Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v4.5.6.msi

Overview

General Information

Sample name:setup64v4.5.6.msi
Analysis ID:1584377
MD5:836b6a2cfe702938dc154dfd256a9537
SHA1:105efdbedd740d8530eec3a62a60efc15211f188
SHA256:e8ed66a74aad1736a15b12e4a080bfe6bf3ad94f9a3051465d0482fe365b3ff3
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 5028 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v4.5.6.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 1960 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 2920 cmdline: C:\Windows\System32\MsiExec.exe -Embedding A3BD070724C9894B03DB4F6598CA4191 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI4AA7.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI4AA7.tmpVirustotal: Detection: 27%Perma Link
Source: setup64v4.5.6.msiVirustotal: Detection: 13%Perma Link
Source: setup64v4.5.6.msiReversingLabs: Detection: 15%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b448b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{C244B00C-3AE7-4A53-B5BB-A2E3DCB6586A}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI468F.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b448d.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3b448d.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4AA7.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\3b448d.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI4AA7.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI4AA7.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: setup64v4.5.6.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v4.5.6.msi
Source: MSI4AA7.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI4AA7.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI4AA7.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF96EB7D49E2542D90.TMPJump to behavior
Source: setup64v4.5.6.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v4.5.6.msiVirustotal: Detection: 13%
Source: setup64v4.5.6.msiReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v4.5.6.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding A3BD070724C9894B03DB4F6598CA4191 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding A3BD070724C9894B03DB4F6598CA4191 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v4.5.6.msiStatic file information: File size 9224192 > 1048576
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name:
Source: MSI4AA7.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI4AA7.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI4AA7.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI4AA7.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4AA7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4AA7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI4AA7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
2
Software Packing
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager11
Peripheral Device Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS11
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
File Deletion
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584377 Sample: setup64v4.5.6.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI4AA7.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v4.5.6.msi14%VirustotalBrowse
setup64v4.5.6.msi16%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI4AA7.tmp16%ReversingLabs
C:\Windows\Installer\MSI4AA7.tmp28%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584377
Start date and time:2025-01-05 10:09:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:setup64v4.5.6.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 20.109.210.53, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI4AA7.tmpinstaller64v1.2.8.msiGet hashmaliciousUnknownBrowse
    setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
      setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
        setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
          setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
            setup64v8.5.6.msiGet hashmaliciousUnknownBrowse
              setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
                setup64v8.6.7.msiGet hashmaliciousUnknownBrowse
                  setup64v8.2.4.msiGet hashmaliciousUnknownBrowse
                    setup64v6.6.5.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003366
                      Entropy (8bit):7.986513704744776
                      Encrypted:false
                      SSDEEP:196608:OB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OH:O6TCe30s0nvfcy67yBHLgfVH
                      MD5:071DB5349BAF7DCA3992C2C7E0436EDB
                      SHA1:31BB6E81375290100D4EF64773446D18F69CE653
                      SHA-256:6C34F84129EBAD477C28A59B84DD4B79226D33658E1E4F8C5758D555964366EA
                      SHA-512:4818270451FC31C0BCF5BB16FEBDDF904A2E9B6E69C9F49AE26B2FF05AFC3532DB6A73B546248F78732E81E1EE174C10005443933A9280F7851DDA5F68CB06AF
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@C!%Z.@.....@.....@.....@.....@.....@......&.{C244B00C-3AE7-4A53-B5BB-A2E3DCB6586A}..Setup..setup64v4.5.6.msi.@.....@.....@.....@........&.{C2FF4594-99D1-47A0-B07D-095AC48E2C6D}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{C244B00C-3AE7-4A53-B5BB-A2E3DCB6586A}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):2185169
                      Entropy (8bit):7.999925034810436
                      Encrypted:true
                      SSDEEP:49152:VCKY0Xc38Xv3J1Dwf4eGXrUc+wchM3k7dfVWm7M64QO:VhHJXvXVjrUbwc+iGm7MeO
                      MD5:4DD56D9A61957D885A4F297906D44F08
                      SHA1:F230E86D83F9382CE14B8D9634DBBDB810FBD688
                      SHA-256:BA37718400B152C8C647F47340E5E1777DDF5AA1B7A6CF65D2D3399BDE1F897F
                      SHA-512:16A2D7AF685E8453F1DD92C68CD4339FC4B28C7900411A3483F98642955A9F4EBB9BFB44E08686B80BE9B345EADC7675B768C1FE70BCB15130387D0C74BF4BFD
                      Malicious:false
                      Reputation:low
                      Preview:.@S...................... .b..(".'.W?Y.F0.f....K....F.....>2....x...R.........zq..aMcqD.3O..+W.H..*,.....';;.....nL..@UCmD.{B.to..<.....O^.0x..8.../....."....H..... 3..[-..O....)....W......(...O.=8B9.q.x...D.]..r^.H..{...F._.=...m...;..`N7..v..a./I........A_.....eRB(.D.4....gwV=....9..X#.H%...o..{....n.K3.'`..)..A..9...].>$.S.V Qx.....1......Y.D..*......`.4.....mc....*...|.&]...{.3..xe*..0}....T6....3!.3U^.8.=%<?......J.$6...9x..9@F..r...\%.....2.z'...A..~RK17s.qP9e.2s..$...Q......RC.u6..o.K.%.....k.Q........h....c..Vg_............@Y..g&dym..HMl...i.....~ ....'.9l.1h..Bi.K.. .7,L.79\f,....A..'.]m.....B...3.L....sB.V.:.3...x..yN:.\...I.1..*....*..;......;J^8..AnF.X....=.....9.@..96......GL...A&.......#..5f...wss..T}Bt 7..../.&..=....3......c.t_.......T..p..M....2...j.8...B....k..>.........&c.y.i.6*n....../>........wLf.[B.....A..kSv..[.....q.l..?\1..;..$..3..4..5&.6.....\M......`A...K.....H...}*f..'.r.B..h..rKU.*n....i.y..u.HG.....-.
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: srtgfdh, Template: Intel;1033, Revision Number: {C2FF4594-99D1-47A0-B07D-095AC48E2C6D}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9224192
                      Entropy (8bit):7.988563569295975
                      Encrypted:false
                      SSDEEP:196608:irTPBHlpl3B6TCe30sKTDnHPfctFaEfVr7yBh1LRTKh4O:0FHlplx6TCe30sKnvfcy67yBHLghV
                      MD5:836B6A2CFE702938DC154DFD256A9537
                      SHA1:105EFDBEDD740D8530EEC3A62A60EFC15211F188
                      SHA-256:E8ED66A74AAD1736A15B12E4A080BFE6BF3AD94F9A3051465D0482FE365B3FF3
                      SHA-512:5B177D4973B08ECB99AB762059831B38AF3403652E0ED3558B3E68A3E69FFBDEC4D7D559FC4A3A9252A11D15EC597CA0859F0496B7AC67E2E577B3E39AC5B0DD
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: srtgfdh, Template: Intel;1033, Revision Number: {C2FF4594-99D1-47A0-B07D-095AC48E2C6D}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9224192
                      Entropy (8bit):7.988563569295975
                      Encrypted:false
                      SSDEEP:196608:irTPBHlpl3B6TCe30sKTDnHPfctFaEfVr7yBh1LRTKh4O:0FHlplx6TCe30sKnvfcy67yBHLghV
                      MD5:836B6A2CFE702938DC154DFD256A9537
                      SHA1:105EFDBEDD740D8530EEC3A62A60EFC15211F188
                      SHA-256:E8ED66A74AAD1736A15B12E4A080BFE6BF3AD94F9A3051465D0482FE365B3FF3
                      SHA-512:5B177D4973B08ECB99AB762059831B38AF3403652E0ED3558B3E68A3E69FFBDEC4D7D559FC4A3A9252A11D15EC597CA0859F0496B7AC67E2E577B3E39AC5B0DD
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997672
                      Entropy (8bit):7.986815071731855
                      Encrypted:false
                      SSDEEP:196608:/B6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Og:Z6TCe30s0nvfcy67yBHLgfVg
                      MD5:E3BE90E77D011FB331E864EB87533408
                      SHA1:52FC73425BF401050252AD3CBFF900ED1CAF0FD2
                      SHA-256:0E525835D5B8CBA1A266E044E5BBAC2651D419C0E0EE8E34801D3CE5872A7307
                      SHA-512:0E9126DF6BF149AAB47C85515F6ACF637830452F3E9E10D0383956B3050D194F1BF51BDBC5B7A785C5417DF2CDB05AA5D3F047753837183AA32C87B8B0F65FFB
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@B!%Z.@.....@.....@.....@.....@.....@......&.{C244B00C-3AE7-4A53-B5BB-A2E3DCB6586A}..Setup..setup64v4.5.6.msi.@.....@.....@.....@........&.{C2FF4594-99D1-47A0-B07D-095AC48E2C6D}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.W!..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\3b448b.msi.........@........file.dat..l4d..file.dat.@.....@.W!..@.......@.............@.........@.....@.....@M.m..@a.}..@ZO)y.@..O......._....J..._.@A.......j.MZx.....................@..............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 28%, Browse
                      Joe Sandbox View:
                      • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: setup64v8.5.6.msi, Detection: malicious, Browse
                      • Filename: setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v8.6.7.msi, Detection: malicious, Browse
                      • Filename: setup64v8.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.6.5.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1661546847855033
                      Encrypted:false
                      SSDEEP:12:JSbX72FjxQAGiLIlHVRpEh/7777777777777777777777777vDHFIFWW/l0i8Q:JnQQI5UmSF
                      MD5:B2CCDB9DF60B7C7458E175EBA6D01C6E
                      SHA1:73460390A234358BD1DA8D7055C9ADF797990679
                      SHA-256:FF554A3A8956BE920157C45D19778E2E7DC6BBF652D70E8DF36F9891F635D642
                      SHA-512:67E24450CC2CAF8CCF25667E91116E43D217B9661EA20081F55B2D3C6434070B4DDF6454707CBC74CB0A4E9CC3400F86CD9BCCB58A7AF81492F992D9FF8320AB
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4656255979215782
                      Encrypted:false
                      SSDEEP:48:98PhAuRc06WXJMnT50kvHJdeS5drideSIWFD0:ghA1vnTrvKqiF
                      MD5:9A342A0847E16AD68B06191C84369FFA
                      SHA1:7F2870A7A04277BA8FF4A33578D47654DD12180E
                      SHA-256:9B1A4897B30E5560C85BE5577826D8C466AFA8A025EDA611628C430C246DD8CF
                      SHA-512:73607FD5FDE2BA448FB69C0AC0D491A001C7C5360123ECF9DD3DE607B98690E38F30DDCEEC7F220A76436A15573D4CF2DF48E33DF6EE4C7AD8083FA85D75EA87
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):364484
                      Entropy (8bit):5.365479436822625
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauP:zTtbmkExhMJCIpEI
                      MD5:7DE3D11E96E1DFCFDAD3AA82EC190B2E
                      SHA1:3D57E494DD0ABEF40ACE94E72621087A02C76BFD
                      SHA-256:D4A9F98A7FC3AAC635718F8FE28091183B690F1E7BC7959D209A9F0BF26B7DB4
                      SHA-512:B722FEF0DC28316E76790F9C3A037EFFA0E8FA4E35029394E43B306181447488CA3117B5B92BF45FEAA76E0587C5898D848F36305A88926018BF05378FA3C864
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1811962921257844
                      Encrypted:false
                      SSDEEP:48:9noujNveFXJjT5ekvHJdeS5drideSIWFD0:xov7TBvKqiF
                      MD5:BD943BD8F47A488E3C2FA2902C3F8D13
                      SHA1:0CFDFAE69DAC0C18694A137D82191F51726DDEBF
                      SHA-256:E2A3C8BD863E41B741F1A960B6C85665C59170913E355C7D3713F353674A7A5B
                      SHA-512:E2E3C431EEAC545B17CF0E0C0DBDC0197BB154605F44327ABE86BFD32BE94747020CA154A74C4C5A62367F79E2D92097864E331D1A668AA8D998A7BDBDC61935
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4656255979215782
                      Encrypted:false
                      SSDEEP:48:98PhAuRc06WXJMnT50kvHJdeS5drideSIWFD0:ghA1vnTrvKqiF
                      MD5:9A342A0847E16AD68B06191C84369FFA
                      SHA1:7F2870A7A04277BA8FF4A33578D47654DD12180E
                      SHA-256:9B1A4897B30E5560C85BE5577826D8C466AFA8A025EDA611628C430C246DD8CF
                      SHA-512:73607FD5FDE2BA448FB69C0AC0D491A001C7C5360123ECF9DD3DE607B98690E38F30DDCEEC7F220A76436A15573D4CF2DF48E33DF6EE4C7AD8083FA85D75EA87
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4656255979215782
                      Encrypted:false
                      SSDEEP:48:98PhAuRc06WXJMnT50kvHJdeS5drideSIWFD0:ghA1vnTrvKqiF
                      MD5:9A342A0847E16AD68B06191C84369FFA
                      SHA1:7F2870A7A04277BA8FF4A33578D47654DD12180E
                      SHA-256:9B1A4897B30E5560C85BE5577826D8C466AFA8A025EDA611628C430C246DD8CF
                      SHA-512:73607FD5FDE2BA448FB69C0AC0D491A001C7C5360123ECF9DD3DE607B98690E38F30DDCEEC7F220A76436A15573D4CF2DF48E33DF6EE4C7AD8083FA85D75EA87
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10368495910549687
                      Encrypted:false
                      SSDEEP:24:mD0jHZLdB5GipVGdB5GipV7VQwGwlrkgq+kxIgk:mD0jHldeScdeS5drqHdk
                      MD5:BD1675FA754701C0105FC6B3419C2F3C
                      SHA1:5DF7B55FC92E14C7800DE2D39147EF023A9952C0
                      SHA-256:8EB833DE825367675FC563774AD49ECF4ECC541E50467E1247BAC4A1D7105732
                      SHA-512:83C9A8D0F7A9A02405096ACE6A21E70D5324035617A22CA7D414B1485BDC0025B1E4AF3CC14715D8231544167929991F3FE4B62F29425FC74A2A5D47505E20F6
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1811962921257844
                      Encrypted:false
                      SSDEEP:48:9noujNveFXJjT5ekvHJdeS5drideSIWFD0:xov7TBvKqiF
                      MD5:BD943BD8F47A488E3C2FA2902C3F8D13
                      SHA1:0CFDFAE69DAC0C18694A137D82191F51726DDEBF
                      SHA-256:E2A3C8BD863E41B741F1A960B6C85665C59170913E355C7D3713F353674A7A5B
                      SHA-512:E2E3C431EEAC545B17CF0E0C0DBDC0197BB154605F44327ABE86BFD32BE94747020CA154A74C4C5A62367F79E2D92097864E331D1A668AA8D998A7BDBDC61935
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07315196838698244
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOs7WKFFWkSVky6lV1:2F0i8n0itFzDHFIFWW/
                      MD5:21584B347E713AA5EAAE04CA8DE97D78
                      SHA1:F025E353EBD5CEB6A11C3A0A99C936BA0263EB71
                      SHA-256:C2C5DA6B08B0E76D7C9DF77D201E717D7CAF4E4A21228AFBE494927693C6994B
                      SHA-512:CDB884BD545907A31423CCA8350422AF6718A1E16E195FE3CD81F375B860C436624307A4A81632321ED1E20B566DFFFAA36D5D2DD37F4939320EE5D2A8E8CCF7
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1811962921257844
                      Encrypted:false
                      SSDEEP:48:9noujNveFXJjT5ekvHJdeS5drideSIWFD0:xov7TBvKqiF
                      MD5:BD943BD8F47A488E3C2FA2902C3F8D13
                      SHA1:0CFDFAE69DAC0C18694A137D82191F51726DDEBF
                      SHA-256:E2A3C8BD863E41B741F1A960B6C85665C59170913E355C7D3713F353674A7A5B
                      SHA-512:E2E3C431EEAC545B17CF0E0C0DBDC0197BB154605F44327ABE86BFD32BE94747020CA154A74C4C5A62367F79E2D92097864E331D1A668AA8D998A7BDBDC61935
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: srtgfdh, Template: Intel;1033, Revision Number: {C2FF4594-99D1-47A0-B07D-095AC48E2C6D}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.988563569295975
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:setup64v4.5.6.msi
                      File size:9'224'192 bytes
                      MD5:836b6a2cfe702938dc154dfd256a9537
                      SHA1:105efdbedd740d8530eec3a62a60efc15211f188
                      SHA256:e8ed66a74aad1736a15b12e4a080bfe6bf3ad94f9a3051465d0482fe365b3ff3
                      SHA512:5b177d4973b08ecb99ab762059831b38af3403652e0ed3558b3e68a3e69ffbdec4d7d559fc4a3a9252a11d15ec597ca0859f0496b7ac67e2e577b3e39ac5b0dd
                      SSDEEP:196608:irTPBHlpl3B6TCe30sKTDnHPfctFaEfVr7yBh1LRTKh4O:0FHlplx6TCe30sKnvfcy67yBHLghV
                      TLSH:16963360B8AF96FAF6316B364D6471A20082FE7027E280461B157F0D047DB71E77BA6D
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:04:10:02
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v4.5.6.msi"
                      Imagebase:0x7ff65a0f0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:04:10:03
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff65a0f0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:04:10:05
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding A3BD070724C9894B03DB4F6598CA4191 E Global\MSI0000
                      Imagebase:0x7ff65a0f0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly