File name:

AlternativeA2dpSetup-1.5.0.1.msi

Full analysis: https://app.any.run/tasks/26c4139e-9867-4c69-959e-3eddda3c9a7e
Verdict: Malicious activity
Analysis date: October 13, 2024, 13:50:08
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 950, Title: Installation Database, Subject: Alternative A2DP Driver 1.5.0.1 Installer, Author: Luculent Systems, LLC, Keywords: Installer, Comments: This installer database contains the logic and data required to install Alternative A2DP Driver., Create Time/Date: Thu May 2 22:00:22 2024, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 4, Template: x64;1033, Last Saved By: x64;1028, Revision Number: {5028B03F-2F44-4769-9548-3024BC29B1F4}1.5.0.1;{E2337CB5-C90C-474D-AEC0-D2EDB55A4067}1.5.0.1;{CA77BF22-352D-4D96-957A-AD0E9E7164B6}, Number of Pages: 500, Number of Characters: 131135
MD5:

689111264AD2A7291C2DC72A2204E25D

SHA1:

2E616CE00366A5203E6B224D250DDA01500D1208

SHA256:

49233D1B6F34208F6F1A46F9208C1E39ABE14A320125539BA1F33666F39FDAA0

SSDEEP:

98304:wqBd2QioIvqO/suqxhVzhViQd2RNMVkKtOe0lcTY91depNOaUYSE5sQkuGZV4O1I:9U8h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 4312)
      • AltA2dpSVC.exe (PID: 1952)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2648)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2648)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2648)
  • INFO

    • Reads the software policy settings

      • msiexec.exe (PID: 6708)
    • An automatically generated document

      • msiexec.exe (PID: 6708)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 6708)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6708)
      • msiexec.exe (PID: 2648)
    • Manages system restore points

      • SrTasks.exe (PID: 6160)
    • Application launched itself

      • msiexec.exe (PID: 2648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Alternative A2DP Driver 1.5.0.1 Installer
Author: Luculent Systems, LLC
Keywords: Installer
Comments: This installer database contains the logic and data required to install Alternative A2DP Driver.
RevisionNumber: {91B79B35-3FBD-4AE5-8741-57A59714A250}
CreateDate: 2024:05:02 21:59:46
ModifyDate: 2024:05:02 21:59:46
Pages: 500
Words: 2
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
Template: x64;1033,1031,1041,1042,1045,1049,2052,1033
LastModifiedBy: x64;1031
Characters: 131135
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
14
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe alta2dpsvc.exe no specs msiexec.exe no specs alta2dpconfig.exe no specs sppextcomobj.exe no specs slui.exe no specs pickerhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700C:\Windows\System32\MsiExec.exe -Embedding 52D26FD3D3060818F88DC27211E517F0 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
1952"C:\Program Files\Luculent Systems\AltA2DP\AltA2dpSVC.exe"C:\Program Files\Luculent Systems\AltA2DP\AltA2dpSVC.exeservices.exe
User:
SYSTEM
Company:
Luculent Systems, LLC
Integrity Level:
SYSTEM
Description:
Alternative A2DP Driver Service
Version:
1.5.0.1
Modules
Images
c:\program files\luculent systems\alta2dp\alta2dpsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2000"C:\Program Files\Luculent Systems\AltA2DP\AltA2dpConfig.exe" C:\Program Files\Luculent Systems\AltA2DP\AltA2dpConfig.exemsiexec.exe
User:
admin
Company:
Luculent Systems, LLC
Integrity Level:
MEDIUM
Description:
Alternative A2DP Driver Configurator
Version:
1.5.0.1
Modules
Images
c:\program files\luculent systems\alta2dp\alta2dpconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2648C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\coml2.dll
c:\windows\system32\srclient.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\spp.dll
3728C:\Windows\System32\PickerHost.exe -EmbeddingC:\Windows\System32\PickerHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
File Picker UI Host
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\pickerhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
4312C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5240C:\Windows\syswow64\MsiExec.exe -Embedding 2CC81E351478A898E17A2A75BFD24F4B CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5624C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6136C:\Windows\System32\MsiExec.exe -Embedding 81112C6614EF3297F912D25BC2F0FA5A E Global\MSI0000C:\Windows\System32\msiexec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6160C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
15 474
Read events
15 110
Write events
339
Delete events
25

Modification events

(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000D850E6D8761DDB01580A0000EC140000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000D850E6D8761DDB01580A0000EC140000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000005E2B30D9761DDB01580A0000EC140000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000005E2B30D9761DDB01580A0000EC140000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000050F234D9761DDB01580A0000EC140000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000B37B3ED9761DDB01580A0000EC140000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000002F0AC4D9761DDB01580A0000EC140000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2648) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000000EBFC8D9761DDB01580A0000D4100000E8030000010000000000000000000000886E050A33480B4983B1C4EA2B6F463D00000000000000000000000000000000
(PID) Process:(4312) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000F01CD7D9761DDB01D8100000BC150000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
18
Suspicious files
31
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2648msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2648msiexec.exeC:\Windows\Installer\MSI3A1F.tmp
MD5:
SHA256:
6708msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\161832C90068D02CF65B25D285AB768A_3E5CCA2E9839DA0DDB183F1D9E86F21Fder
MD5:3A834C30AD6C7E212811792CD7D2BD21
SHA256:A452F801382AEA8D67AE5330CE9F7E4BBC631E975FF7376C1BBA5EB1C2B878E8
6708msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICE74.tmpexecutable
MD5:43EBFBB20CB58C4CAFC98BF73DF19648
SHA256:36615B2E3F6ADC9433A172F2730000EFA5B7B9098FA9F7A58CE9F2733893088E
6708msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7380F5583113DEA65E7FA32B0B37D85Dbinary
MD5:E6EE07230841633FCB1BF81AF8751EAD
SHA256:E09069E59C31B25940CB560C438B873C9503AD2E99261B42F6FBCB8FA84FC304
2648msiexec.exeC:\Windows\Installer\93721.msiexecutable
MD5:689111264AD2A7291C2DC72A2204E25D
SHA256:49233D1B6F34208F6F1A46F9208C1E39ABE14A320125539BA1F33666F39FDAA0
2648msiexec.exeC:\Windows\Installer\MSI3A8E.tmpexecutable
MD5:43EBFBB20CB58C4CAFC98BF73DF19648
SHA256:36615B2E3F6ADC9433A172F2730000EFA5B7B9098FA9F7A58CE9F2733893088E
2648msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:4FE53498199EB1C6E4B71DBDA50C319D
SHA256:BA986313664EB504F09C2A9D3B8B81C154A71D80F6123D2D98FE3F891F4D9BAB
2648msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{0a056e88-4833-490b-83b1-c4ea2b6f463d}_OnDiskSnapshotPropbinary
MD5:4FE53498199EB1C6E4B71DBDA50C319D
SHA256:BA986313664EB504F09C2A9D3B8B81C154A71D80F6123D2D98FE3F891F4D9BAB
2648msiexec.exeC:\Windows\Installer\MSI3A3F.tmpexecutable
MD5:9D9A45F017D425179B7907410FD4D124
SHA256:51F05B7AEC5C1E565C36B33A456CE2E3500669399ABD9EAD2BD217D847805415
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
70
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6708
msiexec.exe
GET
200
18.244.18.60:80
http://crls.ssl.com/SSLcom-SubCA-EV-codeSigning-ECC-384-R2.crl
unknown
whitelisted
6708
msiexec.exe
GET
200
100.24.223.135:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT4XPMAgX8rbNb10iD9IkFVxGbTWwQUW8pe5d7SgarNqC1kUbbZcpuX5k8CEG7dTyXnMX05gVcxNM%2FB3KA%3D
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5084
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5084
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6136
msiexec.exe
GET
200
2.23.197.184:80
http://x1.c.lencr.org/
unknown
whitelisted
6136
msiexec.exe
GET
200
95.101.54.195:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgTMlHFJ8roG7EjC0wUF6JBi1w%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.110.171:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6708
msiexec.exe
100.24.223.135:80
ocsps.ssl.com
AMAZON-AES
US
whitelisted
6708
msiexec.exe
18.244.18.60:80
crls.ssl.com
US
whitelisted
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6376
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.110.171
  • 2.16.110.121
whitelisted
google.com
  • 142.250.184.238
whitelisted
ocsps.ssl.com
  • 100.24.223.135
  • 34.237.184.165
  • 52.6.97.148
whitelisted
crls.ssl.com
  • 18.244.18.60
  • 18.244.18.54
  • 18.244.18.92
  • 18.244.18.55
whitelisted
login.live.com
  • 40.126.32.68
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
th.bing.com
  • 2.16.110.171
  • 2.16.110.121
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted

Threats

No threats detected
No debug info