48:xnoujPveFXJXT52UEddeS5rrideSI7cn:toZ/TNJ4Pc
                  MD5:39E3A6BBB5547D639F681C019C15A00E
                  SHA1:A03A52A61B7333E3C98BA412F0A54A777B65D9A8
                  SHA-256:48BE4E50B5A7929F3377DA965BE59EB94BCC9B970623567CF4920052258B60DA
                  SHA-512:50B9A2F2755E886C1991173ACBE51BE6FB330A10311F054AF1193F9B73FD2D7EF2CACF0320C36C02485CE23C9A5A339FE37B9D1B81AD6FEC42B094853E7AE84E
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:Composite Document File V2 Document, Cannot read section info
                  Category:dropped
                  Size (bytes):20480
                  Entropy (8bit):1.4634883478789376
                  Encrypted:false
                  SSDEEP:48:y8PhAuRc06WXJWFT5YUEddeS5rrideSI7cn:dhA1tFTfJ4Pc
                  MD5:ADEC21BC3D6A7E00C9744A2413D1032D
                  SHA1:237B6FFF2350FF532DAF46508B80EBC559151645
                  SHA-256:481876676B672F74ED54838CEB6404EC2134A99CB91F628179E0160A27BC27FB
                  SHA-512:DF4491A1758F3C75B4EFD768A80BE4FF8B29199191AD669FCEF24093058FE3ADA45311B09E062176B8A9112DAAD8690B5887028DECCF09A122A2E7C2C4C97AED
                  Malicious:false
                  Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  Process:C:\Windows\System32\msiexec.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):512
                  Entropy (8bit):0.0
                  Encrypted:false
                  SSDEEP:3::
                  MD5:BF619EAC0CDF3F68D496EA9344137E8B
                  SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                  SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                  SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                  Malicious:false
                  Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {BA060549-6155-46DD-ADDA-6E6F0FA6469D}, Create Time/Date: Sat Jan 4 01:58:42 2025, Last Saved Time/Date: Sat Jan 4 01:58:42 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                  Entropy (8bit):7.988174785666731
                  TrID:
                  • Microsoft Windows Installer (60509/1) 88.31%
                  • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                  File name:wlTYtdNJP8.msi
                  File size:8'761'344 bytes
                  MD5:1ff22b0e2277abe37a89bca5a4d9f5d8
                  SHA1:124e473d3858061ba3c93ff1fdc8e6db51f2067d
                  SHA256:1b3b04875b79904236403b95c742641c1686d72308a364eacb49a7269566100d
                  SHA512:2bcb74885911d3121020ae1113bd328a0232828eab2432dde77845f99bb7dabe4cd404345dd7dfe372e908a32d0dc792f35ba39b84e814e1061047b5de502225
                  SSDEEP:196608:XogU+BpUzdKph8v4drS9vBuxWwIF4Z4GHpKnAzd:4gU+BpMdF4VkW1Q4Z48KAzd
                  TLSH:04963312B13BDABDF86234B24D756710C0163EE2B9B049276BC83A8C1772F24177779A
                  File Content Preview:........................>......................................................................................................................................................................................................................................
                  Icon Hash:2d2e3797b32b2b99
                  No network behavior found

                  Click to jump to process

                  Click to jump to process

                  Click to jump to process

                  Target ID:0
                  Start time:23:26:06
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\wlTYtdNJP8.msi"
                  Imagebase:0x7ff7beff0000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:2
                  Start time:23:26:06
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\msiexec.exe /V
                  Imagebase:0x7ff7beff0000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:false

                  Target ID:3
                  Start time:23:26:08
                  Start date:03/01/2025
                  Path:C:\Windows\System32\msiexec.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\System32\MsiExec.exe -Embedding 0A2686AEF5EA0F8D89DF9E5C53215DB9 E Global\MSI0000
                  Imagebase:0x7ff7beff0000
                  File size:69'632 bytes
                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  No disassembly