Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v6.4.5.msi

Overview

General Information

Sample name:setup64v6.4.5.msi
Analysis ID:1584380
MD5:539f9b9c6c904867e3638053c444cf28
SHA1:0ba29914b793b01a919f014863ff324689431784
SHA256:06a94174603a072d5eee1ff190f41d5e7e514477034f092242b5e4ca727a00f8
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7456 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.4.5.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7504 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7628 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 21B8D4016A1EA3ECD3BA8555C45D5459 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI2E58.tmpReversingLabs: Detection: 15%
Source: setup64v6.4.5.msiReversingLabs: Detection: 15%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6f22dd.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{D7A38DDC-AC36-4DEE-8972-DC0C67531B11}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2A50.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6f22df.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\6f22df.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2E58.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\6f22df.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI2E58.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI2E58.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: setup64v6.4.5.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs setup64v6.4.5.msi
Source: MSI2E58.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI2E58.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI2E58.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF3B664023A573217F.TMPJump to behavior
Source: setup64v6.4.5.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: setup64v6.4.5.msiReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.4.5.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 21B8D4016A1EA3ECD3BA8555C45D5459 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 21B8D4016A1EA3ECD3BA8555C45D5459 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v6.4.5.msiStatic file information: File size 8540160 > 1048576
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name:
Source: MSI2E58.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI2E58.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI2E58.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI2E58.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2E58.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2E58.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI2E58.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7668Thread sleep count: 816 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exe TID: 7668Thread sleep count: 50 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584380 Sample: setup64v6.4.5.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI2E58.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v6.4.5.msi16%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI2E58.tmp16%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0017.t-0009.t-msedge.net
13.107.246.45
truefalse
    high
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1584380
    Start date and time:2025-01-05 10:10:20 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 4m 33s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:9
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:setup64v6.4.5.msi
    Detection:MAL
    Classification:mal60.winMSI@4/21@0/0
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • Found application associated with file extension: .msi
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
    • Excluded IPs from analysis (whitelisted): 13.107.246.45, 4.245.163.56
    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    • VT rate limit hit for: setup64v6.4.5.msi
    No simulations
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    s-part-0017.t-0009.t-msedge.net3LcZO15oTC.exeGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    3LcZO15oTC.exeGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    Tax_Refund_Claim_2024_Australian_Taxation_Office.jsGet hashmaliciousRemcosBrowse
    • 13.107.246.45
    4XYAW8PbZH.exeGet hashmaliciousRemcosBrowse
    • 13.107.246.45
    GpuXmm386e.msiGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    yKkpG6xM4S.msiGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    IlPF8gbvGl.msiGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    iGhDjzEiDU.exeGet hashmaliciousRemcosBrowse
    • 13.107.246.45
    random.exeGet hashmaliciousUnknownBrowse
    • 13.107.246.45
    3lhrJ4X.exeGet hashmaliciousLiteHTTP BotBrowse
    • 13.107.246.45
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    C:\Windows\Installer\MSI2E58.tmpsetup64v2.4.3.msiGet hashmaliciousUnknownBrowse
      setup64v4.5.6.msiGet hashmaliciousUnknownBrowse
        installer64v1.2.8.msiGet hashmaliciousUnknownBrowse
          setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
            setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
              setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
                setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
                  setup64v8.5.6.msiGet hashmaliciousUnknownBrowse
                    setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
                      setup64v8.6.7.msiGet hashmaliciousUnknownBrowse
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):7003358
                        Entropy (8bit):7.986515577568035
                        Encrypted:false
                        SSDEEP:196608:KB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OR:C6TCe30s0nvfcy67yBHLgfVR
                        MD5:65F674C80C8ECBD9CA7BCF1DBA6F254C
                        SHA1:BBEB8D67FEAEC5C6A3BC1F956F857481C7086471
                        SHA-256:08653B2D543D1A15946CB4466287408FA695500570ACEACE9A25150528ED35B6
                        SHA-512:6B75D7C37E26203FE05B345EDA0042D03E2F55F0F1943A6995B6D7CDE5A1C76B1DE90F0FCB46502C2077551035A9463BE8CF98347021254B53849786FFED50B8
                        Malicious:false
                        Reputation:low
                        Preview:...@IXOS.@.....@i!%Z.@.....@.....@.....@.....@.....@......&.{D7A38DDC-AC36-4DEE-8972-DC0C67531B11}..Setup..setup64v6.4.5.msi.@.....@.....@.....@........&.{4198A649-CA9C-48E1-82C0-DCC44C80A936}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{D7A38DDC-AC36-4DEE-8972-DC0C67531B11}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):1502400
                        Entropy (8bit):7.999874508810137
                        Encrypted:true
                        SSDEEP:24576:er35nlD00PEY4dT6hGCdJwCDkqt7E9psR0BziY4JMp7Vbr0tJJUI76XvEtTOAV1O:exlAXydJwAdo9pFBW2qJ7AvQ6ALDy
                        MD5:FB8D181419A2EF7DD7D97AA3A0F9D851
                        SHA1:167F73D2BDC19E4599536F16611854F055491773
                        SHA-256:425477CFCFA2D43F5F6A46E25FB51384461F89246960F32FBE7756EABC204615
                        SHA-512:D7B8A30F559F2EAB1344BB351C6B4EE4D2D4A8B1E5DB715BA5BE7ED19718542D22CADD2FB9CD9F778602110E3F6CEE140BF900B9393020E9F2FBBB36AF8A732A
                        Malicious:false
                        Reputation:low
                        Preview:.@S...."..v..................^q...QfX....-.?..Z..'..R.!tG..m..c.#....!...FSdS...[.}.@Z.B.XhL....di.."-.b...x.f.x.&...y.........`..X.W.1.;qf./h.fB.....4s.-<=i.@..+....=....'<...5...b....8.p=.H"'={.Vx..Q;g..........3`i...d._..K.......f~X...$B..9O.-7..N..P..9~.....R..D..]........?. .|.|NA...{.D...;...>.Ef.l*D..;..Kqb\.....Np.z!B....>*e.....x+..4...I.+d{I. .%h..)#..(.\.t[.......K.]<...N....uL...)....J.N.F#..7r......1.....-A.n...]>.H..e.A.lvp.dL...'.....\azX...L.gK..CB..@.....;..lj.mLw JU......&..6i..R.i?.~T..eZw.O...6./..x8...V3...I&..Zt+ LU...l......U.V..a..k.Z..../%.5x.Z.by..4..l.=..T.....")Z..67&w...Il.`1.......i....8.z..$+0.r.~"Hg..e...&..J4...oq6...=.o/.-$..s.m.o..2.?.}:T..=...o6....y...........N`9j+g......}a.#{.xkb.....+........Y.........[.@TX.a.DXb.[.~....X..=n5..{.q.b..8.j.(./..!7Y....".@6.QP:[j.X...../.Y...N..z..i8E.....|...p.B..2)...x...........OPO.|.Pl .-!...~..b|...:.Bx.M....u\.\.w...3.p....R....Qa.a=5V[.V|R.-L{./.;....6..F.:&.$:.BW...
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: wrqfegfhghk, Template: Intel;1033, Revision Number: {4198A649-CA9C-48E1-82C0-DCC44C80A936}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Category:dropped
                        Size (bytes):8540160
                        Entropy (8bit):7.987104849421101
                        Encrypted:false
                        SSDEEP:196608:qzBQdALbB6TCe30s0TDZHPfctFaEfVr7yBh1LRTKf4R:qVQq6TCe30s0Zvfcy67yBHLgfC
                        MD5:539F9B9C6C904867E3638053C444CF28
                        SHA1:0BA29914B793B01A919F014863FF324689431784
                        SHA-256:06A94174603A072D5EEE1FF190F41D5E7E514477034F092242B5E4CA727A00F8
                        SHA-512:9ABEB0FB778BCC224C3F081B464327A1957B8E9A865E9FF6AF89637543FED5F7821FC5F1716E3D655220D554E70FAEE691432C248A25287AD6D0872A92CF5D14
                        Malicious:false
                        Reputation:low
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: wrqfegfhghk, Template: Intel;1033, Revision Number: {4198A649-CA9C-48E1-82C0-DCC44C80A936}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Category:dropped
                        Size (bytes):8540160
                        Entropy (8bit):7.987104849421101
                        Encrypted:false
                        SSDEEP:196608:qzBQdALbB6TCe30s0TDZHPfctFaEfVr7yBh1LRTKf4R:qVQq6TCe30s0Zvfcy67yBHLgfC
                        MD5:539F9B9C6C904867E3638053C444CF28
                        SHA1:0BA29914B793B01A919F014863FF324689431784
                        SHA-256:06A94174603A072D5EEE1FF190F41D5E7E514477034F092242B5E4CA727A00F8
                        SHA-512:9ABEB0FB778BCC224C3F081B464327A1957B8E9A865E9FF6AF89637543FED5F7821FC5F1716E3D655220D554E70FAEE691432C248A25287AD6D0872A92CF5D14
                        Malicious:false
                        Reputation:low
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):6997666
                        Entropy (8bit):7.986815236978612
                        Encrypted:false
                        SSDEEP:196608:wB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Op:Q6TCe30s0nvfcy67yBHLgfVp
                        MD5:B000203E99607C3AC7FAE95110B134BB
                        SHA1:092C534408AC3B6EB0FC400C2C236634987F3958
                        SHA-256:ED7BDB9A8F907E5FA2FC266675A78665F03210BB714F2BFE09AA4C22F172A9B9
                        SHA-512:38C47307C39064B913D4D362814766A33AF4ABEC7FD78B411334E296B023AE1A3FD33EAE01C00E2530A2DC7CAC736367E8D0FE7CB190D7B20B0B33A4A3A0C05E
                        Malicious:false
                        Reputation:low
                        Preview:...@IXOS.@.....@i!%Z.@.....@.....@.....@.....@.....@......&.{D7A38DDC-AC36-4DEE-8972-DC0C67531B11}..Setup..setup64v6.4.5.msi.@.....@.....@.....@........&.{4198A649-CA9C-48E1-82C0-DCC44C80A936}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\6f22dd.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@.....@...}.@..z..@...Q......_....J..._.@A.......j.MZx.....................@..............................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                        Category:modified
                        Size (bytes):6995968
                        Entropy (8bit):7.9868922155503945
                        Encrypted:false
                        SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                        MD5:735124825FE57CBDDBC31F3CF1248171
                        SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                        SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                        SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 16%
                        Joe Sandbox View:
                        • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                        • Filename: setup64v4.5.6.msi, Detection: malicious, Browse
                        • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                        • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                        • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                        • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                        • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                        • Filename: setup64v8.5.6.msi, Detection: malicious, Browse
                        • Filename: setup64v3.6.5.msi, Detection: malicious, Browse
                        • Filename: setup64v8.6.7.msi, Detection: malicious, Browse
                        Reputation:moderate, very likely benign file
                        Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.164200997438174
                        Encrypted:false
                        SSDEEP:12:JSbX72FjuAGiLIlHVRpEh/7777777777777777777777777vDHFsDbLW/l0i8Q:JEQI5UeF
                        MD5:4D1E983910C451EB7D240D0BE4F284A7
                        SHA1:9D6BFE3E4B33DEC5379D7716E47C161D1657024D
                        SHA-256:D191FE2E70DE340B05DE1E9A6B92D52B928D0D0A419EED2CAE2F490204A98B6E
                        SHA-512:EBFAD11840CBB752E44EE189506629DDDCCBBB8B7E005F7E4002B44780253BBC81BDCCE1233554AACA79B7A78C974D33CFA2317632847990EBDC886020122A0A
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4611584294833277
                        Encrypted:false
                        SSDEEP:48:g8PhkuRc06WXJwFT5rAtu9deS5g0rCdeSIJ79h4iD:Phk1zFTlAkudox7t
                        MD5:D76A8A4426441B8AA2C6C89AE008DCEF
                        SHA1:4D26EFAB09E8BF7A49C41AF586E0055F24E596ED
                        SHA-256:B5412914C5FF9D58638E0B899AA07F8DF23D8534688E20FDB2D483F4969511DD
                        SHA-512:081E1147FBFD27358C15B57CB2B3ABBF653886DC62F08A6A2086985E4574A5A4EBACF56850155C98C7E5E979DD78F593AACF3339CE89892294C09A1C2C059F7D
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):360001
                        Entropy (8bit):5.362952754721141
                        Encrypted:false
                        SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauI:zTtbmkExhMJCIpE9
                        MD5:682F5948B3356FE82CBDEA7772E22742
                        SHA1:AA019F9BAF085EF1C33057EB6645C2F367DEACF9
                        SHA-256:00DEBEEF1CC21E73D97354E07C8ED6C44BFE29F09768F7E95935FD0FBE3109B5
                        SHA-512:70F9EFFAF7BE4CA341C7755E6EBF4347709291D2D5389F652222D78193768F0C30EFFB82FF6454E9DE64F2B4E86A6E13D9E72F0FC8B619B9375D2811B6127A28
                        Malicious:false
                        Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):0.07281589432529563
                        Encrypted:false
                        SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOUhi8+SMfWkSVky6lV1:2F0i8n0itFzDHFsDbLW/
                        MD5:389386E967BA2DE5BE90C7E0264ECEA0
                        SHA1:012149B84854BC30805428E69887DE844189F981
                        SHA-256:BC01AEC51A28B813CCE845CA57796ABA9414A2745CC92C5EDE97F7146A22179B
                        SHA-512:DADA3E9CD66822D94868A99264FA49B4044A3F264E088E1815A32FB14310E0D7D4470F461EE756079E6B98474FBE79E71D80A0984037AA1A84BFBA433956920A
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.1779943697728221
                        Encrypted:false
                        SSDEEP:48:znMufPveFXJ1T5JAtu9deS5g0rCdeSIJ79h4iD:rMVdTvAkudox7t
                        MD5:C3C36112263846097CFEB36B278E2E07
                        SHA1:EF928AB94C2184C59972078167731D4E5D5EBEBF
                        SHA-256:84C31E2232453F33C768062372F0C76C2FA1AA71EB170CA0CE7D5C7500BD898D
                        SHA-512:FBAE65268116906255ED22006578F7431A6045D3ACE9C041FCE98B168148E1DAE7BD5E5146A9E686137FDABB60B5074A78692CE5A585C7D0D1F3ADCD5F950B9E
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4611584294833277
                        Encrypted:false
                        SSDEEP:48:g8PhkuRc06WXJwFT5rAtu9deS5g0rCdeSIJ79h4iD:Phk1zFTlAkudox7t
                        MD5:D76A8A4426441B8AA2C6C89AE008DCEF
                        SHA1:4D26EFAB09E8BF7A49C41AF586E0055F24E596ED
                        SHA-256:B5412914C5FF9D58638E0B899AA07F8DF23D8534688E20FDB2D483F4969511DD
                        SHA-512:081E1147FBFD27358C15B57CB2B3ABBF653886DC62F08A6A2086985E4574A5A4EBACF56850155C98C7E5E979DD78F593AACF3339CE89892294C09A1C2C059F7D
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):69632
                        Entropy (8bit):0.10194957407747762
                        Encrypted:false
                        SSDEEP:24:Qjh4iDdM1ZLdB5GipVGdB5GipV7VqKwGPlrkgrh+It8:2h4iDdM1ldeScdeS5g0r9nt8
                        MD5:7F03956260DC3F877840D1C2D4F7CCEF
                        SHA1:86D13E3B82860597F41C6F01DD3E3AB702276529
                        SHA-256:FB9BA0294FC1D9E1EA4BB7C9762DE83E365B1EBD9E8889F68B1E7D191F452641
                        SHA-512:F74808C89C3B0A39E46CF9E74CA6F379FA52AEBA95DE5D80C84286C9F408ED5AE45081486899573AD909486F249B9E5199F938821D546189718778F3BF00A8B1
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.1779943697728221
                        Encrypted:false
                        SSDEEP:48:znMufPveFXJ1T5JAtu9deS5g0rCdeSIJ79h4iD:rMVdTvAkudox7t
                        MD5:C3C36112263846097CFEB36B278E2E07
                        SHA1:EF928AB94C2184C59972078167731D4E5D5EBEBF
                        SHA-256:84C31E2232453F33C768062372F0C76C2FA1AA71EB170CA0CE7D5C7500BD898D
                        SHA-512:FBAE65268116906255ED22006578F7431A6045D3ACE9C041FCE98B168148E1DAE7BD5E5146A9E686137FDABB60B5074A78692CE5A585C7D0D1F3ADCD5F950B9E
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.1779943697728221
                        Encrypted:false
                        SSDEEP:48:znMufPveFXJ1T5JAtu9deS5g0rCdeSIJ79h4iD:rMVdTvAkudox7t
                        MD5:C3C36112263846097CFEB36B278E2E07
                        SHA1:EF928AB94C2184C59972078167731D4E5D5EBEBF
                        SHA-256:84C31E2232453F33C768062372F0C76C2FA1AA71EB170CA0CE7D5C7500BD898D
                        SHA-512:FBAE65268116906255ED22006578F7431A6045D3ACE9C041FCE98B168148E1DAE7BD5E5146A9E686137FDABB60B5074A78692CE5A585C7D0D1F3ADCD5F950B9E
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4611584294833277
                        Encrypted:false
                        SSDEEP:48:g8PhkuRc06WXJwFT5rAtu9deS5g0rCdeSIJ79h4iD:Phk1zFTlAkudox7t
                        MD5:D76A8A4426441B8AA2C6C89AE008DCEF
                        SHA1:4D26EFAB09E8BF7A49C41AF586E0055F24E596ED
                        SHA-256:B5412914C5FF9D58638E0B899AA07F8DF23D8534688E20FDB2D483F4969511DD
                        SHA-512:081E1147FBFD27358C15B57CB2B3ABBF653886DC62F08A6A2086985E4574A5A4EBACF56850155C98C7E5E979DD78F593AACF3339CE89892294C09A1C2C059F7D
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: wrqfegfhghk, Template: Intel;1033, Revision Number: {4198A649-CA9C-48E1-82C0-DCC44C80A936}, Create Time/Date: Sat Jan 4 04:39:58 2025, Last Saved Time/Date: Sat Jan 4 04:39:58 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Entropy (8bit):7.987104849421101
                        TrID:
                        • Microsoft Windows Installer (60509/1) 88.31%
                        • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                        File name:setup64v6.4.5.msi
                        File size:8'540'160 bytes
                        MD5:539f9b9c6c904867e3638053c444cf28
                        SHA1:0ba29914b793b01a919f014863ff324689431784
                        SHA256:06a94174603a072d5eee1ff190f41d5e7e514477034f092242b5e4ca727a00f8
                        SHA512:9abeb0fb778bcc224c3f081b464327a1957b8e9a865e9ff6af89637543fed5f7821fc5f1716e3d655220d554e70faee691432c248a25287ad6d0872a92cf5d14
                        SSDEEP:196608:qzBQdALbB6TCe30s0TDZHPfctFaEfVr7yBh1LRTKf4R:qVQq6TCe30s0Zvfcy67yBHLgfC
                        TLSH:1E863361B8EF52FBEA367B320D5472A20042AE742BF6904B5B053F0C147DA70D677A6D
                        File Content Preview:........................>......................................................................................................................................................................................................................................
                        Icon Hash:2d2e3797b32b2b99
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Jan 5, 2025 10:11:10.913096905 CET1.1.1.1192.168.2.90xad9cNo error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                        Jan 5, 2025 10:11:10.913096905 CET1.1.1.1192.168.2.90xad9cNo error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false

                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:04:11:14
                        Start date:05/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v6.4.5.msi"
                        Imagebase:0x7ff70de70000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:2
                        Start time:04:11:14
                        Start date:05/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\msiexec.exe /V
                        Imagebase:0x7ff70de70000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:3
                        Start time:04:11:17
                        Start date:05/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\System32\MsiExec.exe -Embedding 21B8D4016A1EA3ECD3BA8555C45D5459 E Global\MSI0000
                        Imagebase:0x7ff70de70000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        No disassembly