File name:

rms.viewer.6.8.ru.msi

Full analysis: https://app.any.run/tasks/8957ba09-17d2-4c8c-a13d-9e1e8a3f2e40
Verdict: No threats detected
Analysis date: May 01, 2019, 21:17:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: RMS - 6.8, Comments: This installer contains the logic and data to install RMS - Viewer 6.8, Keywords: Installer,MSI,Database, Subject: RMS - Viewer, Author: TektonIT, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2015 - Premier Edition with Virtualization Pack 22, Last Saved Time/Date: Fri Sep 1 01:07:30 2017, Create Time/Date: Fri Sep 1 01:07:30 2017, Last Printed: Fri Sep 1 01:07:30 2017, Revision Number: {3E4E561F-BC9F-472C-B151-2AFBE543B999}, Code page: 1251, Template: Intel;1049
MD5:

54E5F477F503E7FD47DA40B1B5EDCF22

SHA1:

432C18BF81714791755AB2AD073BB761A73B27DE

SHA256:

160E6207DF4201D8E3F9C4A50EF67510A95AE7E70DAB93E4230C6F89F1509563

SSDEEP:

196608:WJh9+E03tgGCs9ivB10p5145BFYzF/HdFYRNfzuldXHAbb3YHMW11/U09vLmbX9t:Iqp70vB1g145BFcFYv7WpAbEH/1lRCf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (84.2)
.mst | Windows SDK Setup Transform Script (9.5)
.flo | iGrafx FlowCharter document (5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Characters: -
LastModifiedBy: InstallShield
Words: -
Title: ????? ????????? RMS - ?????? 6.8
Comments: This installer contains the logic and data to install RMS - Viewer 6.8
Keywords: Installer,MSI,Database
Subject: RMS - Viewer
Author: TektonIT
Security: Password protected
Pages: 200
Software: InstallShield? 2015 - Premier Edition with Virtualization Pack 22
ModifyDate: 2017:09:01 00:07:30
CreateDate: 2017:09:01 00:07:30
LastPrinted: 2017:09:01 00:07:30
RevisionNumber: {3E4E561F-BC9F-472C-B151-2AFBE543B999}
CodePage: Windows Cyrillic
Template: Intel;1049
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2400C:\Windows\system32\MsiExec.exe -Embedding 9F51E9B7A0B2C12729F3BB59AD86C2A7 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2728C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3312"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\rms.viewer.6.8.ru.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
121
Read events
111
Write events
10
Delete events
0

Modification events

(PID) Process:(3312) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3312msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI131E.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info