File name:

OfficeCustomUIEditorSetup.msi

Full analysis: https://app.any.run/tasks/c2111fb6-1120-4831-a62a-4c06f62b7ea4
Verdict: No threats detected
Analysis date: June 15, 2018, 16:33:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {7D8C5F8C-E242-495D-B18D-95026AB36637}, Title: Custom UI Editor for Microsoft Office, Author: [email protected], Comments: Custom UI Editor for Microsoft Office Documents, Number of Words: 2, Last Saved Time/Date: Thu Nov 12 00:37:59 2009, Last Printed: Thu Nov 12 00:37:59 2009
MD5:

C9B9E2F4D1468B48F28A09FBAE36130D

SHA1:

8F0FCCECFF632BCBEF0E6DBFE8368AA7940328B1

SHA256:

06EBB61F52090D895B26129D60269ADAAB6A99C693D9F3779BA6FFC7927C7099

SSDEEP:

6144:daevx9Rrvrgw72ws9wcUh9pFtyXuo0UfvazuyOTbMmpyRwk:1vVrDgw7s9wBhnyXuobvazuHTbM1u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 2700)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
. | Generic OLE2 / Multistream Compound File (1.4)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {7D8C5F8C-E242-495D-B18D-95026AB36637}
Title: Custom UI Editor for Microsoft Office
Subject: -
Author: [email protected]
Keywords: -
Comments: Custom UI Editor for Microsoft Office Documents
Words: 2
ModifyDate: 2009:11:12 00:37:59
LastPrinted: 2009:11:12 00:37:59
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2320C:\Windows\system32\MsiExec.exe -Embedding D0CF24CE2E5920D485A3F35189C05676 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2700C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3232"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\OfficeCustomUIEditorSetup.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
135
Read events
135
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3232msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIFDFB.tmp
MD5:
SHA256:
3232msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIFE69.tmp
MD5:
SHA256:
2320MsiExec.exeC:\Users\admin\AppData\Local\Temp\CFGFE68.tmpxml
MD5:17AF548F88A3199AA8A63A72201F470F
SHA256:A558DBE555749CD3BDD62060FDBBA72720C4F4A186D5870B977ED2ACF9721D9E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info