Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
installer64v1.2.8.msi

Overview

General Information

Sample name:installer64v1.2.8.msi
Analysis ID:1584374
MD5:1bdab98ace357167c92c22d58271c644
SHA1:295277eb9889ecd955b5117e2cc3afc5de2ea392
SHA256:1b0de1c0fbe215ee45c39210abbfb6b24cc9fd1c23f126d7f2fa3ec10c2e7d0d
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7956 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v1.2.8.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7996 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6956 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 9A5F5B462856F04E262DE6355F0EDC38 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIBF64.tmpReversingLabs: Detection: 15%
Source: installer64v1.2.8.msiReversingLabs: Detection: 15%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: global trafficTCP traffic: 192.168.2.10:54479 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.10:57586 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1

System Summary

barindex
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5db60d.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{902DEE9F-A3DC-4D62-B01C-3B932DB5BDF6}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIB87E.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5db60f.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5db60f.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF64.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\5db60f.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIBF64.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSIBF64.tmp.5.drStatic PE information: Number of sections : 13 > 10
Source: installer64v1.2.8.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs installer64v1.2.8.msi
Source: MSIBF64.tmp.5.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSIBF64.tmp.5.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSIBF64.tmp.5.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFA5AC5FC31F08F5FE.TMPJump to behavior
Source: installer64v1.2.8.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: installer64v1.2.8.msiReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v1.2.8.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 9A5F5B462856F04E262DE6355F0EDC38 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 9A5F5B462856F04E262DE6355F0EDC38 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: installer64v1.2.8.msiStatic file information: File size 8335360 > 1048576
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name:
Source: MSIBF64.tmp.5.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSIBF64.tmp.5.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSIBF64.tmp.5.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSIBF64.tmp.5.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIBF64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 6712Thread sleep count: 619 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584374 Sample: installer64v1.2.8.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIBF64.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
installer64v1.2.8.msi16%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIBF64.tmp16%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584374
Start date and time:2025-01-05 10:06:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:13
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:installer64v1.2.8.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, Sgrmuserer.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.109.210.53
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: installer64v1.2.8.msi
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIBF64.tmpsetup64v9..2.4.msiGet hashmaliciousUnknownBrowse
    setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
      setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
        setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
          setup64v8.5.6.msiGet hashmaliciousUnknownBrowse
            setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
              setup64v8.6.7.msiGet hashmaliciousUnknownBrowse
                setup64v8.2.4.msiGet hashmaliciousUnknownBrowse
                  setup64v6.6.5.msiGet hashmaliciousUnknownBrowse
                    setup64v9.3.4.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003366
                      Entropy (8bit):7.986514246753555
                      Encrypted:false
                      SSDEEP:196608:7B6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Ok:d6TCe30s0nvfcy67yBHLgfVk
                      MD5:5943306A9C6C4947009D0349A98005D1
                      SHA1:4AF9A286DD9FA070A64C67E93B277C1442127EFB
                      SHA-256:CF3524BFCA62D2ED1DBB2560A339D4A3E5D23B87164653C8713B53B4ED0DC4DF
                      SHA-512:6D978FBE3FEF9C2671BEFD6DF05848BF2CA1EA6CF96F4A7DBEFA63D7A406BB3FBD539F703DA940FC385C92490A8E0107822999B8F426E18070085F43A29AC08A
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{902DEE9F-A3DC-4D62-B01C-3B932DB5BDF6}..Setup..installer64v1.2.8.msi.@.....@.....@.....@........&.{14AE419F-2981-493A-9AFA-8F2D89F7D3E5}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{902DEE9F-A3DC-4D62-B01C-3B932DB5BDF6}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1299600
                      Entropy (8bit):7.999876336238904
                      Encrypted:true
                      SSDEEP:24576:xoZpGaPYSoNLpP3UPyn+++VgavZPjIkrNUyzEgTy7UfH1WGE2A:SZNPvohpcPyn+++CaxzNtzeg/JbA
                      MD5:5B296B7342A977A741424A2473BD7481
                      SHA1:9C3475E78F30851FB9083D6949D4E9C9DA43AB10
                      SHA-256:85DC1209933A9E07546E99D858030E0FAB979DB81FDDEEA9405E7CB5AEDBBBA3
                      SHA-512:0E5C92A183F4D09CE4B0D3A7205A2F403DB8053A7C3C0C1611EF90BE8460D87BEBCB2FAD15B17CF7C1C0AB3407C5A43F717257C3F92BB43CA8070963053CEF47
                      Malicious:false
                      Reputation:low
                      Preview:.@S.....!..(...............)S...r.yr<Rm..#V...._.cK...e..I.{...B+.2.f..g.u..l.M..............(.3d..=1..Bj....u.u1..n.&..k.>2y...N.&.w#........t/^.+..gb..F..... ..|.8B.r....y..@&x.u.j.^..... HHw......<.I.Xt]5........1.Y.K.%....I`$P..Up....`....<"...L.U..3.A..@....G.;OV....|......AG./......=.Y..k..!...........A&.v.]..W.Z.s(LXw......U.%.,...2..|......T...Uy.".wQ.lCl..Y )...C..S0..6 ...U\.1...B..f1......=g...}..<..2!..i..P..;..{..%..m..#......8.....<.bN.F.bs#.7.......d..g......j.x.....7..U.7..c...1L.V....,.G...'/%....Bs.....R..(.}...j.kF.%.h..f..D.,_g.(.G.ft...K...9.P:S. U##...".....Y..lR..G.1...=...yL{Cl..e..f...CS?.6.@....5.U....7.;Lq.w._.......}.Xa.t...tY...... .....9.e..Y.U.aa.[..&H.G92....L...E....@J.;=V.g..D^.t'...H...w...6.X..S.5C_3..}4W...d..V|..=<z!.#H.....A-.(.M.=..lK .o=Q.s..y....Y..4Ir.WM:]...y..I0u0]L.^#..:......Dx..,.l}.@......9.Q..e.....XVi...E..)U%PT..m.......I<..H.j.1..)...(j......Z.Rohps..d..0QE....{...5@.C......
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfertgtuj, Template: Intel;1033, Revision Number: {14AE419F-2981-493A-9AFA-8F2D89F7D3E5}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8335360
                      Entropy (8bit):7.98625211960116
                      Encrypted:false
                      SSDEEP:196608:o4LtplhBB6TCe30s0TDnNPfctFaEfVr7yBh1LRTKf4O:o4Ltplhj6TCe30s0npfcy67yBHLgfV
                      MD5:1BDAB98ACE357167C92C22D58271C644
                      SHA1:295277EB9889ECD955B5117E2CC3AFC5DE2EA392
                      SHA-256:1B0DE1C0FBE215EE45C39210ABBFB6B24CC9FD1C23F126D7F2FA3EC10C2E7D0D
                      SHA-512:2A78432F83A7A779DEE77B93524C1016FFB41A1024DF761E9B9C74F6CC44E683B5C68E2E5DD5A764B30346BF96D0F1DB8F71D1EFC68CAE9627CDD3457FAC5EB0
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfertgtuj, Template: Intel;1033, Revision Number: {14AE419F-2981-493A-9AFA-8F2D89F7D3E5}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8335360
                      Entropy (8bit):7.98625211960116
                      Encrypted:false
                      SSDEEP:196608:o4LtplhBB6TCe30s0TDnNPfctFaEfVr7yBh1LRTKf4O:o4Ltplhj6TCe30s0npfcy67yBHLgfV
                      MD5:1BDAB98ACE357167C92C22D58271C644
                      SHA1:295277EB9889ECD955B5117E2CC3AFC5DE2EA392
                      SHA-256:1B0DE1C0FBE215EE45C39210ABBFB6B24CC9FD1C23F126D7F2FA3EC10C2E7D0D
                      SHA-512:2A78432F83A7A779DEE77B93524C1016FFB41A1024DF761E9B9C74F6CC44E683B5C68E2E5DD5A764B30346BF96D0F1DB8F71D1EFC68CAE9627CDD3457FAC5EB0
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997670
                      Entropy (8bit):7.986814992412479
                      Encrypted:false
                      SSDEEP:196608:OB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OI:O6TCe30s0nvfcy67yBHLgfVI
                      MD5:5E7081627F162219B65900634B82FCA4
                      SHA1:13DB07BA526674AA3DE78629E33DCBDEA69C20A4
                      SHA-256:7D184B0492CBFE7CAC7828D98405213993A68B9E5A7479D82C83BB46C35DB2B0
                      SHA-512:FD86E3DE569F221C92EAB0F7B53111595CFC4BF077105824F8D989F70CDEC4096A4344A9CE2FD94C2DB59DADA54FDFC37AA7AA3E38F7C5A31DD8118C152ACF4B
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@. %Z.@.....@.....@.....@.....@.....@......&.{902DEE9F-A3DC-4D62-B01C-3B932DB5BDF6}..Setup..installer64v1.2.8.msi.@.....@.....@.....@........&.{14AE419F-2981-493A-9AFA-8F2D89F7D3E5}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\5db60d.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@[)ks.@B.w..@ABJ$.@s.t......._....J..._.@A.......j.MZx.....................@..........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      Joe Sandbox View:
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: setup64v8.5.6.msi, Detection: malicious, Browse
                      • Filename: setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v8.6.7.msi, Detection: malicious, Browse
                      • Filename: setup64v8.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v9.3.4.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1676977730224594
                      Encrypted:false
                      SSDEEP:12:JSbX72FjfAGiLIlHVRpwh/7777777777777777777777777vDHF9F+bgXL7jXl0G:JlQI5YJ+++F
                      MD5:83C563F2B6D4800020EE9E360EAF3F69
                      SHA1:32006D5A593AD6D4E779B9462F11488B733D8C0E
                      SHA-256:69A1C141996C63266F6ED0054CC9D2E0B6B6591C2CF6A2926C1B468A4E7FF6CF
                      SHA-512:F814C8E074CE6CD88C07210931103671DCD22AEA6B7B64F2267297EF729B0A9D268691037756C6353F8DC07D81F460A2A92A4B40F471A22E20804BA47F57EF20
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.463297242859138
                      Encrypted:false
                      SSDEEP:48:E8PhkuRc06WXJIFT5DSdeS5ArCdeSIbdp:bhk1rFTdP7v
                      MD5:768854D1A91CD40F634F034C7FD147AC
                      SHA1:33449BC5AFE5C4378BE6934F0A3A455FCC8602EE
                      SHA-256:5BFB197DE730483F560F299F6E4932B053C234189D25DA9E776B0CFC7E7CBC07
                      SHA-512:2E8A115DB33CAE1D833309FCBFBD39F2BEBB5CD52D1A2EE4A2A3BCD9AF2B439B7A223E6019D6C65889820B7C7B365AD4847E395A1AC3335D73141B56D4C4BA69
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):363829
                      Entropy (8bit):5.365419774191549
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgauh:zTtbmkExhMJCIpEg
                      MD5:DC91B2B8FD608B422CB86447DF02D666
                      SHA1:C5616B0D6EE757D8AC5E5B29312D8DF6B1E0ADB4
                      SHA-256:412066C96B816B061F3A9401335789D51357C7F0E606FF0D940ABDEA3A1ACA31
                      SHA-512:556EA2250C1AC8F08777C8ABBC31A5A3F3038A004931BA0DCFDD5025B5886256DA6629240FC66EE37C7E4551F6EFF1FEC71767594AB8E9C4923D12AEA20C2B1B
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.463297242859138
                      Encrypted:false
                      SSDEEP:48:E8PhkuRc06WXJIFT5DSdeS5ArCdeSIbdp:bhk1rFTdP7v
                      MD5:768854D1A91CD40F634F034C7FD147AC
                      SHA1:33449BC5AFE5C4378BE6934F0A3A455FCC8602EE
                      SHA-256:5BFB197DE730483F560F299F6E4932B053C234189D25DA9E776B0CFC7E7CBC07
                      SHA-512:2E8A115DB33CAE1D833309FCBFBD39F2BEBB5CD52D1A2EE4A2A3BCD9AF2B439B7A223E6019D6C65889820B7C7B365AD4847E395A1AC3335D73141B56D4C4BA69
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1794559760818277
                      Encrypted:false
                      SSDEEP:24:JwhC3nMuxhiCipKP2xza2tzhAhZfagUMClXtd85N8+H1dB5GipV7VPwGKlrkgCdS:BnMufPveFXJNT5JSdeS5ArCdeSIbdp
                      MD5:4568E9217A587A7CD223352158FDFCA1
                      SHA1:D96E7E2B7C4DDD3C99355885A3A9C10301309DAD
                      SHA-256:F99CAE85EFAF9C1AC7517EE6EBBEFBAE4AC68530EEB15B84EBDC242AB89545F5
                      SHA-512:D1ACB9491A72DEC004BF60DD6CB6EC08C7585C3B81DCA52A711A6DE804D6DCB5A2A0565AE81D9F48364804FDFE5DF005B444946DB98EB2DC7FF858A57A86C813
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.463297242859138
                      Encrypted:false
                      SSDEEP:48:E8PhkuRc06WXJIFT5DSdeS5ArCdeSIbdp:bhk1rFTdP7v
                      MD5:768854D1A91CD40F634F034C7FD147AC
                      SHA1:33449BC5AFE5C4378BE6934F0A3A455FCC8602EE
                      SHA-256:5BFB197DE730483F560F299F6E4932B053C234189D25DA9E776B0CFC7E7CBC07
                      SHA-512:2E8A115DB33CAE1D833309FCBFBD39F2BEBB5CD52D1A2EE4A2A3BCD9AF2B439B7A223E6019D6C65889820B7C7B365AD4847E395A1AC3335D73141B56D4C4BA69
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1794559760818277
                      Encrypted:false
                      SSDEEP:24:JwhC3nMuxhiCipKP2xza2tzhAhZfagUMClXtd85N8+H1dB5GipV7VPwGKlrkgCdS:BnMufPveFXJNT5JSdeS5ArCdeSIbdp
                      MD5:4568E9217A587A7CD223352158FDFCA1
                      SHA1:D96E7E2B7C4DDD3C99355885A3A9C10301309DAD
                      SHA-256:F99CAE85EFAF9C1AC7517EE6EBBEFBAE4AC68530EEB15B84EBDC242AB89545F5
                      SHA-512:D1ACB9491A72DEC004BF60DD6CB6EC08C7585C3B81DCA52A711A6DE804D6DCB5A2A0565AE81D9F48364804FDFE5DF005B444946DB98EB2DC7FF858A57A86C813
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10275634963528399
                      Encrypted:false
                      SSDEEP:24:7STlp/CZLdB5GipVGdB5GipV7VPwGKlrkgkC+K:8p/CldeScdeS5ArT
                      MD5:9DE477DA61DA46371199C9378DA339B2
                      SHA1:3E101A1B5BB1D0544660C7C77FD18A985F2D399E
                      SHA-256:994D8DCF5E40C51E66E2C0D6C438CAF1FE37BC4F9781A8B295E6074A8F834B63
                      SHA-512:C4EFEDCF019C693AA4F7B62B5618970CF4087A0F94EF8AC10EAA48667A011A93975ACF7AD6D82B186D65A9C8662A2C96B5C5C2977D91825B1BF4EA6491A035B9
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1794559760818277
                      Encrypted:false
                      SSDEEP:24:JwhC3nMuxhiCipKP2xza2tzhAhZfagUMClXtd85N8+H1dB5GipV7VPwGKlrkgCdS:BnMufPveFXJNT5JSdeS5ArCdeSIbdp
                      MD5:4568E9217A587A7CD223352158FDFCA1
                      SHA1:D96E7E2B7C4DDD3C99355885A3A9C10301309DAD
                      SHA-256:F99CAE85EFAF9C1AC7517EE6EBBEFBAE4AC68530EEB15B84EBDC242AB89545F5
                      SHA-512:D1ACB9491A72DEC004BF60DD6CB6EC08C7585C3B81DCA52A711A6DE804D6DCB5A2A0565AE81D9F48364804FDFE5DF005B444946DB98EB2DC7FF858A57A86C813
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07425031053905752
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOQNS1FuvPDgXTRlDtCVky6ljX:2F0i8n0itFzDHF9F+bgXL7jX
                      MD5:61ADB5DDFBC1DFC6976C1EE973F11E73
                      SHA1:DA39E31453BD220B005C44C282DDB7EAAAC85B96
                      SHA-256:10DB9DC3E7AF4B5ACFDC71C2776435312FB2F5E3CE6B7C0D908C986C86F983CF
                      SHA-512:1B0E49DB2E1B90A3911AF0D8F385A2FA0E0E35B17315FA1B1160BB62FC7B767608C2145D4804F660F12647E6AAF95405A8C9F102B3D61AFF6B9237026C39BA64
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: sdfertgtuj, Template: Intel;1033, Revision Number: {14AE419F-2981-493A-9AFA-8F2D89F7D3E5}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.98625211960116
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:installer64v1.2.8.msi
                      File size:8'335'360 bytes
                      MD5:1bdab98ace357167c92c22d58271c644
                      SHA1:295277eb9889ecd955b5117e2cc3afc5de2ea392
                      SHA256:1b0de1c0fbe215ee45c39210abbfb6b24cc9fd1c23f126d7f2fa3ec10c2e7d0d
                      SHA512:2a78432f83a7a779dee77b93524c1016ffb41a1024df761e9b9c74f6cc44e683b5c68e2e5dd5a764b30346bf96d0f1db8f71d1efc68cae9627cdd3457fac5eb0
                      SSDEEP:196608:o4LtplhBB6TCe30s0TDnNPfctFaEfVr7yBh1LRTKf4O:o4Ltplhj6TCe30s0npfcy67yBHLgfV
                      TLSH:5D863321B89F92F7F5776B360E5072A20052AEB057B3814667143F4C047DBB4E6BBA2D
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 5, 2025 10:07:17.867947102 CET5758653192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:17.872721910 CET53575861.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:17.873378992 CET5758653192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:17.878148079 CET53575861.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:18.337996960 CET5758653192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:18.342842102 CET53575861.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:18.344255924 CET5758653192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:32.413512945 CET5447953192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:32.418351889 CET53544791.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:32.418461084 CET5447953192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:32.423268080 CET53544791.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:32.871397972 CET5447953192.168.2.101.1.1.1
                      Jan 5, 2025 10:07:32.876386881 CET53544791.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:32.876487970 CET5447953192.168.2.101.1.1.1
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 5, 2025 10:07:17.865839958 CET53507151.1.1.1192.168.2.10
                      Jan 5, 2025 10:07:32.413002968 CET53514871.1.1.1192.168.2.10

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:4
                      Start time:04:06:58
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v1.2.8.msi"
                      Imagebase:0x7ff72cde0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:5
                      Start time:04:06:58
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff72cde0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:8
                      Start time:04:07:01
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 9A5F5B462856F04E262DE6355F0EDC38 E Global\MSI0000
                      Imagebase:0x7ff72cde0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly