Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
ws8xbtbe12.msi

Overview

General Information

Sample name:ws8xbtbe12.msi
renamed because original name is a hash value
Original sample name:e59040383fcc8b6c3d0f0212e0aeea0c4675afd2132ee3a9af3295faae85f939.msi
Analysis ID:1584065
MD5:46ff7ad559250cde806930b95a4639fd
SHA1:9828950386628f80398a28f1a85f579a4afe58ee
SHA256:e59040383fcc8b6c3d0f0212e0aeea0c4675afd2132ee3a9af3295faae85f939
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7528 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\ws8xbtbe12.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 1384 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6052 cmdline: C:\Windows\System32\MsiExec.exe -Embedding BAE0365E84B2EE69D920D2512552695E E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI4F8F.tmpReversingLabs: Detection: 13%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: global trafficTCP traffic: 192.168.2.10:54154 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.10:60430 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1

System Summary

barindex
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5446c4.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{AF2C9903-723C-48B7-9266-249B410223FA}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI48B8.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5446c6.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5446c6.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4F8F.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\5446c6.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI4F8F.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSI4F8F.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: ws8xbtbe12.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs ws8xbtbe12.msi
Source: MSI4F8F.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSI4F8F.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSI4F8F.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal52.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF519953E1790B6987.TMPJump to behavior
Source: ws8xbtbe12.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\ws8xbtbe12.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding BAE0365E84B2EE69D920D2512552695E E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding BAE0365E84B2EE69D920D2512552695E E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: ws8xbtbe12.msiStatic file information: File size 8560640 > 1048576
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name:
Source: MSI4F8F.tmp.2.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSI4F8F.tmp.2.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSI4F8F.tmp.2.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSI4F8F.tmp.2.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4F8F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4F8F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI4F8F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 736Thread sleep count: 480 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584065 Sample: ws8xbtbe12.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 52 15 Multi AV Scanner detection for dropped file 2->15 17 PE file has nameless sections 2->17 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI4F8F.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ws8xbtbe12.msi8%ReversingLabs
ws8xbtbe12.msi5%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI4F8F.tmp13%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584065
Start date and time:2025-01-04 05:26:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:ws8xbtbe12.msi
renamed because original name is a hash value
Original Sample Name:e59040383fcc8b6c3d0f0212e0aeea0c4675afd2132ee3a9af3295faae85f939.msi
Detection:MAL
Classification:mal52.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.109.210.53, 20.3.187.198
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI4F8F.tmpIlPF8gbvGl.msiGet hashmaliciousUnknownBrowse
    wlTYtdNJP8.msiGet hashmaliciousUnknownBrowse
      BBEYH73ThQ.msiGet hashmaliciousUnknownBrowse
        xkUUkjILS6.msiGet hashmaliciousUnknownBrowse
          81Fh0BEPAB.msiGet hashmaliciousUnknownBrowse
            T1#U52a9#U624b1.0.2.msiGet hashmaliciousUnknownBrowse
              installer64v9.5.7.msiGet hashmaliciousUnknownBrowse
                installer64v1.2.5.msiGet hashmaliciousUnknownBrowse
                  installer64v3.2.6.msiGet hashmaliciousUnknownBrowse
                    installer64v0.2.8.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6910168
                      Entropy (8bit):7.988454772836048
                      Encrypted:false
                      SSDEEP:98304:IhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdY:IKph8v4drS9vBExWwIF4Z4GHpKnazdY
                      MD5:630309DEEB33BA9EBE577B40EEA923F9
                      SHA1:35F69067A9E8ED9D3C4DBC07433CB9BF77ADA7C2
                      SHA-256:004949A8DA1B06B984CC614E12CA63C9154BA622EECDECD098B0D52F80E9A970
                      SHA-512:5B2F628F22FE2D6143F6DD1EBBA3CC5745E13A6243B244861B7FD02DA66B1F87D3AEA7BF9AD879279E68F69FDC9EE327F8B6EEB787F198263232E9C808652A13
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@c.#Z.@.....@.....@.....@.....@.....@......&.{AF2C9903-723C-48B7-9266-249B410223FA}..Setup..ws8xbtbe12.msi.@.....@.....@.....@........&.{831A0769-0F52-4C95-8283-883044C11896}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{AF2C9903-723C-48B7-9266-249B410223FA}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1610064
                      Entropy (8bit):7.999883788793441
                      Encrypted:true
                      SSDEEP:49152:R1prZVUe/CkF+KMXDiH1lP8qke4gkkkjjjIT:VrZJ/RAKeiVWk0jjIT
                      MD5:8BDEC9B14C87C48E8234C57FBC5F8E7C
                      SHA1:C924790840D8361F69F83B48FFCB2BB1B67AC0A9
                      SHA-256:37AAC56A84440B2CBD2A249D846E419172689BA0AB02799E9F6EB9981694FFC2
                      SHA-512:7D88F43F93EF822B074ACF77C1ADC8DB0F9D61C3697FE5AB5E74F8872CEC43906A748812FCBAFDAD8EB4215A57EA8006F5BCD2403E46903FD8138E1EB0C9D222
                      Malicious:false
                      Reputation:low
                      Preview:.@S.......W.l..............(........4. .}...WNt.&.Av.q .\$.~|lh..&.A......=7b..PF.rN.#@..b.&.F.c.n..=q9.[....Ie.(..|....o..k..(.8...y.Mk......c:. ..|'K=r...Q`M....D.9Y/......E;}.g.:W....D.dCj....I0O.#.c#...Y.|\....z...v0..<`.O^.yU./`..C2.."..;..b.."...../.x.; 3Qk.h...AzhD.1..s...s.Z.?....k.%.....V.L.....P.........*W..."q.YO*.B..gB..J...hm.>..57.~SS.F.W..9!.f.\dF}...7*..&..j...C..}).'.l......^..ytvG.....[.;g.....H...d..pNS.Y\~c....dS$.0......a)......\<.Q...o.D.|..k7F..D...Z.6......E..$j.b.w...b...RK....a<.[.......\.......Knvv.....9.Tzo....5J..t1r....g....WDk.f.Zpo|..U.7..O.?...*. 5;.....{..F.H<%..u/....qj..!....kK.....=.....\...i.M.R.l..Jg..^.......G....C.SY.....h~<'..js...-.........rJ..o.....B$G..L..W.M....B.g<sf.<I.G.DJ)..x...Nt.s.....=.F4E........#u.)..`....;.....q......Y.c...?./E...?z.....7..^..}..RU.~.\vo...".3..l....soE.ki....4..`&...V..y5.J.Y..Ax....X.2.~....j(".g..IGb.O.S.A.........=......F#.4|.|.....#.&..p$.L....;f...,+....oe.J...
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dgfhdruhtgk, Template: Intel;1033, Revision Number: {831A0769-0F52-4C95-8283-883044C11896}, Create Time/Date: Fri Jan 3 16:02:50 2025, Last Saved Time/Date: Fri Jan 3 16:02:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8560640
                      Entropy (8bit):7.987425468956513
                      Encrypted:false
                      SSDEEP:196608:CuPKhUhtIWjIFKph8v4drS9vB2xWwIF4Z4GHpKnazW:vPH/IWEFF4Vk+1Q4Z48KazW
                      MD5:46FF7AD559250CDE806930B95A4639FD
                      SHA1:9828950386628F80398A28F1A85F579A4AFE58EE
                      SHA-256:E59040383FCC8B6C3D0F0212E0AEEA0C4675AFD2132EE3A9AF3295FAAE85F939
                      SHA-512:FE85F948031D1CF8CD30B40CABAED8F3F4857F2030F761386DF4CC27D215D76A4115454970A79C4EE4B23422B6D1952F20C9C902BA33BE74BA6C2F56574B0808
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dgfhdruhtgk, Template: Intel;1033, Revision Number: {831A0769-0F52-4C95-8283-883044C11896}, Create Time/Date: Fri Jan 3 16:02:50 2025, Last Saved Time/Date: Fri Jan 3 16:02:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8560640
                      Entropy (8bit):7.987425468956513
                      Encrypted:false
                      SSDEEP:196608:CuPKhUhtIWjIFKph8v4drS9vB2xWwIF4Z4GHpKnazW:vPH/IWEFF4Vk+1Q4Z48KazW
                      MD5:46FF7AD559250CDE806930B95A4639FD
                      SHA1:9828950386628F80398A28F1A85F579A4AFE58EE
                      SHA-256:E59040383FCC8B6C3D0F0212E0AEEA0C4675AFD2132EE3A9AF3295FAAE85F939
                      SHA-512:FE85F948031D1CF8CD30B40CABAED8F3F4857F2030F761386DF4CC27D215D76A4115454970A79C4EE4B23422B6D1952F20C9C902BA33BE74BA6C2F56574B0808
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6904479
                      Entropy (8bit):7.9887512294301635
                      Encrypted:false
                      SSDEEP:98304:QhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdz:QKph8v4drS9vBExWwIF4Z4GHpKnazdz
                      MD5:43E11095B0E11BFB1ECB9527788634C9
                      SHA1:4F6AD6F3E1C4B6EFF430D5D0DB79ABDAA7F3FC00
                      SHA-256:9864A050FF6EE22DD41C17B3033BDE74C20A1808A3A82050BDF2B37B948D58BD
                      SHA-512:79DFBC98B16490B92F5229D3D7C2E1DB1B44C5F18EADDE403AD210AC3D3339493476B31392865F6B1494F18D7476DE2DD36C6ED6B679E4429CF1E74A4E23C797
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@c.#Z.@.....@.....@.....@.....@.....@......&.{AF2C9903-723C-48B7-9266-249B410223FA}..Setup..ws8xbtbe12.msi.@.....@.....@.....@........&.{831A0769-0F52-4C95-8283-883044C11896}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@P....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\5446c4.msi.........@........file.dat..l4d..file.dat.@.....@P....@.......@.............@.........@.....@.....@....@L...@.4...@._.|......_....J..._.@A......Ti.MZx.....................@.................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:dropped
                      Size (bytes):6902784
                      Entropy (8bit):7.988828924696361
                      Encrypted:false
                      SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
                      MD5:258FF5AB92030549125E08E161FD2E19
                      SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
                      SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
                      SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 13%
                      Joe Sandbox View:
                      • Filename: IlPF8gbvGl.msi, Detection: malicious, Browse
                      • Filename: wlTYtdNJP8.msi, Detection: malicious, Browse
                      • Filename: BBEYH73ThQ.msi, Detection: malicious, Browse
                      • Filename: xkUUkjILS6.msi, Detection: malicious, Browse
                      • Filename: 81Fh0BEPAB.msi, Detection: malicious, Browse
                      • Filename: T1#U52a9#U624b1.0.2.msi, Detection: malicious, Browse
                      • Filename: installer64v9.5.7.msi, Detection: malicious, Browse
                      • Filename: installer64v1.2.5.msi, Detection: malicious, Browse
                      • Filename: installer64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: installer64v0.2.8.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1644354078093575
                      Encrypted:false
                      SSDEEP:12:JSbX72FjjhAGiLIlHVRpZh/7777777777777777777777777vDHFqVWTfddhit/z:JzQI5tiWbddsiF
                      MD5:768B8C37A1BA403B2B04B5B20FAE3C18
                      SHA1:14570E281A1A8AB175F514AE7264E64220F2B228
                      SHA-256:F8B046E2BDA34849C3445ACBF0D2ADBDC617D8329D8C70C81612B12AD938AAD4
                      SHA-512:09D670A098FD12912CBD6074CB2556F596B0F7C7C06AB341C570D874DF5E19A707B413543345956DFF1D52C37F867AF1415A091C06658250E6B377ECBDAA01FD
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4603302581577822
                      Encrypted:false
                      SSDEEP:48:L8PhkuRc06WXJajT5iYH4RldeS5HrCdeSIbwL:yhk1RjT1YMEvwL
                      MD5:E02B0F7714492F40A2434AA5DA8DF265
                      SHA1:ADB1F2295064BF0928C69D61E1236B2C3E520644
                      SHA-256:4CCE08CB2B46F71DDD2F775CD8F7E02A0C7E528080D89224087EFB9F248CC503
                      SHA-512:2C6FFB39548C6D2B72A59030EF92556331BCBCE3FAE2B6E9E31280C64AA20B1C98120BF150411C2126E2118BDAE094B23A2F2CD6D9F0AF39CC27C65BD70E0A78
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):363829
                      Entropy (8bit):5.36540371022681
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgaua:zTtbmkExhMJCIpEv
                      MD5:B067A8BAF94D05C42B93F916817629CD
                      SHA1:3342CF2F3A8DE5674D0E0387670B43691A9A67C9
                      SHA-256:F603532E4962799F4753A4A433C486860DE1E9D9E1109FD3AC4D917E4866891F
                      SHA-512:2A686DC7FFFD3E0460BB7C8BD1927FF90EFCE5103B71D61099629FE64F968F88EC4B22F6BC51ADD69835A72B8718F8869B89D008B0BE95D1D86F5CE7EB8999A2
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4603302581577822
                      Encrypted:false
                      SSDEEP:48:L8PhkuRc06WXJajT5iYH4RldeS5HrCdeSIbwL:yhk1RjT1YMEvwL
                      MD5:E02B0F7714492F40A2434AA5DA8DF265
                      SHA1:ADB1F2295064BF0928C69D61E1236B2C3E520644
                      SHA-256:4CCE08CB2B46F71DDD2F775CD8F7E02A0C7E528080D89224087EFB9F248CC503
                      SHA-512:2C6FFB39548C6D2B72A59030EF92556331BCBCE3FAE2B6E9E31280C64AA20B1C98120BF150411C2126E2118BDAE094B23A2F2CD6D9F0AF39CC27C65BD70E0A78
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1774873701157125
                      Encrypted:false
                      SSDEEP:48:0nMufJveFXJtT5UYH4RldeS5HrCdeSIbwL:6MHVTnYMEvwL
                      MD5:31708EB465AB112FD2B12364C4F4EC05
                      SHA1:70C497FF173C1E6D100520956F97B9B6817D96F1
                      SHA-256:E9BE91DBA674688E3A66348F4BD1FF7CA1479460542C9774654A97A56479D2B0
                      SHA-512:BFDBC6A39B87E8AF0759FBC90CB86C4F90DFEEC58AB3FD89092EC05D01E73A010E55E54D154967BFCA88EC192D6CCA035DD7A692F63734DC06F3CA5210569CE6
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07197920858457876
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOqVMXEg0c9fddEgVky6lit/:2F0i8n0itFzDHFqVWTfddOit/
                      MD5:EE815210C061A4810ADE81204B4DEE88
                      SHA1:87BF3625F770DD8E9B6A88E53D9FD89DFFBA01E6
                      SHA-256:3ED3EFB8FE5D2CB70590A565CFB22081881F407B70FC6832AE3144E1DC7AE817
                      SHA-512:60D740B24207107797CF6593638D02AAA5700956E7A1DB968103017E3623CCBD4952429677E0ABF26CD0B92368CAEBC8A45E02485F368487C9298EB48AA266C1
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10121662331478762
                      Encrypted:false
                      SSDEEP:24:h+VWJfCZLdB5GipVGdB5GipV7VPwGPlrkgqB+e442:hLRCldeScdeS5HrqBH4V
                      MD5:FBD88FBB3D9FB7694C1E2FAA9C7F3AD9
                      SHA1:EEEED4627685F568675EEEEAF86B6984A34C735F
                      SHA-256:8278A632968A83D53CD6A5B5D2299996CE3CB34D786B613D3943CF9160C46342
                      SHA-512:90E6CC35EAC1C0BE0F215C343259AEE59234CAF255B27D52C639E044A734695CBBD3421A5E05143100B1E3B7B15865D5FD7F1117DFACE6D1929583200632D8DD
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1774873701157125
                      Encrypted:false
                      SSDEEP:48:0nMufJveFXJtT5UYH4RldeS5HrCdeSIbwL:6MHVTnYMEvwL
                      MD5:31708EB465AB112FD2B12364C4F4EC05
                      SHA1:70C497FF173C1E6D100520956F97B9B6817D96F1
                      SHA-256:E9BE91DBA674688E3A66348F4BD1FF7CA1479460542C9774654A97A56479D2B0
                      SHA-512:BFDBC6A39B87E8AF0759FBC90CB86C4F90DFEEC58AB3FD89092EC05D01E73A010E55E54D154967BFCA88EC192D6CCA035DD7A692F63734DC06F3CA5210569CE6
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:modified
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4603302581577822
                      Encrypted:false
                      SSDEEP:48:L8PhkuRc06WXJajT5iYH4RldeS5HrCdeSIbwL:yhk1RjT1YMEvwL
                      MD5:E02B0F7714492F40A2434AA5DA8DF265
                      SHA1:ADB1F2295064BF0928C69D61E1236B2C3E520644
                      SHA-256:4CCE08CB2B46F71DDD2F775CD8F7E02A0C7E528080D89224087EFB9F248CC503
                      SHA-512:2C6FFB39548C6D2B72A59030EF92556331BCBCE3FAE2B6E9E31280C64AA20B1C98120BF150411C2126E2118BDAE094B23A2F2CD6D9F0AF39CC27C65BD70E0A78
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1774873701157125
                      Encrypted:false
                      SSDEEP:48:0nMufJveFXJtT5UYH4RldeS5HrCdeSIbwL:6MHVTnYMEvwL
                      MD5:31708EB465AB112FD2B12364C4F4EC05
                      SHA1:70C497FF173C1E6D100520956F97B9B6817D96F1
                      SHA-256:E9BE91DBA674688E3A66348F4BD1FF7CA1479460542C9774654A97A56479D2B0
                      SHA-512:BFDBC6A39B87E8AF0759FBC90CB86C4F90DFEEC58AB3FD89092EC05D01E73A010E55E54D154967BFCA88EC192D6CCA035DD7A692F63734DC06F3CA5210569CE6
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dgfhdruhtgk, Template: Intel;1033, Revision Number: {831A0769-0F52-4C95-8283-883044C11896}, Create Time/Date: Fri Jan 3 16:02:50 2025, Last Saved Time/Date: Fri Jan 3 16:02:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.987425468956513
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:ws8xbtbe12.msi
                      File size:8'560'640 bytes
                      MD5:46ff7ad559250cde806930b95a4639fd
                      SHA1:9828950386628f80398a28f1a85f579a4afe58ee
                      SHA256:e59040383fcc8b6c3d0f0212e0aeea0c4675afd2132ee3a9af3295faae85f939
                      SHA512:fe85f948031d1cf8cd30b40cabaed8f3f4857f2030f761386df4cc27d215d76a4115454970a79c4ee4b23422b6d1952f20c9c902ba33be74ba6c2f56574b0808
                      SSDEEP:196608:CuPKhUhtIWjIFKph8v4drS9vB2xWwIF4Z4GHpKnazW:vPH/IWEFF4Vk+1Q4Z48KazW
                      TLSH:4C863312B83FD6BCF46238B29DB56754C05A2EA2A9B045135B843FCC1776F241B7339A
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 4, 2025 05:27:23.826039076 CET6043053192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:23.830833912 CET53604301.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:23.833614111 CET6043053192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:23.838471889 CET53604301.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:24.307559013 CET6043053192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:24.312619925 CET53604301.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:24.312701941 CET6043053192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:25.310036898 CET5415453192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:25.314866066 CET53541541.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:25.314971924 CET5415453192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:25.323339939 CET53541541.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:25.758922100 CET5415453192.168.2.101.1.1.1
                      Jan 4, 2025 05:27:25.763943911 CET53541541.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:25.764148951 CET5415453192.168.2.101.1.1.1
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 4, 2025 05:27:23.822334051 CET53640671.1.1.1192.168.2.10
                      Jan 4, 2025 05:27:25.308588982 CET53542011.1.1.1192.168.2.10

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:23:27:03
                      Start date:03/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\ws8xbtbe12.msi"
                      Imagebase:0x7ff6a28b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:2
                      Start time:23:27:03
                      Start date:03/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff6a28b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:23:27:06
                      Start date:03/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding BAE0365E84B2EE69D920D2512552695E E Global\MSI0000
                      Imagebase:0x7ff6a28b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly