| File name: | Win10.0_System_Upgrade_Software.msi |
| Full analysis: | https://app.any.run/tasks/bdc532ff-bc36-422d-bece-dbc057e40652 |
| Verdict: | Malicious activity |
| Analysis date: | May 21, 2022, 08:00:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Installer, Author: Corporation, Keywords: Installer, Comments: Installer Package, Template: Intel;1033, Revision Number: {DEBB4A85-EC27-4415-B5D6-DF4F44095086}, Create Time/Date: Wed Apr 27 17:56:46 2022, Last Saved Time/Date: Wed Apr 27 17:56:46 2022, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4163), Security: 2 |
| MD5: | 5D4E40D1D41C4588FBF7065FA85454E7 |
| SHA1: | CA876C335EF0A4D90B456F13CC975C04016A5CC1 |
| SHA256: | 4C7314083933A283C87DC28ABBED3082040F12E92EDAC47FF72F8539AF6E3EA1 |
| SSDEEP: | 768:qhDfhKuI7+HwtCvdttj42XZ5uNenzMtKf17xXbdTXbkVB3YoyWMDCTyWMDC/YifW:8u7+ACu2XZ/zMkIVCo0D80DO7fxP |
| .msi | | | Microsoft Installer (100) |
|---|
| Security: | Read-only recommended |
|---|---|
| Software: | Windows Installer XML Toolset (3.11.2.4163) |
| Words: | 10 |
| Pages: | 200 |
| ModifyDate: | 2022:04:27 16:56:46 |
| CreateDate: | 2022:04:27 16:56:46 |
| RevisionNumber: | {DEBB4A85-EC27-4415-B5D6-DF4F44095086} |
| Template: | Intel;1033 |
| Comments: | Installer Package |
| Keywords: | Installer |
| Author: | Corporation |
| Subject: | Installer |
| Title: | Installation Database |
| CodePage: | Windows Latin 1 (Western European) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1960 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2960 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Win10.0_System_Upgrade_Software.msi" | C:\Windows\System32\msiexec.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3452 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3984 | C:\Windows\system32\MsiExec.exe -Embedding A75499F5DC81DD03B257BAFC91430EC0 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000005A5B09D0E86CD8017C0D00000C0C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000005A5B09D0E86CD8017C0D00000C0C0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 69 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000009AA655D0E86CD8017C0D00000C0C0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000F40858D0E86CD8017C0D0000D8080000E8030000010000000000000000000000F14E0BDE8B161A438AD0749B97E3D8D20000000000000000 | |||
| (PID) Process: | (1960) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8CD5CD0E86CD801A8070000840C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1960) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8CD5CD0E86CD801A807000080060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1960) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8CD5CD0E86CD801A8070000600F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1960) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8CD5CD0E86CD801A8070000AC0D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3452 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Users\admin\AppData\Local\uhau8i5a9k | — | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Windows\Installer\fe864.ipi | binary | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Windows\Installer\fe863.msi | executable | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{de0b4ef1-168b-431a-8ad0-749b97e3d8d2}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFA770A979D88BF0D5.TMP | gmc | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF113365585415C952.TMP | gmc | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Windows\Installer\SourceHash{1FB7F52F-AE2D-47D5-93EC-49261060D88C} | binary | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 3452 | msiexec.exe | C:\Windows\Installer\MSIEA28.tmp | executable | |
MD5:— | SHA256:— | |||