Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Setup64v0.0.7.msi

Overview

General Information

Sample name:Setup64v0.0.7.msi
Analysis ID:1586535
MD5:2bd9f3a998d0fdce8c57bd918d0eae79
SHA1:57d81dc7fb80ec48f55fc846062e9deb9b7b563f
SHA256:48c55a1c602eb9775660ab39122d7214882bd8a2f5edfb7bd710d90520856418
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 792 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v0.0.7.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 6192 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7264 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 5A52A07E6F19699CC2CF0204D70B1F1A E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIF0A6.tmpVirustotal: Detection: 20%Perma Link
Source: Setup64v0.0.7.msiVirustotal: Detection: 10%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\53e76e.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{B3078164-3EC9-4C08-A714-527D4AA49225}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIECBD.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\53e770.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\53e770.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF0A6.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\53e770.msiJump to behavior
Source: MSIF0A6.tmp.4.drStatic PE information: Number of sections : 13 > 10
Source: Setup64v0.0.7.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs Setup64v0.0.7.msi
Source: MSIF0A6.tmp.4.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSIF0A6.tmp.4.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSIF0A6.tmp.4.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF206C402A7481603E.TMPJump to behavior
Source: Setup64v0.0.7.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: Setup64v0.0.7.msiVirustotal: Detection: 10%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v0.0.7.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 5A52A07E6F19699CC2CF0204D70B1F1A E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 5A52A07E6F19699CC2CF0204D70B1F1A E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: Setup64v0.0.7.msiStatic file information: File size 8773632 > 1048576
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name:
Source: MSIF0A6.tmp.4.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSIF0A6.tmp.4.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSIF0A6.tmp.4.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSIF0A6.tmp.4.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF0A6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF0A6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIF0A6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
2
Software Packing
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager11
Peripheral Device Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS11
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
File Deletion
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1586535 Sample: Setup64v0.0.7.msi Startdate: 09/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIF0A6.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Setup64v0.0.7.msi10%VirustotalBrowse
Setup64v0.0.7.msi11%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIF0A6.tmp21%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586535
Start date and time:2025-01-09 09:30:16 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:13
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:Setup64v0.0.7.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 52.149.20.212
  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
No context
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):7003378
Entropy (8bit):7.986514618257453
Encrypted:false
SSDEEP:196608:6B6TCe30s0TVnHPfctFaEfVr7yBh1LRTKf4Oq:S6TCe30s0Bvfcy67yBHLgfVq
MD5:055406BDF218DD9E0BED21758FF31D1A
SHA1:7D84B960C09DF70D6B85376DF5A6D88CE3DC5B6B
SHA-256:C8DFBE8D7EA680B8692C3B141B29ED9F2F274ABD6324443B841F95CE9BF7C843
SHA-512:DA3EC58328FC1382491C4E20591E8C311B67EFA2BBA03B3AB1E0234B9072689D432C98338E977D19A4647E35188FBE5717BD1B89DF2E8FCC80E2323941C89609
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@..)Z.@.....@.....@.....@.....@.....@......&.{B3078164-3EC9-4C08-A714-527D4AA49225}..Setup..Setup64v0.0.7.msi.@.....@.....@.....@........&.{6633D37E-4C11-4EB8-835F-EA8F63939877}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{B3078164-3EC9-4C08-A714-527D4AA49225}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz................................................k...`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q.............................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):1731984
Entropy (8bit):7.999891357249935
Encrypted:true
SSDEEP:49152:Qz/73CoYM7Oi6yzJvMQe8mZz2Ur+vaV4Yo/8K3m6ay/X4:Qr73f6yNvWzXr3VDa8KWTy/o
MD5:1EB1B3277463E91BD369C8F261BFC6AF
SHA1:3E82A68D3F172E9714374A394F49F8AE3B5212BB
SHA-256:F0018BE520CC1A0F43314BED4217F50D87DCB58E8E9F309DB9975FF27FA8F230
SHA-512:4E2EDADF7F8F231C2439699E6B35C803822B520DAE2235FB2AB90A3EC06350FAF604532B853B73709879DE41A01F3CD770D7DD32A65DF4DD04A4FDB46CCAB917
Malicious:false
Reputation:low
Preview:.@S....|.(..................h..q...;.$.Dk..3{.h..)S./XC..v..(&-.M+[.&8.g........ ..Q6.btL...5>F..).EY...@.#r.{.t.=.3..U+..d.. ........../...g.U.=..R.n.bf..%......x/g.... mXx.O..%.}Vo......U..Z..+..W,.oUB.p.'.#..o..1..4nj....8...].I..@..<XC.h.9.h....._{..{..G.P..'t....u..[.z..Hp..N.h..5T...........96.N(.c..m..3..{[.....loW.a]...!.m.....f....,u...Onn.h..3..gn...qj$<..:..u....*.._.t....R.]5..............jD..z.c..gL.;))B.^._........&.Y.....]..B..M.C..@.......=j<i..r..2.L..O.;..x..LJJd...~.i..p..UC.a.....{.,...Q...^%..5C..<j...\P....i...c.......A...s*R..wS.3T..O .......A,.....r..;...C...1`D..4.=s.(.......Swv...wf..>...i.$s...i=.qC.....'+....CjE.P..B.`....mM1...3.4[.k3g*..T.......{H..u..R..]1...A.....%....Tq....^.IX..|...ox_]tq....d$.".....s..!.}..G_..?.4~..o....A.z.Z.?.?Az{BF.......0."R... x.`...5v`..E.._..-....^....S..g9..i%D..Ns.......r.PUv.N.O.:....../z\.E..L..#..`"...u.5H,a.8.o..W..9yQ/.uN QZ.Q.V......b...........sg.V.....*y......2.m..6..
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdfgerk, Template: Intel;1033, Revision Number: {6633D37E-4C11-4EB8-835F-EA8F63939877}, Create Time/Date: Thu Jan 9 05:10:24 2025, Last Saved Time/Date: Thu Jan 9 05:10:24 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):8773632
Entropy (8bit):7.986935213717394
Encrypted:false
SSDEEP:196608:HHh4gGVVA8Kxy0B6TCe30s0TfnHPfctFaEfVr7yBh1LRTKf9O:HHh4vVVCo86TCe30s0Lvfcy67yBHLgfo
MD5:2BD9F3A998D0FDCE8C57BD918D0EAE79
SHA1:57D81DC7FB80EC48F55FC846062E9DEB9B7B563F
SHA-256:48C55A1C602EB9775660AB39122D7214882BD8A2F5EDFB7BD710D90520856418
SHA-512:7B6D0CB1F9550E1169BEAD7F0183B0C9B859089C23658E13224E9096245606781F9EF24791E89CD05236D377C823F2FFAB81CA4B32E3AD2E40264CB84553E741
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdfgerk, Template: Intel;1033, Revision Number: {6633D37E-4C11-4EB8-835F-EA8F63939877}, Create Time/Date: Thu Jan 9 05:10:24 2025, Last Saved Time/Date: Thu Jan 9 05:10:24 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Category:dropped
Size (bytes):8773632
Entropy (8bit):7.986935213717394
Encrypted:false
SSDEEP:196608:HHh4gGVVA8Kxy0B6TCe30s0TfnHPfctFaEfVr7yBh1LRTKf9O:HHh4vVVCo86TCe30s0Lvfcy67yBHLgfo
MD5:2BD9F3A998D0FDCE8C57BD918D0EAE79
SHA1:57D81DC7FB80EC48F55FC846062E9DEB9B7B563F
SHA-256:48C55A1C602EB9775660AB39122D7214882BD8A2F5EDFB7BD710D90520856418
SHA-512:7B6D0CB1F9550E1169BEAD7F0183B0C9B859089C23658E13224E9096245606781F9EF24791E89CD05236D377C823F2FFAB81CA4B32E3AD2E40264CB84553E741
Malicious:false
Reputation:low
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):6997681
Entropy (8bit):7.986814537390154
Encrypted:false
SSDEEP:196608:AB6TCe30s0TVnHPfctFaEfVr7yBh1LRTKf4Oq:A6TCe30s0Bvfcy67yBHLgfVq
MD5:A6BC3FA4FA9A1AA4CCBE7BB3224BC07F
SHA1:34CC5F7F508B066FED17B96C7DD3241A9003298D
SHA-256:0CF9728A029F5DCE2C99B19667C217290D1FF40923CB0DB738657E12541BFD86
SHA-512:73BABAEAE969DEF130C7FDBD18A7379418A3DFB164AA726497F6AF110405CBBD1D729BA645C6EDEA792B5747107658FE85F72BF7BD067CB6D3B7F2610025D7ED
Malicious:false
Reputation:low
Preview:...@IXOS.@.....@..)Z.@.....@.....@.....@.....@.....@......&.{B3078164-3EC9-4C08-A714-527D4AA49225}..Setup..Setup64v0.0.7.msi.@.....@.....@.....@........&.{6633D37E-4C11-4EB8-835F-EA8F63939877}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.m...@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\53e76e.msi.........@........file.dat..l4d..file.dat.@.....@.m...@.......@.............@.........@.....@.....@...'.@tc...@.i...@a........_....J..._.@A.......j.MZx.....................@..............................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
Category:modified
Size (bytes):6995968
Entropy (8bit):7.986891883556172
Encrypted:false
SSDEEP:196608:hB6TCe30s0TVnHPfctFaEfVr7yBh1LRTKf4O:D6TCe30s0Bvfcy67yBHLgfV
MD5:A9573870E97887443F3A234D0D936129
SHA1:5832BD4DC872AA27959EC794CD6625483778C804
SHA-256:455687165BC7382FEC70C334D8955F8445F5F2816AF8B6F5C918A03934C8D824
SHA-512:5C315EAB8594C779096092F0B08E8F411A29563F4871BDB0536B90F2A00DA5C606BF45CB20EA9E65430919DFD8808451153CFF489664749178181567F00089D2
Malicious:true
Antivirus:
  • Antivirus: Virustotal, Detection: 21%, Browse
Reputation:low
Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz................................................k...`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.165409033220719
Encrypted:false
SSDEEP:12:JSbX72Fj7AGiLIlHVRpEh/7777777777777777777777777vDHFCZ1Vk/l0i8Q:JRQI5UUXvF
MD5:55101A6CE030C5C2FD073A21BCA7F8E4
SHA1:309F504EDF87BF9DD924C4F26900354EE0305CAE
SHA-256:8FD4A4A1EC25361867103743938ED8C76C588909B0BBFC74A615FFEC2B6D3047
SHA-512:B2607D460CB1F6556618048DC6F3447C495256AB91A53183CB76F2F06AA2A7A397FF0C641A168536D0C9AF65E154096CEDB60614FDDFC200E31761096AC48AF3
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4683556809876315
Encrypted:false
SSDEEP:48:t8PheuRc06WXJqFT5kIVHlGddeS5MUrCdeSIAC7E:Qhe1hFTGiHlGOTocC7E
MD5:112233E35071DC47EA67E93AE87BAD57
SHA1:2B502364011606F9BF83585B14C5B50946FAA7E7
SHA-256:EA8746701367C53072BA0EEB4111A9F1B4077886B18C1D90ACAA74CC125D0E03
SHA-512:CA161F968E3CD665A9805D4264BCE1B64759B711AC908CE5AF68D64186670FEF2394ECEF0142733318FAD89C4DA3306FC9F921137551051D65575253EC33C3E2
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):360001
Entropy (8bit):5.3629687824367664
Encrypted:false
SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauX:zTtbmkExhMJCIpEG
MD5:F403A0E56557863CD0BB85631CF81267
SHA1:00687303EB26E003FCF48D241591C0A67BF486D1
SHA-256:A42A1BD553C23AFC0E64C2DD5AF4EACA8250B8C259FB509CA36CDC1052882450
SHA-512:92250707803825DDA88E057BD5CEF36C1C7F0EB6CBAFF71AE745B2C7EAA26AB7D65A5858AC8C0AC674643A8972C5DF09DAABF5F179A03D39E88C3D75023DFF9F
Malicious:false
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):69632
Entropy (8bit):0.10470897344625257
Encrypted:false
SSDEEP:24:o4ZCkoJ1EZLdB5GipVGdB5GipV7VqewGTlrkgW6+pIVHG:oEE1EldeScdeS5MUrW68IVH
MD5:23DEF8B8EBE7659013DB2A33506AA3AF
SHA1:0B861BFA73A4AFEF34F4EB19E0153FF2B5303064
SHA-256:33B78FCD913BBD9EC0619425CFFA0AA3D24288DF893C53E9AD85C5944A4A17C9
SHA-512:A0DC60795682D2E58394BB63D08AC2639E3501146F7FEFCD2803AF3447EF19662F90B035C24BA734C22B3076416BEDB43E96688BB6C167F94B83B7E4FBB6A35D
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07285565778076458
Encrypted:false
SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOZ8Z1nVn7ZHkSVky6lV1:2F0i8n0itFzDHFCZ1Vk/
MD5:11FF2C0478F190B567A0810B3084A6B2
SHA1:A17C9DBD79891E9C7D9BBF0A19BB2F76EF3FF2A2
SHA-256:6E18525B8E1BC5AAFEF47A8ACB1A5C6835F0B79F1670FE3C8466D774324605CB
SHA-512:6643CE8E4DBD5CEBF6BD5BCA277A17AD440816B09FC048B729889BADE24C9889E70889D5B9F58D502D709A0B9C207143422377138B5DACA611D80C60519EEBFD
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4683556809876315
Encrypted:false
SSDEEP:48:t8PheuRc06WXJqFT5kIVHlGddeS5MUrCdeSIAC7E:Qhe1hFTGiHlGOTocC7E
MD5:112233E35071DC47EA67E93AE87BAD57
SHA1:2B502364011606F9BF83585B14C5B50946FAA7E7
SHA-256:EA8746701367C53072BA0EEB4111A9F1B4077886B18C1D90ACAA74CC125D0E03
SHA-512:CA161F968E3CD665A9805D4264BCE1B64759B711AC908CE5AF68D64186670FEF2394ECEF0142733318FAD89C4DA3306FC9F921137551051D65575253EC33C3E2
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.4683556809876315
Encrypted:false
SSDEEP:48:t8PheuRc06WXJqFT5kIVHlGddeS5MUrCdeSIAC7E:Qhe1hFTGiHlGOTocC7E
MD5:112233E35071DC47EA67E93AE87BAD57
SHA1:2B502364011606F9BF83585B14C5B50946FAA7E7
SHA-256:EA8746701367C53072BA0EEB4111A9F1B4077886B18C1D90ACAA74CC125D0E03
SHA-512:CA161F968E3CD665A9805D4264BCE1B64759B711AC908CE5AF68D64186670FEF2394ECEF0142733318FAD89C4DA3306FC9F921137551051D65575253EC33C3E2
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1832164461391375
Encrypted:false
SSDEEP:48:tn2unPveFXJbT5iIVHlGddeS5MUrCdeSIAC7E:B2NDTgiHlGOTocC7E
MD5:551F6C9E919F2015D57C5AF3A57E98E0
SHA1:002299DF65A6ACE652A05BF4025A6DB87B2B0A29
SHA-256:B841205CF45BDB2BD0262C8646FD079DF5124C5CE434943BE707C69D13A3D53C
SHA-512:1D3B293E057111319F9DE6A22329405028FF693265810E81CEBBC76610B4691EA88B6C29B5B3B314407B59FEFCFBC1EE5CEADDC36C370E4307310F705E2E3CAF
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1832164461391375
Encrypted:false
SSDEEP:48:tn2unPveFXJbT5iIVHlGddeS5MUrCdeSIAC7E:B2NDTgiHlGOTocC7E
MD5:551F6C9E919F2015D57C5AF3A57E98E0
SHA1:002299DF65A6ACE652A05BF4025A6DB87B2B0A29
SHA-256:B841205CF45BDB2BD0262C8646FD079DF5124C5CE434943BE707C69D13A3D53C
SHA-512:1D3B293E057111319F9DE6A22329405028FF693265810E81CEBBC76610B4691EA88B6C29B5B3B314407B59FEFCFBC1EE5CEADDC36C370E4307310F705E2E3CAF
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.1832164461391375
Encrypted:false
SSDEEP:48:tn2unPveFXJbT5iIVHlGddeS5MUrCdeSIAC7E:B2NDTgiHlGOTocC7E
MD5:551F6C9E919F2015D57C5AF3A57E98E0
SHA1:002299DF65A6ACE652A05BF4025A6DB87B2B0A29
SHA-256:B841205CF45BDB2BD0262C8646FD079DF5124C5CE434943BE707C69D13A3D53C
SHA-512:1D3B293E057111319F9DE6A22329405028FF693265810E81CEBBC76610B4691EA88B6C29B5B3B314407B59FEFCFBC1EE5CEADDC36C370E4307310F705E2E3CAF
Malicious:false
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: gfdfgerk, Template: Intel;1033, Revision Number: {6633D37E-4C11-4EB8-835F-EA8F63939877}, Create Time/Date: Thu Jan 9 05:10:24 2025, Last Saved Time/Date: Thu Jan 9 05:10:24 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
Entropy (8bit):7.986935213717394
TrID:
  • Microsoft Windows Installer (60509/1) 88.31%
  • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
File name:Setup64v0.0.7.msi
File size:8'773'632 bytes
MD5:2bd9f3a998d0fdce8c57bd918d0eae79
SHA1:57d81dc7fb80ec48f55fc846062e9deb9b7b563f
SHA256:48c55a1c602eb9775660ab39122d7214882bd8a2f5edfb7bd710d90520856418
SHA512:7b6d0cb1f9550e1169bead7f0183b0c9b859089c23658e13224e9096245606781f9ef24791e89cd05236d377c823f2ffab81ca4b32e3ad2e40264cb84553e741
SSDEEP:196608:HHh4gGVVA8Kxy0B6TCe30s0TfnHPfctFaEfVr7yBh1LRTKf9O:HHh4vVVCo86TCe30s0Lvfcy67yBHLgfo
TLSH:27963331BCAF96FAE6366B730D5071920402AF7127F28049AB053B4D047EA74E6B7B5D
File Content Preview:........................>......................................................................................................................................................................................................................................
Icon Hash:2d2e3797b32b2b99
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:1
Start time:03:31:17
Start date:09/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v0.0.7.msi"
Imagebase:0x7ff614e60000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:4
Start time:03:31:18
Start date:09/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\msiexec.exe /V
Imagebase:0x7ff614e60000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:false

Target ID:8
Start time:03:31:23
Start date:09/01/2025
Path:C:\Windows\System32\msiexec.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\MsiExec.exe -Embedding 5A52A07E6F19699CC2CF0204D70B1F1A E Global\MSI0000
Imagebase:0x7ff614e60000
File size:69'632 bytes
MD5 hash:E5DA170027542E25EDE42FC54C929077
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

No disassembly