File name:

EfirAddInInstaller.msi

Full analysis: https://app.any.run/tasks/12411c8a-73c5-48fa-824c-bcbb452ad28e
Verdict: Malicious activity
Analysis date: December 26, 2023, 08:16:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1251, Title: Installation Database, Subject: Microsoft Excel, Author: , Keywords: , Comments: 2013-2023 , Template: Intel;1049, Revision Number: {1A26C865-6FA5-4AD1-BB77-9927C4056DFF}, Create Time/Date: Thu Dec 21 10:10:22 2023, Last Saved Time/Date: Thu Dec 21 10:10:22 2023, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

23F242FB6D6117CF31BFA152A0FD4B48

SHA1:

27B4C0CF53E77DBF18235F49B6AC17ED4313A93D

SHA256:

43BADBE1B21B996EF8C7A9C08C61D892F0C198677F8EE1FD757C293955C6DE51

SSDEEP:

98304:kFK8ObiNWuP17S0zwOZ/bEe6EN1Kn//9hzNa898M/JQOyLJQuWGo03+v1NPGHsC/:b2P1NjUNL5itRs11tdZKgtro

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connection from MS Office application

      • EXCEL.EXE (PID: 2504)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 324)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 1636)
    • Reads data from a file (MACROS)

      • EXCEL.EXE (PID: 2504)
  • INFO

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2036)
      • rundll32.exe (PID: 1844)
      • rundll32.exe (PID: 2636)
      • rundll32.exe (PID: 2692)
      • msiexec.exe (PID: 324)
      • rundll32.exe (PID: 2296)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2036)
    • Reads the computer name

      • msiexec.exe (PID: 324)
      • msiexec.exe (PID: 1636)
      • ngen.exe (PID: 1384)
      • ngen.exe (PID: 1600)
    • Checks supported languages

      • msiexec.exe (PID: 324)
      • msiexec.exe (PID: 1636)
      • ngen.exe (PID: 1600)
      • ngen.exe (PID: 1384)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2268)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 324)
      • msiexec.exe (PID: 1636)
    • Create files in a temporary directory

      • msiexec.exe (PID: 324)
      • rundll32.exe (PID: 1844)
      • rundll32.exe (PID: 2636)
      • rundll32.exe (PID: 2692)
      • rundll32.exe (PID: 2296)
    • Application launched itself

      • msiexec.exe (PID: 324)
    • Reads Microsoft Office registry keys

      • rundll32.exe (PID: 1844)
      • rundll32.exe (PID: 2296)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 324)
    • Creates files in the program directory

      • EXCEL.EXE (PID: 2504)
    • Manual execution by a user

      • EXCEL.EXE (PID: 2504)
    • Reads mouse settings

      • EXCEL.EXE (PID: 2504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Cyrillic
Title: Installation Database
Subject: Интерфакс ЭФиР Надстройка для Microsoft Excel
Author: АО Интерфакс
Keywords: Интерфакс ЭФиР Надстройка
Comments: Копирайт © 2013-2023 АО Интерфакс
Template: Intel;1049
RevisionNumber: {1A26C865-6FA5-4AD1-BB77-9927C4056DFF}
CreateDate: 2023:12:21 10:10:22
ModifyDate: 2023:12:21 10:10:22
Pages: 200
Words: 10
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
11
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs ngen.exe no specs ngen.exe no specs excel.exe

Process information

PID
CMD
Path
Indicators
Parent process
324C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1384C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe install "C:\Users\admin\AppData\Roaming\Microsoft\AddIns\Interfax\EfirExcel-AddIn.xll"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
1600C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe update /queueC:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
1636C:\Windows\system32\MsiExec.exe -Embedding 0E272763F517ADE929C78E24D75E470EC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1844rundll32.exe "C:\Windows\Installer\MSI31BD.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_930265 24 InstallerCA!InstallerCA.CustomActions.CaRegisterAddInC:\Windows\System32\rundll32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2036"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\EfirAddInInstaller.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2268C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2296rundll32.exe "C:\Windows\Installer\MSI3074.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_929937 18 InstallerCA!InstallerCA.CustomActions.CaUnRegisterAddInC:\Windows\System32\rundll32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2504"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2636rundll32.exe "C:\Windows\Installer\MSI32B8.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_930500 35 InstallerCA!InstallerCA.CustomActions.ClearOldCacheC:\Windows\System32\rundll32.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
16 356
Read events
16 106
Write events
88
Delete events
162

Modification events

(PID) Process:(2036) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
73
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(324) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
Executable files
18
Suspicious files
71
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
324msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
324msiexec.exeC:\Windows\Installer\e2af4.msi
MD5:
SHA256:
324msiexec.exeC:\Windows\Installer\e2af5.ipibinary
MD5:7D915A9D4D4E5DE079FB322AE97C8288
SHA256:6B99D146BEB3659E5F3B4DF7BF8AC58CD79D224720C065476211B597B1EC6195
2296rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\InstallerCA.dllexecutable
MD5:431E44402FF4651723DAF2B85FCD1794
SHA256:928AC9DEB0C2D8C51AC1CA1FB2D63473E4961939B94AA8CBCF8F12D74B72BB18
2296rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\Microsoft.Deployment.WindowsInstaller.dllexecutable
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
324msiexec.exeC:\Windows\Installer\MSI31BD.tmpexecutable
MD5:BBF4D8F2A3ABAB1CC1CB45100271BADA
SHA256:C3B954106313DD5BAC989217CFAAB3CB58714D83D5ACA0F21CF9E1D034E3A242
2636rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI32B8.tmp-\InstallerCA.dllexecutable
MD5:431E44402FF4651723DAF2B85FCD1794
SHA256:928AC9DEB0C2D8C51AC1CA1FB2D63473E4961939B94AA8CBCF8F12D74B72BB18
2296rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI3074.tmp-\CustomAction.configxml
MD5:C304D067FB99DF21DA522C92F68689E9
SHA256:9B62717B5F47825F7369A26A511929388E11827EAAF95B51B6CDB1861E3D9D58
2636rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI32B8.tmp-\Microsoft.Deployment.WindowsInstaller.dllexecutable
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
1844rundll32.exeC:\Users\admin\AppData\Local\Temp\MSI31BD.tmp-\Microsoft.Deployment.WindowsInstaller.dllexecutable
MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
SHA256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2504
EXCEL.EXE
46.28.21.180:443
addin.efir-net.ru
Closed Joint Stock Company Interfax
RU
unknown

DNS requests

Domain
IP
Reputation
addin.efir-net.ru
  • 46.28.21.180
unknown

Threats

No threats detected
No debug info