Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v8.6.7.msi

Overview

General Information

Sample name:setup64v8.6.7.msi
Analysis ID:1584314
MD5:a4b14081d7e9316efa1d7cb1c91deb45
SHA1:dfa7ce86425205ff3d51bd5f0186207fc2639964
SHA256:75c6f5bd6b7963d735b6ff6da2d38230a790dfc125ebffeeddde13d8af7deef1
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 3796 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v8.6.7.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7028 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 5828 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 2F2C76DF9B84CC4B3A29731147788F5E E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI955A.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI955A.tmpVirustotal: Detection: 14%Perma Link
Source: setup64v8.6.7.msiVirustotal: Detection: 11%Perma Link
Source: setup64v8.6.7.msiReversingLabs: Detection: 13%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\428cfc.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{E29365CC-8642-4BC3-AA3E-7B7E8084C00C}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI8EB2.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\428cfe.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\428cfe.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI955A.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\428cfe.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI955A.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI955A.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: setup64v8.6.7.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v8.6.7.msi
Source: MSI955A.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI955A.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI955A.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF4B0E935ED8548C44.TMPJump to behavior
Source: setup64v8.6.7.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v8.6.7.msiVirustotal: Detection: 11%
Source: setup64v8.6.7.msiReversingLabs: Detection: 13%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v8.6.7.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 2F2C76DF9B84CC4B3A29731147788F5E E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 2F2C76DF9B84CC4B3A29731147788F5E E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v8.6.7.msiStatic file information: File size 9265152 > 1048576
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name:
Source: MSI955A.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI955A.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI955A.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI955A.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI955A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI955A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI955A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 348Thread sleep count: 145 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584314 Sample: setup64v8.6.7.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI955A.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v8.6.7.msi12%VirustotalBrowse
setup64v8.6.7.msi13%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI955A.tmp16%ReversingLabs
C:\Windows\Installer\MSI955A.tmp15%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584314
Start date and time:2025-01-05 07:33:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:setup64v8.6.7.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 20.12.23.50, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
TimeTypeDescription
07:34:08Task SchedulerRun new task: {6ED8B89B-4E21-4C2D-BBE3-84EBC542B18B} path: .
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI955A.tmpsetup64v3.2.6.msiGet hashmaliciousUnknownBrowse
    setup64v3.3.5.msiGet hashmaliciousUnknownBrowse
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):7003366
      Entropy (8bit):7.98651431261417
      Encrypted:false
      SSDEEP:196608:zB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OA:16TCe30s0nvfcy67yBHLgfVA
      MD5:07039BF0ED24B8F397DCAA71B826D5AA
      SHA1:977D9D9B8DE85BEFB62DC4CC6E510918B25443E6
      SHA-256:F1E7C0C33EDF36F4BD6E7418F0602003F1B138B51696BC065DFDE59507C8E876
      SHA-512:B62F78F6609BC2B2392FB0A43F7B5156677CFE72E4B65EC41C18165670E826B0C08063AAA56D240147338A894C092825280DFADFF5E62DD737502965D3845040
      Malicious:false
      Reputation:low
      Preview:...@IXOS.@.....@J.%Z.@.....@.....@.....@.....@.....@......&.{E29365CC-8642-4BC3-AA3E-7B7E8084C00C}..Setup..setup64v8.6.7.msi.@.....@.....@.....@........&.{012A50D2-5DD7-4C2C-8EF1-9F17D2BFA02A}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{E29365CC-8642-4BC3-AA3E-7B7E8084C00C}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):2225505
      Entropy (8bit):7.999919647396996
      Encrypted:true
      SSDEEP:49152:Fb5UmHp1uIHwtzWT8wr5dP5l6+amNVycSCizYtNgKRN+GmmAD:Vm0x4Y5V5fOzYtNguYl
      MD5:336FBD8CCD046101CB95B7AC59D93073
      SHA1:F77559C571CE705ED680748105888CB41374205A
      SHA-256:13D90FF624EEBE8D002FFBB48E9A34F1667740C4593CE5C4E0C9F45E040B05B9
      SHA-512:E446AE508530DDB4401C39402A07C74ED3F7BEBC66BB27E5CED86DCCC8A9BDE305C4E082D1D0C4194E036B9B77F6ADCB78E0DCE52705D6AE691FDB6C4CF4377B
      Malicious:false
      Reputation:low
      Preview:.@S..... .{.................5...lXnD5....<.|.....Z..W.1.xN:....!.85...k......U4...0...F..G...7..<..!.T@%..z.&.f.h.Q5E........0..6"\g.>.W....z...R..{//(6..u......:..w.-.......'...3.@.s.....7Um..s.....O...9...i...........f........mf.`....-<.....9B9..o`.&7<.W{..Jg.......f`HoE.[8O...9i..X$.......G..S.A..Nb.v..e...UH.h..!...!>.8oU.....yVO..B]x[F..|.?^.....Gj.0D.i...(J...>9.RT@...;...#.&.y..K.v6.....L.d...-6...s........J.o.yd*..u..0a.e..1....^....|.n_....V.......p...G.s.#.<...U.'...hX...M...3(..e.6BN.. 2@.hPw8kM.K6......-i........FS..mY..E..[4............p:....W..y..^9.......{...@..?f^.s.<{c..........,.M.0..6u...5...f.w...a?.e.j.`.........U.D.b.h....%._h.k....[a.2....d..9%......1./.YW.U.~.h.u]...a.An......~........*Hm.V.Pb..QId,....`.S.a......0.^]......Wy......e..1.B...=N...#.6.:n.ffK.....h.......DN....=.s7...d....~.M.~..7r........T.P...m.@.]z...'..1.].......-....Z..M..r...p..:miQ_....g...>.Mu....Zv.}g.Z4`).l..u...k[.Rs[V8..~..n..ad|.. .
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsrtgfgh, Template: Intel;1033, Revision Number: {012A50D2-5DD7-4C2C-8EF1-9F17D2BFA02A}, Create Time/Date: Sat Jan 4 04:40:16 2025, Last Saved Time/Date: Sat Jan 4 04:40:16 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Category:dropped
      Size (bytes):9265152
      Entropy (8bit):7.988508953204642
      Encrypted:false
      SSDEEP:196608:fyMOQrxB6TCe30sGTDnHPfctFaEfVr7yBh1LRTK84O:fyMxz6TCe30sGnvfcy67yBHLg8V
      MD5:A4B14081D7E9316EFA1D7CB1C91DEB45
      SHA1:DFA7CE86425205FF3D51BD5F0186207FC2639964
      SHA-256:75C6F5BD6B7963D735B6FF6DA2D38230A790DFC125EBFFEEDDDE13D8AF7DEEF1
      SHA-512:0E8B13953B8FE5A3BEB2E9C92A69577C3210FD1B7D9AF12DD49E72F3B01FABEE31936D9DA521C732575008E62F2543BC42B22980CDBA341C156DCCEE89333B1E
      Malicious:false
      Reputation:low
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsrtgfgh, Template: Intel;1033, Revision Number: {012A50D2-5DD7-4C2C-8EF1-9F17D2BFA02A}, Create Time/Date: Sat Jan 4 04:40:16 2025, Last Saved Time/Date: Sat Jan 4 04:40:16 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Category:dropped
      Size (bytes):9265152
      Entropy (8bit):7.988508953204642
      Encrypted:false
      SSDEEP:196608:fyMOQrxB6TCe30sGTDnHPfctFaEfVr7yBh1LRTK84O:fyMxz6TCe30sGnvfcy67yBHLg8V
      MD5:A4B14081D7E9316EFA1D7CB1C91DEB45
      SHA1:DFA7CE86425205FF3D51BD5F0186207FC2639964
      SHA-256:75C6F5BD6B7963D735B6FF6DA2D38230A790DFC125EBFFEEDDDE13D8AF7DEEF1
      SHA-512:0E8B13953B8FE5A3BEB2E9C92A69577C3210FD1B7D9AF12DD49E72F3B01FABEE31936D9DA521C732575008E62F2543BC42B22980CDBA341C156DCCEE89333B1E
      Malicious:false
      Reputation:low
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):6997672
      Entropy (8bit):7.98681530666607
      Encrypted:false
      SSDEEP:196608:WB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OD:26TCe30s0nvfcy67yBHLgfVD
      MD5:18C3FAF5B1C92612419FA7058BF19EC1
      SHA1:381E7C0D004F3B097AAF85C7FDEC97A5CEBEB2E3
      SHA-256:418D0A7B6F9163308822481FB4B6DA237FF64B2F2E41811FF486BA98CF609741
      SHA-512:94D9776BA391DAE09365B66011BAC78D9CA8987262D2C3288E5726C0F84676CE3D60E8112FEC11EB2561BEBF98E1802779198376B1A791DBF893F1C89BA1A89A
      Malicious:false
      Reputation:low
      Preview:...@IXOS.@.....@I.%Z.@.....@.....@.....@.....@.....@......&.{E29365CC-8642-4BC3-AA3E-7B7E8084C00C}..Setup..setup64v8.6.7.msi.@.....@.....@.....@........&.{012A50D2-5DD7-4C2C-8EF1-9F17D2BFA02A}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@a.!..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\428cfc.msi.........@........file.dat..l4d..file.dat.@.....@a.!..@.......@.............@.........@.....@.....@3o...@..a..@....@Y.0s......_....J..._.@A.......j.MZx.....................@..............................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:modified
      Size (bytes):6995968
      Entropy (8bit):7.9868922155503945
      Encrypted:false
      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
      MD5:735124825FE57CBDDBC31F3CF1248171
      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
      Malicious:true
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 16%
      • Antivirus: Virustotal, Detection: 15%, Browse
      Joe Sandbox View:
      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
      • Filename: setup64v3.3.5.msi, Detection: malicious, Browse
      Reputation:low
      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.1654340973116355
      Encrypted:false
      SSDEEP:12:JSbX72Fj2AGiLIlHVRpEh/7777777777777777777777777vDHFHTeOW/l0i8Q:J8QI5URqKF
      MD5:F02B15128EAF77D6BDB7139288DC50D8
      SHA1:25A903DB67DBD817CDB3D8819377B7968F1B4899
      SHA-256:4777B9CD2D4F7337B436E3D0ED6A89E72EAE40E0E5ADC56369E65DE81CE689DB
      SHA-512:98C507F25B152236F6310B253C1500175B0EB3FB2A1A61E01CFFB30E610E11E6F43FE43C1AFD056C3103A9832350E77AA4A52AD3B480FA88C377B6607F2A365D
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4648356177492596
      Encrypted:false
      SSDEEP:48:V8PhAuRc06WXJMFT5gBq1hUdeS5SrideSI7:4hA1vFTt1/9P
      MD5:6BB93FC53D1D7CBFC25333DEEB2670A3
      SHA1:C2FAB8835E4B639F0B3606497D107E12A9EFA21B
      SHA-256:6A12B86D84C37F65E39A61E6F2BD530DD27221BE9193A4B56902E72F55F1E443
      SHA-512:C14C14F5E7F1482A43EA78DBC00F7122670644182B2216D4B5441E9FD6053C0D7876F7F409DBA2B0089BBA4F253FD79FC580D2404D650D2786907D03E909A53D
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):360001
      Entropy (8bit):5.362967004886781
      Encrypted:false
      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauH:zTtbmkExhMJCIpEy
      MD5:6C67C1502B2F9CF839F09132151285B2
      SHA1:3559E080C374BD8D1C51C6F0FFDE46E4F54C4494
      SHA-256:9896F1E0116D2E809D75EBD477D029D5D9A071206A03275D0B6A316FE34F663B
      SHA-512:5453FBEAFCB2E6E2435E20758822EFD9EA248C88DF837A51CF0E4F85AD33EC77F2234CD1828EF2949B4294A747F6383AE8061C462FAE3D1DE3FCA59214721A01
      Malicious:false
      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1806497532372293
      Encrypted:false
      SSDEEP:48:Y5noujPveFXJBT5KBq1hUdeS5SrideSI7:YVoZZTv1/9P
      MD5:B4D7F4D5A76602E200F7F0A608E698AA
      SHA1:26EA11BD2242899E96A1039660D5272BD92E4D8E
      SHA-256:30575931EC61842E1DAAC7B42C4DEA2AB63057823C793DAB2C886217CBC60083
      SHA-512:DEF461FB1CFBEBA621C5A6DF97E0D74737B2981D59D334B921B8C54785A39C169E50EC2BDD3E17CCFD27531C53BA81DA10F95E8E2E3EF2509CDA0BE76C8AD0E6
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1806497532372293
      Encrypted:false
      SSDEEP:48:Y5noujPveFXJBT5KBq1hUdeS5SrideSI7:YVoZZTv1/9P
      MD5:B4D7F4D5A76602E200F7F0A608E698AA
      SHA1:26EA11BD2242899E96A1039660D5272BD92E4D8E
      SHA-256:30575931EC61842E1DAAC7B42C4DEA2AB63057823C793DAB2C886217CBC60083
      SHA-512:DEF461FB1CFBEBA621C5A6DF97E0D74737B2981D59D334B921B8C54785A39C169E50EC2BDD3E17CCFD27531C53BA81DA10F95E8E2E3EF2509CDA0BE76C8AD0E6
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):69632
      Entropy (8bit):0.10334906498835378
      Encrypted:false
      SSDEEP:24:g0JyCZLdB5GipVGdB5GipV7VPwGslrkg23fL+MCHeNe:oCldeScdeS5Sr2jbqe
      MD5:5FBFF843919F47080EB762D3523FEBD7
      SHA1:C8243AFC83D8FE9EEA4AA893D0F4AC4038641BA2
      SHA-256:772A29A5AA5C932E0D079B643E6ECEB2F33CF966CABAA93A51420CF0E0D3AEAB
      SHA-512:BE9829F9A6A6DD3724612889A8536DBC0F068DBC58D743010DF729E657AECC452075313726E630A0B7ADC325ADCF405B1E557DF01E47871C55891519B329C353
      Malicious:false
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4648356177492596
      Encrypted:false
      SSDEEP:48:V8PhAuRc06WXJMFT5gBq1hUdeS5SrideSI7:4hA1vFTt1/9P
      MD5:6BB93FC53D1D7CBFC25333DEEB2670A3
      SHA1:C2FAB8835E4B639F0B3606497D107E12A9EFA21B
      SHA-256:6A12B86D84C37F65E39A61E6F2BD530DD27221BE9193A4B56902E72F55F1E443
      SHA-512:C14C14F5E7F1482A43EA78DBC00F7122670644182B2216D4B5441E9FD6053C0D7876F7F409DBA2B0089BBA4F253FD79FC580D2404D650D2786907D03E909A53D
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):0.07270494852380029
      Encrypted:false
      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOwqY6TnOpOkSVky6lV1:2F0i8n0itFzDHFHTeOW/
      MD5:AC628A4456E9E997838DA3C73D4F3DCD
      SHA1:AC4BAD5AEB3FE11E6F1AC192221D353259CB7882
      SHA-256:1A6EE2C552C16EE6916D8F94792B1BC9147DCDD5DEF7D53B908956F529D310E7
      SHA-512:ADE72C801BA91D84249802001A1AE4F50256A95A562F43F397CCA65F75E2461B280048EE10F5C786C5C8DFDF939C268C591BD023A1C18ABD7542BA604E4225DF
      Malicious:false
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1806497532372293
      Encrypted:false
      SSDEEP:48:Y5noujPveFXJBT5KBq1hUdeS5SrideSI7:YVoZZTv1/9P
      MD5:B4D7F4D5A76602E200F7F0A608E698AA
      SHA1:26EA11BD2242899E96A1039660D5272BD92E4D8E
      SHA-256:30575931EC61842E1DAAC7B42C4DEA2AB63057823C793DAB2C886217CBC60083
      SHA-512:DEF461FB1CFBEBA621C5A6DF97E0D74737B2981D59D334B921B8C54785A39C169E50EC2BDD3E17CCFD27531C53BA81DA10F95E8E2E3EF2509CDA0BE76C8AD0E6
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4648356177492596
      Encrypted:false
      SSDEEP:48:V8PhAuRc06WXJMFT5gBq1hUdeS5SrideSI7:4hA1vFTt1/9P
      MD5:6BB93FC53D1D7CBFC25333DEEB2670A3
      SHA1:C2FAB8835E4B639F0B3606497D107E12A9EFA21B
      SHA-256:6A12B86D84C37F65E39A61E6F2BD530DD27221BE9193A4B56902E72F55F1E443
      SHA-512:C14C14F5E7F1482A43EA78DBC00F7122670644182B2216D4B5441E9FD6053C0D7876F7F409DBA2B0089BBA4F253FD79FC580D2404D650D2786907D03E909A53D
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fdsrtgfgh, Template: Intel;1033, Revision Number: {012A50D2-5DD7-4C2C-8EF1-9F17D2BFA02A}, Create Time/Date: Sat Jan 4 04:40:16 2025, Last Saved Time/Date: Sat Jan 4 04:40:16 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Entropy (8bit):7.988508953204642
      TrID:
      • Microsoft Windows Installer (60509/1) 88.31%
      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
      File name:setup64v8.6.7.msi
      File size:9'265'152 bytes
      MD5:a4b14081d7e9316efa1d7cb1c91deb45
      SHA1:dfa7ce86425205ff3d51bd5f0186207fc2639964
      SHA256:75c6f5bd6b7963d735b6ff6da2d38230a790dfc125ebffeeddde13d8af7deef1
      SHA512:0e8b13953b8fe5a3beb2e9c92a69577c3210fd1b7d9af12dd49e72f3b01fabee31936d9da521c732575008e62f2543bc42b22980cdba341c156dccee89333b1e
      SSDEEP:196608:fyMOQrxB6TCe30sGTDnHPfctFaEfVr7yBh1LRTK84O:fyMxz6TCe30sGnvfcy67yBHLg8V
      TLSH:6E963321B4EF93FBEA6166335E5570A60002AFB067A7800A5B053F0D107DB74D7BBA6D
      File Content Preview:........................>......................................................................................................................................................................................................................................
      Icon Hash:2d2e3797b32b2b99
      No network behavior found

      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:34:17
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v8.6.7.msi"
      Imagebase:0x7ff74d3d0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:true

      Target ID:2
      Start time:01:34:17
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\system32\msiexec.exe /V
      Imagebase:0x7ff74d3d0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:3
      Start time:01:34:19
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 2F2C76DF9B84CC4B3A29731147788F5E E Global\MSI0000
      Imagebase:0x7ff74d3d0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:true

      No disassembly