analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

UniversalAdbDriverSetup.msi

Full analysis: https://app.any.run/tasks/9f23f54e-3952-4bcb-a600-87c4c4fe02db
Verdict: Malicious activity
Analysis date: May 20, 2019, 19:37:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {6B6AEE4D-046A-41C9-BF62-B092D307049D}, Title: UniversalAdbDriverSetup, Author: ClockworkMod, Number of Words: 2, Last Saved Time/Date: Sat Aug 1 00:09:28 2015, Last Printed: Sat Aug 1 00:09:28 2015
MD5:

A0B1CC7C5C26044738798BA2E5E8C217

SHA1:

745BB99063748A2F309888467AAC70C3C7EF6A2E

SHA256:

4E77E303BBA6CF84588BDB6DA91F7A875D406F7930CBE9F4D2AAE0B643C0C928

SSDEEP:

393216:Hc2Ryzq2+0lkPEezmlMUH9n0sEf0/c++oLw525IgfLJ5pz3:azHPKmVB0MUzMw525ljpz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • makecert.exe (PID: 2424)
      • signtool.exe (PID: 3292)
      • signtool.exe (PID: 1256)
    • Changes settings of System certificates

      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • makecert.exe (PID: 2424)
      • signtool.exe (PID: 1256)
  • SUSPICIOUS

    • Executed via COM

      • DrvInst.exe (PID: 3536)
      • DrvInst.exe (PID: 2832)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2320)
      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • DrvInst.exe (PID: 2832)
    • Executed as Windows Service

      • vssvc.exe (PID: 2892)
    • Creates files in the program directory

      • makecert.exe (PID: 2424)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 2832)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2832)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2832)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 2320)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 3536)
      • DrvInst.exe (PID: 2832)
    • Searches for installed software

      • msiexec.exe (PID: 2320)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 3536)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2892)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2320)
    • Creates files in the program directory

      • msiexec.exe (PID: 2320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2015:08:31 23:09:28
ModifyDate: 2015:08:31 23:09:28
Words: 2
Comments: -
Keywords: -
Author: ClockworkMod
Subject: -
Title: UniversalAdbDriverSetup
RevisionNumber: {6B6AEE4D-046A-41C9-BF62-B092D307049D}
Pages: 200
Template: Intel;1033
CodePage: Windows Latin 1 (Western European)
Security: Password protected
Software: Windows Installer
CreateDate: 1999:06:21 07:00:00
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs universaladbdriverinstaller.exe makecert.exe signtool.exe signtool.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
3184"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\UniversalAdbDriverSetup.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2320C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2816C:\Windows\system32\MsiExec.exe -Embedding CFE9AAA7158C9953ADB5F8C2DE51F55D CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2892C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3536DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000580" "00000388"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1572C:\Windows\system32\MsiExec.exe -Embedding 812438A8180E2046B21534A354867417C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3868"C:\Program Files\ClockworkMod\Universal Adb Driver\UniversalAdbDriverInstaller.exe"C:\Program Files\ClockworkMod\Universal Adb Driver\UniversalAdbDriverInstaller.exe
msiexec.exe
User:
admin
Integrity Level:
MEDIUM
Description:
UniveralAdbDriverInstaller
Exit code:
0
Version:
1.0.0.0
2424"C:\Program Files\ClockworkMod\Universal Adb Driver\makecert.exe" -r -pe -ss PrivateCertStore -n CN=UniversalADB "C:\Program Files\ClockworkMod\Universal Adb Driver\UniversalADB.cer"C:\Program Files\ClockworkMod\Universal Adb Driver\makecert.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
ECM MakeCert
Exit code:
0
Version:
10.0.10240.16384 (th1.150709-1700)
1256"C:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe" sign /v /s PrivateCertStore /n UniversalADB /t http://timestamp.verisign.com/scripts/timstamp.dll usb_driver\androidwinusb86.catC:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Authenticode(R) - signing and verifying tool
Exit code:
0
Version:
4.00 (th1.150709-1700)
3292"C:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe" sign /v /s PrivateCertStore /n UniversalADB /t http://timestamp.verisign.com/scripts/timstamp.dll usb_driver\androidwinusba64.catC:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Authenticode(R) - signing and verifying tool
Exit code:
0
Version:
4.00 (th1.150709-1700)
Total events
840
Read events
452
Write events
0
Delete events
0

Modification events

No data
Executable files
29
Suspicious files
21
Text files
268
Unknown types
10

Dropped files

PID
Process
Filename
Type
3184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI4AB8.tmp
MD5:
SHA256:
3184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI4B46.tmp
MD5:
SHA256:
2320msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2320msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{aee004d3-91cb-41ac-aaaa-c4d4177c7522}_OnDiskSnapshotPropbinary
MD5:7145FEEE4153B2F57A2CE5EF295E4DDB
SHA256:C657E47BC9FA5CE18695C395B76E7071E1A7D7B5D2174412F45F1552C9B5D5AD
3536DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:403F57E5FF9768D8F906117E0B8F37AD
SHA256:BEADD52DB0688AE2B5C4AA859204C7D46DCCA1E6B6777363A9F85C8C28A3FC1C
3536DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:57E586238D0EFE22ED4B71B63BCD5C1A
SHA256:2D9518357CC3329DE7EB3B8AA3CECF7849E1C27BBD69B8AD41DB7E20E22FDE8D
2320msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:7145FEEE4153B2F57A2CE5EF295E4DDB
SHA256:C657E47BC9FA5CE18695C395B76E7071E1A7D7B5D2174412F45F1552C9B5D5AD
3536DrvInst.exeC:\Windows\INF\setupapi.ev3binary
MD5:76DCC60F78B3DFF1AE3627619074F465
SHA256:18541AC1875315C4F9EFF75050C574FAFF83717C029DAE6B366F9C6C3F0C19E0
2816MsiExec.exeC:\Users\admin\AppData\Local\Temp\CFG4B45.tmpxml
MD5:C517737DD6B59D0BD576A0A484C12E8B
SHA256:0774A3FD610BE54DAF2801AC6763F7FDE87073D95435900874C9A61B14F88F50
2320msiexec.exeC:\Windows\Installer\13ab85.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1256
signtool.exe
POST
200
216.168.246.38:80
http://timestamp.verisign.com/scripts/timstamp.dll
US
text
4.07 Kb
unknown
3292
signtool.exe
POST
200
216.168.246.38:80
http://timestamp.verisign.com/scripts/timstamp.dll
US
text
4.07 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3292
signtool.exe
216.168.246.38:80
timestamp.verisign.com
US
unknown
1256
signtool.exe
216.168.246.38:80
timestamp.verisign.com
US
unknown

DNS requests

Domain
IP
Reputation
timestamp.verisign.com
  • 216.168.246.38
unknown

Threats

No threats detected
No debug info