| File name: | EfirAddInInstaller.msi |
| Full analysis: | https://app.any.run/tasks/12411c8a-73c5-48fa-824c-bcbb452ad28e |
| Verdict: | Malicious activity |
| Analysis date: | December 26, 2023, 08:16:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1251, Title: Installation Database, Subject: Microsoft Excel, Author: , Keywords: , Comments: 2013-2023 , Template: Intel;1049, Revision Number: {1A26C865-6FA5-4AD1-BB77-9927C4056DFF}, Create Time/Date: Thu Dec 21 10:10:22 2023, Last Saved Time/Date: Thu Dec 21 10:10:22 2023, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2 |
| MD5: | 23F242FB6D6117CF31BFA152A0FD4B48 |
| SHA1: | 27B4C0CF53E77DBF18235F49B6AC17ED4313A93D |
| SHA256: | 43BADBE1B21B996EF8C7A9C08C61D892F0C198677F8EE1FD757C293955C6DE51 |
| SSDEEP: | 98304:kFK8ObiNWuP17S0zwOZ/bEe6EN1Kn//9hzNa898M/JQOyLJQuWGo03+v1NPGHsC/:b2P1NjUNL5itRs11tdZKgtro |
| .msi | | | Microsoft Installer (100) |
|---|
| CodePage: | Windows Cyrillic |
|---|---|
| Title: | Installation Database |
| Subject: | Интерфакс ЭФиР Надстройка для Microsoft Excel |
| Author: | АО Интерфакс |
| Keywords: | Интерфакс ЭФиР Надстройка |
| Comments: | Копирайт © 2013-2023 АО Интерфакс |
| Template: | Intel;1049 |
| RevisionNumber: | {1A26C865-6FA5-4AD1-BB77-9927C4056DFF} |
| CreateDate: | 2023:12:21 10:10:22 |
| ModifyDate: | 2023:12:21 10:10:22 |
| Pages: | 200 |
| Words: | 10 |
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1384 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "C:\Users\admin\AppData\Roaming\Microsoft\AddIns\Interfax\EfirExcel-AddIn.xll" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Common Language Runtime native compiler Exit code: 4294967295 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1600 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe update /queue | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Common Language Runtime native compiler Exit code: 4294967295 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1636 | C:\Windows\system32\MsiExec.exe -Embedding 0E272763F517ADE929C78E24D75E470E | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1844 | rundll32.exe "C:\Windows\Installer\MSI31BD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_930265 24 InstallerCA!InstallerCA.CustomActions.CaRegisterAddIn | C:\Windows\System32\rundll32.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2036 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\EfirAddInInstaller.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2268 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2296 | rundll32.exe "C:\Windows\Installer\MSI3074.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_929937 18 InstallerCA!InstallerCA.CustomActions.CaUnRegisterAddIn | C:\Windows\System32\rundll32.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2504 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2636 | rundll32.exe "C:\Windows\Installer\MSI32B8.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_930500 35 InstallerCA!InstallerCA.CustomActions.ClearOldCache | C:\Windows\System32\rundll32.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2036) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 73 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (324) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 324 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 324 | msiexec.exe | C:\Windows\Installer\e2af4.msi | — | |
MD5:— | SHA256:— | |||
| 324 | msiexec.exe | C:\Windows\Installer\e2af5.ipi | binary | |
MD5:7D915A9D4D4E5DE079FB322AE97C8288 | SHA256:6B99D146BEB3659E5F3B4DF7BF8AC58CD79D224720C065476211B597B1EC6195 | |||
| 2296 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\InstallerCA.dll | executable | |
MD5:431E44402FF4651723DAF2B85FCD1794 | SHA256:928AC9DEB0C2D8C51AC1CA1FB2D63473E4961939B94AA8CBCF8F12D74B72BB18 | |||
| 2296 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA | SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA | |||
| 324 | msiexec.exe | C:\Windows\Installer\MSI31BD.tmp | executable | |
MD5:BBF4D8F2A3ABAB1CC1CB45100271BADA | SHA256:C3B954106313DD5BAC989217CFAAB3CB58714D83D5ACA0F21CF9E1D034E3A242 | |||
| 2636 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI32B8.tmp-\InstallerCA.dll | executable | |
MD5:431E44402FF4651723DAF2B85FCD1794 | SHA256:928AC9DEB0C2D8C51AC1CA1FB2D63473E4961939B94AA8CBCF8F12D74B72BB18 | |||
| 2296 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\CustomAction.config | xml | |
MD5:C304D067FB99DF21DA522C92F68689E9 | SHA256:9B62717B5F47825F7369A26A511929388E11827EAAF95B51B6CDB1861E3D9D58 | |||
| 2636 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI32B8.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA | SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA | |||
| 1844 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI31BD.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA | SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2504 | EXCEL.EXE | 46.28.21.180:443 | addin.efir-net.ru | Closed Joint Stock Company Interfax | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
addin.efir-net.ru |
| unknown |