| File name: | UCLEARUpdater.msi |
| Full analysis: | https://app.any.run/tasks/fad6773b-1f5b-4bed-ada1-a598637e1fba |
| Verdict: | Malicious activity |
| Analysis date: | December 03, 2019, 00:29:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {8FAD4851-9D6C-420B-A7AD-749B287F951B}, Title: UCLEAR Firmware Update, Author: BITwave Pte Ltd, Number of Words: 2, Last Saved Time/Date: Fri Apr 11 10:33:11 2014, Last Printed: Fri Apr 11 10:33:11 2014 |
| MD5: | 48E839AE0F683F8A26BFB2BE848224D5 |
| SHA1: | F09E8B53C8E78106D862CE45C26FC53E6E1916E3 |
| SHA256: | 18565C425D5D2BCF2F099BD73B1BC84C467E600ED061FCEFCF29225BCE5EEC91 |
| SSDEEP: | 393216:5qSBPyBCqQ+/A+Qe2hPp2NXyMEpdhZwFdXGiQt:5qE6QGA+QeyPpM2sXGiG |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;1033 |
| Pages: | 200 |
| RevisionNumber: | {8FAD4851-9D6C-420B-A7AD-749B287F951B} |
| Title: | UCLEAR Firmware Update |
| Subject: | - |
| Author: | BITwave Pte Ltd |
| Keywords: | - |
| Comments: | - |
| Words: | 2 |
| ModifyDate: | 2014:04:11 09:33:11 |
| LastPrinted: | 2014:04:11 09:33:11 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{40c067ae-a197-31a3-b89f-9b2f53f3eb78}\usbspi.inf" "0" "655a53147" "00000060" "WinSta0\Default" "000003C4" "208" "c:\uclear\drivers\win32" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 896 | DrvInst.exe "4" "8" "C:\Users\admin\AppData\Local\Temp\{052f1986-46e9-7467-ae67-c0406ed7731c}\csrbluecoreusb.inf" "0" "634fc17ef" "000005CC" "WinSta0\Default" "00000060" "208" "c:\uclear\drivers\win32" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1400 | cmd /c ""C:\Users\admin\AppData\Local\Temp\5E18.tmp\DPInst.bat"" | C:\Windows\system32\cmd.exe | — | DPInst0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1648 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\UCLEARUpdater.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1896 | C:\UCLEAR\Drivers\win32\DPInst.exe /S /F /PATH C:\UCLEAR\Drivers\win32 | C:\UCLEAR\Drivers\win32\DPInst.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Driver Package Installer Exit code: 3221226540 Version: 2.1 Modules
| |||||||||||||||
| 2276 | "C:\UCLEAR\Drivers\win32\DPInst.exe" /S /F /PATH C:\UCLEAR\Drivers\win32 | C:\UCLEAR\Drivers\win32\DPInst.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Driver Package Installer Exit code: 3221226540 Version: 2.1 Modules
| |||||||||||||||
| 2588 | "C:\UCLEAR\DPInst0.exe" | C:\UCLEAR\DPInst0.exe | — | msiexec.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2972 | "C:\UCLEAR\Drivers\win32\DPInst.exe" /S /F /PATH C:\UCLEAR\Drivers\win32 | C:\UCLEAR\Drivers\win32\DPInst.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 512 Version: 2.1 Modules
| |||||||||||||||
| 3308 | "C:\Windows\system32\MsiExec.exe" /Y "C:\UCLEAR\msflxgrd\MSFlxGrd.Ocx" | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3704 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3896) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000006C7872BC70A9D501380F0000780B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3896) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000C6DA74BC70A9D501380F0000780B0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3896) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 33 | |||
| (PID) Process: | (3896) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000765EFABC70A9D501380F0000780B0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3896) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D0C0FCBC70A9D501380F000064080000E80300000100000000000000000000006FA40DB170DEE143B6BD0305F017D2180000000000000000 | |||
| (PID) Process: | (3704) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EC0E0BBD70A9D501780E00007C0B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3704) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EC0E0BBD70A9D501780E000094050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3704) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EC0E0BBD70A9D501780E0000440A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3704) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000EC0E0BBD70A9D501780E0000BC060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3704) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000FA3512BD70A9D501780E00007C0B0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3896 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\Windows\Installer\394ec6.msi | — | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFCA4711046D37E1E1.TMP | — | |
MD5:— | SHA256:— | |||
| 3704 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\Windows\Installer\394ec7.ipi | binary | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\UCLEAR\Drivers\win64\DPInst0.exe | executable | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{b10da46f-de70-43e1-b6bd-0305f017d218}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\UCLEAR\HBC200_Update_RC207\hlp\page_connection.htm | html | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\Windows\Installer\MSI563A.tmp | binary | |
MD5:— | SHA256:— | |||
| 3896 | msiexec.exe | C:\UCLEAR\Drivers\win32\CSRBlueCoreUSB.inf | binary | |
MD5:— | SHA256:— | |||