File name:

altinstaller.zip

Full analysis: https://app.any.run/tasks/cd7257a6-4966-4047-a553-895e18338849
Verdict: Malicious activity
Analysis date: December 07, 2023, 23:53:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CAF6DC57668B89BAFE51A0E65AA6AA05

SHA1:

A81475C1FF6DBCDD5D6690877DA54978D3A6D5E6

SHA256:

12C2F14F920E8378F5E4479DF718DDDD6DA35041F4C65D5CA4472D4814A148B7

SSDEEP:

196608:9VSOK9c4+Oy86Enc/JhVrEFlSbuEjNqoJjFJwQ1wDZXsjrd:DSOK9J6qkLgFobrNpRwD9XyJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3784)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 2928)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3784)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3784)
    • Reads the Internet Settings

      • setup.exe (PID: 2608)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 3784)
      • wmpnscfg.exe (PID: 3680)
      • setup.exe (PID: 2608)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1864)
    • Reads the computer name

      • msiexec.exe (PID: 3784)
      • wmpnscfg.exe (PID: 3680)
      • setup.exe (PID: 2608)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3680)
      • WINWORD.EXE (PID: 3736)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3784)
      • setup.exe (PID: 2608)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3784)
      • setup.exe (PID: 2608)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 3784)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:02:20 09:31:46
ZipCRC: 0xc4adeb6a
ZipCompressedSize: 6483263
ZipUncompressedSize: 6689280
ZipFileName: AltInstaller.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs wmpnscfg.exe no specs setup.exe no specs msiexec.exe no specs PhotoViewer.dll no specs winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1864"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\altinstaller.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1868C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2608"C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.23592\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.23592\setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
16.0.31206.173 built by: D16.10
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1864.23592\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2632"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.21056\AltInstaller.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2928C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3680"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3736"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\autoeducation.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
3784C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3916"C:\Windows\system32\msiexec.exe" -I "C:\Users\admin\AppData\Local\Temp\Rar$EXa1864.23592\AltInstaller.msi" C:\Windows\System32\msiexec.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 974
Read events
6 700
Write events
111
Delete events
163

Modification events

(PID) Process:(1864) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
32
Suspicious files
26
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
1864WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1864.21056\AltInstaller.msi
MD5:
SHA256:
3784msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3784msiexec.exeC:\Windows\Installer\216a71.msi
MD5:
SHA256:
3784msiexec.exeC:\Program Files\AltServer\plist.dllexecutable
MD5:3C6548478F160C23CAA5BBC7DA08894B
SHA256:8EB28214B9B115EAFB4AF5EC90179121E81541AD912B95AB4467C723A217D99B
3784msiexec.exeC:\Windows\Installer\216a72.ipibinary
MD5:CBFE4FD71292736C3D5C7C64CF0E4AA2
SHA256:06875DD78E8DEFE24908E5AE6F450DEAC4855E73151B4C521B7EBAC04A5609F9
3784msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF7F24AFD31E9109A7.TMPbinary
MD5:D6489D8952D98F9D4A7AEB0B649ACDA0
SHA256:D7524F91AA21AF86534D37F73D93C983121CBDA1B72B485ABAFE13F63CF76614
3784msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:4F480ECDD9EF5E1E2ADAEBACCCF5A31B
SHA256:CF96EAAA62F3B92E6B9A87140E8FB7008936F74930982AC847BA680DAE210071
3784msiexec.exeC:\Program Files\AltServer\AltServer.exeexecutable
MD5:0DB5AD2CD60C9DD142BEF768045BD35D
SHA256:8C0625E8A583AADF95E604A53480EAF11D717647CFB1457EEFAFCEBB226D7C82
3784msiexec.exeC:\Windows\Installer\MSI6F72.tmpbinary
MD5:0B08C51B6FF60C8939A1A1459088E637
SHA256:1C92903C36C8DAACBBE32F9E67553234017DACC33C688363E1FA42CCA08FB166
3784msiexec.exeC:\Program Files\AltServer\regex2.dllexecutable
MD5:547C43567AB8C08EB30F6C6BACB479A3
SHA256:3A71BF90E8BDDFB813B44F9CBCECF431311A7979C1DEBC976767B3E5E59031AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
868
svchost.exe
49.13.77.253:80
armmf.adobe.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 49.13.77.253
unknown

Threats

No threats detected
No debug info