Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup64v.2.9.7.msi

Overview

General Information

Sample name:setup64v.2.9.7.msi
Analysis ID:1589806
MD5:d41221b81608c8680fb6f9bfb0b410b2
SHA1:aa92bb05c97b38ca001d1f992812c6c9ad8f3c7e
SHA256:e09b34e5a64c9cbf549fdb0d631ad3e69a82b7e2fb3d8586d474926d81d340fc
Tags:msiSilverFoxValleyRATwinosuser-kafan_shengui
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Hides threads from debuggers
Query firmware table information (likely to detect VMs)
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 7644 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v.2.9.7.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 7676 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7784 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 08F6A7EDCB5DE137CE761D3CB9496C60 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: Binary string: D:\APT\CleverSoar\x64\Release\PELoader.pdb source: setup64v.2.9.7.msi, MSI5A5C.tmp.2.dr, 685171.msi.2.dr, 685172.rbs.2.dr, MSI55F6.tmp.2.dr, bof.cd.3.dr, 685173.msi.2.dr
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\685171.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{B81CF2C5-A89B-45B4-8752-3EAD61A15F61}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI55F6.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\685173.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\685173.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI5A5C.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\685173.msiJump to behavior
Source: setup64v.2.9.7.msiBinary or memory string: OriginalFilenameqicns.dll( vs setup64v.2.9.7.msi
Source: classification engineClassification label: mal48.evad.winMSI@4/23@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\build.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF268AF5DD3F8DD39D.TMPJump to behavior
Source: setup64v.2.9.7.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v.2.9.7.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 08F6A7EDCB5DE137CE761D3CB9496C60 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 08F6A7EDCB5DE137CE761D3CB9496C60 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: setup64v.2.9.7.msiStatic file information: File size 8278016 > 1048576
Source: Binary string: D:\APT\CleverSoar\x64\Release\PELoader.pdb source: setup64v.2.9.7.msi, MSI5A5C.tmp.2.dr, 685171.msi.2.dr, 685172.rbs.2.dr, MSI55F6.tmp.2.dr, bof.cd.3.dr, 685173.msi.2.dr
Source: MSI5A5C.tmp.2.drStatic PE information: section name: _RDATA
Source: bof.cd.3.drStatic PE information: section name: _RDATA
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI5A5C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\bof.cdJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI5A5C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\bof.cdJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\msiexec.exeSystem information queried: FirmwareTableInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI5A5C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Windows NT\bof.cdJump to dropped file
Source: C:\Windows\System32\msiexec.exeLast function: Thread delayed
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior

Anti Debugging

barindex
Source: C:\Windows\System32\msiexec.exeThread information set: HideFromDebuggerJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess queried: DebugPortJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
31
Masquerading
OS Credential Dumping21
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
21
Virtualization/Sandbox Evasion
LSASS Memory21
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
File Deletion
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1589806 Sample: setup64v.2.9.7.msi Startdate: 13/01/2025 Architecture: WINDOWS Score: 48 5 msiexec.exe 75 30 2->5         started        8 msiexec.exe 5 2->8         started        file3 14 C:\Windows\Installer\MSI5A5C.tmp, PE32+ 5->14 dropped 10 msiexec.exe 1 5->10         started        process4 file5 16 C:\Program Files (x86)\Windows NT\bof.cd, PE32+ 10->16 dropped 18 Query firmware table information (likely to detect VMs) 10->18 20 Hides threads from debuggers 10->20 signatures6

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
setup64v.2.9.7.msi0%VirustotalBrowse
setup64v.2.9.7.msi0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files (x86)\Windows NT\bof.cd3%ReversingLabs
C:\Program Files (x86)\Windows NT\bof.cd1%VirustotalBrowse
C:\Windows\Installer\MSI5A5C.tmp3%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
truefalse
    high
    No contacted IP infos
    Joe Sandbox version:42.0.0 Malachite
    Analysis ID:1589806
    Start date and time:2025-01-13 07:25:22 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 4m 34s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:8
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:setup64v.2.9.7.msi
    Detection:MAL
    Classification:mal48.evad.winMSI@4/23@0/0
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • Found application associated with file extension: .msi
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
    • Excluded IPs from analysis (whitelisted): 13.107.253.45, 20.12.23.50, 4.245.163.56
    • Excluded domains from analysis (whitelisted): azurefd-t-fb-prod.trafficmanager.net, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    No simulations
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    s-part-0017.t-0009.fb-t-msedge.nethttps://encryption-deme-group.lomiraxen.ru/PdoodjcL/#Mvercauteren.william@deme-group.comGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    17367113452957edfc9b8ae3ec34b8a6a9089df6f896f271bbf1399203c8025fd6cb0731fa872.dat-decoded.exeGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    VlY57c5AF4.exeGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    wN7EPNiHSM.exeGet hashmaliciousFormBookBrowse
    • 13.107.253.45
    http://infarmbureau.comGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    32474162872806629906.jsGet hashmaliciousStrela DownloaderBrowse
    • 13.107.253.45
    0Ie2kYdPTW.exeGet hashmaliciousFormBookBrowse
    • 13.107.253.45
    97q26I8OtN.exeGet hashmaliciousFormBookBrowse
    • 13.107.253.45
    nkCBRtd25H.exeGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    https://www.filemail.com/d/rxythqchkhluipl?skipreg=trueGet hashmaliciousUnknownBrowse
    • 13.107.253.45
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    C:\Windows\Installer\MSI5A5C.tmpsetup64v.2.8.6.msiGet hashmaliciousUnknownBrowse
      T1#U5b89#U88c5#U53051.0.2.msiGet hashmaliciousUnknownBrowse
        T1#U5b89#U88c5#U53051.0.1.msiGet hashmaliciousUnknownBrowse
          setup64v.5.9.6.msiGet hashmaliciousUnknownBrowse
            setup64v.9.6.4.msiGet hashmaliciousUnknownBrowse
              C:\Program Files (x86)\Windows NT\bof.cdsetup64v.2.8.6.msiGet hashmaliciousUnknownBrowse
                T1#U5b89#U88c5#U53051.0.2.msiGet hashmaliciousUnknownBrowse
                  T1#U5b89#U88c5#U53051.0.1.msiGet hashmaliciousUnknownBrowse
                    setup64v.5.9.6.msiGet hashmaliciousUnknownBrowse
                      setup64v.9.6.4.msiGet hashmaliciousUnknownBrowse
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):212761
                        Entropy (8bit):6.260356610674245
                        Encrypted:false
                        SSDEEP:3072:Hz29v3Oq5W/Exc28jjqC6INFnuA00HlSlDlLw3ZTykLA:q9v3tWX28jjq3GFr00iITV0
                        MD5:6C00D024305334D52226EBFD354B1A30
                        SHA1:D4B959B1F9EFD5156EA7D7708137DFB1D3E770AA
                        SHA-256:45B5CA3820AD5F042F2EBFAEA61B8DAA5E6013004FA955B042438573646DE6E8
                        SHA-512:5A93846D8A9FC204711127FA024022C3DE2853C6D68F19E3FF96DCE4CC4796EB9FEB2F209BE056D96BFA9A1E1545FDF96D9324D6B3F6CC6578196BBD0AEFFCCE
                        Malicious:false
                        Reputation:low
                        Preview:...@IXOS.@.....@K.-Z.@.....@.....@.....@.....@.....@......&.{B81CF2C5-A89B-45B4-8752-3EAD61A15F61}..Setup..setup64v.2.9.7.msi.@.....@.....@.....@........&.{00A45B65-2867-43E6-9B3F-1CE27A348F48}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-123D-4311-82DD-4ABAFFD734C4}&.{B81CF2C5-A89B-45B4-8752-3EAD61A15F61}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....+.C:\Program Files (x86)\Windows NT\build.dat....*.C:\Program Files (x86)\Windows NT\file.dat....CustcomActionK...CustcomAction.@A......"..MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................................8...................................S.....S.....S.....S.....Rich..
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                        Category:dropped
                        Size (bytes):205312
                        Entropy (8bit):6.237281514235282
                        Encrypted:false
                        SSDEEP:3072:2z29v3Oq5W/Exc28jjqC6INFnuA00HlSlDlLw3ZTykL:T9v3tWX28jjq3GFr00iITV
                        MD5:E32DED15D485D157F5B14C934F2CCEF7
                        SHA1:081A2D3E7A07086BEB2FE686EBE156B87A4A6739
                        SHA-256:90915C7465530A776B1DC33BE7AA12970B9975C3408AB6D61860510B0FC6E35D
                        SHA-512:143E37EDEADF9F6A8E65BF6917DF47BE7D79B2DEA42F71E71E42A6F847CA88FD42F535803E4BDD79CBEC406EF7CF643DD6EC9D456677EEC8653B521A0A1C5F01
                        Malicious:false
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 3%
                        • Antivirus: Virustotal, Detection: 1%, Browse
                        Joe Sandbox View:
                        • Filename: setup64v.2.8.6.msi, Detection: malicious, Browse
                        • Filename: T1#U5b89#U88c5#U53051.0.2.msi, Detection: malicious, Browse
                        • Filename: T1#U5b89#U88c5#U53051.0.1.msi, Detection: malicious, Browse
                        • Filename: setup64v.5.9.6.msi, Detection: malicious, Browse
                        • Filename: setup64v.9.6.4.msi, Detection: malicious, Browse
                        Reputation:low
                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................................8...................................S.....S.....S.....S.....Rich...........PE..d.....g.........." .....<..........L....................................................`.............................................p...0...(.......4....@..`............p......`...p...............................8............P..h............................text....:.......<.................. ..`.rdata..<....P.......@..............@..@.data....%..........................@....pdata..`....@......................@..@_RDATA.......`......................@..@.reloc.......p......................@..B.rsrc...4...........................@..@................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):5952512
                        Entropy (8bit):7.999877357696195
                        Encrypted:true
                        SSDEEP:98304:3ZtKqfpYpS/RBfnm4+EJH8a7ZdMFERc3XniQpV0iXf6Jembt0RBt3ainK0s:JtupSZBfmCJh7ZC2RejX0iXf63ABt3A
                        MD5:1FB692977C71BBA67B81A200BC59B54E
                        SHA1:86078C63795BB58C894B1EA46A438C6B0C5B3ED6
                        SHA-256:BC41D43FD386D1125CF0D54AD35499B076895335CE84428C589059C08D542D79
                        SHA-512:6E76DD65758289131081282CA1066B37078CDD7CA9C60C589748C097ECC8680E31D7E9CE7B82106E69DE86DB37B0DA58080E1893A990BB1CCE69017F402C4397
                        Malicious:false
                        Reputation:low
                        Preview:.....F.&\8......3e......@.Z+V...V.p}.7...:.?Z..-._t;.;...J.....d+.T..N...../.9..L..'..s..Q8T_`.... o.G.(...l...i.W..R...|F......-...3..D...#&t\..gg.D&.Z...a.......,K#.a..3.H ...!.N.QWj..sp.;..A....(..}....F...6...1..N).b..xW....Y2...`...be...[.=t...rO..8...B*.a.k....!.!Pz......I.:$.....A6....V.p}.7...:.?Z..-/...\}[d..'..!.c..IY..F.......j.^.D..v.{..q..V.p}.7...:.?Z..-...).9.W..........v0.9.=obE..}...v+.....P..d..i^QC....#.]..K..Ehz.;.Je.U..c..t...(...u.C..m...d..].#[.KY..k.Dw.Xj......u.9.......:.-..Ehz.;.Je.U...2.@.%V...7..*MW.\TK..5.:.&T?...zA.E).^...&..Hd...TZuy.rY[...%........0...V?.k7`....C.LS.<.INj.].7.'r..w........z.F.]..S.....e........Ya.U7...Ehz.;.Je.U.........j.$e....6H..a.E......;.(.._Q.s..@r.YC.%.....R.e.r..Ehz.;.Je.U....~....Z.X3.[[..N._.F.q..'.S.7u.Hi.....E..X.! V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7...:.?Z..-V.p}.7..
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2155169
                        Entropy (8bit):7.99990576047351
                        Encrypted:true
                        SSDEEP:49152:ZOnQWjoIrWxyw6/qwnbVytE71WiDjTFYY9Sfq5ag1pJeYZwL7:UnQWjoIrmVsqwbVES1Z1YeSma+BZwX
                        MD5:2D44ECDA86B5C4E5F5413536151CE395
                        SHA1:7C02C0AC1A49D71B698E443F5A97C8604AE09B5B
                        SHA-256:8B8F8E39706F4732DDA1829387DBD3EF15D7F3E837AA42BF6E0B60CB693958E7
                        SHA-512:6F5FAA71DCCE66C5DED5A54BD45B5E0D5C3947EC90D682EFCAF9705D876695C75A742845356FD4D5677317A63234B6479699C30741222506977160A5C727CBA2
                        Malicious:false
                        Reputation:low
                        Preview:.@S......%....................E.}.....#.h.......<.K..e..b.S."-~A.....0?......`%.Dvh...Y....s.SNB..t.hP..^.s[.....o.VW..<....D..A.;..Y.#=.~...P....,N..V.k^Ey...M..s_g.1%#..zT..A.~..6D*..`...A....Z;...d...V..Q^.9l.C.......I..e..:i..p/UV.Lsd.......... ..=.[.'.w6L..Q.x89...CV.n....RQ.Fj...C..x"_.X.....A..Usr..M$^p......>.~....<m......+...=...|..b..:......*UYo5.no..B~......E.".......`.m.g......E.[.(.....o..M'>.*.Z.1.....t]..%...W..2..k]..p...=;M.8G.hag........+....b.\=4BPM.'Q.1(.....\._.+..X.I....U.....|=...&$...!...<Z...H[.;.9T.._7!..qi....r.um%.t.........m12..'.y.......W....h.!....,K......._...D.....n.)W.i..}....]..DA*...F.6.g./.o..6.....nkBM5...\.....}.].....D=.4E]...Am.....'..^.;x.S.p.^.[..x.k.....?..Y.G...&..R.\.L......6..`.%y..K.A..}......^a.,'s..O...J.Qr..f....r.Ac.2R$.lW.....cC..m......FF...S3:.....!...s.C..@......P*.{_...1....h.......#'.^`..0G..ZG#,....EI[.O..}..U.~..T..s.._.#^.~...<B...n6.!....?.f`.. NG.4.&t.w{...-.Z..ko.......)..\.<..
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: QT, Keywords: Installer, Comments: gsdfas, Template: Intel;1033, Revision Number: {00A45B65-2867-43E6-9B3F-1CE27A348F48}, Create Time/Date: Sun Jan 12 13:52:28 2025, Last Saved Time/Date: Sun Jan 12 13:52:28 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Category:dropped
                        Size (bytes):8278016
                        Entropy (8bit):7.990543964031766
                        Encrypted:true
                        SSDEEP:196608:/pG7dn5ducEHT5sUJGhCTXiljArtZA9TDhNwrmVBxOtcqdU:+dLFEHT5sU4hCLi2rtZSTq6ezd
                        MD5:D41221B81608C8680FB6F9BFB0B410B2
                        SHA1:AA92BB05C97B38CA001D1F992812C6C9AD8F3C7E
                        SHA-256:E09B34E5A64C9CBF549FDB0D631AD3E69A82B7E2FB3D8586D474926D81D340FC
                        SHA-512:7FEDE852BBA1EBD97D1E537EBA862E357C6FBA8A6A6669BCDD0C7C813B3953B0DDB8BB1EC50C9458872ECD6375583A50EE1795CF27233CF73DC0A7273000A81E
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: QT, Keywords: Installer, Comments: gsdfas, Template: Intel;1033, Revision Number: {00A45B65-2867-43E6-9B3F-1CE27A348F48}, Create Time/Date: Sun Jan 12 13:52:28 2025, Last Saved Time/Date: Sun Jan 12 13:52:28 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Category:dropped
                        Size (bytes):8278016
                        Entropy (8bit):7.990543964031766
                        Encrypted:true
                        SSDEEP:196608:/pG7dn5ducEHT5sUJGhCTXiljArtZA9TDhNwrmVBxOtcqdU:+dLFEHT5sU4hCLi2rtZSTq6ezd
                        MD5:D41221B81608C8680FB6F9BFB0B410B2
                        SHA1:AA92BB05C97B38CA001D1F992812C6C9AD8F3C7E
                        SHA-256:E09B34E5A64C9CBF549FDB0D631AD3E69A82B7E2FB3D8586D474926D81D340FC
                        SHA-512:7FEDE852BBA1EBD97D1E537EBA862E357C6FBA8A6A6669BCDD0C7C813B3953B0DDB8BB1EC50C9458872ECD6375583A50EE1795CF27233CF73DC0A7273000A81E
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):207130
                        Entropy (8bit):6.245014095174094
                        Encrypted:false
                        SSDEEP:3072:mz29v3Oq5W/Exc28jjqC6INFnuA00HlSlDlLw3ZTykLt/:j9v3tWX28jjq3GFr00iITVl
                        MD5:AAE932FB2A4E0919F6E8A2D49B42D27C
                        SHA1:BBF37D0223236AED78AB7C5026F471F18EE69153
                        SHA-256:1F57D0F04DA506555C98A2392BA3D7157B1093E9A2BD54C92B374AFF3DEE2068
                        SHA-512:BAC0C1FC3C49BC638AECEB64F35B4D33D361136AF256B0CE5DDA9D149BC998CC6563FD07371102D719224274DADA493285362B9021EDCF5EB310CB01977590E1
                        Malicious:false
                        Preview:...@IXOS.@.....@K.-Z.@.....@.....@.....@.....@.....@......&.{B81CF2C5-A89B-45B4-8752-3EAD61A15F61}..Setup..setup64v.2.9.7.msi.@.....@.....@.....@........&.{00A45B65-2867-43E6-9B3F-1CE27A348F48}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-123D-4311-82DD-4ABAFFD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@..{..@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\685171.msi.........@........build.dat..lbd..build.dat.@.....@..Z..@.......@.............@.........@.....@.....@.....@|q...@{....@.Y.N....file.dat..lcd..file.dat.@.....@.. ..@.......@.............@.........@.....@.
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                        Category:modified
                        Size (bytes):205312
                        Entropy (8bit):6.237281514235282
                        Encrypted:false
                        SSDEEP:3072:2z29v3Oq5W/Exc28jjqC6INFnuA00HlSlDlLw3ZTykL:T9v3tWX28jjq3GFr00iITV
                        MD5:E32DED15D485D157F5B14C934F2CCEF7
                        SHA1:081A2D3E7A07086BEB2FE686EBE156B87A4A6739
                        SHA-256:90915C7465530A776B1DC33BE7AA12970B9975C3408AB6D61860510B0FC6E35D
                        SHA-512:143E37EDEADF9F6A8E65BF6917DF47BE7D79B2DEA42F71E71E42A6F847CA88FD42F535803E4BDD79CBEC406EF7CF643DD6EC9D456677EEC8653B521A0A1C5F01
                        Malicious:false
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 3%
                        Joe Sandbox View:
                        • Filename: setup64v.2.8.6.msi, Detection: malicious, Browse
                        • Filename: T1#U5b89#U88c5#U53051.0.2.msi, Detection: malicious, Browse
                        • Filename: T1#U5b89#U88c5#U53051.0.1.msi, Detection: malicious, Browse
                        • Filename: setup64v.5.9.6.msi, Detection: malicious, Browse
                        • Filename: setup64v.9.6.4.msi, Detection: malicious, Browse
                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................................8...................................S.....S.....S.....S.....Rich...........PE..d.....g.........." .....<..........L....................................................`.............................................p...0...(.......4....@..`............p......`...p...............................8............P..h............................text....:.......<.................. ..`.rdata..<....P.......@..............@..@.data....%..........................@....pdata..`....@......................@..@_RDATA.......`......................@..@.reloc.......p......................@..B.rsrc...4...........................@..@................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.1671331165425987
                        Encrypted:false
                        SSDEEP:12:JSbX72Fj/AGiLIlHVRpFh/7777777777777777777777777vDHFh1ql0i8Q:J5QI5BZF
                        MD5:49AA0520BA75C5361EAAFE4634339713
                        SHA1:EDA2F9E1E02162A9275EBABADB830485DC5D7264
                        SHA-256:4914ACFC94A00479C93483261FACE9E4568DEFAB528F9DDD7F821F3C2E1D0452
                        SHA-512:39C2C490E7EE778F38857D90CB6720DDD0BB354D74AAEDB1AE00131BEC893EA70767B7835342D9FC69C37CE846A508A28135C02899EC82089D4A0AD9CB3EE719
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4609595979701409
                        Encrypted:false
                        SSDEEP:48:E8PhkuRc06WXJSjT5otRlldeS5gldrCdeSIJ73v:bhk1JjTGLlWdlpx
                        MD5:F102E16245E395F880392E9E40339515
                        SHA1:87AB87A948085EF4CE8EC057CD57253BBBC4A9F8
                        SHA-256:37891E4BCA230110C246C2F9FF3690F12E32DB6A6A4182AB862AB33EF636D112
                        SHA-512:A855950E8CB1F42F11F867205CCCA291CACD6E371412BE40AC05EB3398389608B6E1ADBF8EA2B4207B9152659B66B785F51469B9A229067393A8A4870ADC6EE6
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):360001
                        Entropy (8bit):5.362970025909078
                        Encrypted:false
                        SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgauy:zTtbmkExhMJCIpEj
                        MD5:0DD2374ACDA1614D3E5EEBC7DA8DEE03
                        SHA1:884990A0F1777661732C8C1E1258A6B5A2313DC0
                        SHA-256:6EFBC2DDFBF53E655799A8515800625FF9DF0037DED1D060BFEF5532D17433D8
                        SHA-512:EA3D57BBED083978DE541626DC037227061F958FB8033B52F39E07C9B9B2C403B22009C9023F376C568F098383ED8D0015855462F776BD5111C3181F0171A81E
                        Malicious:false
                        Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.177981285371441
                        Encrypted:false
                        SSDEEP:48:MnMufJveFXJFT5ytRlldeS5gldrCdeSIJ73v:yMHdT0LlWdlpx
                        MD5:893288D27083DB527D1BFA9744A48235
                        SHA1:9DA59A8B3E556AD5BDFE4D48B77F0F42011A5FD8
                        SHA-256:164179D6903BE7229DE9AA37AA433E39CECDAFD657AAFC7E8D9E69FA447E2996
                        SHA-512:FE18D5C732E9990CCA652F420FE725258F1134CDD05A0A56A46C444D2A579012429561909521C6FEC6598BB2C85A064EA2BDB17590A11C7A7CB2A52962026FA2
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):69632
                        Entropy (8bit):0.10177734852947615
                        Encrypted:false
                        SSDEEP:24:Fuh8Y5M1ZLdB5GipVGdB5GipV7VqKwGADlrkgp+ktR:Mv5M1ldeScdeS5gldrprtR
                        MD5:2F5D58E304774F8A4DB2FED6DEE6629D
                        SHA1:DF04B7981A9A036A21405A4B171DAAA6E71629DF
                        SHA-256:AE16ABADAC04AE54678DC382807BC7BF73D7B5F0F29D5105635D0D7858C02DB4
                        SHA-512:8CF2EA97DC2F6F5CC0926DA07CCD14335A1EE94B5A665986405840286C8348E6BED52C7F37A16CBCDB915D57F8777EDA29E15BDC8A42E8ECBDD207A84B17424E
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4609595979701409
                        Encrypted:false
                        SSDEEP:48:E8PhkuRc06WXJSjT5otRlldeS5gldrCdeSIJ73v:bhk1JjTGLlWdlpx
                        MD5:F102E16245E395F880392E9E40339515
                        SHA1:87AB87A948085EF4CE8EC057CD57253BBBC4A9F8
                        SHA-256:37891E4BCA230110C246C2F9FF3690F12E32DB6A6A4182AB862AB33EF636D112
                        SHA-512:A855950E8CB1F42F11F867205CCCA291CACD6E371412BE40AC05EB3398389608B6E1ADBF8EA2B4207B9152659B66B785F51469B9A229067393A8A4870ADC6EE6
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.177981285371441
                        Encrypted:false
                        SSDEEP:48:MnMufJveFXJFT5ytRlldeS5gldrCdeSIJ73v:yMHdT0LlWdlpx
                        MD5:893288D27083DB527D1BFA9744A48235
                        SHA1:9DA59A8B3E556AD5BDFE4D48B77F0F42011A5FD8
                        SHA-256:164179D6903BE7229DE9AA37AA433E39CECDAFD657AAFC7E8D9E69FA447E2996
                        SHA-512:FE18D5C732E9990CCA652F420FE725258F1134CDD05A0A56A46C444D2A579012429561909521C6FEC6598BB2C85A064EA2BDB17590A11C7A7CB2A52962026FA2
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):1.4609595979701409
                        Encrypted:false
                        SSDEEP:48:E8PhkuRc06WXJSjT5otRlldeS5gldrCdeSIJ73v:bhk1JjTGLlWdlpx
                        MD5:F102E16245E395F880392E9E40339515
                        SHA1:87AB87A948085EF4CE8EC057CD57253BBBC4A9F8
                        SHA-256:37891E4BCA230110C246C2F9FF3690F12E32DB6A6A4182AB862AB33EF636D112
                        SHA-512:A855950E8CB1F42F11F867205CCCA291CACD6E371412BE40AC05EB3398389608B6E1ADBF8EA2B4207B9152659B66B785F51469B9A229067393A8A4870ADC6EE6
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):0.0734746761583202
                        Encrypted:false
                        SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOhK51jmH9HwVky6lq:2F0i8n0itFzDHFh1q
                        MD5:D8D81E1F4B5B750D618FA83245D87B04
                        SHA1:A85222AAA070FE05837D0D054ACC48E616FCECF6
                        SHA-256:322432A8E304127E2D1A544C24979016213309041F0BCA71E380E4A0F90E2630
                        SHA-512:EEB3994C6A37439655A8E2EF04BF43AEA535FE49952E04B6ABD988C60410EB7D13E8A61C69B03345391AEB42B42C815061FF3E6D4A251C72B1B0B310034C4E35
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):1.177981285371441
                        Encrypted:false
                        SSDEEP:48:MnMufJveFXJFT5ytRlldeS5gldrCdeSIJ73v:yMHdT0LlWdlpx
                        MD5:893288D27083DB527D1BFA9744A48235
                        SHA1:9DA59A8B3E556AD5BDFE4D48B77F0F42011A5FD8
                        SHA-256:164179D6903BE7229DE9AA37AA433E39CECDAFD657AAFC7E8D9E69FA447E2996
                        SHA-512:FE18D5C732E9990CCA652F420FE725258F1134CDD05A0A56A46C444D2A579012429561909521C6FEC6598BB2C85A064EA2BDB17590A11C7A7CB2A52962026FA2
                        Malicious:false
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Windows\System32\msiexec.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):512
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                        Malicious:false
                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: QT, Keywords: Installer, Comments: gsdfas, Template: Intel;1033, Revision Number: {00A45B65-2867-43E6-9B3F-1CE27A348F48}, Create Time/Date: Sun Jan 12 13:52:28 2025, Last Saved Time/Date: Sun Jan 12 13:52:28 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                        Entropy (8bit):7.990543964031766
                        TrID:
                        • Microsoft Windows Installer (60509/1) 88.31%
                        • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                        File name:setup64v.2.9.7.msi
                        File size:8'278'016 bytes
                        MD5:d41221b81608c8680fb6f9bfb0b410b2
                        SHA1:aa92bb05c97b38ca001d1f992812c6c9ad8f3c7e
                        SHA256:e09b34e5a64c9cbf549fdb0d631ad3e69a82b7e2fb3d8586d474926d81d340fc
                        SHA512:7fede852bba1ebd97d1e537eba862e357c6fba8a6a6669bcdd0c7c813b3953b0ddb8bb1ec50c9458872ecd6375583a50ee1795cf27233cf73dc0a7273000a81e
                        SSDEEP:196608:/pG7dn5ducEHT5sUJGhCTXiljArtZA9TDhNwrmVBxOtcqdU:+dLFEHT5sU4hCLi2rtZSTq6ezd
                        TLSH:6886331677697268E516833A5A074B8782373CD8A371CD370BB8B724AF77B9161BD380
                        File Content Preview:........................>......................................................................................................................................................................................................................................
                        Icon Hash:2d2e3797b32b2b99
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Jan 13, 2025 07:26:15.164942026 CET1.1.1.1192.168.2.90x6644No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                        Jan 13, 2025 07:26:15.164942026 CET1.1.1.1192.168.2.90x6644No error (0)dual.s-part-0017.t-0009.fb-t-msedge.nets-part-0017.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                        Jan 13, 2025 07:26:15.164942026 CET1.1.1.1192.168.2.90x6644No error (0)s-part-0017.t-0009.fb-t-msedge.net13.107.253.45A (IP address)IN (0x0001)false

                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:1
                        Start time:01:26:16
                        Start date:13/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\setup64v.2.9.7.msi"
                        Imagebase:0x7ff7d5890000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        Target ID:2
                        Start time:01:26:17
                        Start date:13/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\msiexec.exe /V
                        Imagebase:0x7ff7d5890000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:3
                        Start time:01:26:21
                        Start date:13/01/2025
                        Path:C:\Windows\System32\msiexec.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\System32\MsiExec.exe -Embedding 08F6A7EDCB5DE137CE761D3CB9496C60 E Global\MSI0000
                        Imagebase:0x7ff7d5890000
                        File size:69'632 bytes
                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:true

                        No disassembly