| download: | CommunityClipsSetup_1813.msi |
| Full analysis: | https://app.any.run/tasks/7e7038f2-1e01-4af6-a533-973bfddd5448 |
| Verdict: | Malicious activity |
| Analysis date: | October 09, 2019, 14:03:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.2, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {A5766F94-C04B-48F4-9219-A2CA61F01DC0}, Title: Community Clips, Author: Microsoft, Number of Words: 2, Last Saved Time/Date: Thu Jun 19 22:53:38 2008, Last Printed: Thu Jun 19 22:53:38 2008 |
| MD5: | 2349E63E0690385B7579F3CD16FD6915 |
| SHA1: | E6056AB3DE0B86D96C03CF76546860E122E05B9E |
| SHA256: | 2BCDF7918E439556268AAF457A6895F5DBF274C888F272932E18809BB4C48341 |
| SSDEEP: | 196608:SVaOOtokclkc00tE+xeO3yRxDmGmgVyoLzaMUgGcQUrjHj5nasvU3hW0cd4Gn:SVzk6vVtE+o6sw24fkj5ruav |
| .msi | | | Microsoft Windows Installer (93.3) |
|---|---|---|
| .pps/ppt | | | Microsoft PowerPoint document (5.2) |
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;1033 |
| Pages: | 200 |
| RevisionNumber: | {A5766F94-C04B-48F4-9219-A2CA61F01DC0} |
| Title: | Community Clips |
| Subject: | - |
| Author: | Microsoft |
| Keywords: | - |
| Comments: | - |
| Words: | 2 |
| ModifyDate: | 2008:06:19 21:53:38 |
| LastPrinted: | 2008:06:19 21:53:38 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 568 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\WMexfmwp.dll" | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 968 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot23" "" "" "631c88d3b" "00000000" "00000564" "000005AC" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1096 | msiexec.exe /i "C:\Windows\Installer\WMEncoder.msi" /qb | C:\Windows\system32\msiexec.exe | — | WMEncoder.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1300 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmprevu.dll" | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Windows Media Components\Encoder\WMEncAgt.exe" /regserver | C:\Program Files\Windows Media Components\Encoder\WMEncAgt.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Media Encoder Agent Exit code: 0 Version: 9.00.00.2980 Modules
| |||||||||||||||
| 2100 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "00000394" "000003D0" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2168 | wmstypelib.exe /Q:A /R:N | C:\Program Files\Windows Media Components\Encoder\wmstypelib.exe | settmp.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Win32 Cabinet Self-Extractor Exit code: 0 Version: 6.00.2600.0000 Modules
| |||||||||||||||
| 2180 | "C:\Windows\Installer\MSIC799.tmp" /ShutDown | C:\Windows\Installer\MSIC799.tmp | — | msiexec.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2212 | C:\Windows\system32\MsiExec.exe -Embedding 81D974ADDBBAC722A7C0AF17EFA1B73C M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2244 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmesrcwp.dll" | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2612) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3064) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000323A8F86AA7ED501F80B0000F40A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3064) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000008C9C9186AA7ED501F80B0000F40A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000080ACE286AA7ED501540C000048080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000080ACE286AA7ED501540C0000800D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000080ACE286AA7ED501540C0000F00B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000080ACE286AA7ED501540C000030080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000003471E786AA7ED501540C000048080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000008ED3E986AA7ED501540C0000800D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3156) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000E835EC86AA7ED501540C000030080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2612 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI7E06.tmp | — | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\Windows\Installer\193917.msi | — | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\Windows\Installer\MSI3D4E.tmp | — | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFD4F99371F735BD77.TMP | — | |
MD5:— | SHA256:— | |||
| 3156 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 3064 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{78a34cdb-6f0e-4357-9c4f-88e90e003a63}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 2100 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 2100 | DrvInst.exe | C:\Windows\INF\setupapi.ev1 | binary | |
MD5:— | SHA256:— | |||
Domain | IP | Reputation |
|---|---|---|
www.officelabs.com |
| unknown |
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
rundll32.exe | MSOOBCI: DoInstall failed with error: 0x80070002
|
rundll32.exe | MSOOBCI: DoInstall failed with error: 0x80070002
|