File name:

app__v7.3.5_.msi

Full analysis: https://app.any.run/tasks/6c1f5809-278f-4626-9624-912c8281bdae
Verdict: Malicious activity
Analysis date: October 01, 2024, 13:49:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {EE3A39B9-5A50-459E-950A-80F951511BDC}, Number of Words: 10, Subject: NoqotApp, Author: Haye Cosq, Name of Creating Application: NoqotApp, Template: x64;2057, Comments: This installer database contains the logic and data required to install NoqotApp., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Mon Sep 30 15:03:45 2024, Last Saved Time/Date: Mon Sep 30 15:03:45 2024, Last Printed: Mon Sep 30 15:03:45 2024, Number of Pages: 450
MD5:

2D6151DBBBB50C077564EF7FFC971A4E

SHA1:

B67EC6DD683F5F8B12D52AA79AEEE9A498380589

SHA256:

2EAE05E829F353C9A8D01683187EB759DBF73F90CCD435F03D46761B03247FBD

SSDEEP:

393216:rF/OV/TzUBUYpyIn+SasCCKr+DEhNjle68emtS4HFMFLpvevE6UXjRXaTqO:rFaNtOhG+DsFsc4eFNgEDaT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 7016)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6328)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 7016)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 6328)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 7016)
      • msiexec.exe (PID: 6328)
    • Checks supported languages

      • msiexec.exe (PID: 7016)
      • msiexec.exe (PID: 6328)
    • Checks proxy server information

      • msiexec.exe (PID: 6328)
    • Reads Environment values

      • msiexec.exe (PID: 6328)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 7016)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6328)
    • Create files in a temporary directory

      • msiexec.exe (PID: 6328)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 6328)
    • Reads the software policy settings

      • msiexec.exe (PID: 6328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {EE3A39B9-5A50-459E-950A-80F951511BDC}
Words: 10
Subject: NoqotApp
Author: Haye Cosq
LastModifiedBy: -
Software: NoqotApp
Template: x64;2057
Comments: This installer database contains the logic and data required to install NoqotApp.
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2024:09:30 15:03:45
ModifyDate: 2024:09:30 15:03:45
LastPrinted: 2024:09:30 15:03:45
Pages: 450
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
122
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe msiexec.exe

Process information

PID
CMD
Path
Indicators
Parent process
5364"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\app__v7.3.5_.msiC:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6328C:\Windows\syswow64\MsiExec.exe -Embedding 1238EA8263454F806F01F6880840808DC:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7016C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
4 778
Read events
4 708
Write events
70
Delete events
0

Modification events

(PID) Process:(7016) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
681B0000987AA8D70814DB01
(PID) Process:(7016) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
882ECCEA293C52536B486F65F5558B0290181BA800C33F8A42EF323DD48FBFC6
(PID) Process:(7016) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6328) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings
Operation:writeName:JITDebug
Value:
0
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3fbb50.rbs
Value:
31134728
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3fbb50.rbsLow
Value:
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Users\admin\AppData\Roaming\Microsoft\Installer\
Value:
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\61A469CFD9BAFEA40A993A392563EBD4
Operation:writeName:EFEE82E319251E34AA164E3DB5164119
Value:
C:\Users\admin\AppData\Roaming\Haye Cosq\NoqotApp\
(PID) Process:(7016) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\296D0B16CDD8D824A867B2B957512C71
Operation:writeName:EFEE82E319251E34AA164E3DB5164119
Value:
21:\Software\Haye Cosq\NoqotApp\Version
Executable files
53
Suspicious files
22
Text files
37
Unknown types
0

Dropped files

PID
Process
Filename
Type
7016msiexec.exeC:\Windows\Installer\3fbb4e.msi
MD5:
SHA256:
7016msiexec.exeC:\Windows\Installer\MSIC48B.tmpexecutable
MD5:1A2B237796742C26B11A008D0B175E29
SHA256:81E0DF47BCB2B3380FB0FB58B0D673BE4EF1B0367FD2B0D80AB8EE292FC8F730
7016msiexec.exeC:\Windows\Installer\MSIC1F8.tmpexecutable
MD5:B158D8D605571EA47A238DF5AB43DFAA
SHA256:CA763693CC25D316F14A9EBAD80EBF00590329550C45ADB7E5205486533C2504
7016msiexec.exeC:\Windows\Installer\MSIC070.tmpexecutable
MD5:B158D8D605571EA47A238DF5AB43DFAA
SHA256:CA763693CC25D316F14A9EBAD80EBF00590329550C45ADB7E5205486533C2504
7016msiexec.exeC:\Windows\Installer\MSIBC96.tmpexecutable
MD5:B158D8D605571EA47A238DF5AB43DFAA
SHA256:CA763693CC25D316F14A9EBAD80EBF00590329550C45ADB7E5205486533C2504
6328msiexec.exeC:\Users\admin\AppData\Local\Temp\{3E28EEFE-5291-43E1-AA61-E4D35B611491}\Spring.742DA8B7\box.svgimage
MD5:F7F3379FF3A90C3BA70CA47E579C17EE
SHA256:B169D8F11915957D649537E2940640ACD970F09154E37047A7A90C84380CA3D0
6328msiexec.exeC:\Users\admin\AppData\Local\Temp\{3E28EEFE-5291-43E1-AA61-E4D35B611491}\Spring.742DA8B7\welcome.htmlhtml
MD5:406175F55851187D71E50DD78B429EF8
SHA256:90AF6D1907FCBD0197683CB2B98FB793AE46E30B62B4D1D8078C8B1A7E518072
7016msiexec.exeC:\Windows\Installer\MSID528.tmpexecutable
MD5:61123CBC153CB7F178DDBB318A7EA000
SHA256:E5E0183DFD9F65406042762C0427BBCFF010402B9934DADD2BDDBB6C382D625C
6328msiexec.exeC:\Users\admin\AppData\Local\Temp\{3E28EEFE-5291-43E1-AA61-E4D35B611491}\Spring.742DA8B7\box-custom.svgimage
MD5:A0A6276BAB21E14FE618DB774B52D3BD
SHA256:83B8B86445C41B8B832BEA1A4F80A51E42A7B810E7F30E6E41F22F279CDB88B0
7016msiexec.exeC:\Windows\Installer\MSID49A.tmpexecutable
MD5:B158D8D605571EA47A238DF5AB43DFAA
SHA256:CA763693CC25D316F14A9EBAD80EBF00590329550C45ADB7E5205486533C2504
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
41
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6516
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2144
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4880
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5668
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6328
msiexec.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6328
msiexec.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
5668
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
239.255.255.250:1900
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6516
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4880
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
check-key.com
  • 172.67.129.237
  • 104.21.1.209
unknown

Threats

No threats detected
No debug info