Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Setup64v6.5.6.msi

Overview

General Information

Sample name:Setup64v6.5.6.msi
Analysis ID:1588833
MD5:5231c2ff4e149e7e292a370d2363f323
SHA1:38d24db47b728ed2705799758bbf6b768e0e443b
SHA256:a27419f1b922d08cda5c8e514961a7d49c30a2a695ec514ddf5cbdba4219d9dc
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7416 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v6.5.6.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7448 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7576 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 1F2DD0CE43CFAC7E85879F19C08163BD E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSIAB47.tmpReversingLabs: Detection: 13%
Source: C:\Windows\Installer\MSIAB47.tmpVirustotal: Detection: 22%Perma Link
Source: Setup64v6.5.6.msiVirustotal: Detection: 13%Perma Link
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55a0c6.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{127E16AA-0E4E-40A7-BB1E-851486585CCF}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIA56A.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55a0c8.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\55a0c8.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIAB47.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\55a0c8.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSIAB47.tmp 6874DAE2F5ABFD0C901B499F80A1AD3DEF6D8D056CDDFAABBCEDB4EE54BA0E3B
Source: MSIAB47.tmp.1.drStatic PE information: Number of sections : 13 > 10
Source: Setup64v6.5.6.msiBinary or memory string: OriginalFilenameqicns.dll( vs Setup64v6.5.6.msi
Source: MSIAB47.tmp.1.drStatic PE information: Section: ZLIB complexity 1.0000962336653814
Source: MSIAB47.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999239042207793
Source: MSIAB47.tmp.1.drStatic PE information: Section: ZLIB complexity 0.9999027262870733
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF49C6617B1452985A.TMPJump to behavior
Source: Setup64v6.5.6.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: Setup64v6.5.6.msiVirustotal: Detection: 13%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v6.5.6.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 1F2DD0CE43CFAC7E85879F19C08163BD E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 1F2DD0CE43CFAC7E85879F19C08163BD E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: Setup64v6.5.6.msiStatic file information: File size 10899456 > 1048576
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name:
Source: MSIAB47.tmp.1.drStatic PE information: section name: entropy: 7.999806318282915
Source: MSIAB47.tmp.1.drStatic PE information: section name: entropy: 7.994161631429829
Source: MSIAB47.tmp.1.drStatic PE information: section name: entropy: 7.999730989304491
Source: MSIAB47.tmp.1.drStatic PE information: section name: entropy: 7.039235148787067
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIAB47.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIAB47.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIAB47.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 7608Thread sleep count: 126 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1588833 Sample: Setup64v6.5.6.msi Startdate: 11/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSIAB47.tmp, PE32+ 6->13 dropped 11 msiexec.exe 1 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Setup64v6.5.6.msi13%VirustotalBrowse
Setup64v6.5.6.msi8%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSIAB47.tmp13%ReversingLabs
C:\Windows\Installer\MSIAB47.tmp23%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1588833
Start date and time:2025-01-11 06:05:59 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:Setup64v6.5.6.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.246.45
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSIAB47.tmpT1#U5b89#U88c5#U53051.0.1.msiGet hashmaliciousUnknownBrowse
    T1#U5b89#U88c5#U53051.0.3.msiGet hashmaliciousUnknownBrowse
      Setup64v2.5.6.msiGet hashmaliciousUnknownBrowse
        Setup64v3.2.6.msiGet hashmaliciousUnknownBrowse
          Setup64v3.6.4.msiGet hashmaliciousUnknownBrowse
            Setup64v0.4.7.msiGet hashmaliciousUnknownBrowse
              Setup64v2.3.6.msiGet hashmaliciousUnknownBrowse
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):9367767
                Entropy (8bit):7.991844338307325
                Encrypted:true
                SSDEEP:196608:BhADVh7QnCkk/riIpvC3CD5fxWTMDIhmm5d/1W19h/lYEn0bOzi1uNq/:EInjkzXpqyD5fKMCd5uZibOzr8
                MD5:2042E99A27A04B2AF2C80CDBCFAB571C
                SHA1:8566ADC9F27BB619B7F96BAB8B916830D695A5E5
                SHA-256:79AF014576666E69B6B17636485DC9BB28A40A0FE8FE6E5A1D6B272A1D1E45E8
                SHA-512:06F4FFBBEF585BAF07A93946DB65E9581927AD80D6BE8725E5053962FEDF5964DC02EF421BCB84667CBA84FD99706D2A59FAE32C16B1F5FB79F3F3ACEEB2F74F
                Malicious:false
                Reputation:low
                Preview:...@IXOS.@.....@..+Z.@.....@.....@.....@.....@.....@......&.{127E16AA-0E4E-40A7-BB1E-851486585CCF}..Setup..Setup64v6.5.6.msi.@.....@.....@.....@........&.{2593B0E7-4206-4073-A87F-0E0E3F990AAD}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{127E16AA-0E4E-40A7-BB1E-851486585CCF}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A........MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....9.[.........." .....J..........Dn..............................................fB....`... ...... ........ ...... ..............`.O.^.....O.\.....4.0.....O.............@.O.............................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):1493808
                Entropy (8bit):7.999882290109612
                Encrypted:true
                SSDEEP:24576:2aHDckFMxR3i/6vcFmDmZmwn+XNuSCaS4WXBRfRydXVHSS7a0Bj0vvRNJN8Sp+1P:2aHDym6AFn+X4SCaSFLfRydFHS+a0BjL
                MD5:A8F2786F5E62011865C18ED703423FB3
                SHA1:2841BB39FD3A8F55FA46656E578ED92723DBA26A
                SHA-256:1D03CF4BFAAA4E2A5D7F884B97987547EE8C295A564A9E74418278B85E02458A
                SHA-512:B518C135BDAA043D39DB3596E084CB956356127058EAF47FD2466790DEC66E4A9B9BDDE285704116BA16EBCF79B4AAC5D282E58EB9163A1BC2FA0113968A4D4A
                Malicious:false
                Reputation:low
                Preview:.@S.......,6..............V........&S_....Z....$.*.5-..,.=.$..*.GJ..YP..|n.......%g{D. .%.Xw..7.5..k.(Nf..0<p.Kw.w.7y.v.......<Dc..)ih....$..........G..`[~.c..Z5rH.?.k....s..g.|....5w..ba...UxY..U.8..`.$../.+...X{vt...e....y.^....j.....Y8....:..?..t5.H3.......ym......aQ.XxN..z....~2rj.r.=....MA<.+.)>.....-#....oYvQ..=......a%....x..*..}.J..Z...Vk......;..r...\.W...+....G...(...D)n.V..).:.|X...E=..|...3.b..|l;..D.^.......h=......z|.~Ga..\].o.........S..A.K...1.Y.........y~.>A....nM..)a1>r.;.....~T.....N.<.!KU..{.x.W.;....p.i.-..W.u.q...N.\G.m.6....).h?...2..0...r;v....[.>$..9c....x....v.{X...7V.5.LI..U.....i'.].._..S.f.).y;.....r.3...>..J/.......(].j ........m..T3..-...D.9.m.[......W2....I9.S...U....c...Ul.....v.<)......+.m...0.\...2..S..C.....$c..q.).{..)>...(.E.3^..A.{...h..1..{.Jx7.o.DD]..P/............,.W.}.U.[.5X.X*...f.:....+y.g*F..b9.!.b.l.f........9~....S.......Rj...@<#.`..J.q.#.2..X. F.......i.....T...x...L..C.:.=.{<X..
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fgjtyjh, Template: Intel;1033, Revision Number: {2593B0E7-4206-4073-A87F-0E0E3F990AAD}, Create Time/Date: Fri Jan 10 08:07:26 2025, Last Saved Time/Date: Fri Jan 10 08:07:26 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                Category:dropped
                Size (bytes):10899456
                Entropy (8bit):7.99085226909781
                Encrypted:true
                SSDEEP:196608:5eDFBfR1y+YhADVh7QnCkk/riIpvChCD5fxWTMDIhmm5d/1W19hGlYEn0bOzi1uo:YDfPyoInjkzXpqUD5fKMCd5u8ibOzr
                MD5:5231C2FF4E149E7E292A370D2363F323
                SHA1:38D24DB47B728ED2705799758BBF6B768E0E443B
                SHA-256:A27419F1B922D08CDA5C8E514961A7D49C30A2A695EC514DDF5CBDBA4219D9DC
                SHA-512:206634D6B4D30434EB64B6B4361117017B3FBC390E41F0C0221C11F0D0DCA361BE2651E701CDB65A3278B6F380B613288374EB0CF891CBBC48A4AF2D8B172A3A
                Malicious:false
                Reputation:low
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fgjtyjh, Template: Intel;1033, Revision Number: {2593B0E7-4206-4073-A87F-0E0E3F990AAD}, Create Time/Date: Fri Jan 10 08:07:26 2025, Last Saved Time/Date: Fri Jan 10 08:07:26 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                Category:dropped
                Size (bytes):10899456
                Entropy (8bit):7.99085226909781
                Encrypted:true
                SSDEEP:196608:5eDFBfR1y+YhADVh7QnCkk/riIpvChCD5fxWTMDIhmm5d/1W19hGlYEn0bOzi1uo:YDfPyoInjkzXpqUD5fKMCd5u8ibOzr
                MD5:5231C2FF4E149E7E292A370D2363F323
                SHA1:38D24DB47B728ED2705799758BBF6B768E0E443B
                SHA-256:A27419F1B922D08CDA5C8E514961A7D49C30A2A695EC514DDF5CBDBA4219D9DC
                SHA-512:206634D6B4D30434EB64B6B4361117017B3FBC390E41F0C0221C11F0D0DCA361BE2651E701CDB65A3278B6F380B613288374EB0CF891CBBC48A4AF2D8B172A3A
                Malicious:false
                Reputation:low
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):9362074
                Entropy (8bit):7.992026980581284
                Encrypted:true
                SSDEEP:196608:6hADVh7QnCkk/riIpvC3CD5fxWTMDIhmm5d/1W19h/lYEn0bOzi1uNq7:nInjkzXpqyD5fKMCd5uZibOzrE
                MD5:64FEFA65E962CACDB7CBE9F6A3F73C42
                SHA1:7C39DBD073FFA9BA69CB2A891D9B290A8CC1C21C
                SHA-256:B5899DFB965CF0AA4782BD6FCCCF3FD578903C22CEC697296179D1A71AC2CE81
                SHA-512:8647DAF9E1AB3BE2A78C8364ADEF138F59792DC663714D9F807DCBDCB1D3B9BD0907789E0A47904A4836B82858D803D40AA51EDB8729F8D8D8760D64B52EFCC2
                Malicious:false
                Reputation:low
                Preview:...@IXOS.@.....@..+Z.@.....@.....@.....@.....@.....@......&.{127E16AA-0E4E-40A7-BB1E-851486585CCF}..Setup..Setup64v6.5.6.msi.@.....@.....@.....@........&.{2593B0E7-4206-4073-A87F-0E0E3F990AAD}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@0....@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\55a0c6.msi.........@........file.dat..l4d..file.dat.@.....@0....@.......@.............@.........@.....@.....@..xo.@^b...@e....@.B?......._....J..._.@A........MZx.....................@..............................
                Process:C:\Windows\System32\msiexec.exe
                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                Category:modified
                Size (bytes):9360384
                Entropy (8bit):7.992073098718644
                Encrypted:true
                SSDEEP:196608:chADVh7QnCkk/riIpvC3CD5fxWTMDIhmm5d/1W19h/lYEn0bOzi1uNq:FInjkzXpqyD5fKMCd5uZibOzr
                MD5:2A695EF634A5D4D9C5838FDD1298FE06
                SHA1:94DA33CC3DA467242BF046E073234459846AB24B
                SHA-256:6874DAE2F5ABFD0C901B499F80A1AD3DEF6D8D056CDDFAABBCEDB4EE54BA0E3B
                SHA-512:7F39DAD6B60C209D49ED18DDED6955367324112443BC383C1B976053AD448ACAF759F1EE231F1A8D0CE4C7D673E6E9E426E022F55D5EA46C1DE2D1F19A16AC55
                Malicious:true
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 13%
                • Antivirus: Virustotal, Detection: 23%, Browse
                Joe Sandbox View:
                • Filename: T1#U5b89#U88c5#U53051.0.1.msi, Detection: malicious, Browse
                • Filename: T1#U5b89#U88c5#U53051.0.3.msi, Detection: malicious, Browse
                • Filename: Setup64v2.5.6.msi, Detection: malicious, Browse
                • Filename: Setup64v3.2.6.msi, Detection: malicious, Browse
                • Filename: Setup64v3.6.4.msi, Detection: malicious, Browse
                • Filename: Setup64v0.4.7.msi, Detection: malicious, Browse
                • Filename: Setup64v2.3.6.msi, Detection: malicious, Browse
                Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....9.[.........." .....J..........Dn..............................................fB....`... ...... ........ ...... ..............`.O.^.....O.\.....4.0.....O.............@.O...............................O.(............................................................P.......<..................@................`.......@..............@............`.... .....................@............@...@4....... .............@.................4....... .............@.................4....... .............@.................4....... .............@.................4....... .............@.................4....... .............@.................4....... .............@....rsrc...0.....4....... .............@..@.........`....4...+... .............@............PB..PO..PB...L.............@...................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.1663425984296427
                Encrypted:false
                SSDEEP:12:JSbX72FjjAGiLIlHVRpEh/7777777777777777777777777vDHFpduaVitFLIWWr:J1QI5UpuaV+9F
                MD5:052E7FA968D49F4E7C99AF694EAC2989
                SHA1:021A2E919DA2C5C353D66FB965F7C23548C5DC83
                SHA-256:6EE4FE0AEE2C8D88C468E9D4588F2B3696A8D2485CFA2AF127523B90D276106F
                SHA-512:8445623D04313A161C884D92D04A488DA3B8C10435E510E5AEF7DFAAF0745A68704C8D270798DF66FD5316F67F5C9AB6D2054C418DA1777D10DCE659D7C2F278
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.4629710421284665
                Encrypted:false
                SSDEEP:48:t8Ph2uRc06WXJSnT5EpVPgJdeS5o7brydeSIy:Qh21JnTaPzLG
                MD5:384B668B756E63FEBBBF9BFD4582B99A
                SHA1:A6391AF44026DB8928612A456B2AB5F99ED97D14
                SHA-256:158245C8AD842923A297EF21C9AE26EC9813A853A4BE715F11F4887C91C63915
                SHA-512:069D2DC62CD8A8F73F8ED2614BFF050080E1D1DC5B7172ACB59581D42C26148445EDBE7AAE90203B73FD901039FB2C8B4BB568DF622DB6E089CFD6B375BA1B93
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                Category:dropped
                Size (bytes):432221
                Entropy (8bit):5.37517016616521
                Encrypted:false
                SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgauz:zTtbmkExhMJCIpErq
                MD5:89066E6B8F67C9AE409398491AE1611E
                SHA1:416E5B6A70794779E76A6E289C871461AC189FB7
                SHA-256:36AE614BED4E443B4F0073FA17651F06850D352678B1FEF79BE08E8975FC803E
                SHA-512:9B4542849027A3989193A7CCF04375C6858301E01FA9466AFF561AB39A3D75960B1B8E834D803CBAF0D502EC19AB0DE8FFBD9939CAE915166FEE5EF066163685
                Malicious:false
                Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:3::
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):0.07306258890415102
                Encrypted:false
                SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOQGduMNViL2bXi3FLIWkSVky6lV1:2F0i8n0itFzDHFpduaVitFLIWW/
                MD5:161824BBDC6634498FDF576B6220A91B
                SHA1:54998EDD0CE71F87FC5C3E867F17094B3708349F
                SHA-256:BD1BC690B169600DE696A0D2D410C22D0B348F0A03AA8C02364395B4D0BC86F9
                SHA-512:CC03C426542BA2B90D8418CC1AF98D93BEFFA12704BE42C352DC005FEACFDFFA447DD9A573C308203716419DDD666390D9BE12465116839DD69CA9E0D656FA7F
                Malicious:false
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:3::
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:3::
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.4629710421284665
                Encrypted:false
                SSDEEP:48:t8Ph2uRc06WXJSnT5EpVPgJdeS5o7brydeSIy:Qh21JnTaPzLG
                MD5:384B668B756E63FEBBBF9BFD4582B99A
                SHA1:A6391AF44026DB8928612A456B2AB5F99ED97D14
                SHA-256:158245C8AD842923A297EF21C9AE26EC9813A853A4BE715F11F4887C91C63915
                SHA-512:069D2DC62CD8A8F73F8ED2614BFF050080E1D1DC5B7172ACB59581D42C26148445EDBE7AAE90203B73FD901039FB2C8B4BB568DF622DB6E089CFD6B375BA1B93
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):69632
                Entropy (8bit):0.10275820612187614
                Encrypted:false
                SSDEEP:24:2p+zZLdB5GipVGdB5GipV7V2BwG5Flrkgi+v8pV:hzldeScdeS5o7brig8pV
                MD5:CA6E1CFA2E46995F48B8EA6E9C343F23
                SHA1:20ED7B69A6E7020077BACDCC6EC905DB980D89E7
                SHA-256:09C60EFBAC69A1BDC966678E773FAF813487476786402A6738DDADDE9DFC8F52
                SHA-512:EFE4D2232772F121BE0B6D22D3985E64D87EAF32C3C32203012D8CD38B12477F7E15C1B07A9A9AC5AD374C0274A9A19845DA0714A00E94033164F45649559DEF
                Malicious:false
                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:3::
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):20480
                Entropy (8bit):1.4629710421284665
                Encrypted:false
                SSDEEP:48:t8Ph2uRc06WXJSnT5EpVPgJdeS5o7brydeSIy:Qh21JnTaPzLG
                MD5:384B668B756E63FEBBBF9BFD4582B99A
                SHA1:A6391AF44026DB8928612A456B2AB5F99ED97D14
                SHA-256:158245C8AD842923A297EF21C9AE26EC9813A853A4BE715F11F4887C91C63915
                SHA-512:069D2DC62CD8A8F73F8ED2614BFF050080E1D1DC5B7172ACB59581D42C26148445EDBE7AAE90203B73FD901039FB2C8B4BB568DF622DB6E089CFD6B375BA1B93
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):1.179797735007309
                Encrypted:false
                SSDEEP:48:y5neuxNveFXJBT5ipVPgJdeS5o7brydeSIy:EexZTUPzLG
                MD5:DCD10D219B7B561DD9269572766CF2F1
                SHA1:761C243E6A9B159AFD7E32CC6E77A8A5DC448D3A
                SHA-256:EB8DBE9F7F43D1DF5A34F8F712932412380E8B123EF9A23532C0C8A2DDF49219
                SHA-512:AAF22CAC5F0753FF76326264AFA3F94ADDA535387D0ED01CC6F38D13FBA455A39A9D7A92EF7BE5C435940C1CE59D4FF2E5E7EC5A83C9FCA58F15C70B2B1DB2B7
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:data
                Category:dropped
                Size (bytes):512
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:3::
                MD5:BF619EAC0CDF3F68D496EA9344137E8B
                SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                Malicious:false
                Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):1.179797735007309
                Encrypted:false
                SSDEEP:48:y5neuxNveFXJBT5ipVPgJdeS5o7brydeSIy:EexZTUPzLG
                MD5:DCD10D219B7B561DD9269572766CF2F1
                SHA1:761C243E6A9B159AFD7E32CC6E77A8A5DC448D3A
                SHA-256:EB8DBE9F7F43D1DF5A34F8F712932412380E8B123EF9A23532C0C8A2DDF49219
                SHA-512:AAF22CAC5F0753FF76326264AFA3F94ADDA535387D0ED01CC6F38D13FBA455A39A9D7A92EF7BE5C435940C1CE59D4FF2E5E7EC5A83C9FCA58F15C70B2B1DB2B7
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Windows\System32\msiexec.exe
                File Type:Composite Document File V2 Document, Cannot read section info
                Category:dropped
                Size (bytes):32768
                Entropy (8bit):1.179797735007309
                Encrypted:false
                SSDEEP:48:y5neuxNveFXJBT5ipVPgJdeS5o7brydeSIy:EexZTUPzLG
                MD5:DCD10D219B7B561DD9269572766CF2F1
                SHA1:761C243E6A9B159AFD7E32CC6E77A8A5DC448D3A
                SHA-256:EB8DBE9F7F43D1DF5A34F8F712932412380E8B123EF9A23532C0C8A2DDF49219
                SHA-512:AAF22CAC5F0753FF76326264AFA3F94ADDA535387D0ED01CC6F38D13FBA455A39A9D7A92EF7BE5C435940C1CE59D4FF2E5E7EC5A83C9FCA58F15C70B2B1DB2B7
                Malicious:false
                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fgjtyjh, Template: Intel;1033, Revision Number: {2593B0E7-4206-4073-A87F-0E0E3F990AAD}, Create Time/Date: Fri Jan 10 08:07:26 2025, Last Saved Time/Date: Fri Jan 10 08:07:26 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                Entropy (8bit):7.99085226909781
                TrID:
                • Microsoft Windows Installer (60509/1) 88.31%
                • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                File name:Setup64v6.5.6.msi
                File size:10'899'456 bytes
                MD5:5231c2ff4e149e7e292a370d2363f323
                SHA1:38d24db47b728ed2705799758bbf6b768e0e443b
                SHA256:a27419f1b922d08cda5c8e514961a7d49c30a2a695ec514ddf5cbdba4219d9dc
                SHA512:206634d6b4d30434eb64b6b4361117017b3fbc390e41f0c0221c11f0d0dca361be2651e701cdb65a3278b6f380b613288374eb0cf891cbbc48a4af2d8b172a3a
                SSDEEP:196608:5eDFBfR1y+YhADVh7QnCkk/riIpvChCD5fxWTMDIhmm5d/1W19hGlYEn0bOzi1uo:YDfPyoInjkzXpqUD5fKMCd5u8ibOzr
                TLSH:67B6330379BF6FBEE91639364CC56F92C71A7F9068B6011B8308371D9239A5325AB1F4
                File Content Preview:........................>......................................................................................................................................................................................................................................
                Icon Hash:2d2e3797b32b2b99
                No network behavior found

                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:00:06:55
                Start date:11/01/2025
                Path:C:\Windows\System32\msiexec.exe
                Wow64 process (32bit):false
                Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\Setup64v6.5.6.msi"
                Imagebase:0x7ff79b440000
                File size:69'632 bytes
                MD5 hash:E5DA170027542E25EDE42FC54C929077
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                Target ID:1
                Start time:00:06:56
                Start date:11/01/2025
                Path:C:\Windows\System32\msiexec.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\msiexec.exe /V
                Imagebase:0x7ff79b440000
                File size:69'632 bytes
                MD5 hash:E5DA170027542E25EDE42FC54C929077
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:false

                Target ID:2
                Start time:00:07:00
                Start date:11/01/2025
                Path:C:\Windows\System32\msiexec.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\System32\MsiExec.exe -Embedding 1F2DD0CE43CFAC7E85879F19C08163BD E Global\MSI0000
                Imagebase:0x7ff79b440000
                File size:69'632 bytes
                MD5 hash:E5DA170027542E25EDE42FC54C929077
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:true

                No disassembly