Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Setup64v2.3.6.msi

Overview

General Information

Sample name:Setup64v2.3.6.msi
Analysis ID:1584630
MD5:94656af323184e760fc068b138bd830b
SHA1:0f9c1c827fa15291ba66678cda95a09f1afc3a77
SHA256:e59be80da8616abb570739f259b2bc5b6ed8c0821803fa6517a13f836caa4778
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 6616 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v2.3.6.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 3840 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6592 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 994A75071AF2A44E653B3A6763A3E34E E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI8762.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI8762.tmpVirustotal: Detection: 35%Perma Link
Source: Setup64v2.3.6.msiVirustotal: Detection: 26%Perma Link
Source: Setup64v2.3.6.msiReversingLabs: Detection: 28%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: global trafficTCP traffic: 192.168.2.5:52244 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1

System Summary

barindex
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\527f33.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{C9852F2D-9C94-439A-AEE5-EAA229EB26AD}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI8127.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\527f35.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\527f35.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI8762.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\527f35.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI8762.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI8762.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: Setup64v2.3.6.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs Setup64v2.3.6.msi
Source: MSI8762.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI8762.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI8762.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF34EB01528C19DA41.TMPJump to behavior
Source: Setup64v2.3.6.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: Setup64v2.3.6.msiVirustotal: Detection: 26%
Source: Setup64v2.3.6.msiReversingLabs: Detection: 28%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v2.3.6.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 994A75071AF2A44E653B3A6763A3E34E E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 994A75071AF2A44E653B3A6763A3E34E E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: Setup64v2.3.6.msiStatic file information: File size 8818688 > 1048576
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name:
Source: MSI8762.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI8762.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI8762.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI8762.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI8762.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI8762.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI8762.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 6472Thread sleep count: 352 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584630 Sample: Setup64v2.3.6.msi Startdate: 06/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI8762.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Setup64v2.3.6.msi27%VirustotalBrowse
Setup64v2.3.6.msi29%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI8762.tmp16%ReversingLabs
C:\Windows\Installer\MSI8762.tmp36%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584630
Start date and time:2025-01-06 04:39:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:Setup64v2.3.6.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
  • Excluded IPs from analysis (whitelisted): 172.202.163.200, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI8762.tmp#U7a0b#U5e8fv9.3.5.msiGet hashmaliciousUnknownBrowse
    setup64v6.4.5.msiGet hashmaliciousUnknownBrowse
      installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
        setup64v2.3.5.msiGet hashmaliciousUnknownBrowse
          setup64v2.4.3.msiGet hashmaliciousUnknownBrowse
            setup64v4.5.6.msiGet hashmaliciousUnknownBrowse
              installer64v1.2.8.msiGet hashmaliciousUnknownBrowse
                setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
                  setup64v9.7.4.msiGet hashmaliciousUnknownBrowse
                    setup64v6.3.2.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003366
                      Entropy (8bit):7.9865153619472045
                      Encrypted:false
                      SSDEEP:196608:0B6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O8:86TCe30s0nvfcy67yBHLgfV8
                      MD5:043391B05E098FFC03E6896C66455338
                      SHA1:B2EF404FD1B3AEB0F7C96664397C7D85A9ECB585
                      SHA-256:FC2EB3C151B080EAF08B5EDF30274DBFC9D45F4D00B86BF43E0A482E24803301
                      SHA-512:8E42F21F7F02F62E1201FE807B549D4E050418A6A699E23E432950D60D1082CD5878E0C68D5C39D71EBEF0B9AA86626992B238E924BAC585715ADE579047FF67
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@..%Z.@.....@.....@.....@.....@.....@......&.{C9852F2D-9C94-439A-AEE5-EAA229EB26AD}..Setup..Setup64v2.3.6.msi.@.....@.....@.....@........&.{BF87A77F-D2E3-40BD-8083-CF8175DECC04}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{C9852F2D-9C94-439A-AEE5-EAA229EB26AD}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1777296
                      Entropy (8bit):7.999892395779385
                      Encrypted:true
                      SSDEEP:49152:AYTohaRnFgigjrx8snBa4li7XywfNabyF:AGo4RFYjrfc45wf0bs
                      MD5:0FA85F1DA598879CB9618E766BAD11AB
                      SHA1:A49977919BA59F07301CF067562883215E1FED9E
                      SHA-256:DF152BE2D0B1B6B7C60F39E8C93E6E0B356DCB4AD63AC10ED543A8A9BD17DB30
                      SHA-512:FF31037A72F013CA6E55402ADAC0FFFF9BE6B38A1F9F8F510D3FEB3CC124BDE4076FFFE5D24037CB9352A7FB93CA68226427BF70CB37FEEE7233823DA50056C0
                      Malicious:false
                      Reputation:low
                      Preview:.@S....CY.f.................c...#.(pc.+.$0.....a.(j.=...........l.d.....U...q._.h.J..\tk.]..........S...7`Qi..,.......~7.w%.YVD..^.....|....|x.j(..y....b....w..]....o..!..3V..KR...*.P.L..[ [..#^....N;3..(...CY.....#......./(.R&Z~={K....u....$>.S....g._..LN...{...,p(.j.n..O?......E.';#4.b......D..:.....;_..j..~.>b..T.V.i.sy....].......R..\ ..}........c...R../..@..q...Y...p..]a...yw..u;.{...Yl}?.O..:i../...)~.h2u..5..X~.C....>..QyN..s..g...7l.Z2!..#=.......*..z..y.X,.\....y..M.X*l.........0....R..5.c..y......X..=...'....Z...*o3k.Y,/_.=.`(.e..E...Ok'..S.._.<3P..c.J...i(..rW@.Jd..\TT..D......:.+YEG.G|.` .R..... 5..Z<..f..,.....O.7.w]})....qW"....d...1..O.......B....-....{fY...cA...|;wq...A}=y%.x.8.w.\.W..UZ.S....m...?..bt...[e..C..V.}.i...+..1i...9MN.Y...V..5go.ob.<1Y.V../t...i....7..V.ZadT..M..E.jX..y..m.Xv..n..;..X.o......Ya...>u......Q....U..H{..j.9.!}....x.,6.n.B'.$..*....`..{.m......y.!z..ap.......H.X.P......8.r`$.#G..r...Q@.%..
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: bfhgtrhytyhj, Template: Intel;1033, Revision Number: {BF87A77F-D2E3-40BD-8083-CF8175DECC04}, Create Time/Date: Mon Jan 6 02:35:54 2025, Last Saved Time/Date: Mon Jan 6 02:35:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8818688
                      Entropy (8bit):7.987133456103736
                      Encrypted:false
                      SSDEEP:196608:YpteFtQRfaB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:YTezQR66TCe30s01vfcy67yBHLgf6
                      MD5:94656AF323184E760FC068B138BD830B
                      SHA1:0F9C1C827FA15291BA66678CDA95A09F1AFC3A77
                      SHA-256:E59BE80DA8616ABB570739F259B2BC5B6ED8C0821803FA6517A13F836CAA4778
                      SHA-512:DBE1EF902104D0AE7AD75609338F13A4C0E682C443A79160DF5EB09112F6F84A6FA63586C97EF31929B8CDF19F52295E434E0C54FAD779B3568DE3F8CD52E373
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: bfhgtrhytyhj, Template: Intel;1033, Revision Number: {BF87A77F-D2E3-40BD-8083-CF8175DECC04}, Create Time/Date: Mon Jan 6 02:35:54 2025, Last Saved Time/Date: Mon Jan 6 02:35:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8818688
                      Entropy (8bit):7.987133456103736
                      Encrypted:false
                      SSDEEP:196608:YpteFtQRfaB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:YTezQR66TCe30s01vfcy67yBHLgf6
                      MD5:94656AF323184E760FC068B138BD830B
                      SHA1:0F9C1C827FA15291BA66678CDA95A09F1AFC3A77
                      SHA-256:E59BE80DA8616ABB570739F259B2BC5B6ED8C0821803FA6517A13F836CAA4778
                      SHA-512:DBE1EF902104D0AE7AD75609338F13A4C0E682C443A79160DF5EB09112F6F84A6FA63586C97EF31929B8CDF19F52295E434E0C54FAD779B3568DE3F8CD52E373
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997672
                      Entropy (8bit):7.986815036831793
                      Encrypted:false
                      SSDEEP:196608:jB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Oy:F6TCe30s0nvfcy67yBHLgfVy
                      MD5:E9BE58B63230F93B72BADFC33294166C
                      SHA1:CF9704F60A6FDCC27E018C63A42DB47F132EC420
                      SHA-256:05D888262B19F58728DBAAE8931C34BF01EB159961ACF3E2655C1091FEB848A4
                      SHA-512:2AA7FF0BAA334A57878C145C71C46593D02019A4EDC686E831A62A7AB387CCA4A914707595CC3A8D711B2E42CC08F1ADA49E07412E16FA4B3BBFFA2D9BBB9302
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@..%Z.@.....@.....@.....@.....@.....@......&.{C9852F2D-9C94-439A-AEE5-EAA229EB26AD}..Setup..Setup64v2.3.6.msi.@.....@.....@.....@........&.{BF87A77F-D2E3-40BD-8083-CF8175DECC04}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\527f33.msi.........@........file.dat..l4d..file.dat.@.....@.....@.......@.............@.........@.....@.....@.._..@.....@.a.v.@k........._....J..._.@A.......j.MZx.....................@..............................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 36%, Browse
                      Joe Sandbox View:
                      • Filename: #U7a0b#U5e8fv9.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v6.4.5.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v2.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                      • Filename: setup64v4.5.6.msi, Detection: malicious, Browse
                      • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v9.7.4.msi, Detection: malicious, Browse
                      • Filename: setup64v6.3.2.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1655665701398679
                      Encrypted:false
                      SSDEEP:12:JSbX72FjDmSAGiLIlHVRpEh/7777777777777777777777777vDHFqy9fSN3/l0G:JASQI5UZfS4F
                      MD5:76F3FC62ACE1F6B45EA3E2EBD719E7E6
                      SHA1:ECFA6411C4A64211AAF7AD1B4B6B1200A598EDE7
                      SHA-256:DDB5B4500F9084324E24F08038CDDE946EA991A2CB1E4A3862FE7E7A30D7DF09
                      SHA-512:0373E7C6B09F4A4589452C90CAF36E885AE9626A21F76AD05DE61BBD1B0CC996B4BC620BC2E80D473867A5C2BF103944D86F8CDB4900DAFAA03A640F0C6F54D5
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4649059227684786
                      Encrypted:false
                      SSDEEP:48:/8PhAuRc06WXJMnT56Ont2deS5pbrideSIWj:+hA1vnTzBSi
                      MD5:226E9EBEE3A6FD1B9D34D3E0AF841B9B
                      SHA1:43EE4B5CB91DACDD92B3A52E5C302C8452AE40DF
                      SHA-256:C601C6BD190BAF8D33CEF79B1266976F812472B2836474B7733C1F1FE5AD6E00
                      SHA-512:732CD3466537514A779B506F34B3D38D8C8D49047938C550517C591B0AF475D552E2456CAFE8266538D7A38E8212D8F5E672704806697641C8E0640703BDECF9
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):364484
                      Entropy (8bit):5.365481418355128
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgaud:zTtbmkExhMJCIpEq
                      MD5:775A3653B356EFB774FBBA30340F4B06
                      SHA1:A49F14E8A5A9EE6D9DF0FF69383B71CBCBAE024F
                      SHA-256:186D1E212F6B0DD8C4CBD7347BB1BC7D8E5678E5723C82FE1BFC523BEDA1196D
                      SHA-512:5F9568F73C05C33DAB71CE1BEF282F35B7ED1FE8E41D6F1DC299C14297357DDBAB1420EC03699A02FB7EEC3CA6476D5C949BA0F4BD5EF0CD315641D0DDA03580
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.0729645382890187
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOqy9fSe5ohSVky6lV1:2F0i8n0itFzDHFqy9fSN3/
                      MD5:08819C7226E8B25677DC2FF45A7D988A
                      SHA1:7C77E95535908C34B3ED3DA59BB9D747D24DCC01
                      SHA-256:F5DF6578E04F0460676D670E4C9362BFD7357604E4389D5E2D9D01A79D828B41
                      SHA-512:6C9BA50332410E16ACCE78FC42A644B0B227EBBA9DF42FA372A7AEE1A83368BAB1D17604C2DD56E0C60707A8D953CC1899C66CF2BB5317AAC649AC1A9F7D4E6A
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810129834421739
                      Encrypted:false
                      SSDEEP:48:cnoujNveFXJjT5sOnt2deS5pbrideSIWj:iov7TBBSi
                      MD5:CD80207212C8085BCFC48680BD6C68AD
                      SHA1:9D4128221D4420F7034830372E14ECC41F444491
                      SHA-256:F6404BF7FAED42F525E52AB9A61F21A4BF6A3FAD4621FA27F12C5E93B2798C75
                      SHA-512:4ED7FF1B79B71119493AD963AEF760415578EAD385548CD7E85CD686A77495EE6F186555871892A4553D5D414E77908CA0B6A4F0FCA39AB9039B252051FB8EB7
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10345790580145499
                      Encrypted:false
                      SSDEEP:24:+c6HZLdB5GipVGdB5GipV7VQwGwFlrkgs5+KDsH7:+ZHldeScdeS5pbratDs
                      MD5:BC65A0A8FC1BFAD999D563893273FC1D
                      SHA1:B6ACDC949600BB7BCE97691092B20FDA64BA81BC
                      SHA-256:F2EC268FE7D0EF367DD7732BDB24405371642F3E0F042580D8BAFC11DDA2F46E
                      SHA-512:E1AF15898C64EF29C03F084166F54D1CCFEDD9646C386EFE5EB4DEDA03721A0B51D3298BB6310DD288E7410142E236EB447490C6C50E9335FA66D97B7198730A
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4649059227684786
                      Encrypted:false
                      SSDEEP:48:/8PhAuRc06WXJMnT56Ont2deS5pbrideSIWj:+hA1vnTzBSi
                      MD5:226E9EBEE3A6FD1B9D34D3E0AF841B9B
                      SHA1:43EE4B5CB91DACDD92B3A52E5C302C8452AE40DF
                      SHA-256:C601C6BD190BAF8D33CEF79B1266976F812472B2836474B7733C1F1FE5AD6E00
                      SHA-512:732CD3466537514A779B506F34B3D38D8C8D49047938C550517C591B0AF475D552E2456CAFE8266538D7A38E8212D8F5E672704806697641C8E0640703BDECF9
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810129834421739
                      Encrypted:false
                      SSDEEP:48:cnoujNveFXJjT5sOnt2deS5pbrideSIWj:iov7TBBSi
                      MD5:CD80207212C8085BCFC48680BD6C68AD
                      SHA1:9D4128221D4420F7034830372E14ECC41F444491
                      SHA-256:F6404BF7FAED42F525E52AB9A61F21A4BF6A3FAD4621FA27F12C5E93B2798C75
                      SHA-512:4ED7FF1B79B71119493AD963AEF760415578EAD385548CD7E85CD686A77495EE6F186555871892A4553D5D414E77908CA0B6A4F0FCA39AB9039B252051FB8EB7
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4649059227684786
                      Encrypted:false
                      SSDEEP:48:/8PhAuRc06WXJMnT56Ont2deS5pbrideSIWj:+hA1vnTzBSi
                      MD5:226E9EBEE3A6FD1B9D34D3E0AF841B9B
                      SHA1:43EE4B5CB91DACDD92B3A52E5C302C8452AE40DF
                      SHA-256:C601C6BD190BAF8D33CEF79B1266976F812472B2836474B7733C1F1FE5AD6E00
                      SHA-512:732CD3466537514A779B506F34B3D38D8C8D49047938C550517C591B0AF475D552E2456CAFE8266538D7A38E8212D8F5E672704806697641C8E0640703BDECF9
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1810129834421739
                      Encrypted:false
                      SSDEEP:48:cnoujNveFXJjT5sOnt2deS5pbrideSIWj:iov7TBBSi
                      MD5:CD80207212C8085BCFC48680BD6C68AD
                      SHA1:9D4128221D4420F7034830372E14ECC41F444491
                      SHA-256:F6404BF7FAED42F525E52AB9A61F21A4BF6A3FAD4621FA27F12C5E93B2798C75
                      SHA-512:4ED7FF1B79B71119493AD963AEF760415578EAD385548CD7E85CD686A77495EE6F186555871892A4553D5D414E77908CA0B6A4F0FCA39AB9039B252051FB8EB7
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: bfhgtrhytyhj, Template: Intel;1033, Revision Number: {BF87A77F-D2E3-40BD-8083-CF8175DECC04}, Create Time/Date: Mon Jan 6 02:35:54 2025, Last Saved Time/Date: Mon Jan 6 02:35:54 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.987133456103736
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:Setup64v2.3.6.msi
                      File size:8'818'688 bytes
                      MD5:94656af323184e760fc068b138bd830b
                      SHA1:0f9c1c827fa15291ba66678cda95a09f1afc3a77
                      SHA256:e59be80da8616abb570739f259b2bc5b6ed8c0821803fa6517a13f836caa4778
                      SHA512:dbe1ef902104d0ae7ad75609338f13a4c0e682c443a79160df5eb09112f6f84a6fa63586c97ef31929b8cdf19f52295e434e0c54fad779b3568de3f8cd52e373
                      SSDEEP:196608:YpteFtQRfaB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:YTezQR66TCe30s01vfcy67yBHLgf6
                      TLSH:8F963361F8AFA7FAF0396772099071A20012EF7427F685169B143F0C147E570E6B7A6E
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 6, 2025 04:40:21.242737055 CET5224453192.168.2.51.1.1.1
                      Jan 6, 2025 04:40:21.247581005 CET53522441.1.1.1192.168.2.5
                      Jan 6, 2025 04:40:21.247937918 CET5224453192.168.2.51.1.1.1
                      Jan 6, 2025 04:40:21.252813101 CET53522441.1.1.1192.168.2.5
                      Jan 6, 2025 04:40:21.716564894 CET5224453192.168.2.51.1.1.1
                      Jan 6, 2025 04:40:21.721594095 CET53522441.1.1.1192.168.2.5
                      Jan 6, 2025 04:40:21.721687078 CET5224453192.168.2.51.1.1.1
                      TimestampSource PortDest PortSource IPDest IP
                      Jan 6, 2025 04:40:21.242039919 CET53640571.1.1.1192.168.2.5

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:22:40:01
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v2.3.6.msi"
                      Imagebase:0x7ff634f20000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:22:40:01
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff634f20000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:22:40:04
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 994A75071AF2A44E653B3A6763A3E34E E Global\MSI0000
                      Imagebase:0x7ff634f20000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly