Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
#U7a0b#U5e8fv9.3.5.msi

Overview

General Information

Sample name:#U7a0b#U5e8fv9.3.5.msi
renamed because original name is a hash value
Original sample name:v9.3.5.msi
Analysis ID:1584399
MD5:44843c6b70d7546d4dc7af9b4f28ad34
SHA1:c54d00ba3a1dcc4036b7590e5a55680686e05c78
SHA256:9f344057ed2f934b4975bdb0f5c4c7ff86848b2abf0c1c7ececbaa923173acec
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7520 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.3.5.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7556 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7652 cmdline: C:\Windows\System32\MsiExec.exe -Embedding B68E0724E626022DBC2923D91326CB8F E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSID7CE.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSID7CE.tmpVirustotal: Detection: 27%Perma Link
Source: #U7a0b#U5e8fv9.3.5.msiVirustotal: Detection: 13%Perma Link
Source: #U7a0b#U5e8fv9.3.5.msiReversingLabs: Detection: 15%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\67d29d.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{151028AD-E0D2-409C-B3EC-8348C68EAD59}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID462.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\67d29f.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\67d29f.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID7CE.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\67d29f.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSID7CE.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSID7CE.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: #U7a0b#U5e8fv9.3.5.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs #U7a0b#U5e8fv9.3.5.msi
Source: MSID7CE.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSID7CE.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSID7CE.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFA949CE84E7F39A25.TMPJump to behavior
Source: #U7a0b#U5e8fv9.3.5.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: #U7a0b#U5e8fv9.3.5.msiVirustotal: Detection: 13%
Source: #U7a0b#U5e8fv9.3.5.msiReversingLabs: Detection: 15%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.3.5.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding B68E0724E626022DBC2923D91326CB8F E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding B68E0724E626022DBC2923D91326CB8F E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: #U7a0b#U5e8fv9.3.5.msiStatic file information: File size 9154560 > 1048576
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name:
Source: MSID7CE.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSID7CE.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSID7CE.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSID7CE.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID7CE.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID7CE.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSID7CE.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7700Thread sleep count: 315 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584399 Sample: #U7a0b#U5e8fv9.3.5.msi Startdate: 05/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSID7CE.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
#U7a0b#U5e8fv9.3.5.msi13%VirustotalBrowse
#U7a0b#U5e8fv9.3.5.msi16%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSID7CE.tmp16%ReversingLabs
C:\Windows\Installer\MSID7CE.tmp28%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584399
Start date and time:2025-01-05 12:12:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:#U7a0b#U5e8fv9.3.5.msi
renamed because original name is a hash value
Original Sample Name:v9.3.5.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 4.245.163.56, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSID7CE.tmpsetup64v6.4.5.msiGet hashmaliciousUnknownBrowse
    installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
      setup64v2.3.5.msiGet hashmaliciousUnknownBrowse
        setup64v2.4.3.msiGet hashmaliciousUnknownBrowse
          setup64v4.5.6.msiGet hashmaliciousUnknownBrowse
            installer64v1.2.8.msiGet hashmaliciousUnknownBrowse
              setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
                setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
                  setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
                    setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003373
                      Entropy (8bit):7.986515904802159
                      Encrypted:false
                      SSDEEP:196608:xB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Oi:z6TCe30s0nvfcy67yBHLgfVi
                      MD5:E1569E7728CBD09AF79485A353366497
                      SHA1:107D7C0FF0854EDEAFFAC02144782DEBA2ED6081
                      SHA-256:ED437E977D4F47EC1B22C94D3581A4409419BE4B9AD326EB4AF1C8C5D13EBF61
                      SHA-512:0452BC0ADCF7FBD095D8DE3AE0246B4D99BA1ADB6D1F5E8130FA1E4C4AE4038A4A70EF1F1EFDBFA68BC4C860554087D63181005F99C42E4500874F23ADE2256E
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.1%Z.@.....@.....@.....@.....@.....@......&.{151028AD-E0D2-409C-B3EC-8348C68EAD59}..Setup..#U7a0b#U5e8fv9.3.5.msi.@.....@.....@.....@........&.{6620BA4B-19A8-4D89-ACA5-026A228776D7}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{151028AD-E0D2-409C-B3EC-8348C68EAD59}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):2115809
                      Entropy (8bit):7.999896242794777
                      Encrypted:true
                      SSDEEP:49152:x8kDERr/7EjtVDPVlAWD7s/6z5wJEa1TPAXASp9D4nn5TCJ58vF6:5EJ/72jTjzD705TPHSp9D4n5TS5AM
                      MD5:A3C6309B31098FDC3C8832CF1782D6E4
                      SHA1:24D20EF333D199B5BDF009ADDFCA6C60D2AECEAA
                      SHA-256:1B217F8442E59415833BB4D192AEC251FC00AAC94990B510E2B4178319858843
                      SHA-512:C60D04CA935C74B6DCDB18B1B3AAE968FBB80B2D8CC5626B99B8A10809CF44F2C5EB95B0BF7E7EB4F295B8EFC450E77A15E5DDAE0742446D68202A26567DE1D9
                      Malicious:false
                      Reputation:low
                      Preview:.@S....Z.M.|...............>.8...U........p.<efU..l....g..9u.....=#..B.....dfI.*.5...o......=..C.....v...x.}f..4j..^..L4S..<.....<...)..k`|....[.so.~..8..`..s.4E[..........p4>..$.'.rH...RO.W..;.vkQ.D......R.....V~9.?......ku..D?UnU.,......F....0,..'...e.......E,..'beM.BC.<./.."..t........9.2..TO......i.Ni...6...1;hnsI.......D.Fr.(^+..r.3..W.A.=...T.".F...o].{.........s....b.g......>....R.`3..0......j2...U..$.6'.l..@".UY..?. '....nD9#..z...jt....^..M....n.....E...!,.......w.`".PuF..=D.D.h..3.....CrS...{..2..l}...>.....%.........4....FGO(.}....>7M....l.zpN......^<Ro..._..g..u..].R.B-.......`{.?.>...p.8.=....s<..x_.Ga.7.K..qSd.V...L`J..!J..z...!.1...*]~...t.K."....W.....7...%.O.....)..l!f.f....Z>.TP ...&...b1!88...,.%pRGr;...j.......<V....+0f&.k.....l@XU(....*.>.k.KV...T.'...;.\A..&1u..x...GJ..AK...t@....r........`.VLj..fp..b.8..WQ*...o..^.f...`.."yU.o.%E..05@.g......&e.?.Kh8g..@....F..k..e;."9[1.v/..B...MH.K.<x...eB...y...4..>%.p.(
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsetr, Template: Intel;1033, Revision Number: {6620BA4B-19A8-4D89-ACA5-026A228776D7}, Create Time/Date: Sat Jan 4 04:39:54 2025, Last Saved Time/Date: Sat Jan 4 04:39:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9154560
                      Entropy (8bit):7.988412712374893
                      Encrypted:false
                      SSDEEP:196608:zwGc0r6GNmkP5pwB6TCe30s05DnHPfctFaEfVr7yBh1LRTKN4O:z1c0r6WmkP5pQ6TCe30s0Bvfcy67yBHS
                      MD5:44843C6B70D7546D4DC7AF9B4F28AD34
                      SHA1:C54D00BA3A1DCC4036B7590E5A55680686E05C78
                      SHA-256:9F344057ED2F934B4975BDB0F5C4C7FF86848B2ABF0C1C7ECECBAA923173ACEC
                      SHA-512:2AFA005FF0C0202FB5101E3A07F97253913D6264B2B14E0F1369F38CAA2420C41FCFA75256C2FEE92B6647DAFB4DBA7476AC83137427ADDF4497C6486CDAD3AD
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsetr, Template: Intel;1033, Revision Number: {6620BA4B-19A8-4D89-ACA5-026A228776D7}, Create Time/Date: Sat Jan 4 04:39:54 2025, Last Saved Time/Date: Sat Jan 4 04:39:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9154560
                      Entropy (8bit):7.988412712374893
                      Encrypted:false
                      SSDEEP:196608:zwGc0r6GNmkP5pwB6TCe30s05DnHPfctFaEfVr7yBh1LRTKN4O:z1c0r6WmkP5pQ6TCe30s0Bvfcy67yBHS
                      MD5:44843C6B70D7546D4DC7AF9B4F28AD34
                      SHA1:C54D00BA3A1DCC4036B7590E5A55680686E05C78
                      SHA-256:9F344057ED2F934B4975BDB0F5C4C7FF86848B2ABF0C1C7ECECBAA923173ACEC
                      SHA-512:2AFA005FF0C0202FB5101E3A07F97253913D6264B2B14E0F1369F38CAA2420C41FCFA75256C2FEE92B6647DAFB4DBA7476AC83137427ADDF4497C6486CDAD3AD
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997674
                      Entropy (8bit):7.986814929271761
                      Encrypted:false
                      SSDEEP:196608:fB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Oa:56TCe30s0nvfcy67yBHLgfVa
                      MD5:3C808903203C166C1AA2CB709FE93034
                      SHA1:2FC18BC6E54856723D58A72327F2142D5E5FF5C4
                      SHA-256:4D5F321E4C49A81BE10A3B89E77130FCCD3D20CB5CF21DFBB50158F13C6762C4
                      SHA-512:B4F0F15944415C69D9157019F926CDAF2C5A5BC32BB02F76AEA600BB4848B74587BB27268EC27ACCAF351B7B8C06BC124B3B9ABE624CB56E58A517C0BA5BD7E3
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.1%Z.@.....@.....@.....@.....@.....@......&.{151028AD-E0D2-409C-B3EC-8348C68EAD59}..Setup..#U7a0b#U5e8fv9.3.5.msi.@.....@.....@.....@........&.{6620BA4B-19A8-4D89-ACA5-026A228776D7}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.H ..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\67d29d.msi.........@........file.dat..l4d..file.dat.@.....@.H ..@.......@.............@.........@.....@.....@..0..@1....@<.2..@........._....J..._.@A.......j.MZx.....................@.........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 28%, Browse
                      Joe Sandbox View:
                      • Filename: setup64v6.4.5.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v2.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                      • Filename: setup64v4.5.6.msi, Detection: malicious, Browse
                      • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      • Filename: setup64v3.2.6.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1689188695314687
                      Encrypted:false
                      SSDEEP:12:JSbX72FjzAGiLIlHVRpRh/7777777777777777777777777vDHFjA1Z+l0i8Q:JVQI5FJeF
                      MD5:4ABEFDF69E6221AFDE02E5A88F0193F2
                      SHA1:6CEEFFD01371248F21033C1FB1EF518570443E0C
                      SHA-256:E2930BC87703C672EADF4ADD1A29F29EE5A445AFFBDC95D77C88861F1E1B399A
                      SHA-512:8150730199A5A1FF4EB735507D22DEF7AFFE4F4537586DABD9D571CB2C71BF5A455047F37E3B849380060FC256C63706DCB378CAAF5213A261BF56CFBD11B329
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.466562010838194
                      Encrypted:false
                      SSDEEP:48:38Ph2uRc06WXJEFT5EppAk+UdeS5oDrydeSIyF:2h21HFTKoJfGF
                      MD5:E02C0510F7B5618AFC48578B2A1FCC7D
                      SHA1:9F9CFBE738A7C0DD80CC0A35A52E621E8E6F311F
                      SHA-256:4870D6AFA7C0E96AFF28B5CE50356C128283755397F4B43CEC7778522C61A2F4
                      SHA-512:735CCBBD06F880B09ABB4472EA43E9D0B0D1E0A586495D84B63B78487DDA71F3253F5D9B6581B8D8FC92FE540F0718E04E7796F4C09757059395BA0B362FB167
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):432221
                      Entropy (8bit):5.375165603282833
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau4:zTtbmkExhMJCIpErd
                      MD5:C0267318A37335A676963086354F596C
                      SHA1:43FD66FBBF09F45AA9B079EAD85FC0CEFFE171CF
                      SHA-256:F83226E736FC4374CB124A20EC4B6C5085A021CE94670E5D8B00F882CB9D4769
                      SHA-512:7E60D987C8CCEFCD6A4070485A6A0185EF43802674FEC54E9721917EE7BD4D5D6E8158A6F945D991AB37DD2B49B348C163B98CEA9843AF1F9BEC4F12674F63B5
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1816413463695756
                      Encrypted:false
                      SSDEEP:48:eneuxPveFXJ5T5eppAk+UdeS5oDrydeSIyF:AeHhTYoJfGF
                      MD5:60BF890EDF8551A4FB0545E4A86E935C
                      SHA1:C1D581BE26EFE4F6B777FC58B7B249B10798AB7B
                      SHA-256:D7E632917B2B343DE8BCBB3E4E1C5F6F2F5733FD0F21BE736961924648C462FF
                      SHA-512:D392D514581C52B9A7A3AD305DDBB59440E86B1D935A34134573102507A24C4A7262E2F3E654BE6DF25CA1D1C85B9ECFB1725AE51B71F3ACEF041A76EFEF3075
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.466562010838194
                      Encrypted:false
                      SSDEEP:48:38Ph2uRc06WXJEFT5EppAk+UdeS5oDrydeSIyF:2h21HFTKoJfGF
                      MD5:E02C0510F7B5618AFC48578B2A1FCC7D
                      SHA1:9F9CFBE738A7C0DD80CC0A35A52E621E8E6F311F
                      SHA-256:4870D6AFA7C0E96AFF28B5CE50356C128283755397F4B43CEC7778522C61A2F4
                      SHA-512:735CCBBD06F880B09ABB4472EA43E9D0B0D1E0A586495D84B63B78487DDA71F3253F5D9B6581B8D8FC92FE540F0718E04E7796F4C09757059395BA0B362FB167
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1816413463695756
                      Encrypted:false
                      SSDEEP:48:eneuxPveFXJ5T5eppAk+UdeS5oDrydeSIyF:AeHhTYoJfGF
                      MD5:60BF890EDF8551A4FB0545E4A86E935C
                      SHA1:C1D581BE26EFE4F6B777FC58B7B249B10798AB7B
                      SHA-256:D7E632917B2B343DE8BCBB3E4E1C5F6F2F5733FD0F21BE736961924648C462FF
                      SHA-512:D392D514581C52B9A7A3AD305DDBB59440E86B1D935A34134573102507A24C4A7262E2F3E654BE6DF25CA1D1C85B9ECFB1725AE51B71F3ACEF041A76EFEF3075
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10365594027476478
                      Encrypted:false
                      SSDEEP:24:k85zZLdB5GipVGdB5GipV7V2BwGnlrkgGp+GpAk8:kCzldeScdeS5oDruXpAk8
                      MD5:651FF29E1DDDBC8E31728DF2056E4815
                      SHA1:8A861C6C34E2E4CC65F1290CE2090C9823268B0A
                      SHA-256:75101B87F63BA247B4CE1E3F58EE2224E8044AC11DC7CAF4818F6D5F0D5D2890
                      SHA-512:352C10019A38AF53D7CF8B8DC81B7ED16C88AE27530E64BB6DE679B3CEAFD82276A183259D7E3E10CF6B19322BF8BF3B42B648E0E984626792DDE6925176A7FC
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07552662180959271
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOjeJ0bfGOoNAVky6l+:2F0i8n0itFzDHFjA1Z+
                      MD5:FF96B653A402093A8A480F928EDEF260
                      SHA1:7766560B20510209AB3D9D5340D4740C01E9527A
                      SHA-256:0801642582C2C8FB809AE29C3F54A1A4C8EC8B49F2E8C3E6DF9EC8BFCA90488E
                      SHA-512:3DB3669AE4940CE80CDC51425D43C42F4CF938AE573650563861CACF364C9CB51404DF834B8BC93EBB4AAE812A7CF516C79612149F24DE29DC64EBD208638F47
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.466562010838194
                      Encrypted:false
                      SSDEEP:48:38Ph2uRc06WXJEFT5EppAk+UdeS5oDrydeSIyF:2h21HFTKoJfGF
                      MD5:E02C0510F7B5618AFC48578B2A1FCC7D
                      SHA1:9F9CFBE738A7C0DD80CC0A35A52E621E8E6F311F
                      SHA-256:4870D6AFA7C0E96AFF28B5CE50356C128283755397F4B43CEC7778522C61A2F4
                      SHA-512:735CCBBD06F880B09ABB4472EA43E9D0B0D1E0A586495D84B63B78487DDA71F3253F5D9B6581B8D8FC92FE540F0718E04E7796F4C09757059395BA0B362FB167
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1816413463695756
                      Encrypted:false
                      SSDEEP:48:eneuxPveFXJ5T5eppAk+UdeS5oDrydeSIyF:AeHhTYoJfGF
                      MD5:60BF890EDF8551A4FB0545E4A86E935C
                      SHA1:C1D581BE26EFE4F6B777FC58B7B249B10798AB7B
                      SHA-256:D7E632917B2B343DE8BCBB3E4E1C5F6F2F5733FD0F21BE736961924648C462FF
                      SHA-512:D392D514581C52B9A7A3AD305DDBB59440E86B1D935A34134573102507A24C4A7262E2F3E654BE6DF25CA1D1C85B9ECFB1725AE51B71F3ACEF041A76EFEF3075
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: dfsetr, Template: Intel;1033, Revision Number: {6620BA4B-19A8-4D89-ACA5-026A228776D7}, Create Time/Date: Sat Jan 4 04:39:54 2025, Last Saved Time/Date: Sat Jan 4 04:39:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.988412712374893
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:#U7a0b#U5e8fv9.3.5.msi
                      File size:9'154'560 bytes
                      MD5:44843c6b70d7546d4dc7af9b4f28ad34
                      SHA1:c54d00ba3a1dcc4036b7590e5a55680686e05c78
                      SHA256:9f344057ed2f934b4975bdb0f5c4c7ff86848b2abf0c1c7ececbaa923173acec
                      SHA512:2afa005ff0c0202fb5101e3a07f97253913d6264b2b14e0f1369f38caa2420c41fcfa75256c2fee92b6647dafb4dba7476ac83137427addf4497c6486cdad3ad
                      SSDEEP:196608:zwGc0r6GNmkP5pwB6TCe30s05DnHPfctFaEfVr7yBh1LRTKN4O:z1c0r6WmkP5pQ6TCe30s0Bvfcy67yBHS
                      TLSH:38963371BCEFE3FAE66A26720A5071D24002AE7027B34146AB457F0C047D764D777AAD
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:06:12:57
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.3.5.msi"
                      Imagebase:0x7ff66b370000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:06:12:57
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff66b370000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:2
                      Start time:06:12:59
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding B68E0724E626022DBC2923D91326CB8F E Global\MSI0000
                      Imagebase:0x7ff66b370000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly