| File name: | Radmin_Server_3.5.2.1_RU.msi |
| Full analysis: | https://app.any.run/tasks/f7c9cf49-7ad4-4cfb-b899-f8eb4c695391 |
| Verdict: | Malicious activity |
| Analysis date: | January 21, 2020, 14:33:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Number of Characters: 0, Last Saved By: DavidHacker, Number of Words: 0, Title: Radmin Server 3.5.2 installation package, Comments: This installer contains the logic and data to install Radmin Server 3.5.2, Keywords: Installer,MSI,Database, Subject: Radmin Server 3.5.2, Author: Famatech, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 12 - Professional Edition 12.0, Revision Number: {BBD285CD-D1FE-41B1-B6B4-7FF7C27F553B}, Last Saved Time/Date: Wed Dec 13 16:04:58 2017, Create Time/Date: Wed Dec 13 16:04:58 2017, Last Printed: Wed Dec 13 16:04:58 2017, Code page: 0, Template: Intel;0,1033,1049 |
| MD5: | 9FC37B651AAAA8D9A822BD00C56CA3F6 |
| SHA1: | AF2AFB71A99D350F709C8B98AAAE20E21B9DCBD0 |
| SHA256: | 083E7911712589E68084C87C6A843BD66D67CF0EAD499761D6262CFD14312122 |
| SSDEEP: | 98304:N4Yy6osoYmHAMoHIQ2MRZQTgMbL1dM3UXqNw+cCWegOmCnGuuY:NPdoY9HIQJRad1sUXqG+cCxgOmCnGE |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| Characters: | - |
|---|---|
| LastModifiedBy: | DavidHacker |
| Words: | - |
| Title: | Radmin Server 3.5.2 installation package |
| Comments: | This installer contains the logic and data to install Radmin Server 3.5.2 |
| Keywords: | Installer,MSI,Database |
| Subject: | Radmin Server 3.5.2 |
| Author: | Famatech |
| Security: | Password protected |
| Pages: | 200 |
| Software: | InstallShield? 12 - Professional Edition 12.0 |
| RevisionNumber: | {BBD285CD-D1FE-41B1-B6B4-7FF7C27F553B} |
| ModifyDate: | 2017:12:13 16:04:58 |
| CreateDate: | 2017:12:13 16:04:58 |
| LastPrinted: | 2017:12:13 16:04:58 |
| CodePage: | Unknown (0) |
| Template: | Intel;0,1033,1049 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Windows\system32\rserver30\RServer3.exe" /service | C:\Windows\system32\rserver30\RServer3.exe | services.exe | ||||||||||||
User: SYSTEM Company: Famatech Corp. Integrity Level: SYSTEM Description: Radmin Server Exit code: 0 Version: 3, 5, 2, 0 Modules
| |||||||||||||||
| 284 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 408 | "C:\Windows\System32\rserver30\rserver3.exe" /setup | C:\Windows\System32\rserver30\rserver3.exe | rsl.exe | ||||||||||||
User: admin Company: Famatech Corp. Integrity Level: HIGH Description: Radmin Server Exit code: 1 Version: 3, 5, 2, 0 Modules
| |||||||||||||||
| 1528 | "C:\Windows\system32\rserver30\FamItrfc.Exe" | C:\Windows\system32\rserver30\FamItrfc.Exe | — | FamItrfc.Exe | |||||||||||
User: admin Company: Famatech Corp. Integrity Level: MEDIUM Description: Radmin component Exit code: 0 Version: 3,5,2,1205 Modules
| |||||||||||||||
| 1584 | C:\Windows\system32\MsiExec.exe -Embedding 81BACFC98CB4F5328188312422BBDC8E | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1596 | C:\Windows\system32\rserver30\rsl.exe /setup | C:\Windows\system32\rserver30\rsl.exe | — | msiexec.exe | |||||||||||
User: admin Company: Famatech Corp. Integrity Level: MEDIUM Description: Radmin Server component Exit code: 1 Version: 3, 5, 2, 0 Modules
| |||||||||||||||
| 1740 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Radmin_Server_3.5.2.1_RU.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2060 | "C:\Windows\System32\rserver30\rserver3.exe" /setup | C:\Windows\System32\rserver30\rserver3.exe | — | rsl.exe | |||||||||||
User: admin Company: Famatech Corp. Integrity Level: MEDIUM Description: Radmin Server Exit code: 3221226540 Version: 3, 5, 2, 0 Modules
| |||||||||||||||
| 2136 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem4.inf" "mirrorv3.inf:Mirror.Mfg:mirrorv3:3.0.0.0:radmin_mirror_v3" "60bbf019f" "0000052C" "000005E0" "000005E4" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | "C:\Users\admin\AppData\Local\Temp\{1B704FD1-C00F-482F-8997-82F2F19E10E7}\rsetup.exe" /stop | C:\Users\admin\AppData\Local\Temp\{1B704FD1-C00F-482F-8997-82F2F19E10E7}\rsetup.exe | — | MsiExec.exe | |||||||||||
User: SYSTEM Company: Famatech Corp. Integrity Level: SYSTEM Description: Radmin Setup Helper Exit code: 1 Version: 3, 5, 2, 0 Modules
| |||||||||||||||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
| (PID) Process: | (1740) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-844 |
Value: BitLocker Data Recovery Agent | |||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000CA7B44C567D0D501900F0000AC0F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000CA7B44C567D0D501900F0000AC0F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 33 | |||
| (PID) Process: | (3984) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000056028CC567D0D501900F0000AC0F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1740 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIAE5B.tmp | — | |
MD5:— | SHA256:— | |||
| 1740 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIAED9.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Windows\Installer\39ed1a.msi | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Windows\Installer\MSIF1AD.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF92213F09152F8249.TMP | — | |
MD5:— | SHA256:— | |||
| 284 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Windows\Installer\MSIF325.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Windows\Installer\MSIF4CE.tmp | — | |
MD5:— | SHA256:— | |||
| 3984 | msiexec.exe | C:\Windows\Installer\MSIF54C.tmp | — | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
RServer3.exe | %n%n%n%n%n%n%n%n%n |
rserver3.exe | %n%n%n%n%n%n%n%n%n |