Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
T1#U5b89#U88c5#U53051.0.3.msi

Overview

General Information

Sample name:T1#U5b89#U88c5#U53051.0.3.msi
renamed because original name is a hash value
Original sample name:T11.0.3.msi
Analysis ID:1584640
MD5:fa1f2bb0df3cf8b61926f1d974b3e49f
SHA1:87c7012347a0a902fc5f6d5b8e4bb3f2413bb07e
SHA256:0b89d9792688fb3de9b164302ffc53d73c63a8ac10164cd75a066df9bbb66219
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7284 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.3.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7320 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7436 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 4A761E21B55AE73BE1757CBB21C23442 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI520A.tmpReversingLabs: Detection: 15%
Source: T1#U5b89#U88c5#U53051.0.3.msiVirustotal: Detection: 28%Perma Link
Source: T1#U5b89#U88c5#U53051.0.3.msiReversingLabs: Detection: 28%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\69492f.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{4CBD9F7D-7522-4692-9696-B51CF758FAA5}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4B04.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\694931.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\694931.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI520A.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\694931.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI520A.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI520A.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: T1#U5b89#U88c5#U53051.0.3.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs T1#U5b89#U88c5#U53051.0.3.msi
Source: MSI520A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI520A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI520A.tmp.1.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF1A0D44A8D6CB6D37.TMPJump to behavior
Source: T1#U5b89#U88c5#U53051.0.3.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: T1#U5b89#U88c5#U53051.0.3.msiVirustotal: Detection: 28%
Source: T1#U5b89#U88c5#U53051.0.3.msiReversingLabs: Detection: 28%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.3.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 4A761E21B55AE73BE1757CBB21C23442 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 4A761E21B55AE73BE1757CBB21C23442 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: T1#U5b89#U88c5#U53051.0.3.msiStatic file information: File size 9326592 > 1048576
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name:
Source: MSI520A.tmp.1.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI520A.tmp.1.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI520A.tmp.1.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI520A.tmp.1.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI520A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI520A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI520A.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7472Thread sleep count: 425 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584640 Sample: T1#U5b89#U88c5#U53051.0.3.msi Startdate: 06/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI520A.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
T1#U5b89#U88c5#U53051.0.3.msi28%VirustotalBrowse
T1#U5b89#U88c5#U53051.0.3.msi29%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI520A.tmp16%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584640
Start date and time:2025-01-06 04:46:14 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:T1#U5b89#U88c5#U53051.0.3.msi
renamed because original name is a hash value
Original Sample Name:T11.0.3.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 4.175.87.197, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI520A.tmpSetup64v6.3.6.msiGet hashmaliciousUnknownBrowse
    #U7a0b#U5e8fv9.9.9.msiGet hashmaliciousUnknownBrowse
      Setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
        T1#U5b89#U88c5#U53051.0.5.msiGet hashmaliciousUnknownBrowse
          T1#U5b89#U88c5#U53051.0.6.msiGet hashmaliciousUnknownBrowse
            Setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
              Setup64v2.3.6.msiGet hashmaliciousUnknownBrowse
                #U7a0b#U5e8fv9.3.5.msiGet hashmaliciousUnknownBrowse
                  setup64v6.4.5.msiGet hashmaliciousUnknownBrowse
                    installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003386
                      Entropy (8bit):7.986513228790081
                      Encrypted:false
                      SSDEEP:196608:vB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4OU:p6TCe30s0nvfcy67yBHLgfVU
                      MD5:C5C36C0250E9DC79168A1E901B6FAD6E
                      SHA1:680BA2F4EBDFA833CC83096BD10FDB8DE018C4F8
                      SHA-256:5E4BF445877A22274B9C65661D1F5A568EEC235814BFFC7BC990F8F97EECB797
                      SHA-512:BDFA2DB48DE182B0911B1F7655EC8293F249FFEB9DC13265A47029F75F726A886DBF5F07D0F52E60FD3536A1073610B15C0BF6D43F52C9D5AA57740BB001670E
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.%Z.@.....@.....@.....@.....@.....@......&.{4CBD9F7D-7522-4692-9696-B51CF758FAA5}..Setup..T1#U5b89#U88c5#U53051.0.3.msi.@.....@.....@.....@........&.{2A01FD62-FDDE-4D4C-B4FD-E8DCEC6C2D84}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{4CBD9F7D-7522-4692-9696-B51CF758FAA5}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):2286817
                      Entropy (8bit):7.999926770724676
                      Encrypted:true
                      SSDEEP:49152:X91vhKnFZ+/DC67oHmHLNCYWQ1fTvsISX4F5Z2JMaH:DIF07bsQgLQ1fDlF2iaH
                      MD5:B2EC7FE117DEBE715356AE0DD3FECDEF
                      SHA1:F53052F5E1D38171A54297C8E89F9349E48D2119
                      SHA-256:4D6FE29C0938A694A57BA783C3CCA1438343940F20880A3136394FB4A1F519E3
                      SHA-512:F0A2530A2494B7EFBD7E16A4406B42EF6A2478A7E2E973296D2ED63756F6C9CCE99E5AF903B6CFE00736AB26FD09398AD572109D3E0BFECBA8EAAD7204A542BC
                      Malicious:false
                      Reputation:low
                      Preview:.@S....3.C.|......................I....Ap6.,.b.o$m5..`z2...<.n....AS.P..e.t....X....G.7.....*..[.C.u.....8f.@.@....E..4.t..Z.2...0T...R.,.+.#O...8R.1Z......R.E.B.E......m......d...../.M/!(..nZ..>~.H..n.....j.....k^.+.....0.G..S.)H '....`k#.m....g.<....a.l0.x...A....y.7>Gl........Z..,..Nph.S...q...AW9\t....qu....1.q..{..O..cq.MOS....ns.._...$.[21....:.G.......5...E..G........h,.RNB...?.ZNq..%3m...Y._...U.K..=s~S2-.&.<..U.K.tqrka..|{.Q....BKP......."S...1...\N...z.t.7.k.?3...r.m....2=,Y. }..._.....+J..m..(.p.W:.N.6T.i..."....j.""Ah..5....ZJ..v.^.K{...#.K.c...u....c......M....rLU:.......|..)..y..K.Y6Mn......9..1.....1qAh.{E..Q.B...Q\......{B.....7L.....&..8..w.c?R...R.qOM..It..k...E6...Ub.........k..>^.(h....QO=.[....!4./ ..3....Q..b?.Z...o.....=`.LS}..4....L~E....)\...._...g#....."..e...P..3F.x....%u....R...Ei..p...k...T.1..B.&[".FRQ{..]V...-....G......h..Fy...#.,C.8.y!P....z.C..a.....J.km.<.)...T....F_..<q..|*>.@\P...Nv.....`.\....'
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {2A01FD62-FDDE-4D4C-B4FD-E8DCEC6C2D84}, Create Time/Date: Sun Jan 5 12:23:50 2025, Last Saved Time/Date: Sun Jan 5 12:23:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9326592
                      Entropy (8bit):7.988614327901856
                      Encrypted:false
                      SSDEEP:196608:7VJeftXB6TCe30sWTDnHPfctFaEfVr7yBh1LRTKu4O:7V8j6TCe30sWnvfcy67yBHLguV
                      MD5:FA1F2BB0DF3CF8B61926F1D974B3E49F
                      SHA1:87C7012347A0A902FC5F6D5B8E4BB3F2413BB07E
                      SHA-256:0B89D9792688FB3DE9B164302FFC53D73C63A8AC10164CD75A066DF9BBB66219
                      SHA-512:59548C50D90276168A34C2038F9B1F4509146DD3FFA548C882A04386E95485954BBE2A1FB938C63ACEB3EC61D9DFE7ED14862CE9EFB9B951F486492528E871DE
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {2A01FD62-FDDE-4D4C-B4FD-E8DCEC6C2D84}, Create Time/Date: Sun Jan 5 12:23:50 2025, Last Saved Time/Date: Sun Jan 5 12:23:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):9326592
                      Entropy (8bit):7.988614327901856
                      Encrypted:false
                      SSDEEP:196608:7VJeftXB6TCe30sWTDnHPfctFaEfVr7yBh1LRTKu4O:7V8j6TCe30sWnvfcy67yBHLguV
                      MD5:FA1F2BB0DF3CF8B61926F1D974B3E49F
                      SHA1:87C7012347A0A902FC5F6D5B8E4BB3F2413BB07E
                      SHA-256:0B89D9792688FB3DE9B164302FFC53D73C63A8AC10164CD75A066DF9BBB66219
                      SHA-512:59548C50D90276168A34C2038F9B1F4509146DD3FFA548C882A04386E95485954BBE2A1FB938C63ACEB3EC61D9DFE7ED14862CE9EFB9B951F486492528E871DE
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997681
                      Entropy (8bit):7.986814903630673
                      Encrypted:false
                      SSDEEP:196608:eB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O+:+6TCe30s0nvfcy67yBHLgfV+
                      MD5:6E9DBBFDC3A290BC0C305C5AEA44555C
                      SHA1:06CECD618230CD880F01B982987BFB7B426CA061
                      SHA-256:7DFBFC50FB694CBFC53B82F077B37B9531F05E278149D48DE4C7A9FD7B4B1988
                      SHA-512:FC22F880E3067DAE324E87A82ECC9DC225D31DE4D5E38323654556B645B87757079738EB0F2F6DD8E9AD9F05DFE957CE84D4483EDC4A1D58A914AA5D6E0F7F39
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.%Z.@.....@.....@.....@.....@.....@......&.{4CBD9F7D-7522-4692-9696-B51CF758FAA5}..Setup..T1#U5b89#U88c5#U53051.0.3.msi.@.....@.....@.....@........&.{2A01FD62-FDDE-4D4C-B4FD-E8DCEC6C2D84}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.."..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\69492f.msi.........@........file.dat..l4d..file.dat.@.....@.."..@.......@.............@.........@.....@.....@.....@..q.@SV...@........._....J..._.@A.......j.MZx.....................@..................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:dropped
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      Joe Sandbox View:
                      • Filename: Setup64v6.3.6.msi, Detection: malicious, Browse
                      • Filename: #U7a0b#U5e8fv9.9.9.msi, Detection: malicious, Browse
                      • Filename: Setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: T1#U5b89#U88c5#U53051.0.5.msi, Detection: malicious, Browse
                      • Filename: T1#U5b89#U88c5#U53051.0.6.msi, Detection: malicious, Browse
                      • Filename: Setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: Setup64v2.3.6.msi, Detection: malicious, Browse
                      • Filename: #U7a0b#U5e8fv9.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v6.4.5.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1742584609836297
                      Encrypted:false
                      SSDEEP:12:JSbX72FjdSQAGiLIlHVRpIh/7777777777777777777777777vDHF0fayOBrl0i5:JfSQQI5wSfa9EF
                      MD5:0698DA8A6662A722309781E29115F362
                      SHA1:5BFEC274041D0DE7C42237FB64AE2E2E933E87E5
                      SHA-256:48362E0350AF6CF21E09AEA34F2CAD3F66A0A89DA6A8B91EC0DA9386CD1D5385
                      SHA-512:F8953CB5788D97039502B784176738EEA163332693C69210DB0D5141C985549D8EE2DD479509AB7BECD60F515D4A88700DFF74C54A867D3D741737382F834119
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4712154487588958
                      Encrypted:false
                      SSDEEP:48:P8Ph2uRc06WXJ6nT5vDCKajgdeS5o4rydeSIy09:Oh21xnTIKYUGU
                      MD5:79A10656484B2D2D8D2845DB37A7F7AE
                      SHA1:8E9E92F5F4CB9327E046573A4A70EF9606476802
                      SHA-256:C04E4CD835ABF8D5E1699966C0FE2002B0F163E56683075C186C1625EA6C9630
                      SHA-512:C3B79F110A231B0C5C5874A245BED3E177340DFF93049FF04D7F547DF64876050FE0BD1A1BD27447AEB7912CE88DA7B938C21D77449C11E1771754F82B1222B5
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):432221
                      Entropy (8bit):5.375169523148736
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgaur:zTtbmkExhMJCIpEru
                      MD5:845EE9901756C296B29F2623FABA262A
                      SHA1:79F9EF972F6D3FE094543BEED6621F025FAEB593
                      SHA-256:8528449AF06ACE38F9613FB4A964E041CAEC4D3AB8E18CD41F79334BD353E78C
                      SHA-512:BB6ED8C2D82B11B449D13D79AEF5844B901A77AD2F6E7EE32C4E61DB82B2BBA5BF3F0E0AC22ABC46688F5985891547B98F07D6A8C546A0C5B2646CB66E7FC978
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4712154487588958
                      Encrypted:false
                      SSDEEP:48:P8Ph2uRc06WXJ6nT5vDCKajgdeS5o4rydeSIy09:Oh21xnTIKYUGU
                      MD5:79A10656484B2D2D8D2845DB37A7F7AE
                      SHA1:8E9E92F5F4CB9327E046573A4A70EF9606476802
                      SHA-256:C04E4CD835ABF8D5E1699966C0FE2002B0F163E56683075C186C1625EA6C9630
                      SHA-512:C3B79F110A231B0C5C5874A245BED3E177340DFF93049FF04D7F547DF64876050FE0BD1A1BD27447AEB7912CE88DA7B938C21D77449C11E1771754F82B1222B5
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10542574530304044
                      Encrypted:false
                      SSDEEP:24:99f5zZLdB5GipVGdB5GipV7V2BwGGlrkgWL8+N5+CUWCL:99hzldeScdeS5o4r68a+CW
                      MD5:6A33B95A13AFAF63A96BD0C6F8E7D40D
                      SHA1:C679E6DD4736740B50D3273970B1EB81D09351F4
                      SHA-256:DADE1EC01F40A045189CA5F84E675E83DE98582BCD3200701CF02FB11A4424B4
                      SHA-512:56E2984B5213D1B2C61FCD2D73E6CDC49A4E9B863A097612610216696C982B96F13E3AF28E4FFC96FAF1B9E0A03C1CE70DBDC6B40D6CED66D635FB0E02B7BBDF
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07858343323143925
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKO0fNifA00OltiVky6l51:2F0i8n0itFzDHF0fayOBr
                      MD5:5F92B1B5C484B451D063E2E8F6720829
                      SHA1:D2CC4FB4C46B51EB5D06781B6D913C690FA4F9C7
                      SHA-256:540F3774746B5892AB8157472C5FC1E840E0F940443C59E1DBD9452E05779D34
                      SHA-512:7ED8E5593E7FFFBBFA6F532B999A8C728720F76A36FA3F2FC9CE96B3ECD16589011CC337CA60F6640FFF8C36355859F52A34FE3A68C630C1B3DC767C88F375AC
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4712154487588958
                      Encrypted:false
                      SSDEEP:48:P8Ph2uRc06WXJ6nT5vDCKajgdeS5o4rydeSIy09:Oh21xnTIKYUGU
                      MD5:79A10656484B2D2D8D2845DB37A7F7AE
                      SHA1:8E9E92F5F4CB9327E046573A4A70EF9606476802
                      SHA-256:C04E4CD835ABF8D5E1699966C0FE2002B0F163E56683075C186C1625EA6C9630
                      SHA-512:C3B79F110A231B0C5C5874A245BED3E177340DFF93049FF04D7F547DF64876050FE0BD1A1BD27447AEB7912CE88DA7B938C21D77449C11E1771754F82B1222B5
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:modified
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848819918367512
                      Encrypted:false
                      SSDEEP:48:sneuxNveFXJJT5lDCKajgdeS5o4rydeSIy09:SexxT6KYUGU
                      MD5:09373951B1E876E5BDA6B1A606908D23
                      SHA1:57CADBDD06309DA56B9C97B4649D94A70E5B6FC5
                      SHA-256:894B7B2247E6E2CE901FCA7FC4D7B6784CCA4DBAA297BDB9A8BB82DB07DC3266
                      SHA-512:A1379AFF07A65E54E184182306227AAA995CB71659806D79373F170712FDB0CBC2BD21645E1A5A46882F7FE3731724C030DF2321152D0E8A94D0A970A7CC3DD3
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848819918367512
                      Encrypted:false
                      SSDEEP:48:sneuxNveFXJJT5lDCKajgdeS5o4rydeSIy09:SexxT6KYUGU
                      MD5:09373951B1E876E5BDA6B1A606908D23
                      SHA1:57CADBDD06309DA56B9C97B4649D94A70E5B6FC5
                      SHA-256:894B7B2247E6E2CE901FCA7FC4D7B6784CCA4DBAA297BDB9A8BB82DB07DC3266
                      SHA-512:A1379AFF07A65E54E184182306227AAA995CB71659806D79373F170712FDB0CBC2BD21645E1A5A46882F7FE3731724C030DF2321152D0E8A94D0A970A7CC3DD3
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848819918367512
                      Encrypted:false
                      SSDEEP:48:sneuxNveFXJJT5lDCKajgdeS5o4rydeSIy09:SexxT6KYUGU
                      MD5:09373951B1E876E5BDA6B1A606908D23
                      SHA1:57CADBDD06309DA56B9C97B4649D94A70E5B6FC5
                      SHA-256:894B7B2247E6E2CE901FCA7FC4D7B6784CCA4DBAA297BDB9A8BB82DB07DC3266
                      SHA-512:A1379AFF07A65E54E184182306227AAA995CB71659806D79373F170712FDB0CBC2BD21645E1A5A46882F7FE3731724C030DF2321152D0E8A94D0A970A7CC3DD3
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: b, Template: Intel;1033, Revision Number: {2A01FD62-FDDE-4D4C-B4FD-E8DCEC6C2D84}, Create Time/Date: Sun Jan 5 12:23:50 2025, Last Saved Time/Date: Sun Jan 5 12:23:50 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.988614327901856
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:T1#U5b89#U88c5#U53051.0.3.msi
                      File size:9'326'592 bytes
                      MD5:fa1f2bb0df3cf8b61926f1d974b3e49f
                      SHA1:87c7012347a0a902fc5f6d5b8e4bb3f2413bb07e
                      SHA256:0b89d9792688fb3de9b164302ffc53d73c63a8ac10164cd75a066df9bbb66219
                      SHA512:59548c50d90276168a34c2038f9b1f4509146dd3ffa548c882a04386e95485954bbe2a1fb938c63aceb3ec61d9dfe7ed14862ce9efb9b951f486492528e871de
                      SSDEEP:196608:7VJeftXB6TCe30sWTDnHPfctFaEfVr7yBh1LRTKu4O:7V8j6TCe30sWnvfcy67yBHLguV
                      TLSH:41963321ACEFD6FBF6666332096471A14503AEB027A3C0465B113F0D1479BB1D7BBA6C
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:22:47:08
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\T1#U5b89#U88c5#U53051.0.3.msi"
                      Imagebase:0x7ff651fb0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:1
                      Start time:22:47:08
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff651fb0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:2
                      Start time:22:47:11
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 4A761E21B55AE73BE1757CBB21C23442 E Global\MSI0000
                      Imagebase:0x7ff651fb0000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly