Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
T1#U5b89#U88c5#U53051.0.2.msi

Overview

General Information

Sample name:T1#U5b89#U88c5#U53051.0.2.msi
renamed because original name is a hash value
Original sample name:T11.0.2.msi
Analysis ID:1584372
MD5:bb059f89003f1b95374a3daebaa3cdb4
SHA1:b23fb0042b1000f9f863d0020266628c4d5ecb99
SHA256:f57f2c92987487b7110a4e8017211c94a8c66ca2baa62ae5e1216da73665f884
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7468 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.2.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7508 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7656 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 48011E1AF29F427D04837E0D08253AC4 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI80EA.tmpVirustotal: Detection: 23%Perma Link
Source: C:\Windows\Installer\MSI80EA.tmpReversingLabs: Detection: 13%
Source: T1#U5b89#U88c5#U53051.0.2.msiVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b7782.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{0AE851F3-5F2D-40D4-B1FE-12F2F4C1E1B9}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI7947.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b7784.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b7784.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI80EA.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\3b7784.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI80EA.tmp FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
Source: MSI80EA.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: T1#U5b89#U88c5#U53051.0.2.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs T1#U5b89#U88c5#U53051.0.2.msi
Source: MSI80EA.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999472595728198
Source: MSI80EA.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9951171875
Source: MSI80EA.tmp.2.drStatic PE information: Section: ZLIB complexity 0.9999869501670379
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFCC3D8F2985C23970.TMPJump to behavior
Source: T1#U5b89#U88c5#U53051.0.2.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: T1#U5b89#U88c5#U53051.0.2.msiVirustotal: Detection: 13%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.2.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 48011E1AF29F427D04837E0D08253AC4 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 48011E1AF29F427D04837E0D08253AC4 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: T1#U5b89#U88c5#U53051.0.2.msiStatic file information: File size 9236480 > 1048576
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name:
Source: MSI80EA.tmp.2.drStatic PE information: section name: entropy: 7.999809897741427
Source: MSI80EA.tmp.2.drStatic PE information: section name: entropy: 7.989237046014286
Source: MSI80EA.tmp.2.drStatic PE information: section name: entropy: 7.9997562514215215
Source: MSI80EA.tmp.2.drStatic PE information: section name: entropy: 7.1633860049775056
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI80EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI80EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI80EA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7684Thread sleep count: 47 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584372 Sample: T1#U5b89#U88c5#U53051.0.2.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI80EA.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
T1#U5b89#U88c5#U53051.0.2.msi13%VirustotalBrowse
T1#U5b89#U88c5#U53051.0.2.msi11%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI80EA.tmp24%VirustotalBrowse
C:\Windows\Installer\MSI80EA.tmp13%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584372
Start date and time:2025-01-05 10:04:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:T1#U5b89#U88c5#U53051.0.2.msi
renamed because original name is a hash value
Original Sample Name:T11.0.2.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.12.23.50
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI80EA.tmpT1#U5b89#U88c5#U53051.0.4.msiGet hashmaliciousUnknownBrowse
    T1#U5b89#U88c5#U53051.0.6.msiGet hashmaliciousUnknownBrowse
      74Zsa4xjZD.msiGet hashmaliciousUnknownBrowse
        6UflnqqlRm.msiGet hashmaliciousUnknownBrowse
          kynqzO7eBv.msiGet hashmaliciousUnknownBrowse
            ws8xbtbe12.msiGet hashmaliciousUnknownBrowse
              IlPF8gbvGl.msiGet hashmaliciousUnknownBrowse
                wlTYtdNJP8.msiGet hashmaliciousUnknownBrowse
                  BBEYH73ThQ.msiGet hashmaliciousUnknownBrowse
                    xkUUkjILS6.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6910198
                      Entropy (8bit):7.988452742984004
                      Encrypted:false
                      SSDEEP:98304:qhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd0:qKph8v4drS9vBExWwIF4Z4GHpKnazd0
                      MD5:94B83EB38AA2CF00B50D589A808305E9
                      SHA1:13FD2AC7B9F50C26E1690239D7917722CC31AF43
                      SHA-256:FE6ADB5279529A3F2C9511E3F438F06790D6C2A2314D84E41BA6E1DBFAD2D7EE
                      SHA-512:440AD0C5FEB81E7E7A5837CAB5163435F1166D63E382A910EDA09CB51DAA2FAD4EFCE2A333D2B0CF4004EB8606A86D563597A1A288E37A8619E1E17DC64586F4
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{0AE851F3-5F2D-40D4-B1FE-12F2F4C1E1B9}..Setup..T1#U5b89#U88c5#U53051.0.2.msi.@.....@.....@.....@........&.{CEC9327A-B047-4BFE-A750-9E420ACB0361}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{0AE851F3-5F2D-40D4-B1FE-12F2F4C1E1B9}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A......Ti.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q.................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):2288193
                      Entropy (8bit):7.999921811918192
                      Encrypted:true
                      SSDEEP:49152:/8wpbZoMJsfniduny8KWS68xrq0rHbtfWC+eED3T82acJMe:kwpbZodiMy8KWex20bp+hD3I2acd
                      MD5:654F2E004B84D7CB34673D35C02CD548
                      SHA1:F1AA704C7557AA7FEBCAE89F54EE4D34F2DF52B8
                      SHA-256:66E017F118D7DC579C6A0E08C4801D2EA060E056CFC8250F0AA6AB49B36BA69D
                      SHA-512:4D9BCD90EAFE04320FEFC7360C7E42727E1157DB044B215657026E540C702E4571622A6A263A33D577375AAABAA6F68CA39D7949D4145964F8027F9B82256705
                      Malicious:false
                      Reputation:low
                      Preview:.@S....n....................7...!.3.3..@I..qs...3.}..(.....,r~r...(.....v.s...F1..o}._.p.....I.&..{..a.....7.L...J.m.X......J..c.w..E3...v.N7'B,..p..~..QJ...SR.1....8.eFy(....k..k.._:S...f.%.tb.....w.Q.Q'.A.e+.>{d.N...;.{.4..jOT....P....%.!=.v..=Q&|..y....e.ms.h..bd.<<Q"!... ;........4.vM].4.~-G...v..c:.6.6..{x}.zM.....B......[.*i5......D.F]......=.=..=....<...k..(...*......E....n..:...v..j..?7YSu.....c....2)..C..\E..S...{.......L..~...*.{!D..()_e......^\].w.cL..Jx..G...C.g.;..5{...\.0A....>....+.~.5{.....X.5.c...A...hG#.......{.....h8m.8m./g.c.?...y.F<9.Oi.%....0..we=:2.qo.....h...8....9HK!..6Jm..=#..>.....-s.5..Z...."{.N.......+t....%.)..[.Z;B.).....U.r..mmf...+.3d..f..k$.\,.....gdn.U..R..d.\........G.G"x.......?.. 4.............Gp.M.G.~.....).!9..3..........|1.q.W..MO..-...n6....p.PS.M.=......7..$.G.....^.*/... ..3#.6....1.;zP..GD...t.GC...ha..G '7.....x.U.qW./5.+........|....Z.D...]qF$........`.q.|.....S..3..."..yTmJ............
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {CEC9327A-B047-4BFE-A750-9E420ACB0361}, Create Time/Date: Sat Jan 4 01:58:44 2025, Last Saved Time/Date: Sat Jan 4 01:58:44 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9236480
                      Entropy (8bit):7.989404274601191
                      Encrypted:false
                      SSDEEP:196608:/a65KraKLhD3N/WKph8v4drE9vBExWwIF4Z4GHpKnszd:CiCLpN/WF4VWc1Q4Z48Kszd
                      MD5:BB059F89003F1B95374A3DAEBAA3CDB4
                      SHA1:B23FB0042B1000F9F863D0020266628C4D5ECB99
                      SHA-256:F57F2C92987487B7110A4E8017211C94A8C66CA2BAA62AE5E1216DA73665F884
                      SHA-512:CFCB5C612CE30A18C27B9B44D4D3F93DF5089A330E82907AD2729F0396DA7309269894FF8F0ACB04253A97A76A2B3AEDA311C9BAC1C4AF3690F1D7E5D49C2281
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {CEC9327A-B047-4BFE-A750-9E420ACB0361}, Create Time/Date: Sat Jan 4 01:58:44 2025, Last Saved Time/Date: Sat Jan 4 01:58:44 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9236480
                      Entropy (8bit):7.989404274601191
                      Encrypted:false
                      SSDEEP:196608:/a65KraKLhD3N/WKph8v4drE9vBExWwIF4Z4GHpKnszd:CiCLpN/WF4VWc1Q4Z48Kszd
                      MD5:BB059F89003F1B95374A3DAEBAA3CDB4
                      SHA1:B23FB0042B1000F9F863D0020266628C4D5ECB99
                      SHA-256:F57F2C92987487B7110A4E8017211C94A8C66CA2BAA62AE5E1216DA73665F884
                      SHA-512:CFCB5C612CE30A18C27B9B44D4D3F93DF5089A330E82907AD2729F0396DA7309269894FF8F0ACB04253A97A76A2B3AEDA311C9BAC1C4AF3690F1D7E5D49C2281
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6904494
                      Entropy (8bit):7.9887506346486505
                      Encrypted:false
                      SSDEEP:98304:nhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEdr:nKph8v4drS9vBExWwIF4Z4GHpKnazdr
                      MD5:50200B88EE4C9D8E95C57729DBF63ABC
                      SHA1:CA0029696BFE3B7DD67EA4265AEFDF52D2F1415E
                      SHA-256:26D4ADCFA3EFB49E861A0A1ED8C88F01E53B1F911E7519739A59EDCEDBF4C806
                      SHA-512:61C2C1487202C9DFD3FFA97BB20074205B1C122CC3914F51552F693EC3F352F5CE1ADE12E4EB9A311873DB45E010F6DD2066255EB9F2E6FB9A79CF8122E4871A
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{0AE851F3-5F2D-40D4-B1FE-12F2F4C1E1B9}..Setup..T1#U5b89#U88c5#U53051.0.2.msi.@.....@.....@.....@........&.{CEC9327A-B047-4BFE-A750-9E420ACB0361}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@A."..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\3b7782.msi.........@........file.dat..l4d..file.dat.@.....@A."..@.......@.............@.........@.....@.....@eO...@K....@4g=5.@.,.H......_....J..._.@A......Ti.MZx.....................@..................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6902784
                      Entropy (8bit):7.988828924696361
                      Encrypted:false
                      SSDEEP:98304:AhwpMne8X/4dQKJS9v8vR6VkZfLcG7lEjEIF4ZIHNTeNx7Dph0f+TQZZ4zNAEd:AKph8v4drS9vBExWwIF4Z4GHpKnazd
                      MD5:258FF5AB92030549125E08E161FD2E19
                      SHA1:4EAFFDF8240C15451E4E2FABD95B081F1DB6BC16
                      SHA-256:FAB293D8E32BCE21A31885EF35F0A473AB4370EC2040DF884F0265AA156717F9
                      SHA-512:6FC043DC3BC9963F0979B20398F3ABB45279ACCCC362B34BF82E1F2A01D75C57486777A2A06C66872B0293E7E0418AF9BCEF8B925376C9E3981CDBDA02A01CF5
                      Malicious:true
                      Antivirus:
                      • Antivirus: Virustotal, Detection: 24%, Browse
                      • Antivirus: ReversingLabs, Detection: 13%
                      Joe Sandbox View:
                      • Filename: T1#U5b89#U88c5#U53051.0.4.msi, Detection: malicious, Browse
                      • Filename: T1#U5b89#U88c5#U53051.0.6.msi, Detection: malicious, Browse
                      • Filename: 74Zsa4xjZD.msi, Detection: malicious, Browse
                      • Filename: 6UflnqqlRm.msi, Detection: malicious, Browse
                      • Filename: kynqzO7eBv.msi, Detection: malicious, Browse
                      • Filename: ws8xbtbe12.msi, Detection: malicious, Browse
                      • Filename: IlPF8gbvGl.msi, Detection: malicious, Browse
                      • Filename: wlTYtdNJP8.msi, Detection: malicious, Browse
                      • Filename: BBEYH73ThQ.msi, Detection: malicious, Browse
                      • Filename: xkUUkjILS6.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S3Y.........." ................d{....................................................`... ...... ........ ...... ..............`.Q.....`lR.\....04......vR.@...........@.Q...............................Q.(.......................................................................................@............0..........................@................. ......F..............@............@....3......N .............@.................3......N .............@.................3......P .............@.................3......R .............@.................4......R .............@.................4......T .............@................ 4......T .............@....rsrc........04......\ .............@..@.........@...@4......` .............@............0A...Q..*A..*(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1729178856810196
                      Encrypted:false
                      SSDEEP:12:JSbX72FjIAGiLIlHVRpIh/7777777777777777777777777vDHFniXucf/Drl0i5:JuQI5wOCF
                      MD5:2EC9B6C82703A8A2568AB062D6D105E3
                      SHA1:1404C681F537F5C3B2ECC3B22592620B5C369480
                      SHA-256:5F65A11BF2337AD30B35BF101A3702204481C142AD92BEC30D50B8D3B299A6BF
                      SHA-512:A57E18C0851A437828798E6352A6508BB2D785F6B334755F365002D175F1ECAD6311FC7D3412F870F9509BE1B4D31469F07FDAB58D05B1E8B581469FC7C173F2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4654167108330745
                      Encrypted:false
                      SSDEEP:48:38PhkuRc06WXJYBT533zlwdeS5gLrCdeSIJ7:2hk17BT53zl1d/x
                      MD5:B0F60498EE777A794580A804B0742001
                      SHA1:C353221F68FBBCF156AA1BB4E733607D03893ABC
                      SHA-256:2152D89001311A89DABA722D9B7B9D0878F8549AFFA039E64372EDEF853F54D3
                      SHA-512:CE7733831414F1DCA54BCF200611ECF08A156C891B31F88CCD1A387DF4B9D8978D0E104191BF19AD8ED3D3D792A9F3ED5E44259D26BC31843E4598B06D03F3BF
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):360001
                      Entropy (8bit):5.362946821909348
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgauj:zTtbmkExhMJCIpEa
                      MD5:F1F9ED769B6A5408FF280F5EA576F91A
                      SHA1:94CADE7FF7A4B9390E0F26AE1ACEAD38BFEFEBF7
                      SHA-256:011B8E1E7DB0142AA753E27AE25A38BD76BB87D93F0589443AEA276ED3D1E623
                      SHA-512:2BE583327D5055E45E21BDD8BB9E693AC92C8794CAD1B1EB73B4B9CAA684D48B042E03E2335CC3CBB54FCBCEDCFAA1FCB53E0CED679F9505882A7497E6B6FFE7
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07813522013042422
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOMUOVXnucQ2wiMKliVky6l51:2F0i8n0itFzDHFniXucf/Dr
                      MD5:893FDEE022E65D4799AA6480A4154A56
                      SHA1:382CF021B03D1186990F12C7350EFD2131DBF133
                      SHA-256:7A43F75B133499F0595C9D1611CAB70C051E54A33CF7788674F0A31EE6DEF2A0
                      SHA-512:C403AB44C696C99B4F6BDFE5AFCEBA15243A5140422DC46B0E9870C853A34290B25AE540DB24576E1F68B5DD7D2E083A38138EE2F64411BEA5105DA68194050C
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810924255412023
                      Encrypted:false
                      SSDEEP:48:nnMuf1veFXJZT5t3zlwdeS5gLrCdeSIJ7:nMjxTr3zl1d/x
                      MD5:A4D43E598D6EFA069A56B224DC22F02C
                      SHA1:E1F83CF79AE717BEB3332207EFB3E621F7C8526C
                      SHA-256:C1523DB27ABF33DFE8BCD2BDA1B2800C4272CC2B93FE2ACB7D27E6E659CA2414
                      SHA-512:43403D50572BADF84619CA2C3ABB3DAC55EE911D536D75B68C0BCCEFE27D631C2CD903BB35A9F99795ABF667CA2C3CB2728D36A787504C6C8A68ED47614EB545
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810924255412023
                      Encrypted:false
                      SSDEEP:48:nnMuf1veFXJZT5t3zlwdeS5gLrCdeSIJ7:nMjxTr3zl1d/x
                      MD5:A4D43E598D6EFA069A56B224DC22F02C
                      SHA1:E1F83CF79AE717BEB3332207EFB3E621F7C8526C
                      SHA-256:C1523DB27ABF33DFE8BCD2BDA1B2800C4272CC2B93FE2ACB7D27E6E659CA2414
                      SHA-512:43403D50572BADF84619CA2C3ABB3DAC55EE911D536D75B68C0BCCEFE27D631C2CD903BB35A9F99795ABF667CA2C3CB2728D36A787504C6C8A68ED47614EB545
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4654167108330745
                      Encrypted:false
                      SSDEEP:48:38PhkuRc06WXJYBT533zlwdeS5gLrCdeSIJ7:2hk17BT53zl1d/x
                      MD5:B0F60498EE777A794580A804B0742001
                      SHA1:C353221F68FBBCF156AA1BB4E733607D03893ABC
                      SHA-256:2152D89001311A89DABA722D9B7B9D0878F8549AFFA039E64372EDEF853F54D3
                      SHA-512:CE7733831414F1DCA54BCF200611ECF08A156C891B31F88CCD1A387DF4B9D8978D0E104191BF19AD8ED3D3D792A9F3ED5E44259D26BC31843E4598B06D03F3BF
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4654167108330745
                      Encrypted:false
                      SSDEEP:48:38PhkuRc06WXJYBT533zlwdeS5gLrCdeSIJ7:2hk17BT53zl1d/x
                      MD5:B0F60498EE777A794580A804B0742001
                      SHA1:C353221F68FBBCF156AA1BB4E733607D03893ABC
                      SHA-256:2152D89001311A89DABA722D9B7B9D0878F8549AFFA039E64372EDEF853F54D3
                      SHA-512:CE7733831414F1DCA54BCF200611ECF08A156C891B31F88CCD1A387DF4B9D8978D0E104191BF19AD8ED3D3D792A9F3ED5E44259D26BC31843E4598B06D03F3BF
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10345744218054609
                      Encrypted:false
                      SSDEEP:24:IeM1ZLdB5GipVGdB5GipV7VqKwGSlrkgxv+kfaB3UJ:BM1ldeScdeS5gLrxv83
                      MD5:B341FA529F8A316BF635A160E6D0BFE6
                      SHA1:96041C8041F624E131509F35C9A30AE385D9A2CD
                      SHA-256:C9DBBEE2CC7300C80FE0EF25F43470AFD78ABB42939F5416BFF0E57B7FA5BA1D
                      SHA-512:72A77A2DCAC49A2FA0206CFB3C0CA42EABD17C6C10677B3FD4E0D84DDFED10797F91E68721255B9067B49776744D637E3FCCB9432E8FB2ADC27D64D8DA4AEAD5
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810924255412023
                      Encrypted:false
                      SSDEEP:48:nnMuf1veFXJZT5t3zlwdeS5gLrCdeSIJ7:nMjxTr3zl1d/x
                      MD5:A4D43E598D6EFA069A56B224DC22F02C
                      SHA1:E1F83CF79AE717BEB3332207EFB3E621F7C8526C
                      SHA-256:C1523DB27ABF33DFE8BCD2BDA1B2800C4272CC2B93FE2ACB7D27E6E659CA2414
                      SHA-512:43403D50572BADF84619CA2C3ABB3DAC55EE911D536D75B68C0BCCEFE27D631C2CD903BB35A9F99795ABF667CA2C3CB2728D36A787504C6C8A68ED47614EB545
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {CEC9327A-B047-4BFE-A750-9E420ACB0361}, Create Time/Date: Sat Jan 4 01:58:44 2025, Last Saved Time/Date: Sat Jan 4 01:58:44 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.989404274601191
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:T1#U5b89#U88c5#U53051.0.2.msi
                      File size:9'236'480 bytes
                      MD5:bb059f89003f1b95374a3daebaa3cdb4
                      SHA1:b23fb0042b1000f9f863d0020266628c4d5ecb99
                      SHA256:f57f2c92987487b7110a4e8017211c94a8c66ca2baa62ae5e1216da73665f884
                      SHA512:cfcb5c612ce30a18c27b9b44d4d3f93df5089a330e82907ad2729f0396da7309269894ff8f0acb04253a97a76a2b3aeda311c9bac1c4af3690f1d7e5d49c2281
                      SSDEEP:196608:/a65KraKLhD3N/WKph8v4drE9vBExWwIF4Z4GHpKnszd:CiCLpN/WF4VWc1Q4Z48Kszd
                      TLSH:9C963312B53FEAACF492B4B25EF59654C0066E61BDB085239B843B8C1771F2507733EA
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:04:05:03
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.2.msi"
                      Imagebase:0x7ff67b280000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:2
                      Start time:04:05:04
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff67b280000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:04:05:06
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 48011E1AF29F427D04837E0D08253AC4 E Global\MSI0000
                      Imagebase:0x7ff67b280000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly