Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
installer64v6.2.4.msi

Overview

General Information

Sample name:installer64v6.2.4.msi
Analysis ID:1584379
MD5:2acf1781557f30f01b68a850332c07d1
SHA1:8f5eab6710a76e96fe87caedaa0aab2d1b41695b
SHA256:15cfe8889cf12035c69b8b8c9d20d8a8af7dfcd6d791dbc9f40189d740bdbfe4
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 4184 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v6.2.4.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7004 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 2884 cmdline: C:\Windows\System32\MsiExec.exe -Embedding CA1B9A227C14880B00C2304542C63EB5 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI3A5D.tmpReversingLabs: Detection: 15%
Source: installer64v6.2.4.msiVirustotal: Detection: 11%Perma Link
Source: installer64v6.2.4.msiReversingLabs: Detection: 15%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6c3163.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{A40907DC-3DD2-48E9-9D3B-EA2001DE3431}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3635.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6c3165.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6c3165.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3A5D.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\6c3165.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI3A5D.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI3A5D.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: installer64v6.2.4.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs installer64v6.2.4.msi
Source: MSI3A5D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI3A5D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI3A5D.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFDC4BE606648DBC4C.TMPJump to behavior
Source: installer64v6.2.4.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: installer64v6.2.4.msiVirustotal: Detection: 11%
Source: installer64v6.2.4.msiReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v6.2.4.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding CA1B9A227C14880B00C2304542C63EB5 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding CA1B9A227C14880B00C2304542C63EB5 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: installer64v6.2.4.msiStatic file information: File size 9072640 > 1048576
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name:
Source: MSI3A5D.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI3A5D.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI3A5D.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI3A5D.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3A5D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3A5D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI3A5D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 3832Thread sleep count: 646 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584379 Sample: installer64v6.2.4.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI3A5D.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
installer64v6.2.4.msi12%VirustotalBrowse
installer64v6.2.4.msi16%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI3A5D.tmp16%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584379
Start date and time:2025-01-05 10:10:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:installer64v6.2.4.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 4.245.163.56
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI3A5D.tmpsetup64v2.4.3.msiGet hashmaliciousUnknownBrowse
    setup64v4.5.6.msiGet hashmaliciousUnknownBrowse
      installer64v1.2.8.msiGet hashmaliciousUnknownBrowse
        setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
          setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
            setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
              setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
                setup64v8.5.6.msiGet hashmaliciousUnknownBrowse
                  setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
                    setup64v8.6.7.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003374
                      Entropy (8bit):7.986516432730403
                      Encrypted:false
                      SSDEEP:196608:CB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Or:66TCe30s0nvfcy67yBHLgfVr
                      MD5:898BF79FDD25BDE5BC50F3851881D91E
                      SHA1:C412340B8B237C5EA542D86357F3B41AC82755E2
                      SHA-256:379AF1B902F29C340BAA515BCB3D35C46A8B0D7AA1F0C0C449D30A09A5C8073E
                      SHA-512:E1D2D8B99D36EB42C6E949C4EF717BC8AB42D8B2E555BAF6A7C63DFAE6074A0E494DFEB6D79C5DD532FDCE19D558C04669F9B8CE88B9943D356E2223AEBE6BA4
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@j!%Z.@.....@.....@.....@.....@.....@......&.{A40907DC-3DD2-48E9-9D3B-EA2001DE3431}..Setup..installer64v6.2.4.msi.@.....@.....@.....@........&.{0CB1E39A-6BF2-4A52-9B51-3C3EBE20B288}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{A40907DC-3DD2-48E9-9D3B-EA2001DE3431}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):2033840
                      Entropy (8bit):7.9999236788638495
                      Encrypted:true
                      SSDEEP:49152:ePvEas9HEbvhCGI3BodWhREYm+XILZ1kshA:eXEOFvI3idw+Ym+YLZOs6
                      MD5:C1A7E0A324B01DC9A649FB33EF8339F4
                      SHA1:FAA2C8D89B711E10C9EFB14EC69435F744101F6B
                      SHA-256:325D5306D62F91275B99EF557F3D95FB2947BA4911809AE23171A29A9F7DD765
                      SHA-512:33E73AC2D4B9BEF3491B420F8E3CD5F5C30A12A86242A98E0E199F23D21F41ED7F249E45FC71D1E4A0391DB65B7341D7636563F5256CC2163DFBFA9CAF4D5B9C
                      Malicious:false
                      Reputation:low
                      Preview:.@S.......................].O.8..`N.....g.mi.`._!c...e.....I..P!..X...O...E".zb...._J.....:r.N.Q..d.z..^=>......v.+O.B........*.:....AB:MAB...x~h...h`].......;.:...."#1x[K..Y./.F....?_`..h.P8.C.s...~.T...a4)1fB#&..y;.{*.9.>*8o..pE.|'...l.fR.o.j..MDg.....P.oD9.[./3r...X.U.@...#..<.#[.B.e.o+Z=`.>......Z.X!.SE0......Q...pe..sqMZ..s....-....6$.L..`pw......_8.....o........ }...w.pZYBu.....\.[@...M)up9...Y..y..5J0..5u..4.._(O1....,O..a.YB.Z...$...A.(..|.|....[.$#.+e+.vkE..!......w.C..+.'3M..!8S..w.2ag.M....b....3L..R...E|..Qb=..b.'..O..t.6-97.......t...3Y..K..'..an..lGD........}...c].lW..>..R..&..Z...,.....G..Y.-|ya.-a"...\.>.S.7.i...zA...P%t..e{..:..0.w..H....@..w...+S..9..J.=....B...'.d......K.?Z.....<)......z.v.i.j9....g....Q]..1.Al..E....s........5h.I.KJ..K.Xg.......w:iz..."......&D.PIZ.S..>..WcEx..\..WG.....2....?.vH...6ZD. B....7`. jv]....X..r.....pl's..M..h(.....|...7.....z.O.....g.....-.c.\.g..9D(.....Z8.{...W....v.QS..YCF.r.
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsfhrt, Template: Intel;1033, Revision Number: {0CB1E39A-6BF2-4A52-9B51-3C3EBE20B288}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9072640
                      Entropy (8bit):7.988266094129745
                      Encrypted:false
                      SSDEEP:196608:nN2vvAvvuo0yVyB6TCe30s0TlnHPfctFaEfVr7yBh1LRTK14O:0Iv2oQ6TCe30s0hvfcy67yBHLg1V
                      MD5:2ACF1781557F30F01B68A850332C07D1
                      SHA1:8F5EAB6710A76E96FE87CAEDAA0AAB2D1B41695B
                      SHA-256:15CFE8889CF12035C69B8B8C9D20D8A8AF7DFCD6D791DBC9F40189D740BDBFE4
                      SHA-512:F4E7E1B7B8FB5FA51BD3F94D63933733AD66531C97B1434ACEA62649D1EB6FEB1CC89676BBDD855B1EE865851D3228AF7ABF50A301CE0642A8877A5273E33E25
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsfhrt, Template: Intel;1033, Revision Number: {0CB1E39A-6BF2-4A52-9B51-3C3EBE20B288}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9072640
                      Entropy (8bit):7.988266094129745
                      Encrypted:false
                      SSDEEP:196608:nN2vvAvvuo0yVyB6TCe30s0TlnHPfctFaEfVr7yBh1LRTK14O:0Iv2oQ6TCe30s0hvfcy67yBHLg1V
                      MD5:2ACF1781557F30F01B68A850332C07D1
                      SHA1:8F5EAB6710A76E96FE87CAEDAA0AAB2D1B41695B
                      SHA-256:15CFE8889CF12035C69B8B8C9D20D8A8AF7DFCD6D791DBC9F40189D740BDBFE4
                      SHA-512:F4E7E1B7B8FB5FA51BD3F94D63933733AD66531C97B1434ACEA62649D1EB6FEB1CC89676BBDD855B1EE865851D3228AF7ABF50A301CE0642A8877A5273E33E25
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997676
                      Entropy (8bit):7.986815066881808
                      Encrypted:false
                      SSDEEP:196608:iB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4On:a6TCe30s0nvfcy67yBHLgfVn
                      MD5:5983AD6F0F611523CFD2A833612ABC5F
                      SHA1:8E3D2F73ED1B3CEE73ADBA5746FA5892C451FAD7
                      SHA-256:B496CA8A3D1512E6AF1CFCA4E414500F4743AA6A0D4592119C49F82A1FAE9943
                      SHA-512:5740580CE72CB8B5A2AB05EF6C6353D77BD4F1479AB13F7DBC82079A2DC70B376E44BE4DECCA064F338BA0078EDC974DD2FEF7249920EBD97B9A4307CEC26046
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@j!%Z.@.....@.....@.....@.....@.....@......&.{A40907DC-3DD2-48E9-9D3B-EA2001DE3431}..Setup..installer64v6.2.4.msi.@.....@.....@.....@........&.{0CB1E39A-6BF2-4A52-9B51-3C3EBE20B288}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\6c3163.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@....@$....@.I.3.@.9......_....J..._.@A.......j.MZx.....................@..........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      Joe Sandbox View:
                      • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                      • Filename: setup64v4.5.6.msi, Detection: malicious, Browse
                      • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: setup64v8.5.6.msi, Detection: malicious, Browse
                      • Filename: setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: setup64v8.6.7.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1682517270248005
                      Encrypted:false
                      SSDEEP:12:JSbX72FjqAGiLIlHVRpwh/7777777777777777777777777vDHF6HkEgXonjXl0G:JAQI5YeEDF
                      MD5:E1E8DB408CFB4B144BB7C7249632F5EF
                      SHA1:BCEABAD8E552BC615CBFD7650E908693BD6EDCF0
                      SHA-256:6A8EB8037DD14907666D6EBC40CC7BEF48E803FD0FBBCB92350D9C4864FC4EA0
                      SHA-512:474427CF9C7A7C32BB8E346723D5737A61FBAF80802B4A8425FA709DAFCCD0D0EFFFBEDE8E8B1D8CE8D9BC6AE8808F2C5EB3A394A75406C820789920C869A962
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4662811659498525
                      Encrypted:false
                      SSDEEP:48:18PhAuRc06WXJEFT5gWqdeS58rideSI7NC:YhA1HFTe8XPA
                      MD5:1216ABB24BDC0F3427759F33941FA77C
                      SHA1:9C46B90F5C3CEA4E62E550B9631B48B41A3DE44D
                      SHA-256:131F94E22A7D174515FB9000EB93F9B0311982A84D2FBEE546AA7F76D172EB86
                      SHA-512:754317A9B237934990C78CF76B4FCB96299EBEB7353F8123FE3665007166C0063489C246707B908603AA9541B81AC49D80FF8FA594FE1405355A446AC5307CAE
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):360001
                      Entropy (8bit):5.362965249224102
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauG:zTtbmkExhMJCIpEX
                      MD5:CC6EE740C516B8F9545732EFF867519C
                      SHA1:8698D85A6F31910F17D57418B5CA809B81B12256
                      SHA-256:E953E3EF63FE8FCA89AE911DAF89A753CE5EBA7D34F5138A0636E44F4D8086E5
                      SHA-512:2948107EF5E6ADD3EE7622875853173E2F2A4519B3CB8CDA30101710E7DC38B0056C7C417646BA49DE6C3E4D6F1D4848B6262333CC1E02CE796BE702405EEDDF
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1818130991578055
                      Encrypted:false
                      SSDEEP:24:JYhC3nouxdiCipKP2xza2tzhA9ZfagUMClXtd851+predB5GipV7VPwGOlrkgidn:VnoujPveFXJ5T5qWqdeS58rideSI7NC
                      MD5:FFBC3118A3DD816AEF3A6BD6D4F064E1
                      SHA1:300AA781FB1B6A18A5B628BDAD669E1081E9B5DE
                      SHA-256:4637DEAA142BFA50A391C4129EB1D526C257817BC8AD138C7F6D89C801CED5CC
                      SHA-512:4DBD1E9D7CFE55ED31A776DA2FBF7DA6536DA0FFB4F3DEE0E3F47BBEAFB3025CA8EC921413F769FEE843E1FA5F21AC8EF3E4A364B5004A027D9B1A0CC68FB412
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07452910167399915
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKO6HCYpHOkYBEgXTRihCVky6ljX:2F0i8n0itFzDHF6HkEgXonjX
                      MD5:CC8D76449B48560E588CAB45429808DB
                      SHA1:AED7DFF689588A107232A763356333E37B5AF69C
                      SHA-256:B97ABEE4AB6DFB9389BD7C23B2DD12ADF4D46229AEDD504F5201523A1925F33F
                      SHA-512:C68004F97273396BC3777AD4F32F48EC12A3F226D1D2CC26F003EE43250D3356897DEBB4715936979E48C5B9DF6183008BEFF3EA6DC4D97FC24794E21730C7D0
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4662811659498525
                      Encrypted:false
                      SSDEEP:48:18PhAuRc06WXJEFT5gWqdeS58rideSI7NC:YhA1HFTe8XPA
                      MD5:1216ABB24BDC0F3427759F33941FA77C
                      SHA1:9C46B90F5C3CEA4E62E550B9631B48B41A3DE44D
                      SHA-256:131F94E22A7D174515FB9000EB93F9B0311982A84D2FBEE546AA7F76D172EB86
                      SHA-512:754317A9B237934990C78CF76B4FCB96299EBEB7353F8123FE3665007166C0063489C246707B908603AA9541B81AC49D80FF8FA594FE1405355A446AC5307CAE
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1818130991578055
                      Encrypted:false
                      SSDEEP:24:JYhC3nouxdiCipKP2xza2tzhA9ZfagUMClXtd851+predB5GipV7VPwGOlrkgidn:VnoujPveFXJ5T5qWqdeS58rideSI7NC
                      MD5:FFBC3118A3DD816AEF3A6BD6D4F064E1
                      SHA1:300AA781FB1B6A18A5B628BDAD669E1081E9B5DE
                      SHA-256:4637DEAA142BFA50A391C4129EB1D526C257817BC8AD138C7F6D89C801CED5CC
                      SHA-512:4DBD1E9D7CFE55ED31A776DA2FBF7DA6536DA0FFB4F3DEE0E3F47BBEAFB3025CA8EC921413F769FEE843E1FA5F21AC8EF3E4A364B5004A027D9B1A0CC68FB412
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4662811659498525
                      Encrypted:false
                      SSDEEP:48:18PhAuRc06WXJEFT5gWqdeS58rideSI7NC:YhA1HFTe8XPA
                      MD5:1216ABB24BDC0F3427759F33941FA77C
                      SHA1:9C46B90F5C3CEA4E62E550B9631B48B41A3DE44D
                      SHA-256:131F94E22A7D174515FB9000EB93F9B0311982A84D2FBEE546AA7F76D172EB86
                      SHA-512:754317A9B237934990C78CF76B4FCB96299EBEB7353F8123FE3665007166C0063489C246707B908603AA9541B81AC49D80FF8FA594FE1405355A446AC5307CAE
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1818130991578055
                      Encrypted:false
                      SSDEEP:24:JYhC3nouxdiCipKP2xza2tzhA9ZfagUMClXtd851+predB5GipV7VPwGOlrkgidn:VnoujPveFXJ5T5qWqdeS58rideSI7NC
                      MD5:FFBC3118A3DD816AEF3A6BD6D4F064E1
                      SHA1:300AA781FB1B6A18A5B628BDAD669E1081E9B5DE
                      SHA-256:4637DEAA142BFA50A391C4129EB1D526C257817BC8AD138C7F6D89C801CED5CC
                      SHA-512:4DBD1E9D7CFE55ED31A776DA2FBF7DA6536DA0FFB4F3DEE0E3F47BBEAFB3025CA8EC921413F769FEE843E1FA5F21AC8EF3E4A364B5004A027D9B1A0CC68FB412
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.1039507320009899
                      Encrypted:false
                      SSDEEP:24:hOr+zCZLdB5GipVGdB5GipV7VPwGOlrkg7rx+:kCzCldeScdeS58r7l
                      MD5:AD3A0D81EA2CD84E3D7FC0CBF97A9DA3
                      SHA1:942F8CEC7A153CCDD742FCED81090478B706BBB7
                      SHA-256:A91EDD3690C2B0C6B213650A5A2F55758BFBA01E8DBBC7CC36BD2252711B5DB0
                      SHA-512:6F6A30E1F8BEE5D9A19CA191E5CC7592EB6A833B86F4380D9F8A543A81CFAEF4BD2A0B2BF38D05B9D8C5BAAF346E852319ED9103D5EB80C41DE3CDE47981AAF3
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsfhrt, Template: Intel;1033, Revision Number: {0CB1E39A-6BF2-4A52-9B51-3C3EBE20B288}, Create Time/Date: Sat Jan 4 04:40:02 2025, Last Saved Time/Date: Sat Jan 4 04:40:02 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.988266094129745
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:installer64v6.2.4.msi
                      File size:9'072'640 bytes
                      MD5:2acf1781557f30f01b68a850332c07d1
                      SHA1:8f5eab6710a76e96fe87caedaa0aab2d1b41695b
                      SHA256:15cfe8889cf12035c69b8b8c9d20d8a8af7dfcd6d791dbc9f40189d740bdbfe4
                      SHA512:f4e7e1b7b8fb5fa51bd3f94d63933733ad66531c97b1434acea62649d1eb6feb1cc89676bbdd855b1ee865851d3228af7abf50a301ce0642a8877a5273e33e25
                      SSDEEP:196608:nN2vvAvvuo0yVyB6TCe30s0TlnHPfctFaEfVr7yBh1LRTK14O:0Iv2oQ6TCe30s0hvfcy67yBHLg1V
                      TLSH:BF963371B89F96FAF575AB724D6071A24042AE7027B280462B047F0C093DBB1E777E6D
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:04:11:14
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\installer64v6.2.4.msi"
                      Imagebase:0x7ff6738b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:2
                      Start time:04:11:15
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff6738b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:04:11:19
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding CA1B9A227C14880B00C2304542C63EB5 E Global\MSI0000
                      Imagebase:0x7ff6738b0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly