Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
T1#U5b89#U88c5#U53051.0.6.msi

Overview

General Information

Sample name:T1#U5b89#U88c5#U53051.0.6.msi
renamed because original name is a hash value
Original sample name:T11.0.6.msi
Analysis ID:1584633
MD5:300c49478f8e3e9be4e35a01e99e2063
SHA1:0bcfbd1bca0119ee92ffec243b13be9f78f5e42e
SHA256:d25bd44f8eeb55687e65eaca4aad93c89d2cce5983b28420bacb605fd6a0a1cd
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7412 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.6.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7488 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7596 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 4B0326121B4191117D7A14A664CB6F39 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI6856.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI6856.tmpVirustotal: Detection: 35%Perma Link
Source: T1#U5b89#U88c5#U53051.0.6.msiVirustotal: Detection: 26%Perma Link
Source: T1#U5b89#U88c5#U53051.0.6.msiReversingLabs: Detection: 28%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5e5d97.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{2B0E2369-D67C-4169-B300-1FB731908F39}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI5FBA.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5e5d99.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5e5d99.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6856.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\5e5d99.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI6856.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI6856.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: T1#U5b89#U88c5#U53051.0.6.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs T1#U5b89#U88c5#U53051.0.6.msi
Source: MSI6856.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI6856.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI6856.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFC261C1A463745442.TMPJump to behavior
Source: T1#U5b89#U88c5#U53051.0.6.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: T1#U5b89#U88c5#U53051.0.6.msiVirustotal: Detection: 26%
Source: T1#U5b89#U88c5#U53051.0.6.msiReversingLabs: Detection: 28%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.6.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 4B0326121B4191117D7A14A664CB6F39 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 4B0326121B4191117D7A14A664CB6F39 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: T1#U5b89#U88c5#U53051.0.6.msiStatic file information: File size 8998912 > 1048576
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name:
Source: MSI6856.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI6856.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI6856.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI6856.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6856.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6856.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI6856.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7636Thread sleep count: 32 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exe TID: 7636Thread sleep count: 678 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584633 Sample: T1#U5b89#U88c5#U53051.0.6.msi Startdate: 06/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI6856.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
T1#U5b89#U88c5#U53051.0.6.msi27%VirustotalBrowse
T1#U5b89#U88c5#U53051.0.6.msi29%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI6856.tmp16%ReversingLabs
C:\Windows\Installer\MSI6856.tmp36%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584633
Start date and time:2025-01-06 04:41:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:10
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:T1#U5b89#U88c5#U53051.0.6.msi
renamed because original name is a hash value
Original Sample Name:T11.0.6.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 52.149.20.212
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI6856.tmpSetup64v3.6.5.msiGet hashmaliciousUnknownBrowse
    Setup64v2.3.6.msiGet hashmaliciousUnknownBrowse
      #U7a0b#U5e8fv9.3.5.msiGet hashmaliciousUnknownBrowse
        setup64v6.4.5.msiGet hashmaliciousUnknownBrowse
          installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
            setup64v2.3.5.msiGet hashmaliciousUnknownBrowse
              setup64v2.4.3.msiGet hashmaliciousUnknownBrowse
                setup64v4.5.6.msiGet hashmaliciousUnknownBrowse
                  installer64v1.2.8.msiGet hashmaliciousUnknownBrowse
                    setup64v9..2.4.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003390
                      Entropy (8bit):7.986513084003582
                      Encrypted:false
                      SSDEEP:196608:2B6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Ow:W6TCe30s0nvfcy67yBHLgfVw
                      MD5:65BC0DB8B5172DF05E681061D13B2605
                      SHA1:8770D910CA4B41A64D632D71CCB46B1C813CA730
                      SHA-256:AB65350CFE5261BAF2F570EC7409B9DAFAA5D0EE7E4F4370C533A39C3CEA681D
                      SHA-512:AA901376F61BAC1AC496623E4088B706134C15488DB1FCC5832A9BD4F113CAAC85ACFBFC196D3D304B9EA18BC45C2FCE7FF5A98AEA73D4279313207CA0FDDBE2
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@C.%Z.@.....@.....@.....@.....@.....@......&.{2B0E2369-D67C-4169-B300-1FB731908F39}..Setup..T1#U5b89#U88c5#U53051.0.6.msi.@.....@.....@.....@........&.{FC9DD98E-6834-479B-8E4B-C4B444229183}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{2B0E2369-D67C-4169-B300-1FB731908F39}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1957936
                      Entropy (8bit):7.999889923600609
                      Encrypted:true
                      SSDEEP:49152:V3GlF5gqidfKgeQ922KF8aNNCJ6PUNkd4HaGhMbTw:9Gl4qidigB22KFIqO6/w
                      MD5:B9914B5B42F003D14E62F86C4218A2E2
                      SHA1:0A2481BA885AB71205225C693531E943E1849E03
                      SHA-256:95ADB58BFB629151D175D75B0A58E6FF3445E0FCD61C79F25D2BC597D5E15C52
                      SHA-512:0E8A83A301A2D11627624C21AD516F7590980BF8C57AFD0188B96F8806E92FB6E6C1A3E530ED48E0BB4E46BF32B08B104F8FF3D6C6E7E9E7AAA85DFB98D76299
                      Malicious:false
                      Reputation:low
                      Preview:.@S....}.j.,#..............c.;\.)MS...1f.d.........&yk#....[..D.sH....;..M.G6|.Wk..=.:X...@.M.{/K{....Ul...'........jAW...~N{.....:Y...j...z....e.4.m...=.......x....+..^{..........Xl.T.......cQ..S..J...Z...J.\.\qw.C9..O.....w.E1.2.y[ .?oW..<89..w......oh........#&-V.J.w..C6...A..3...bRR...8.*.-.t.._V....OK.>p.:..7.@.3+.O.?....`.Zg.6&..z~..EUB.9.[..l..t.S.~#.....XpB..(!..E.7...$q4.&.@GbIz.M.T(....v...2.8.9..;~.,.X...1G......4.h.E.Q2p..wfC.:..a.F'E.......L4Z._.d|qr.*_.._..1....O.97...8......i.....i.K....Je.....o..O.Sp....L...0~..l.9V..S.+S...e......$Z..?.$....*...fO..........w<..zb....}..w..Ak...q...."T..o\t....U..w>.h..)%.....=..F..4t..'...O<.E.X.VT_6....4...Q?U..Q.]#A.K.9..}.=....T.<....'..8....`....2!ef2Z.`....,O......7n@..-..F...Q.q........vP..... I*IoP.M.TE...F...Z.A3k+2...9.l0...tg.H#|R8\...y.0Z...>...Gc.....f.@R.<?.mz?.n.'.F..K..Z.Y.K.xy.$`H...S..67:..).9.n..Z.4.c.....3...XH+..N.N.....&m.....Y...+...S..].Z$.0>....|......'..=...
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {FC9DD98E-6834-479B-8E4B-C4B444229183}, Create Time/Date: Sat Jan 4 04:40:00 2025, Last Saved Time/Date: Sat Jan 4 04:40:00 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8998912
                      Entropy (8bit):7.987594098179806
                      Encrypted:false
                      SSDEEP:196608:APlYQwgEPJRiB6TCe30s0TZnHPfctFaEfVr7yBh1LRTKC4O:ASeoRa6TCe30s0Nvfcy67yBHLgCV
                      MD5:300C49478F8E3E9BE4E35A01E99E2063
                      SHA1:0BCFBD1BCA0119EE92FFEC243B13BE9F78F5E42E
                      SHA-256:D25BD44F8EEB55687E65EACA4AAD93C89D2CCE5983B28420BACB605FD6A0A1CD
                      SHA-512:0A68D57C7A95E8D5FAE56FF2A0FCEA216C03FEE1121615E85A95E226BF0782CF91C80360F0BB050A37E133F899E5EADF0D2532ADD066691396ECB4C18AB00AEB
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {FC9DD98E-6834-479B-8E4B-C4B444229183}, Create Time/Date: Sat Jan 4 04:40:00 2025, Last Saved Time/Date: Sat Jan 4 04:40:00 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8998912
                      Entropy (8bit):7.987594098179806
                      Encrypted:false
                      SSDEEP:196608:APlYQwgEPJRiB6TCe30s0TZnHPfctFaEfVr7yBh1LRTKC4O:ASeoRa6TCe30s0Nvfcy67yBHLgCV
                      MD5:300C49478F8E3E9BE4E35A01E99E2063
                      SHA1:0BCFBD1BCA0119EE92FFEC243B13BE9F78F5E42E
                      SHA-256:D25BD44F8EEB55687E65EACA4AAD93C89D2CCE5983B28420BACB605FD6A0A1CD
                      SHA-512:0A68D57C7A95E8D5FAE56FF2A0FCEA216C03FEE1121615E85A95E226BF0782CF91C80360F0BB050A37E133F899E5EADF0D2532ADD066691396ECB4C18AB00AEB
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997684
                      Entropy (8bit):7.986814778232147
                      Encrypted:false
                      SSDEEP:196608:EB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OL:s6TCe30s0nvfcy67yBHLgfVL
                      MD5:957B46207FD71B385174CC4F8AF6998F
                      SHA1:49684D37ED8B9B3C4E7BE6082FBA7B42A272C877
                      SHA-256:EBDD87BE509483B043A5715E868820E08E3F2925E4A94E3C2814D50E0DD31226
                      SHA-512:983DDF6BC1DA061581DD612CDF9470AAF5D3371F126F070C069114EF084F0EA6C7F40BF5743D26EB2A8B45A5D0C3603ACBDA364E6F02F46409B03E44CCE8A424
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@B.%Z.@.....@.....@.....@.....@.....@......&.{2B0E2369-D67C-4169-B300-1FB731908F39}..Setup..T1#U5b89#U88c5#U53051.0.6.msi.@.....@.....@.....@........&.{FC9DD98E-6834-479B-8E4B-C4B444229183}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@0....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\5e5d97.msi.........@........file.dat..l4d..file.dat.@.....@0....@.......@.............@.........@.....@.....@..K[.@B....@Nb.l.@B........_....J..._.@A.......j.MZx.....................@..................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:modified
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 36%, Browse
                      Joe Sandbox View:
                      • Filename: Setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: Setup64v2.3.6.msi, Detection: malicious, Browse
                      • Filename: #U7a0b#U5e8fv9.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v6.4.5.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v2.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                      • Filename: setup64v4.5.6.msi, Detection: malicious, Browse
                      • Filename: installer64v1.2.8.msi, Detection: malicious, Browse
                      • Filename: setup64v9..2.4.msi, Detection: malicious, Browse
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.173238119335571
                      Encrypted:false
                      SSDEEP:12:JSbX72FjSJAGiLIlHVRpIh/7777777777777777777777777vDHFWuY17Prl0i8Q:JwJQI5wkuc6F
                      MD5:17F48129326E2A7C863035CFD3E7A5CF
                      SHA1:43758419157F444C3856B4C3D73CA943ADDABA4F
                      SHA-256:5198A6FAFD90ABECBC2397BF99266C62C1CBB4DE21C70C7FF0E2C9026A262CD5
                      SHA-512:5B00D2EBF491BF3F59861BE1A1A575D28721299D3B20194E22CDCFD9C8B9514911EBB71DAEC8F78804D8C8F362698104C80FE3E716184559E453CA91C51BEB44
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.46925977767643
                      Encrypted:false
                      SSDEEP:48:W8PhAuRc06WXJUjT5v23wwJQdeS5nrideSI7gI:phA1XjTg3wwL0P
                      MD5:363A808B9C240C72639E69E9E48803A6
                      SHA1:B13CA2F18F06FDA63AF8744324CE7D663B053598
                      SHA-256:B2C7799D9B2070AE15164F2CC1AD1E4EB8A25CCDD43D9CCBF2C0A562967E4DBC
                      SHA-512:7128A33F4BBFBA8B5A4DD5A42C73C78E799CC6D21C2C9F808FB8C5B75911B0B54B0FF8ED7CF224BE5008FA7AD93EE459DBFB829B1FCECC2A2AF755C8CAF1EE6D
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):360001
                      Entropy (8bit):5.36296970924705
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauZ:zTtbmkExhMJCIpE4
                      MD5:CE4C99CA5B5FAB00336A70441B9F1B04
                      SHA1:8DAA16D2497B9BA94BCE57413A7DDAC0B3A9626F
                      SHA-256:DD02A1A5F85C85A28C503D0BD5CAEE86BC41151275AD6E92B2108DAC9BC38144
                      SHA-512:FC07A7448E1599BCF3E44A60E8CA3F7F5EFD456521EC2BAD4002F8734754EBB908E90579448381E56FE660AF2354749FF6DAABE190A7948AD525FED43BE7087C
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1844428065017607
                      Encrypted:false
                      SSDEEP:48:hnoujJveFXJvT5l23wwJQdeS5nrideSI7gI:9oTXTC3wwL0P
                      MD5:B3DD821294B0B1A8D96C89740C41A354
                      SHA1:C6DBEC364836B801406219EE25CEA29AD11B8376
                      SHA-256:7AB4EC9CE8B0DFED0E61D2E77F7071F18C2854F5B39CA8C587C68CCB0CFA232D
                      SHA-512:7D461D8D5E89D48ED134ABD2191DC85D1CD7A9BEDCC52BF1E4A9856EC0FAAE3250A483DF85083571A70789FB8CA72D93C1F1006CEACC27969BA1D8D14636D896
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07774588307768997
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOj/aNkcaWz17/hiVky6l51:2F0i8n0itFzDHFWuY17Pr
                      MD5:97A0C0CBF7BEF1D9E4D46E20874490BB
                      SHA1:7F8143BB496FE094DCA7FAF8BFC39A79F43FF351
                      SHA-256:6922DD9C776B773D66F1B60837D502C194D1F3A4C07819E802D2E83D903D6F0A
                      SHA-512:0DF634BE8E586CE3C35B0C027FCA610F67672F91E34D5645D0B8100FD498DDFCA453C48C664F54C14484F6C090275AEDDF405DA646802C9DB6F0B296007F3AFB
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1844428065017607
                      Encrypted:false
                      SSDEEP:48:hnoujJveFXJvT5l23wwJQdeS5nrideSI7gI:9oTXTC3wwL0P
                      MD5:B3DD821294B0B1A8D96C89740C41A354
                      SHA1:C6DBEC364836B801406219EE25CEA29AD11B8376
                      SHA-256:7AB4EC9CE8B0DFED0E61D2E77F7071F18C2854F5B39CA8C587C68CCB0CFA232D
                      SHA-512:7D461D8D5E89D48ED134ABD2191DC85D1CD7A9BEDCC52BF1E4A9856EC0FAAE3250A483DF85083571A70789FB8CA72D93C1F1006CEACC27969BA1D8D14636D896
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.46925977767643
                      Encrypted:false
                      SSDEEP:48:W8PhAuRc06WXJUjT5v23wwJQdeS5nrideSI7gI:phA1XjTg3wwL0P
                      MD5:363A808B9C240C72639E69E9E48803A6
                      SHA1:B13CA2F18F06FDA63AF8744324CE7D663B053598
                      SHA-256:B2C7799D9B2070AE15164F2CC1AD1E4EB8A25CCDD43D9CCBF2C0A562967E4DBC
                      SHA-512:7128A33F4BBFBA8B5A4DD5A42C73C78E799CC6D21C2C9F808FB8C5B75911B0B54B0FF8ED7CF224BE5008FA7AD93EE459DBFB829B1FCECC2A2AF755C8CAF1EE6D
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.46925977767643
                      Encrypted:false
                      SSDEEP:48:W8PhAuRc06WXJUjT5v23wwJQdeS5nrideSI7gI:phA1XjTg3wwL0P
                      MD5:363A808B9C240C72639E69E9E48803A6
                      SHA1:B13CA2F18F06FDA63AF8744324CE7D663B053598
                      SHA-256:B2C7799D9B2070AE15164F2CC1AD1E4EB8A25CCDD43D9CCBF2C0A562967E4DBC
                      SHA-512:7128A33F4BBFBA8B5A4DD5A42C73C78E799CC6D21C2C9F808FB8C5B75911B0B54B0FF8ED7CF224BE5008FA7AD93EE459DBFB829B1FCECC2A2AF755C8CAF1EE6D
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1844428065017607
                      Encrypted:false
                      SSDEEP:48:hnoujJveFXJvT5l23wwJQdeS5nrideSI7gI:9oTXTC3wwL0P
                      MD5:B3DD821294B0B1A8D96C89740C41A354
                      SHA1:C6DBEC364836B801406219EE25CEA29AD11B8376
                      SHA-256:7AB4EC9CE8B0DFED0E61D2E77F7071F18C2854F5B39CA8C587C68CCB0CFA232D
                      SHA-512:7D461D8D5E89D48ED134ABD2191DC85D1CD7A9BEDCC52BF1E4A9856EC0FAAE3250A483DF85083571A70789FB8CA72D93C1F1006CEACC27969BA1D8D14636D896
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.1052154110840126
                      Encrypted:false
                      SSDEEP:24:zIFCZLdB5GipVGdB5GipV7VPwGvlrkg2L8+/wuUXL:zIFCldeScdeS5nra8wwuy
                      MD5:253F3C7CEBAEFEA81AF196BE18CC7317
                      SHA1:4D3A6597F8938622423435C839387FB2AE495D92
                      SHA-256:049E7CBCD7EF3B9F6D1E930D4199B1D32139C7672844F43360E09070F2B73A17
                      SHA-512:C68E329C387576D6EC858528BC1BD3C969780F4AF1D398EA3B3E8EF2B552E972CBDB7DD3D7A12DDA214AE105CBF7F0440BD9BD8278E808583BF3AC98008D118C
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {FC9DD98E-6834-479B-8E4B-C4B444229183}, Create Time/Date: Sat Jan 4 04:40:00 2025, Last Saved Time/Date: Sat Jan 4 04:40:00 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.987594098179806
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:T1#U5b89#U88c5#U53051.0.6.msi
                      File size:8'998'912 bytes
                      MD5:300c49478f8e3e9be4e35a01e99e2063
                      SHA1:0bcfbd1bca0119ee92ffec243b13be9f78f5e42e
                      SHA256:d25bd44f8eeb55687e65eaca4aad93c89d2cce5983b28420bacb605fd6a0a1cd
                      SHA512:0a68d57c7a95e8d5fae56ff2a0fcea216c03fee1121615e85a95e226bf0782cf91c80360f0bb050a37e133f899e5eadf0d2532add066691396ecb4c18ab00aeb
                      SSDEEP:196608:APlYQwgEPJRiB6TCe30s0TZnHPfctFaEfVr7yBh1LRTKC4O:ASeoRa6TCe30s0Nvfcy67yBHLgCV
                      TLSH:E1963361B8AFA6FBF67627760E6070924142AE7027F2810697043F0D017D6B1D7BBA7D
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:22:42:02
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.6.msi"
                      Imagebase:0x7ff649700000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:2
                      Start time:22:42:02
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff649700000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:22:42:06
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 4B0326121B4191117D7A14A664CB6F39 E Global\MSI0000
                      Imagebase:0x7ff649700000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly