download: | CommunityClipsSetup_1813.msi |
Full analysis: | https://app.any.run/tasks/7e7038f2-1e01-4af6-a533-973bfddd5448 |
Verdict: | Malicious activity |
Analysis date: | October 09, 2019, 14:03:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.2, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {A5766F94-C04B-48F4-9219-A2CA61F01DC0}, Title: Community Clips, Author: Microsoft, Number of Words: 2, Last Saved Time/Date: Thu Jun 19 22:53:38 2008, Last Printed: Thu Jun 19 22:53:38 2008 |
MD5: | 2349E63E0690385B7579F3CD16FD6915 |
SHA1: | E6056AB3DE0B86D96C03CF76546860E122E05B9E |
SHA256: | 2BCDF7918E439556268AAF457A6895F5DBF274C888F272932E18809BB4C48341 |
SSDEEP: | 196608:SVaOOtokclkc00tE+xeO3yRxDmGmgVyoLzaMUgGcQUrjHj5nasvU3hW0cd4Gn:SVzk6vVtE+o6sw24fkj5ruav |
.msi | | | Microsoft Windows Installer (93.3) |
---|---|---|
.pps/ppt | | | Microsoft PowerPoint document (5.2) |
.msi | | | Microsoft Installer (100) |
LastPrinted: | 2008:06:19 21:53:38 |
---|---|
ModifyDate: | 2008:06:19 21:53:38 |
Words: | 2 |
Comments: | - |
Keywords: | - |
Author: | Microsoft |
Subject: | - |
Title: | Community Clips |
RevisionNumber: | {A5766F94-C04B-48F4-9219-A2CA61F01DC0} |
Pages: | 200 |
Template: | Intel;1033 |
CodePage: | Windows Latin 1 (Western European) |
Security: | Password protected |
Software: | Windows Installer |
CreateDate: | 1999:06:21 07:00:00 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2612 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\CommunityClipsSetup_1813.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
3064 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
2508 | C:\Windows\system32\MsiExec.exe -Embedding CFC4DDD4B1AAFCF35785AD03205F32D9 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
3156 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2100 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "00000394" "000003D0" | C:\Windows\system32\DrvInst.exe | — | svchost.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2688 | C:\Windows\system32\MsiExec.exe -Embedding C946BB470EF50EA3D2B64D279A15565E | C:\Windows\system32\MsiExec.exe | — | msiexec.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
2212 | C:\Windows\system32\MsiExec.exe -Embedding 81D974ADDBBAC722A7C0AF17EFA1B73C M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
2500 | "C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe" | C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe | — | msiexec.exe |
User: admin Company: Microsoft Office Labs Integrity Level: MEDIUM Description: CommunityClips Version: 1.0.1813.0 | ||||
2900 | "C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe" /Q | C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe | — | CommunityClips.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Component Setup Application Exit code: 3221226540 Version: 9.00.00.2980 | ||||
2868 | "C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe" /Q | C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe | CommunityClips.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Media Component Setup Application Exit code: 0 Version: 9.00.00.2980 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2612 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI7E06.tmp | — | |
MD5:— | SHA256:— | |||
3064 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
3064 | msiexec.exe | C:\Windows\Installer\193917.msi | — | |
MD5:— | SHA256:— | |||
3064 | msiexec.exe | C:\Windows\Installer\MSI3D4E.tmp | — | |
MD5:— | SHA256:— | |||
3064 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:584E7B2B150A20BF77E1D77131FA3D1C | SHA256:1BE505A100CF543BC4BE2C19F161745F0BB5D11ACAD6268985938490C41EBC41 | |||
2100 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:8F761032829FB6121AEE77E26DC667A6 | SHA256:F83E1592023B7C8F6C15847F26D30770C0A52E6C7304DBA951EEA437E2737649 | |||
3064 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{78a34cdb-6f0e-4357-9c4f-88e90e003a63}_OnDiskSnapshotProp | binary | |
MD5:584E7B2B150A20BF77E1D77131FA3D1C | SHA256:1BE505A100CF543BC4BE2C19F161745F0BB5D11ACAD6268985938490C41EBC41 | |||
3064 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFD4F99371F735BD77.TMP | — | |
MD5:— | SHA256:— | |||
3156 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
2100 | DrvInst.exe | C:\Windows\INF\setupapi.dev.log | ini | |
MD5:7543E903C3C3199A2F4889337111026D | SHA256:5EA0C109DF3150926A768D9DA3A807F884139AFDF58C08B34048FBE8B765D2BA |
Domain | IP | Reputation |
---|---|---|
www.officelabs.com |
| unknown |
dns.msftncsi.com |
| shared |
Process | Message |
---|---|
rundll32.exe | MSOOBCI: DoInstall failed with error: 0x80070002
|
rundll32.exe | MSOOBCI: DoInstall failed with error: 0x80070002
|