Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v6.6.5.msi

Overview

General Information

Sample name:setup64v6.6.5.msi
Analysis ID:1584316
MD5:8d210eedc78bdf6c9b0e81c2cc7ccf2f
SHA1:deed7ccc84a5a031ac93dfae51acee4e86ec5abd
SHA256:e13c283cda823b13798dd56fa2bd32592b7211c3dde2a1c97756e4f1caefa854
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7900 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.6.5.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7972 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 8080 cmdline: C:\Windows\System32\MsiExec.exe -Embedding DDCA04AC64328E9DAE16DFA6AE607776 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI3C7D.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI3C7D.tmpVirustotal: Detection: 14%Perma Link
Source: setup64v6.6.5.msiVirustotal: Detection: 11%Perma Link
Source: setup64v6.6.5.msiReversingLabs: Detection: 13%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5c3299.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{5B4BCE2C-518E-4215-8842-F8650FD63D61}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI345E.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5c329b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5c329b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3C7D.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\5c329b.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI3C7D.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI3C7D.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: setup64v6.6.5.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v6.6.5.msi
Source: MSI3C7D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI3C7D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI3C7D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFD2B8800A0E9215E0.TMPJump to behavior
Source: setup64v6.6.5.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v6.6.5.msiVirustotal: Detection: 11%
Source: setup64v6.6.5.msiReversingLabs: Detection: 13%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.6.5.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding DDCA04AC64328E9DAE16DFA6AE607776 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding DDCA04AC64328E9DAE16DFA6AE607776 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v6.6.5.msiStatic file information: File size 8458240 > 1048576
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name:
Source: MSI3C7D.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI3C7D.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI3C7D.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI3C7D.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3C7D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3C7D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI3C7D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 8116Thread sleep count: 502 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584316 Sample: setup64v6.6.5.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI3C7D.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v6.6.5.msi12%VirustotalBrowse
setup64v6.6.5.msi13%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI3C7D.tmp16%ReversingLabs
C:\Windows\Installer\MSI3C7D.tmp15%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584316
Start date and time:2025-01-05 07:33:17 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:setup64v6.6.5.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.12.23.50
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI3C7D.tmpsetup64v3.2.6.msiGet hashmaliciousUnknownBrowse
    setup64v3.3.5.msiGet hashmaliciousUnknownBrowse
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):7003358
      Entropy (8bit):7.986514441449528
      Encrypted:false
      SSDEEP:196608:wB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Od:Q6TCe30s0nvfcy67yBHLgfVd
      MD5:C82330E68796B3D4C404ADB56CDE6DD9
      SHA1:C039038C185B1DE97D5E136B2C22C7EC38032D99
      SHA-256:295F38B2BC65B0D01F6C31BD8759FD9D40FB42A386C5174BE5273690F5B21968
      SHA-512:F419519A38D724267F680BECC3F2D9ADA31AEF494DD1365F3A8DDEC7962FA8B6AE89CC81C870D557F20C95F210CBBF056666E4B81FFB06088993FFE26F02AE09
      Malicious:false
      Reputation:low
      Preview:...@IXOS.@.....@I.%Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v6.6.5.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):1420112
      Entropy (8bit):7.9998456572268175
      Encrypted:true
      SSDEEP:24576:58dmj15hop6wiuHDvW7LPV5c8WTm6HGgYw/SLnKIX/Npr/sF/54RbbbuvUdujLzH:5lle/iuHDv4Tc8WTm6HrwvDrkF/W1ucy
      MD5:D391AB180D7BDE4CB5170BF64A522D83
      SHA1:6F8422CEA8DDD1CB6CE95D2DFF304BE546C58C3E
      SHA-256:ADD0DA795DE9ACDD8EB63C4C5373F24958C972CB6700F49035B628B65E8A770B
      SHA-512:32F758AD1A3DE31987A890D35C014394628493849FD24BBC304277A60229E1992A9177AAFDD2649744682572AA70F9FEAA608E952153FAD88FDD22F300EEF190
      Malicious:false
      Reputation:low
      Preview:.@S......"..V..............=.]..\Lr...>...of..#r..~.....y.......d.{.....P\.....5.}X.....F...[...IN......D+N.....].`.o.i...;}XC........Z|[KG.nh~.$.%.h.'fIC..JS.mZU.V9.E. ..Q..n..f.K).u.(.-.....:.#..\}..U..\s..m.-2^...../.X..>.....s...H.1...S.&_1y>..D..X.F.#Q.....?...($.Z.'.{=T.;..i..3...R].).4Q...V...H.P... .V..H...w.-..n(O9h ~K..yBq]k..2.$y.ek..)..7crv.:.OY|D....!1....f.V.H......:..G...6....2..#.f.$...0=[}.....4T.P..........5.T...;.\e..^.O..d.|.&.....).u9.,0....N.Y...v..L.Z....^<.....&Z...)a3w. R.d..H.$r..C.b.;.........0LR..G.....X1+~o.+...9X6.%..i.T.h').....B..2.i.+...^.!NiB.k.Z.<..6.......<...h.4`....<....VH...>p..)[..S.o......My.Y......q.........n..7_#.5....+-.b..">.n.....0....k..h....1.)..-.f...Z.K..t...x'j~0.1.....^>..]...;o.....([..5.........Cn...#...........W..F..5.=..*.pU.1i^.@.......J9........m..].u.y.p.t.....Es..xu.>wg`X.w..O...L.;....`A5...K =..w..0...C-...lyt.Y..=...^7.L.1..,x.-.S$.n5..)...6...FXC.....&N...Y"{..A.....$.D...-m..A....a.
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdgrthkj, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Category:dropped
      Size (bytes):8458240
      Entropy (8bit):7.9868043825793675
      Encrypted:false
      SSDEEP:196608:RnUf+6O/9HB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:GBch6TCe30s0pvfcy67yBHLgfV
      MD5:8D210EEDC78BDF6C9B0E81C2CC7CCF2F
      SHA1:DEED7CCC84A5A031AC93DFAE51ACEE4E86EC5ABD
      SHA-256:E13C283CDA823B13798DD56FA2BD32592B7211C3DDE2A1C97756E4F1CAEFA854
      SHA-512:66510E3F11BEAD0D1F2AF329C4208A860E8048596A88E00F06F76929557CC674C1EEC7002603F4D8C445E232367B992791210037D8B1FF56C8EBE863CA647006
      Malicious:false
      Reputation:low
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdgrthkj, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Category:dropped
      Size (bytes):8458240
      Entropy (8bit):7.9868043825793675
      Encrypted:false
      SSDEEP:196608:RnUf+6O/9HB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:GBch6TCe30s0pvfcy67yBHLgfV
      MD5:8D210EEDC78BDF6C9B0E81C2CC7CCF2F
      SHA1:DEED7CCC84A5A031AC93DFAE51ACEE4E86EC5ABD
      SHA-256:E13C283CDA823B13798DD56FA2BD32592B7211C3DDE2A1C97756E4F1CAEFA854
      SHA-512:66510E3F11BEAD0D1F2AF329C4208A860E8048596A88E00F06F76929557CC674C1EEC7002603F4D8C445E232367B992791210037D8B1FF56C8EBE863CA647006
      Malicious:false
      Reputation:low
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):6997666
      Entropy (8bit):7.9868148938809975
      Encrypted:false
      SSDEEP:196608:yB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Oy:K6TCe30s0nvfcy67yBHLgfVy
      MD5:863657CC99566507121AA26837AC4E2D
      SHA1:BB943013FFD7C19F33B19EBB1E58FBF1BCB32B9F
      SHA-256:B84EA9839A0067282FF239F9AF15842D9AEC18EBED2CBE43E3126B8D1113E7B1
      SHA-512:DF125F923718B8B2D2BE50112241D70ABFAF436E2D43B5BB26123BAB55F91DFA9F677EBAABFDB3E9273950DD1290284D960A0ABB8B39C39350D4F98E3EB1994D
      Malicious:false
      Reputation:low
      Preview:...@IXOS.@.....@I.%Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v6.6.5.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@P....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\5c3299.msi.........@........file.dat..l4d..file.dat.@.....@P....@.......@.............@.........@.....@.....@....@.{.L.@.....@JR-......._....J..._.@A.......j.MZx.....................@..............................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):6995968
      Entropy (8bit):7.9868922155503945
      Encrypted:false
      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
      MD5:735124825FE57CBDDBC31F3CF1248171
      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
      Malicious:true
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 16%
      • Antivirus: Virustotal, Detection: 15%, Browse
      Joe Sandbox View:
      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
      • Filename: setup64v3.3.5.msi, Detection: malicious, Browse
      Reputation:low
      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.164970468053011
      Encrypted:false
      SSDEEP:12:JSbX72Fj3SAGiLIlHVRpEh/7777777777777777777777777vDHFJN/nj2/l0i8Q:JhSQI5U31F
      MD5:A322C41DE0F232D8A44B9045E78D265D
      SHA1:8D452B06E8DF705793B31058260664CF9EBE1002
      SHA-256:927D25213B79011033088FF7FF3FED3F842D7B048B8DA1558DF6ED329869279D
      SHA-512:61C0FCA5E62A48E93EFDADA05AE484B450DD08D074CB50B26C01F9333DCF52A43766655E3D5FA8D14EC7FBEBBF472736E9A855656C5F243D8413AC8645BB3071
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4624977516380178
      Encrypted:false
      SSDEEP:48:d8PhkuRc06WXJwFT5Ts+11rdeS5xrCdeSIb9:Ahk1zFTm+1K+v
      MD5:ACF5E61EAB31156AE8A1106607C4E2B5
      SHA1:A812064BE86465921EC49ABF35D2EB208A7E7755
      SHA-256:73D3B0FEB84FEFCE4C28F16152B98604E3CE679DA64417F86003508664BAC83A
      SHA-512:731F451AFF071F32A0C3E0AF92F43A1805F0917F09EFF1CDF3C5588EC8B31B46AF12D1D8716A374ABFC7DDAB98DA803DF138913BF6ABE1FAB7F0D741F525D6DD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):363829
      Entropy (8bit):5.365410680269051
      Encrypted:false
      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauA:zTtbmkExhMJCIpEx
      MD5:A975D7ACF9DFA1A4B10FCA4E4BDBBD6A
      SHA1:A38EEF2578735263B3BD986375ECFDF313BEAB78
      SHA-256:4927BC13CD4D56305491DBECE4A84F73B6B2C0F452CF9FE3098162B62D87CF82
      SHA-512:6E6B109ED87C559F4947F139625DDF6FE62656332A129179EDC97039CCB9C5FBDE5F6173EF624D34E59994023574D493955875989A9342C0BD7595D4E2A5FAE3
      Malicious:false
      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:modified
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):0.07283134346551404
      Encrypted:false
      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOJWc2UnjESVky6lV1:2F0i8n0itFzDHFJN/nj2/
      MD5:70CE564F0096D26779CD25C88615CBFE
      SHA1:461E3BEE92775CCE8849E41D2510999E1FD99619
      SHA-256:798346AEF758A57C94FF92E9164D2D80E18110286F930F45668D3DB33C9A5A49
      SHA-512:E580B71FA6B5C2A62C11D3F965ECFDF47623B39CFC37E9FE23BBC315E9F454581E69A0965DB51E949C8AFD9C7C0506B62D8F39B8B4330069C1386D58880B62C3
      Malicious:false
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1789989372287697
      Encrypted:false
      SSDEEP:48:QnMufPveFXJ1T55s+11rdeS5xrCdeSIb9:+MVdTU+1K+v
      MD5:F30324189958271BB2A355B94909DB7C
      SHA1:1667C3D156F8FBC9FE42BA09039A2E2AFCDD314E
      SHA-256:C43AB16B5E0F1630C507899BDC609C11791982660A0FC316912370EA089E3886
      SHA-512:046AC59EB08451A4E666486709C1F92FF9C06A4CEA1A604C9FA11E8EB0F9F101AC20F13AB61AE9969EFB81B68EBC12CE4F08ED335E30FD8594F1AD80ED62D7BD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1789989372287697
      Encrypted:false
      SSDEEP:48:QnMufPveFXJ1T55s+11rdeS5xrCdeSIb9:+MVdTU+1K+v
      MD5:F30324189958271BB2A355B94909DB7C
      SHA1:1667C3D156F8FBC9FE42BA09039A2E2AFCDD314E
      SHA-256:C43AB16B5E0F1630C507899BDC609C11791982660A0FC316912370EA089E3886
      SHA-512:046AC59EB08451A4E666486709C1F92FF9C06A4CEA1A604C9FA11E8EB0F9F101AC20F13AB61AE9969EFB81B68EBC12CE4F08ED335E30FD8594F1AD80ED62D7BD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4624977516380178
      Encrypted:false
      SSDEEP:48:d8PhkuRc06WXJwFT5Ts+11rdeS5xrCdeSIb9:Ahk1zFTm+1K+v
      MD5:ACF5E61EAB31156AE8A1106607C4E2B5
      SHA1:A812064BE86465921EC49ABF35D2EB208A7E7755
      SHA-256:73D3B0FEB84FEFCE4C28F16152B98604E3CE679DA64417F86003508664BAC83A
      SHA-512:731F451AFF071F32A0C3E0AF92F43A1805F0917F09EFF1CDF3C5588EC8B31B46AF12D1D8716A374ABFC7DDAB98DA803DF138913BF6ABE1FAB7F0D741F525D6DD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.4624977516380178
      Encrypted:false
      SSDEEP:48:d8PhkuRc06WXJwFT5Ts+11rdeS5xrCdeSIb9:Ahk1zFTm+1K+v
      MD5:ACF5E61EAB31156AE8A1106607C4E2B5
      SHA1:A812064BE86465921EC49ABF35D2EB208A7E7755
      SHA-256:73D3B0FEB84FEFCE4C28F16152B98604E3CE679DA64417F86003508664BAC83A
      SHA-512:731F451AFF071F32A0C3E0AF92F43A1805F0917F09EFF1CDF3C5588EC8B31B46AF12D1D8716A374ABFC7DDAB98DA803DF138913BF6ABE1FAB7F0D741F525D6DD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):69632
      Entropy (8bit):0.1022167690954094
      Encrypted:false
      SSDEEP:24:7CVqHCZLdB5GipVGdB5GipV7VPwGJlrkgWoL+p1PZ:mOCldeScdeS5xrWk+1P
      MD5:997BD591CB0F6B0B9EF6E454957DD10E
      SHA1:34ACBCB3CB0E8E7646CCCD1F21DAD79D4F96FF8C
      SHA-256:4FD5C6DD501A2C7D6E7DDBA0CA02A16B585C63E53D83B9ED05D27AAA78835E71
      SHA-512:6224F3512B1177646D7E7311613C31C2D75F1E565741F8B095BEA85D52CF62CEFD8BDFA9E93DA8A6469F90037CB128BFDE39EA0591AAFD98454B0B127018337F
      Malicious:false
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:3::
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.1789989372287697
      Encrypted:false
      SSDEEP:48:QnMufPveFXJ1T55s+11rdeS5xrCdeSIb9:+MVdTU+1K+v
      MD5:F30324189958271BB2A355B94909DB7C
      SHA1:1667C3D156F8FBC9FE42BA09039A2E2AFCDD314E
      SHA-256:C43AB16B5E0F1630C507899BDC609C11791982660A0FC316912370EA089E3886
      SHA-512:046AC59EB08451A4E666486709C1F92FF9C06A4CEA1A604C9FA11E8EB0F9F101AC20F13AB61AE9969EFB81B68EBC12CE4F08ED335E30FD8594F1AD80ED62D7BD
      Malicious:false
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdgrthkj, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
      Entropy (8bit):7.9868043825793675
      TrID:
      • Microsoft Windows Installer (60509/1) 88.31%
      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
      File name:setup64v6.6.5.msi
      File size:8'458'240 bytes
      MD5:8d210eedc78bdf6c9b0e81c2cc7ccf2f
      SHA1:deed7ccc84a5a031ac93dfae51acee4e86ec5abd
      SHA256:e13c283cda823b13798dd56fa2bd32592b7211c3dde2a1c97756e4f1caefa854
      SHA512:66510e3f11bead0d1f2af329c4208a860e8048596a88e00f06f76929557cc674c1eec7002603f4d8c445e232367b992791210037d8b1ff56c8ebe863ca647006
      SSDEEP:196608:RnUf+6O/9HB6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:GBch6TCe30s0pvfcy67yBHLgfV
      TLSH:53863320B8EF96FAF6366B324D5571A20002AFB012B681469B543F0C057DB74DB7BA7D
      File Content Preview:........................>......................................................................................................................................................................................................................................
      Icon Hash:2d2e3797b32b2b99
      No network behavior found

      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:01:34:16
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.6.5.msi"
      Imagebase:0x7ff7380a0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:true

      Target ID:2
      Start time:01:34:16
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\system32\msiexec.exe /V
      Imagebase:0x7ff7380a0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:3
      Start time:01:34:19
      Start date:05/01/2025
      Path:C:\Windows\System32\msiexec.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\System32\MsiExec.exe -Embedding DDCA04AC64328E9DAE16DFA6AE607776 E Global\MSI0000
      Imagebase:0x7ff7380a0000
      File size:69'632 bytes
      MD5 hash:E5DA170027542E25EDE42FC54C929077
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:true

      No disassembly