Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
1iOFUdjjGF.msi

Overview

General Information

Sample name:1iOFUdjjGF.msi
renamed because original name is a hash value
Original sample name:165408c1b490ccc23e0dccbb39083efd2896385a125b7555953163614b20b68e.msi
Analysis ID:1584075
MD5:1c12eef9e9501cfbc02ffc4f726ee941
SHA1:a52a2a71c1d53c6eb69c3b808574ea2a2b5720a8
SHA256:165408c1b490ccc23e0dccbb39083efd2896385a125b7555953163614b20b68e
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 2120 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\1iOFUdjjGF.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 2792 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 3160 cmdline: C:\Windows\System32\MsiExec.exe -Embedding A07606277FD6F3AA400CEA6985F1BB6F E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIF8DA.tmpReversingLabs: Detection: 21%
Source: C:\Windows\Installer\MSIF8DA.tmpVirustotal: Detection: 22%Perma Link
Source: 1iOFUdjjGF.msiVirustotal: Detection: 16%Perma Link
Source: 1iOFUdjjGF.msiReversingLabs: Detection: 18%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55ee89.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{0BABF11D-16F4-4787-BD21-C5AC85913E85}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF157.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55ee8b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55ee8b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8DA.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\55ee8b.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIF8DA.tmp F3D3A87E02222130A7B94A79A4159974FEB26920C1973825FCD4CF1A9FD1F2AA
Source: MSIF8DA.tmp.2.drStatic PE information: Number of sections : 12 > 10
Source: 1iOFUdjjGF.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs 1iOFUdjjGF.msi
Source: MSIF8DA.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0002466528297473
Source: MSIF8DA.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9910824424342105
Source: MSIF8DA.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0002533063139931
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFDC7E2618CB815F5C.TMPJump to behavior
Source: 1iOFUdjjGF.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: 1iOFUdjjGF.msiVirustotal: Detection: 16%
Source: 1iOFUdjjGF.msiReversingLabs: Detection: 18%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\1iOFUdjjGF.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding A07606277FD6F3AA400CEA6985F1BB6F E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding A07606277FD6F3AA400CEA6985F1BB6F E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: 1iOFUdjjGF.msiStatic file information: File size 11075584 > 1048576
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name:
Source: MSIF8DA.tmp.2.drStatic PE information: section name: entropy: 7.99982769013168
Source: MSIF8DA.tmp.2.drStatic PE information: section name: entropy: 7.9833341490111325
Source: MSIF8DA.tmp.2.drStatic PE information: section name: entropy: 7.9998144097828305
Source: MSIF8DA.tmp.2.drStatic PE information: section name: entropy: 6.9689890790259055
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8DA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8DA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIF8DA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 964Thread sleep count: 134 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584075 Sample: 1iOFUdjjGF.msi Startdate: 04/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIF8DA.tmp, PE32+ 6->13 dropped 11 msiexec.exe 1 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
1iOFUdjjGF.msi17%VirustotalBrowse
1iOFUdjjGF.msi18%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIF8DA.tmp22%ReversingLabs
C:\Windows\Installer\MSIF8DA.tmp23%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584075
Start date and time:2025-01-04 05:31:20 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:10
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:1iOFUdjjGF.msi
renamed because original name is a hash value
Original Sample Name:165408c1b490ccc23e0dccbb39083efd2896385a125b7555953163614b20b68e.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 52.149.20.212
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIF8DA.tmpinstaller64v9.2.4.msiGet hashmaliciousUnknownBrowse
    installer64v1.2.7.msiGet hashmaliciousUnknownBrowse
      installer64v5.2.6.msiGet hashmaliciousUnknownBrowse
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):9229544
        Entropy (8bit):7.992378507456016
        Encrypted:true
        SSDEEP:196608:t/SBEbCgfmfwe2lwhUSEVM7EBbekSCza/FT8dMNmwLn6F93we:1xb+IvwhTEHJv2YMNmw7Ne
        MD5:4F492F6C2B0985C03DB7DD3909883A70
        SHA1:3D22056601CD3854D44667DE6A8EDFF714E72C70
        SHA-256:6BECD46467E19EA8B13D40E29EC57993A0AE9B5E9F3BF9C75FCF85D2A330C315
        SHA-512:0DF728FB9F896B839BCF606611F34FAA86AB7365E99E2EA7210243AC010056DD1C531243FCB8A0A7384A4A44C80ACBEA8DA44B6601B56583B45CBA9E3C10F9C9
        Malicious:false
        Reputation:low
        Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{0BABF11D-16F4-4787-BD21-C5AC85913E85}..Setup..1iOFUdjjGF.msi.@.....@.....@.....@........&.{D5339172-BC72-4154-8837-7BE7F8702821}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{0BABF11D-16F4-4787-BD21-C5AC85913E85}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.........MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d......R.........." .........X...........................................................`... ...... ........ ...... ..............`0P....L.P.\.....1.......P.D}..........@0P..............................0P
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):1805840
        Entropy (8bit):7.999896949693291
        Encrypted:true
        SSDEEP:49152:pfWkHcNwGe6deEds/aFd32fIWQBcNW7nEGP1Hr8Ap0x2:w9A6deEGiFd32fHQ7nEwNr8Fx2
        MD5:670813CDBE5FB9ADBDABEE7DC9FC0ED8
        SHA1:76E508CB36458D81B051F255C561E8CC7D07A1EF
        SHA-256:592FC25CD9C28F19DA44B79B49D35708A81F4BD6B5B9819E7636EBBA3F36030E
        SHA-512:B068BA35196C91CAA9F5C6EC7021609B3D2DC49335A6226E01ECDE44207B99BCB6C66E4726F131D7FFC827C0A1D8389428321E9E7451439C7EFEB68E3216236E
        Malicious:false
        Reputation:low
        Preview:.@S...."..)Lq...............^(aeQW.B.l.(...9....O.fsy^....Py^..3.t.E}.|..Ln....iP..E.9b.7JG..p.+....._.....+...^...xNl..7XG.'|.{.\.0'C.@m.(|-...*.3j^...<?..XGN.u..+.W......>...!.^....2T....r3..c.\b....TP.\........#..c....!}.j..)..`..+h?....[..f......B...i.."..v._.[........{lq.(.,..v..G...^.a..]...._:.).Ez..(..............y..d.L..94...|Ct!V."...Om/^.......%H....0.0..Dy....=...e.V..j..9(J$..v#lls(....v.f1dL..l...[.....E...........}.ds.J....60A...q...V.0.x...S*.r..E.<A..f...!.....\..hQ...#36.E.A..O..zk..n.....<...p......%f.kJ...f. ]&....C.u.....3u....HEG.....5...&K*.p.0p.'..*.S....e.#n.E.*.:...Q.a..J.'..<.ZJ..X../.W.[..\.S.......'.F..w?..u....A.'..."u.....pVE.W.8.5.....C..A....Y..#...T..1...1%/....S..;......s..U..+..V~J..V>.IsEk......-L(.'..S].e..EI....$%.@..cN......n.c.vN.g.L...D..AjD..'.M.p1...53.{K..r&w..'N..e....;6W.W..L.#....,|.... .qhbn.Q../..3;[D......]Ca.&T.,ms......N=..UN.\../J.h..E.....5.u..[...h../Mv....X.....,...g8..
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsgjkuloio, Template: Intel;1033, Revision Number: {D5339172-BC72-4154-8837-7BE7F8702821}, Create Time/Date: Fri Jan 3 05:16:56 2025, Last Saved Time/Date: Fri Jan 3 05:16:56 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
        Category:dropped
        Size (bytes):11075584
        Entropy (8bit):7.991261409761509
        Encrypted:true
        SSDEEP:196608:AoNeMwnO4fWQ8XUDz/SBEbCgf4fwe2lwhUSEVM7EBbekSCzK/FT8dMNmwLn6F93w:PhXtqDxbgIvwhTEHJv+YMNmw7N
        MD5:1C12EEF9E9501CFBC02FFC4F726EE941
        SHA1:A52A2A71C1D53C6EB69C3B808574EA2A2B5720A8
        SHA-256:165408C1B490CCC23E0DCCBB39083EFD2896385A125B7555953163614B20B68E
        SHA-512:57F6D62E822DC375E69E5D11361BBEF0F596AA650936A9AC668B7C2B84D2DEC732072F4ACA0C787770A29D51167B1B2F9B1CF9A77839224B953766B6A153F805
        Malicious:false
        Reputation:low
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsgjkuloio, Template: Intel;1033, Revision Number: {D5339172-BC72-4154-8837-7BE7F8702821}, Create Time/Date: Fri Jan 3 05:16:56 2025, Last Saved Time/Date: Fri Jan 3 05:16:56 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
        Category:dropped
        Size (bytes):11075584
        Entropy (8bit):7.991261409761509
        Encrypted:true
        SSDEEP:196608:AoNeMwnO4fWQ8XUDz/SBEbCgf4fwe2lwhUSEVM7EBbekSCzK/FT8dMNmwLn6F93w:PhXtqDxbgIvwhTEHJv+YMNmw7N
        MD5:1C12EEF9E9501CFBC02FFC4F726EE941
        SHA1:A52A2A71C1D53C6EB69C3B808574EA2A2B5720A8
        SHA-256:165408C1B490CCC23E0DCCBB39083EFD2896385A125B7555953163614B20B68E
        SHA-512:57F6D62E822DC375E69E5D11361BBEF0F596AA650936A9AC668B7C2B84D2DEC732072F4ACA0C787770A29D51167B1B2F9B1CF9A77839224B953766B6A153F805
        Malicious:false
        Reputation:low
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):9223851
        Entropy (8bit):7.99257963752527
        Encrypted:true
        SSDEEP:196608:x/SBEbCgfmfwe2lwhUSEVM7EBbekSCza/FT8dMNmwLn6F93wd:xxb+IvwhTEHJv2YMNmw7Nd
        MD5:85E262F96CF4CCBDAC539C011D293C43
        SHA1:6F2878671789BCAE77D03392CC59EAB058C940BD
        SHA-256:56319DF217DB86C25D221293F7121B45902DF2326B7468B6EC5781E30C1F1D55
        SHA-512:CF87D79CADC547A615982D11669B5F00CEF1BF1B5B432F0B2FCC660C04E836BEC067454B449585EF937AD0F7AEED8FC7D94030DAB62F2F2855CF0D3E185BC604
        Malicious:false
        Reputation:low
        Preview:...@IXOS.@.....@..#Z.@.....@.....@.....@.....@.....@......&.{0BABF11D-16F4-4787-BD21-C5AC85913E85}..Setup..1iOFUdjjGF.msi.@.....@.....@.....@........&.{D5339172-BC72-4154-8837-7BE7F8702821}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\55ee89.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@g....@._...@...}.@........._....J..._.@A.........MZx.....................@.................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
        Category:modified
        Size (bytes):9222144
        Entropy (8bit):7.992629920381177
        Encrypted:true
        SSDEEP:196608:5/SBEbCgfmfwe2lwhUSEVM7EBbekSCza/FT8dMNmwLn6F93w:pxb+IvwhTEHJv2YMNmw7N
        MD5:E78A0A61520EF73D709943B2C4154EA8
        SHA1:C9B862E9E0EBA2FFC19434F84BC2F0A97ED04FF3
        SHA-256:F3D3A87E02222130A7B94A79A4159974FEB26920C1973825FCD4CF1A9FD1F2AA
        SHA-512:E72D83B5DE05B0B2EC2AD14ED85E9FD452866FEB66CE095C66063FE092149A8FC9261B9579581E963462397794081AA6260279C0C9308D46E8B2B4DBDB77BB2D
        Malicious:true
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 22%
        • Antivirus: Virustotal, Detection: 23%, Browse
        Joe Sandbox View:
        • Filename: installer64v9.2.4.msi, Detection: malicious, Browse
        • Filename: installer64v1.2.7.msi, Detection: malicious, Browse
        • Filename: installer64v5.2.6.msi, Detection: malicious, Browse
        Reputation:low
        Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d......R.........." .........X...........................................................`... ...... ........ ...... ..............`0P....L.P.\.....1.......P.D}..........@0P..............................0P.(.......................................................................................@............0..........................@............P...........P..............@............@...`1.....................@.................1.....................@.................1.....................@.................1.....................@.................1.....................@.................1.....................@....rsrc.........1.....................@..@..............2...+.................@.............B...P...A...J.............@...........................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):20480
        Entropy (8bit):1.163825667524542
        Encrypted:false
        SSDEEP:12:JSbX72FjWAGiLIlHVRpZh/7777777777777777777777777vDHF4gVMuit/l0i8Q:JQQI5tegKiF
        MD5:CDFBF940F01C34E8E97C5EF3B7554672
        SHA1:CB4D793F5954D422E5B17D5DC86046DC32DC7682
        SHA-256:098B4F5B1104A6BDE7DE56C2F795C29E5B588E483122EF61CFBF65C92F466695
        SHA-512:F14EB0CF8007D5D17DF42543B7D70EF0F21C632932D43DF53EE443D370FFF8E2B822E6F49AE42909F336562937313BF2EC8744D445F5397FD0D83B4868E0B6F7
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):20480
        Entropy (8bit):1.464993144471594
        Encrypted:false
        SSDEEP:48:/8PhMuRc06WXJSnT5pgONdeS5rrCdeSIG:+hM1JnTXc4S
        MD5:6A89B189E59C240C94DDF864B0E4E28A
        SHA1:FD7CCE004895E16263411ACF406F41FD2E365AAA
        SHA-256:36453E4A2FCA537D06BBC6A6B65AC2C69446B8CC43AC75D058085D7E7E355A1A
        SHA-512:587DF0C2B3490C6E8A5BB7C62ADB3B6D550D83FB60AFEDD34237B114667A1DD6DD957EDF750D3A5DA0F177B72660147663F25BE63AC7BFBDF40AC314EEAEE127
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):360001
        Entropy (8bit):5.362993966936762
        Encrypted:false
        SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau0:zTtbmkExhMJCIpEl
        MD5:DD9386A038A60774356BBFCEF8C430DE
        SHA1:6CAFDD59CA4E167FB3382AD24CA9237CF2FD5877
        SHA-256:2856DADAB454A66D8CE9E7C96B81CB4BF729C7A7C153FBAB1071D1A6F602C000
        SHA-512:7E32D51ADD0D5494CF45EF07CCF1DAD1744D20C9A7E47A25785DDE9E7C58094FF822AC225B6FBC3826715454ADDC6FF264434A01A55DD300120E18FC88EFE4DD
        Malicious:false
        Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):20480
        Entropy (8bit):1.464993144471594
        Encrypted:false
        SSDEEP:48:/8PhMuRc06WXJSnT5pgONdeS5rrCdeSIG:+hM1JnTXc4S
        MD5:6A89B189E59C240C94DDF864B0E4E28A
        SHA1:FD7CCE004895E16263411ACF406F41FD2E365AAA
        SHA-256:36453E4A2FCA537D06BBC6A6B65AC2C69446B8CC43AC75D058085D7E7E355A1A
        SHA-512:587DF0C2B3490C6E8A5BB7C62ADB3B6D550D83FB60AFEDD34237B114667A1DD6DD957EDF750D3A5DA0F177B72660147663F25BE63AC7BFBDF40AC314EEAEE127
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):512
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3::
        MD5:BF619EAC0CDF3F68D496EA9344137E8B
        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
        Malicious:false
        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):32768
        Entropy (8bit):0.07098719694436036
        Encrypted:false
        SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOTk1CjE+9Ab/tgVky6lit/:2F0i8n0itFzDHF4gVM/Zit/
        MD5:3525A3D6429882BA8C0D7D63B53BBAF9
        SHA1:01837D553FA2ED9E7D1B04753D91FD541D975ED0
        SHA-256:CC22936B46083AD66B9B19736FE0120D9AB60344FF7FC02ECFA3B2664BD3024F
        SHA-512:B267214D3A55ABDD26E9D221FC3D91265D5622EB529412A9D3CE360ABF50C1966262D52AC5370B83EE4074889C365B54D9D8F29B81FE0331CFB192475A3B8B6B
        Malicious:false
        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):32768
        Entropy (8bit):1.1810864588459673
        Encrypted:false
        SSDEEP:24:JJkLhC3nkuxZiAipKP2xza2tzhAnZdagUMClXtd85s+vONdB5GipV7VgwGWlrkgV:8GnkunNveFXJBT5jgONdeS5rrCdeSIG
        MD5:1893030C6199C2999BA7D39D1E560D59
        SHA1:52E7B556F191645360738ECF78D7A020779C3F61
        SHA-256:A2FDFFA2C5357258DE3872B41B7A7A2D1CF86E08C609DFB37442958F66D5A37C
        SHA-512:BCDEC42C863F31046598922ABA96623A9CAF71AFE7BEA20C1FBAAE4D411A5418387F00051E756E2C55651B1942116D117E6C098BF27606A501E3371555AE5710
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):512
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3::
        MD5:BF619EAC0CDF3F68D496EA9344137E8B
        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
        Malicious:false
        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):32768
        Entropy (8bit):1.1810864588459673
        Encrypted:false
        SSDEEP:24:JJkLhC3nkuxZiAipKP2xza2tzhAnZdagUMClXtd85s+vONdB5GipV7VgwGWlrkgV:8GnkunNveFXJBT5jgONdeS5rrCdeSIG
        MD5:1893030C6199C2999BA7D39D1E560D59
        SHA1:52E7B556F191645360738ECF78D7A020779C3F61
        SHA-256:A2FDFFA2C5357258DE3872B41B7A7A2D1CF86E08C609DFB37442958F66D5A37C
        SHA-512:BCDEC42C863F31046598922ABA96623A9CAF71AFE7BEA20C1FBAAE4D411A5418387F00051E756E2C55651B1942116D117E6C098BF27606A501E3371555AE5710
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):20480
        Entropy (8bit):1.464993144471594
        Encrypted:false
        SSDEEP:48:/8PhMuRc06WXJSnT5pgONdeS5rrCdeSIG:+hM1JnTXc4S
        MD5:6A89B189E59C240C94DDF864B0E4E28A
        SHA1:FD7CCE004895E16263411ACF406F41FD2E365AAA
        SHA-256:36453E4A2FCA537D06BBC6A6B65AC2C69446B8CC43AC75D058085D7E7E355A1A
        SHA-512:587DF0C2B3490C6E8A5BB7C62ADB3B6D550D83FB60AFEDD34237B114667A1DD6DD957EDF750D3A5DA0F177B72660147663F25BE63AC7BFBDF40AC314EEAEE127
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):512
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3::
        MD5:BF619EAC0CDF3F68D496EA9344137E8B
        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
        Malicious:false
        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:Composite Document File V2 Document, Cannot read section info
        Category:dropped
        Size (bytes):32768
        Entropy (8bit):1.1810864588459673
        Encrypted:false
        SSDEEP:24:JJkLhC3nkuxZiAipKP2xza2tzhAnZdagUMClXtd85s+vONdB5GipV7VgwGWlrkgV:8GnkunNveFXJBT5jgONdeS5rrCdeSIG
        MD5:1893030C6199C2999BA7D39D1E560D59
        SHA1:52E7B556F191645360738ECF78D7A020779C3F61
        SHA-256:A2FDFFA2C5357258DE3872B41B7A7A2D1CF86E08C609DFB37442958F66D5A37C
        SHA-512:BCDEC42C863F31046598922ABA96623A9CAF71AFE7BEA20C1FBAAE4D411A5418387F00051E756E2C55651B1942116D117E6C098BF27606A501E3371555AE5710
        Malicious:false
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):512
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3::
        MD5:BF619EAC0CDF3F68D496EA9344137E8B
        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
        Malicious:false
        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):69632
        Entropy (8bit):0.10371185925268571
        Encrypted:false
        SSDEEP:24:DsXZLdB5GipVGdB5GipV7VgwGWlrkgy+vO:oXldeScdeS5rrygO
        MD5:E6ED937305AF53A479F53F9A5E1B2556
        SHA1:5D2AD4B014C1F88FF71F8B09886AAA061C1BAEA1
        SHA-256:C82B18C2CEE7D8AAB1A32BF9D78949FFB6DF45DEA1E8561A4D8D9DDE99CB5650
        SHA-512:6D9DE8C562BFBFE453052D73CDA752B3BFA21A01FCD0465A457AABA6122C0F5F914FFDEDFC588F9BAC4A9F1EB10DB56EECEFE634A8C76F98B7DB7270A6C987DA
        Malicious:false
        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Windows\System32\msiexec.exe
        File Type:data
        Category:dropped
        Size (bytes):512
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:3::
        MD5:BF619EAC0CDF3F68D496EA9344137E8B
        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
        Malicious:false
        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsgjkuloio, Template: Intel;1033, Revision Number: {D5339172-BC72-4154-8837-7BE7F8702821}, Create Time/Date: Fri Jan 3 05:16:56 2025, Last Saved Time/Date: Fri Jan 3 05:16:56 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
        Entropy (8bit):7.991261409761509
        TrID:
        • Microsoft Windows Installer (60509/1) 88.31%
        • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
        File name:1iOFUdjjGF.msi
        File size:11'075'584 bytes
        MD5:1c12eef9e9501cfbc02ffc4f726ee941
        SHA1:a52a2a71c1d53c6eb69c3b808574ea2a2b5720a8
        SHA256:165408c1b490ccc23e0dccbb39083efd2896385a125b7555953163614b20b68e
        SHA512:57f6d62e822dc375e69e5d11361bbef0f596aa650936a9ac668b7c2b84d2dec732072f4aca0c787770a29d51167b1b2f9b1cf9a77839224b953766b6a153f805
        SSDEEP:196608:AoNeMwnO4fWQ8XUDz/SBEbCgf4fwe2lwhUSEVM7EBbekSCzK/FT8dMNmwLn6F93w:PhXtqDxbgIvwhTEHJv+YMNmw7N
        TLSH:A9B63313F13FDA47E8BD23740D316A04DD056D022660486E97297B9E94F67E40BEB2EB
        File Content Preview:........................>......................................................................................................................................................................................................................................
        Icon Hash:2d2e3797b32b2b99
        No network behavior found

        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:1
        Start time:23:32:15
        Start date:03/01/2025
        Path:C:\Windows\System32\msiexec.exe
        Wow64 process (32bit):false
        Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\1iOFUdjjGF.msi"
        Imagebase:0x7ff7c32a0000
        File size:69'632 bytes
        MD5 hash:E5DA170027542E25EDE42FC54C929077
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Target ID:2
        Start time:23:32:16
        Start date:03/01/2025
        Path:C:\Windows\System32\msiexec.exe
        Wow64 process (32bit):false
        Commandline:C:\Windows\system32\msiexec.exe /V
        Imagebase:0x7ff7c32a0000
        File size:69'632 bytes
        MD5 hash:E5DA170027542E25EDE42FC54C929077
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:false

        Target ID:3
        Start time:23:32:19
        Start date:03/01/2025
        Path:C:\Windows\System32\msiexec.exe
        Wow64 process (32bit):false
        Commandline:C:\Windows\System32\MsiExec.exe -Embedding A07606277FD6F3AA400CEA6985F1BB6F E Global\MSI0000
        Imagebase:0x7ff7c32a0000
        File size:69'632 bytes
        MD5 hash:E5DA170027542E25EDE42FC54C929077
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        No disassembly