Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v9..2.4.msi

Overview

General Information

Sample name:setup64v9..2.4.msi
Analysis ID:1584373
MD5:03ce435a6cf40dc537f768575b315c3c
SHA1:18f5279f4f31cd85eb4586236bec270380b017ea
SHA256:0a5cbb89f9d5e556499fe2263fb0311167badf22849404a2da98e828b6521e83
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 2296 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v9..2.4.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 3060 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 5996 cmdline: C:\Windows\System32\MsiExec.exe -Embedding E9EC462832BF1E54C1576E51011A8653 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI6A.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI6A.tmpVirustotal: Detection: 27%Perma Link
Source: setup64v9..2.4.msiReversingLabs: Detection: 15%
Source: setup64v9..2.4.msiVirustotal: Detection: 11%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cf751.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{5B4BCE2C-518E-4215-8842-F8650FD63D61}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF935.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cf753.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cf753.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6A.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\5cf753.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI6A.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI6A.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: setup64v9..2.4.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v9..2.4.msi
Source: MSI6A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI6A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI6A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFD6E268CD1F28D953.TMPJump to behavior
Source: setup64v9..2.4.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v9..2.4.msiReversingLabs: Detection: 15%
Source: setup64v9..2.4.msiVirustotal: Detection: 11%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v9..2.4.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding E9EC462832BF1E54C1576E51011A8653 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding E9EC462832BF1E54C1576E51011A8653 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v9..2.4.msiStatic file information: File size 8458240 > 1048576
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name:
Source: MSI6A.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI6A.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI6A.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI6A.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI6A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 6504Thread sleep count: 1188 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584373 Sample: setup64v9..2.4.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI6A.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v9..2.4.msi16%ReversingLabsWin64.Trojan.Generic
setup64v9..2.4.msi12%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI6A.tmp16%ReversingLabs
C:\Windows\Installer\MSI6A.tmp28%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584373
Start date and time:2025-01-05 10:05:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:setup64v9..2.4.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 4.245.163.56, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI6A.tmpsetup64v9.7.4.msiGet hashmaliciousUnknownBrowse
    setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
      setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
        setup64v8.5.6.msiGet hashmaliciousUnknownBrowse
          setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
            setup64v8.6.7.msiGet hashmaliciousUnknownBrowse
              setup64v8.2.4.msiGet hashmaliciousUnknownBrowse
                setup64v6.6.5.msiGet hashmaliciousUnknownBrowse
                  setup64v9.3.4.msiGet hashmaliciousUnknownBrowse
                    setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003368
                      Entropy (8bit):7.986514544187187
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Of:y6TCe30s0nvfcy67yBHLgfVf
                      MD5:1A8A60ED50253A0718947E69B9A56502
                      SHA1:D6D93E57428256F9075D265A1E3A9FFB046DAEF2
                      SHA-256:82FB94537ECE787C9E2C580BB51D44864916469BE121CD9705E0C3CE7FB3AA83
                      SHA-512:FDB36590C099F61BCE5095DC56F631DDF2DC2BEAC87D86ADCEC9FD5CE400E32C9D3C9D5708A00E9409A1A4C4687DD89B12E7E045B2656978DAF6010DD8CE080B
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v9..2.4.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1420112
                      Entropy (8bit):7.9998456572268175
                      Encrypted:true
                      SSDEEP:24576:58dmj15hop6wiuHDvW7LPV5c8WTm6HGgYw/SLnKIX/Npr/sF/54RbbbuvUdujLzH:5lle/iuHDv4Tc8WTm6HrwvDrkF/W1ucy
                      MD5:D391AB180D7BDE4CB5170BF64A522D83
                      SHA1:6F8422CEA8DDD1CB6CE95D2DFF304BE546C58C3E
                      SHA-256:ADD0DA795DE9ACDD8EB63C4C5373F24958C972CB6700F49035B628B65E8A770B
                      SHA-512:32F758AD1A3DE31987A890D35C014394628493849FD24BBC304277A60229E1992A9177AAFDD2649744682572AA70F9FEAA608E952153FAD88FDD22F300EEF190
                      Malicious:false
                      Reputation:low
                      Preview:.@S......"..V..............=.]..\Lr...>...of..#r..~.....y.......d.{.....P\.....5.}X.....F...[...IN......D+N.....].`.o.i...;}XC........Z|[KG.nh~.$.%.h.'fIC..JS.mZU.V9.E. ..Q..n..f.K).u.(.-.....:.#..\}..U..\s..m.-2^...../.X..>.....s...H.1...S.&_1y>..D..X.F.#Q.....?...($.Z.'.{=T.;..i..3...R].).4Q...V...H.P... .V..H...w.-..n(O9h ~K..yBq]k..2.$y.ek..)..7crv.:.OY|D....!1....f.V.H......:..G...6....2..#.f.$...0=[}.....4T.P..........5.T...;.\e..^.O..d.|.&.....).u9.,0....N.Y...v..L.Z....^<.....&Z...)a3w. R.d..H.$r..C.b.;.........0LR..G.....X1+~o.+...9X6.%..i.T.h').....B..2.i.+...^.!NiB.k.Z.<..6.......<...h.4`....<....VH...>p..)[..S.o......My.Y......q.........n..7_#.5....+-.b..">.n.....0....k..h....1.)..-.f...Z.K..t...x'j~0.1.....^>..]...;o.....([..5.........Cn...#...........W..F..5.=..*.pU.1i^.@.......J9........m..].u.y.p.t.....Es..xu.>wg`X.w..O...L.;....`A5...K =..w..0...C-...lyt.Y..=...^7.L.1..,x.-.S$.n5..)...6...FXC.....&N...Y"{..A.....$.D...-m..A....a.
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fghrt, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8458240
                      Entropy (8bit):7.986803586274072
                      Encrypted:false
                      SSDEEP:196608:XnUf+6O/97B6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:kBcd6TCe30s0pvfcy67yBHLgfV
                      MD5:03CE435A6CF40DC537F768575B315C3C
                      SHA1:18F5279F4F31CD85EB4586236BEC270380B017EA
                      SHA-256:0A5CBB89F9D5E556499FE2263FB0311167BADF22849404A2DA98E828B6521E83
                      SHA-512:559D6F8DD99C03C5F46F2AFAA08AD646E9935EA9A8B99B681243A1FCECB22502F510302A01A42445524061F2FF23581227D5B0D42227208FD5058D56886C33D8
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fghrt, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8458240
                      Entropy (8bit):7.986803586274072
                      Encrypted:false
                      SSDEEP:196608:XnUf+6O/97B6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:kBcd6TCe30s0pvfcy67yBHLgfV
                      MD5:03CE435A6CF40DC537F768575B315C3C
                      SHA1:18F5279F4F31CD85EB4586236BEC270380B017EA
                      SHA-256:0A5CBB89F9D5E556499FE2263FB0311167BADF22849404A2DA98E828B6521E83
                      SHA-512:559D6F8DD99C03C5F46F2AFAA08AD646E9935EA9A8B99B681243A1FCECB22502F510302A01A42445524061F2FF23581227D5B0D42227208FD5058D56886C33D8
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:dropped
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 28%, Browse
                      Joe Sandbox View:
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: setup64v8.5.6.msi, Detection: malicious, Browse
                      • Filename: setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v8.6.7.msi, Detection: malicious, Browse
                      • Filename: setup64v8.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v9.3.4.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997673
                      Entropy (8bit):7.986815061464101
                      Encrypted:false
                      SSDEEP:196608:AB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4ON:A6TCe30s0nvfcy67yBHLgfVN
                      MD5:BB5B298E7309267B5CA768F977C2B025
                      SHA1:0C3A9B937E7895665CA0C911DEE279F0100D65ED
                      SHA-256:A2BBDAAB9A2D5B87DE52E70CA342F9351AE4F29B8A7EC0A42319879C124083EE
                      SHA-512:D5CBE0404F2F3F8DD770622F23BCA1CC9F7D461520B4D7C31653B29FE0B33C4965865C5CBA6CFC963E1DA8D041BA403BDA7E6AB07D5552E845CE89016193BE11
                      Malicious:false
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{5B4BCE2C-518E-4215-8842-F8650FD63D61}..Setup..setup64v9..2.4.msi.@.....@.....@.....@........&.{7E4D0476-28C5-45C2-A3EE-0E8B46198824}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@P....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\5cf751.msi.........@........file.dat..l4d..file.dat.@.....@P....@.......@.............@.........@.....@.....@....@.{.L.@.....@JR-......._....J..._.@A.......j.MZx.....................@.............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1662448774746381
                      Encrypted:false
                      SSDEEP:12:JSbX72FjRQAGiLIlHVRpFh/7777777777777777777777777vDHFjeUq2hOql0i5:JrQQI5BFPvhOF
                      MD5:18D10F3C25D6F06AAA13F352FBC9AAF1
                      SHA1:92FE34A736C9727819B4728974376478C7D0BA50
                      SHA-256:4F8C7DCB89B2EBEC29A526CD21EA8C5E0E79528100565022488BE4367BC100E1
                      SHA-512:4ADA6B1120D49D9AEA61BA1BD57B45053938E572A0CDFFF878B208ADA1A44AAF5B7F8B953B1B2D2F0EFF83BE01AEA16FC38FF0698A884C4D273172A0647071D1
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4635153249387018
                      Encrypted:false
                      SSDEEP:48:B8PhAuRc06WXJujT5+g4deS5drideSIW9:chA1FjTfdai
                      MD5:82E386DDD480DE7E2ABA67A6EAAF78C3
                      SHA1:9E47E78EECE6BE3601EAA68087FD870DC9DF7953
                      SHA-256:92592D7FF9B6335BF7A1B97A49E09768B5FFEE8ADAE833883A7BC9EA273D4F8F
                      SHA-512:D6C4596C3ABF337CD9F04FC74705712F88411E70D8CBDDFFC8A26A069CA321843F7095DFB9C4E66F3CBA22EB513B30EB3A54B81F38F240754E9BD6A2ED473693
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):364484
                      Entropy (8bit):5.365477299843995
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau2:zTtbmkExhMJCIpEl
                      MD5:147FFECAAB6FE4C5D1346F18DCF458BA
                      SHA1:F0F5A4F1BCE6A4B22FBB19954CC791E0BEA00856
                      SHA-256:9ED7135E1B0AAA1B058B4541CC73AFFAC63702EEDE6DCADD0576CEBBB674371A
                      SHA-512:6D4D773C4135F35963A1011C0F3E34083D1A3C70CDA551926E228AF9A306B5AE2B318BAA7675BE131896238FB23696A4F44236A91CAEE51CC995038E3EE71AE0
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07314981034673286
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOjeyp/q2hEwVky6lq:2F0i8n0itFzDHFjeUq2hOq
                      MD5:4E01E686BF026B38AAF9D03D0D3A7E4D
                      SHA1:F90EBE207ED0209AD99F85E306329D1441F79E22
                      SHA-256:4105CFEFBC9E2D66F6DADD07F14DECF46FB17472DA0E4A33325D1458B2DD7405
                      SHA-512:341BA51B30A9C6A9C18166531A9BC165237B4ABBF661B4FADCA6BB637DB4D0C9F62C4FBA0D74B619A5CB43D291BCEF114406FC3DEC57EACA3B92C736FB9056EA
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.180242315816452
                      Encrypted:false
                      SSDEEP:24:JA9MhC3nouxdiEipKP2xza2tzhAjZZagUMClXtd85CWg+HvOGdB5GipV7VQwGglZ:ehnoujJveFXJJT5Ug4deS5drideSIW9
                      MD5:4F6A10701B4D9F810256463BE65909FB
                      SHA1:65D55349AC7EC653339C90BA00641B4D1C98E45D
                      SHA-256:D9B10D55B8D09BB58FD354EC3DAA2E30A24FE0B3B9A972D117CA492D2C01781C
                      SHA-512:581F5E6F57F5FD715EA45D91491E7831DB49A23C1182026775FF4BDC69A38B7E2C5AC331DF12C9F4DE91331B80319095C26E24319F646A12A0327A340634FCB1
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.180242315816452
                      Encrypted:false
                      SSDEEP:24:JA9MhC3nouxdiEipKP2xza2tzhAjZZagUMClXtd85CWg+HvOGdB5GipV7VQwGglZ:ehnoujJveFXJJT5Ug4deS5drideSIW9
                      MD5:4F6A10701B4D9F810256463BE65909FB
                      SHA1:65D55349AC7EC653339C90BA00641B4D1C98E45D
                      SHA-256:D9B10D55B8D09BB58FD354EC3DAA2E30A24FE0B3B9A972D117CA492D2C01781C
                      SHA-512:581F5E6F57F5FD715EA45D91491E7831DB49A23C1182026775FF4BDC69A38B7E2C5AC331DF12C9F4DE91331B80319095C26E24319F646A12A0327A340634FCB1
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4635153249387018
                      Encrypted:false
                      SSDEEP:48:B8PhAuRc06WXJujT5+g4deS5drideSIW9:chA1FjTfdai
                      MD5:82E386DDD480DE7E2ABA67A6EAAF78C3
                      SHA1:9E47E78EECE6BE3601EAA68087FD870DC9DF7953
                      SHA-256:92592D7FF9B6335BF7A1B97A49E09768B5FFEE8ADAE833883A7BC9EA273D4F8F
                      SHA-512:D6C4596C3ABF337CD9F04FC74705712F88411E70D8CBDDFFC8A26A069CA321843F7095DFB9C4E66F3CBA22EB513B30EB3A54B81F38F240754E9BD6A2ED473693
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:modified
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.180242315816452
                      Encrypted:false
                      SSDEEP:24:JA9MhC3nouxdiEipKP2xza2tzhAjZZagUMClXtd85CWg+HvOGdB5GipV7VQwGglZ:ehnoujJveFXJJT5Ug4deS5drideSIW9
                      MD5:4F6A10701B4D9F810256463BE65909FB
                      SHA1:65D55349AC7EC653339C90BA00641B4D1C98E45D
                      SHA-256:D9B10D55B8D09BB58FD354EC3DAA2E30A24FE0B3B9A972D117CA492D2C01781C
                      SHA-512:581F5E6F57F5FD715EA45D91491E7831DB49A23C1182026775FF4BDC69A38B7E2C5AC331DF12C9F4DE91331B80319095C26E24319F646A12A0327A340634FCB1
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4635153249387018
                      Encrypted:false
                      SSDEEP:48:B8PhAuRc06WXJujT5+g4deS5drideSIW9:chA1FjTfdai
                      MD5:82E386DDD480DE7E2ABA67A6EAAF78C3
                      SHA1:9E47E78EECE6BE3601EAA68087FD870DC9DF7953
                      SHA-256:92592D7FF9B6335BF7A1B97A49E09768B5FFEE8ADAE833883A7BC9EA273D4F8F
                      SHA-512:D6C4596C3ABF337CD9F04FC74705712F88411E70D8CBDDFFC8A26A069CA321843F7095DFB9C4E66F3CBA22EB513B30EB3A54B81F38F240754E9BD6A2ED473693
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10305354425591877
                      Encrypted:false
                      SSDEEP:24:7CVqHHZLdB5GipVGdB5GipV7VQwGglrkgsOJ+HK0:mOHldeScdeS5drzN
                      MD5:61511D05489808F54CB240498612B918
                      SHA1:5EEB1EBEA44B5EE40965F1006C6B60FC370BCC16
                      SHA-256:FBC5832FBF73B95BE7C474EA5CBFE84F26DB56629DFF081F3E42171AEE9C0461
                      SHA-512:8FC2AB56CF9749A428A1DB09DD0B9EC86A4E9799169676F5C1DDFE068FF6E21986676FA6431395EC906E32F414F2B264B818FACC4E7078F969EFDEB8BFF98050
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fghrt, Template: Intel;1033, Revision Number: {7E4D0476-28C5-45C2-A3EE-0E8B46198824}, Create Time/Date: Sat Jan 4 04:40:08 2025, Last Saved Time/Date: Sat Jan 4 04:40:08 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.986803586274072
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:setup64v9..2.4.msi
                      File size:8'458'240 bytes
                      MD5:03ce435a6cf40dc537f768575b315c3c
                      SHA1:18f5279f4f31cd85eb4586236bec270380b017ea
                      SHA256:0a5cbb89f9d5e556499fe2263fb0311167badf22849404a2da98e828b6521e83
                      SHA512:559d6f8dd99c03c5f46f2afaa08ad646e9935ea9a8b99b681243a1fcecb22502f510302a01a42445524061f2ff23581227d5b0d42227208fd5058d56886c33d8
                      SSDEEP:196608:XnUf+6O/97B6TCe30s0TDpHPfctFaEfVr7yBh1LRTKf4O:kBcd6TCe30s0pvfcy67yBHLgfV
                      TLSH:B7863320B8EF96FAF6366B324D5571A20002AFB012B681469B543F0C057DB74DB7BA7D
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:04:06:01
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v9..2.4.msi"
                      Imagebase:0x7ff7e8910000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:04:06:01
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff7e8910000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:04:06:04
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding E9EC462832BF1E54C1576E51011A8653 E Global\MSI0000
                      Imagebase:0x7ff7e8910000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly