Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v3.3.5.msi

Overview

General Information

Sample name:setup64v3.3.5.msi
Analysis ID:1584311
MD5:c042c6c8d9a7f8cbe74c88fd5eeb2661
SHA1:252c7859953b1b8bb18820cb3dbc89be485d5dc4
SHA256:3e8e8ea02272c71792cb4493025223bee33d3173a0cea0061b51f39564cd8c42
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 5024 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v3.3.5.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 4920 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6684 cmdline: C:\Windows\System32\MsiExec.exe -Embedding B12BF4E099FBEC35CC549644541AA960 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSID6EA.tmpReversingLabs: Detection: 15%
Source: setup64v3.3.5.msiVirustotal: Detection: 11%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48ceac.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{5B4BCE2C-518E-4215-8842-F8650FD63D61}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID042.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48ceae.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48ceae.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID6EA.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\48ceae.msiJump to behavior
Source: MSID6EA.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: setup64v3.3.5.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v3.3.5.msi
Source: MSID6EA.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSID6EA.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSID6EA.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF6C9A51DD693C5432.TMPJump to behavior
Source: setup64v3.3.5.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v3.3.5.msiVirustotal: Detection: 11%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v3.3.5.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding B12BF4E099FBEC35CC549644541AA960 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding B12BF4E099FBEC35CC549644541AA960 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v3.3.5.msiStatic file information: File size 8458240 > 1048576
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name:
Source: MSID6EA.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSID6EA.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSID6EA.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSID6EA.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID6EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID6EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSID6EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 2128Thread sleep count: 46 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584311 Sample: setup64v3.3.5.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSID6EA.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v3.3.5.msi12%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSID6EA.tmp16%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584311
Start date and time:2025-01-05 07:32:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 31s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:setup64v3.3.5.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
  • Excluded IPs from analysis (whitelisted): 23.56.252.85, 13.107.246.45, 20.109.210.53
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, cdn.onenote.net, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
No context
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):7003374
Entropy (8bit):7.9865143192780526
Encrypted:false
SSDEEP:196608:TB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OH:V6TCe30s0nvfcy67yBHLgfVH
MD5:4271B6051C6BE8685AE9991FFA164B46
SHA1:87785F8F50E55D52595D9654569C00FA9D289E38
SHA-256:DCBEA54AE7053E624267CE562568BAB8CE4C6A16283DEAB1FE9F779DFB93CEA3
SHA-512:2E6AE85A1CA38A299A9EF6F6EAA77D15EB7160E9632D721A154D8D31947B021AAA7B7CE664E882D6BEBE970B6DDFD909EEF4C9C9377E3D0C6DAA59BEE6AF958C
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@$.%Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v3.3.5.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):1420112
Entropy (8bit):7.9998456572268175
Encrypted:true
SSDEEP:24576:58dmj15hop6wiuHDvW7LPV5c8WTm6HGgYw/SLnKIX/Npr/sF/54RbbbuvUdujLzH:5lle/iuHDv4Tc8WTm6HrwvDrkF/W1ucy
MD5:D391AB180D7BDE4CB5170BF64A522D83
SHA1:6F8422CEA8DDD1CB6CE95D2DFF304BE546C58C3E
SHA-256:ADD0DA795DE9ACDD8EB63C4C5373F24958C972CB6700F49035B628B65E8A770B
SHA-512:32F758AD1A3DE31987A890D35C014394628493849FD24BBC304277A60229E1992A9177AAFDD2649744682572AA70F9FEAA608E952153FAD88FDD22F300EEF190
Malicious:false
Reputation:low
Preview:.@S......"..V..............=.]..\Lr...>...of..#r..~.....y.......d.{.....P\.....5.}X.....F...[...IN......D+N.....].`.o.i...;}XC........Z|[KG.nh~.$.%.h.'fIC..JS.mZU.V9.E. ..Q..n..f.K).u.(.-.....:.#..\}..U..\s..m.-2^...../.X..>.....s...H.1...S.&_1y>..D..X.F.#Q.....?...($.Z.'.{=T.;..i..3...R].).4Q...V...H.P... .V..H...w.-..n(O9h ~K..yBq]k..2.$y.ek..)..7crv.:.OY|D....!1....f.V.H......:..G...6....2..#.f.$...0=[}.....4T.P..........5.T...;.\e..^.O..d.|.&.....).u9.,0....N.Y...v..L.Z....^<.....&Z...)a3w. R.d..H.$r..C.b.;.........0LR..G.....X1+~o.+...9X6.%..i.T.h').....B..2.i.+...^.!NiB.k.Z.<..6.......<...h.4`....<....VH...>p..)[..S.o......My.Y......q.........n..7_#.5....+-.b..">.n.....0....k..h....1.)..-.f...Z.K..t...x'j~0.1.....^>..]...;o.....([..5.........Cn...#...........W..F..5.=..*.pU.1i^.@.......J9........m..].u.y.p.t.....Es..xu.>wg`X.w..O...L.;....`A5...K =..w..0...C-...lyt.Y..=...^7.L.1..,x.-.S$.n5..)...6...FXC.....&N...Y"{..A.....$.D...-m..A....a.
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdsrtgrhgk, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):8458240
Entropy (8bit):7.98680462568277
Encrypted:false
SSDEEP:196608:7nUf+6O/9yB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:YBcK6TCe30s0pvfcy67yBHLgfV
MD5:C042C6C8D9A7F8CBE74C88FD5EEB2661
SHA1:252C7859953B1B8BB18820CB3DBC89BE485D5DC4
SHA-256:3E8E8EA02272C71792CB4493025223BEE33D3173A0CEA0061B51F39564CD8C42
SHA-512:5CDFE52DBD8F27E1E0441B55A219CFA012E172136C6FCC15CE55D7EB5102368D0D8A7AC1EEFB8EE09BB7F8150DE1B8FE3A5A4A75153CC54D2AB7A72F5E70CF41
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdsrtgrhgk, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):8458240
Entropy (8bit):7.98680462568277
Encrypted:false
SSDEEP:196608:7nUf+6O/9yB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:YBcK6TCe30s0pvfcy67yBHLgfV
MD5:C042C6C8D9A7F8CBE74C88FD5EEB2661
SHA1:252C7859953B1B8BB18820CB3DBC89BE485D5DC4
SHA-256:3E8E8EA02272C71792CB4493025223BEE33D3173A0CEA0061B51F39564CD8C42
SHA-512:5CDFE52DBD8F27E1E0441B55A219CFA012E172136C6FCC15CE55D7EB5102368D0D8A7AC1EEFB8EE09BB7F8150DE1B8FE3A5A4A75153CC54D2AB7A72F5E70CF41
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):6997678
Entropy (8bit):7.986814874066155
Encrypted:false
SSDEEP:196608:8B6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4ON:E6TCe30s0nvfcy67yBHLgfVN
MD5:3C6745B9DAE278B6DA4C397B08793E29
SHA1:7C4AFABD0A69D7E889DAF3441E166924043CD7EE
SHA-256:05A11EE4087B4BAD76DFF9ECFD89F6FA13DD34E6B3DF0E3EB9A0C14D4EC39695
SHA-512:1EA6B64B53FBC3201A4AEF0124C884A705A6CA27F04882FA6ADB2046ADB43A7647B8CA5D867CCE2BB7D4AA67C0DDBD2B015B9F11A924D81CBBD3A460BCA47D3A
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@$.%Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v3.3.5.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@P....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\48ceac.msi.........@........file.dat..l4d..file.dat.@.....@P....@.......@.............@.........@.....@.....@....@.{.L.@.....@JR-......._....J..._.@A.......j.MZx.....................@..............................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:modified
Size (bytes):6995968
Entropy (8bit):7.9868922155503945
Encrypted:false
SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
MD5:735124825FE57CBDDBC31F3CF1248171
SHA1:41A53E432FAD50A43D195334897C23757AB8433A
SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 16%
Reputation:low
Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.1654615743230785
Encrypted:false
SSDEEP:12:JSbX72Fj/AGiLIlHVRpEh/7777777777777777777777777vDHFFGLwY/l0i8Q:JdQI5UCUxF
MD5:9646E8D4D80E761AFF2B9597585D875B
SHA1:E55321245E1346E8BFF4C25E6E456116D1E1644A
SHA-256:EA2AB23DFEB75307C109DE812D64C88B797DF851CF5F3D92F7633C4DA04BBAC2
SHA-512:BCE0FD9E4DC7E6D20A207449E1A7136EB1469D4C2C827DB4274FA7716BE51684F8634598990C14F6178BDC3636AF67945602B2ABFF8DC4CE9E160C93C4A026C0
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4664247402921813
Encrypted:false
SSDEEP:48:28PhMuRc06WXJIFT58sa4deS55rCdeSIG9:JhM1rFTBadmS
MD5:6A269DEC0FF615D37EEA5917E730ECF1
SHA1:55EC811AD7AC1B8636DA8CFB3BCD138C4F9F408F
SHA-256:1C49295A98DD4634A2DF58A27A865081917ACE73A6D823068FDA0250A2F56C16
SHA-512:D19250A64E915DE3E442B195E60EE262F2D353937F8DB73422C257D19735376B1D7A00D1D4ADCD4359C1CC1B2556C2416A4103088614B9E20881313A6EA535A7
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):360001
Entropy (8bit):5.362975864342232
Encrypted:false
SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauK:zTtbmkExhMJCIpEL
MD5:7EEBFA051689C3376403E10E99797982
SHA1:3960ADDB2E8156D8A34911017F896F077947C289
SHA-256:051B3173796B9AC2C502A655A9EFB456C21C56D7AACBFEC313393FE5F9911FDE
SHA-512:A5EE585526806CA4EF104976D7462CA5469E725BE059BD72722539576F1CD247D828378F9FFD324E7283662763E4F76A068FD9372508F829780580E628F5BB3D
Malicious:false
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1819235540656563
Encrypted:false
SSDEEP:24:JahC3nkuxZiCipKP2xza2tzhAhZfagUMClXtd85CcFO+JD4dB5GipV7VgwGslrk6:/nkunPveFXJNT5msa4deS55rCdeSIG9
MD5:B7374C01132CBFF2FC466E1E22F025E9
SHA1:6E9A1721FF7F90A8ACB5D324E73558F864ED5D1F
SHA-256:54ED90521C29E9EF845067CBE81E0E3A594056067754C22733A97BB345BCBE69
SHA-512:E181A3FF7D25DEC053555423650B8F6ED9DDFA4DDBF2408698CE8414E4192DE44FA1265EB95AA41E2E486205949ED267E514024793B14B688BF5EA7160EF8A5E
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1819235540656563
Encrypted:false
SSDEEP:24:JahC3nkuxZiCipKP2xza2tzhAhZfagUMClXtd85CcFO+JD4dB5GipV7VgwGslrk6:/nkunPveFXJNT5msa4deS55rCdeSIG9
MD5:B7374C01132CBFF2FC466E1E22F025E9
SHA1:6E9A1721FF7F90A8ACB5D324E73558F864ED5D1F
SHA-256:54ED90521C29E9EF845067CBE81E0E3A594056067754C22733A97BB345BCBE69
SHA-512:E181A3FF7D25DEC053555423650B8F6ED9DDFA4DDBF2408698CE8414E4192DE44FA1265EB95AA41E2E486205949ED267E514024793B14B688BF5EA7160EF8A5E
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4664247402921813
Encrypted:false
SSDEEP:48:28PhMuRc06WXJIFT58sa4deS55rCdeSIG9:JhM1rFTBadmS
MD5:6A269DEC0FF615D37EEA5917E730ECF1
SHA1:55EC811AD7AC1B8636DA8CFB3BCD138C4F9F408F
SHA-256:1C49295A98DD4634A2DF58A27A865081917ACE73A6D823068FDA0250A2F56C16
SHA-512:D19250A64E915DE3E442B195E60EE262F2D353937F8DB73422C257D19735376B1D7A00D1D4ADCD4359C1CC1B2556C2416A4103088614B9E20881313A6EA535A7
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4664247402921813
Encrypted:false
SSDEEP:48:28PhMuRc06WXJIFT58sa4deS55rCdeSIG9:JhM1rFTBadmS
MD5:6A269DEC0FF615D37EEA5917E730ECF1
SHA1:55EC811AD7AC1B8636DA8CFB3BCD138C4F9F408F
SHA-256:1C49295A98DD4634A2DF58A27A865081917ACE73A6D823068FDA0250A2F56C16
SHA-512:D19250A64E915DE3E442B195E60EE262F2D353937F8DB73422C257D19735376B1D7A00D1D4ADCD4359C1CC1B2556C2416A4103088614B9E20881313A6EA535A7
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):69632
Entropy (8bit):0.10418446536492161
Encrypted:false
SSDEEP:24:7CVqHXZLdB5GipVGdB5GipV7VgwGslrkglDL+ZFh:mOXldeScdeS55rlvO
MD5:45A5C614A7869F941F4E1A221CAB9234
SHA1:A49A8A2D0BFE1549D4BE36255AB004D54EBA5EA0
SHA-256:A438C5034F9ED6B38CF1A212814A68EC20EE3B56489CE8CA5C139521E8E442C7
SHA-512:1CB461679895746E32CC486514CEFC733E423C46FB036AEC1112F65832592C429FACEBFACA20566CB401918F9B8F30E28B89C38079FE294C3B1115C7C0BADF0A
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07282829581322797
Encrypted:false
SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKO97GLNiPKSVky6lV1:2F0i8n0itFzDHFFGLwY/
MD5:3CF4511A432B70DDA8C4D52025E54285
SHA1:E1FA5D024B135E9BBAA574DEBFE4F8CF9B8D5A71
SHA-256:B9E114CAE3497A836EB99B9B619E6D3AC25A98BB802679FB1A1170C173C707CB
SHA-512:E389C9FB18D743003214C59CAFD3403C26C63B8025C3428AEA06AE76F8B81C32E3E1E6D90E632F6B0CFE23C34A7C993BEC283EB515E3CB8DB8F286A08EAAA66D
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1819235540656563
Encrypted:false
SSDEEP:24:JahC3nkuxZiCipKP2xza2tzhAhZfagUMClXtd85CcFO+JD4dB5GipV7VgwGslrk6:/nkunPveFXJNT5msa4deS55rCdeSIG9
MD5:B7374C01132CBFF2FC466E1E22F025E9
SHA1:6E9A1721FF7F90A8ACB5D324E73558F864ED5D1F
SHA-256:54ED90521C29E9EF845067CBE81E0E3A594056067754C22733A97BB345BCBE69
SHA-512:E181A3FF7D25DEC053555423650B8F6ED9DDFA4DDBF2408698CE8414E4192DE44FA1265EB95AA41E2E486205949ED267E514024793B14B688BF5EA7160EF8A5E
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gdsrtgrhgk, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Entropy (8bit):7.98680462568277
TrID:
  • Microsoft Windows Installer (60509/1) 88.31%
  • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
File name:setup64v3.3.5.msi
File size:8'458'240 bytes
MD5:c042c6c8d9a7f8cbe74c88fd5eeb2661
SHA1:252c7859953b1b8bb18820cb3dbc89be485d5dc4
SHA256:3e8e8ea02272c71792cb4493025223bee33d3173a0cea0061b51f39564cd8c42
SHA512:5cdfe52dbd8f27e1e0441b55a219cfa012e172136c6fcc15ce55d7eb5102368d0d8a7ac1eefb8ee09bb7f8150de1b8fe3a5a4a75153cc54d2ab7a72f5e70cf41
SSDEEP:196608:7nUf+6O/9yB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:YBcK6TCe30s0pvfcy67yBHLgfV
TLSH:48863320B8EF96FAF6366B324D5571A20002AFB012B681469B543F0C057DB74DB7BA7D
File Content Preview:........................>......................................................................................................................................................................................................................................
Icon Hash:2d2e3797b32b2b99
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:01:33:05
Start date:05/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v3.3.5.msi"
Imagebase:0x7ff75c880000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:1
Start time:01:33:06
Start date:05/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\msiexec.exe /V
Imagebase:0x7ff75c880000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:false

Target ID:3
Start time:01:33:08
Start date:05/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\MsiExec.exe -Embedding B12BF4E099FBEC35CC549644541AA960 E Global\MSI0000
Imagebase:0x7ff75c880000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

No disassembly