File name:

6309e1.msi

Full analysis: https://app.any.run/tasks/40b56ff4-0c50-4b4b-b16b-9b8ebb443ae4
Verdict: Malicious activity
Threats:

Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.

Analysis date: November 27, 2023, 14:45:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
generated-doc
bumblebee
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {2D768B99-4878-4983-AFA4-7453DB51F8EF}, Number of Words: 0, Subject: Putty, Author: Putty, Name of Creating Application: Putty (Evaluation Installer), Template: ;1033, Comments: This installer database contains the logic and data required to install Putty. (Evaluation Installer), Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Thu Nov 23 13:09:23 2023, Last Saved Time/Date: Thu Nov 23 13:09:23 2023, Last Printed: Thu Nov 23 13:09:23 2023, Number of Pages: 450
MD5:

9159F9FB42365DC0A492ECE7EC9AA546

SHA1:

8B8426ADE01C916BB1F08F69DEE611D4CD2379B5

SHA256:

33A57EED92FA4ACF1BE788CE387D0F6F3804AAB316D04BCFE8B43CCCAF08BDBF

SSDEEP:

98304:p9IeoYVLtgEBqT0MGpO0PIAu8S+29ZPN8+1rZDQ3qqsY5c4OGeV+uyE1xnC2S0Ro:4S0Rck

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 684)
    • BUMBLEBEE has been detected (YARA)

      • msiexec.exe (PID: 2936)
    • Connects to the CnC server

      • msiexec.exe (PID: 2936)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 2748)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 684)
      • msiexec.exe (PID: 2108)
      • msiexec.exe (PID: 2936)
    • Reads the computer name

      • msiexec.exe (PID: 684)
      • msiexec.exe (PID: 2108)
      • msiexec.exe (PID: 2936)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 684)
      • msiexec.exe (PID: 2108)
      • msiexec.exe (PID: 2936)
    • Create files in a temporary directory

      • msiexec.exe (PID: 2404)
    • Application launched itself

      • msiexec.exe (PID: 684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {2D768B99-4878-4983-AFA4-7453DB51F8EF}
Words: -
Subject: Putty
Author: Putty
LastModifiedBy: -
Software: Putty (Evaluation Installer)
Template: ;1033
Comments: This installer database contains the logic and data required to install Putty. (Evaluation Installer)
Title: Installation Database
Keywords: Installer, MSI, Database
CreateDate: 2023:11:23 13:09:23
ModifyDate: 2023:11:23 13:09:23
LastPrinted: 2023:11:23 13:09:23
Pages: 450
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs #BUMBLEBEE msiexec.exe

Process information

PID
CMD
Path
Indicators
Parent process
684C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2108C:\Windows\syswow64\MsiExec.exe -Embedding 0E27DC6EA0C0B617DB2986342753DEE1C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2404"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\6309e1.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2748C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2936C:\Windows\system32\MsiExec.exe -Embedding 004D81154947C616AD968EDF74B23271C:\Windows\System32\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
3 292
Read events
3 281
Write events
11
Delete events
0

Modification events

(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000C42CD6BE4EB0D9014C0F0000380F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000C42CD6BE4EB0D9014C0F0000380F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
66
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
480000000000000080A00ABF4EB0D9014C0F0000380F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4800000000000000A4CA79C04EB0D9014C0F0000380F0000D30700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4800000000000000A4CA79C04EB0D9014C0F0000380F0000D40700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4800000000000000CE3F8FC04EB0D9014C0F0000380F0000D40700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
48000000000000000CAEE5C24EB0D9014C0F0000380F0000D00700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
48000000000000006610E8C24EB0D9014C0F0000380F0000D50700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(684) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:FirstRun
Value:
0
Executable files
3
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
684msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
684msiexec.exeC:\Windows\Installer\1fab9a.msi
MD5:
SHA256:
684msiexec.exeC:\Windows\Installer\MSIB040.tmpexecutable
MD5:B6E50A33A2F3CAA5346DB94AB198EE99
SHA256:353FDA6E116118809B49DD3001EE532DDFACACAA40A43B951C9F1DD69C8E7491
684msiexec.exeC:\Windows\Installer\MSIAD31.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
684msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:736B7D81E45993B5A86343AACFA7A80D
SHA256:45ED9CEA9670F4083FD6E533F73B27D004C49961997EA18731CC4C45E354E038
684msiexec.exeC:\Windows\Installer\MSIB010.tmpexecutable
MD5:5A1F2196056C0A06B79A77AE981C7761
SHA256:52F41817669AF7AC55B1516894EE705245C3148F2997FA0E6617E9CC6353E41E
684msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{097e7eac-2f75-41f3-9937-9632ec3e8dc3}_OnDiskSnapshotPropbinary
MD5:736B7D81E45993B5A86343AACFA7A80D
SHA256:45ED9CEA9670F4083FD6E533F73B27D004C49961997EA18731CC4C45E354E038
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
17
Threats
19

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
2936
msiexec.exe
178.162.203.211:443
n64c2akw.life
Leaseweb Deutschland GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
n64c2akw.life
  • 85.17.31.122
  • 178.162.203.202
  • 178.162.203.211
  • 178.162.203.226
  • 178.162.217.107
  • 5.79.71.205
  • 5.79.71.225
  • 85.17.31.82
unknown
zefawfb0.life
  • 94.131.9.114
unknown
dph3pby8.life
  • 192.71.249.220
unknown
hx0hysyg.life
  • 185.248.144.178
unknown
1qa3k743.life
  • 178.162.203.211
  • 178.162.203.226
  • 178.162.217.107
  • 5.79.71.205
  • 5.79.71.225
  • 85.17.31.82
  • 85.17.31.122
  • 178.162.203.202
unknown
luw8ubf2.life
  • 178.162.203.211
  • 178.162.203.226
  • 178.162.217.107
  • 5.79.71.205
  • 5.79.71.225
  • 85.17.31.82
  • 85.17.31.122
  • 178.162.203.202
unknown
rbvsf6io.life
unknown
4huoqrsp.life
unknown
8qwcvseh.life
unknown
37zi55wc.life
unknown

Threats

PID
Process
Class
Message
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
2936
msiexec.exe
A Network Trojan was detected
ET MALWARE Win32/Bumblebee Loader Checkin Activity
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
2936
msiexec.exe
A Network Trojan was detected
ET MALWARE Win32/Bumblebee Loader Checkin Activity
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
324
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .life TLD
No debug info