download:

UniversalAdbDriverSetup.msi

Full analysis: https://app.any.run/tasks/9f23f54e-3952-4bcb-a600-87c4c4fe02db
Verdict: Malicious activity
Analysis date: May 20, 2019, 19:37:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {6B6AEE4D-046A-41C9-BF62-B092D307049D}, Title: UniversalAdbDriverSetup, Author: ClockworkMod, Number of Words: 2, Last Saved Time/Date: Sat Aug 1 00:09:28 2015, Last Printed: Sat Aug 1 00:09:28 2015
MD5:

A0B1CC7C5C26044738798BA2E5E8C217

SHA1:

745BB99063748A2F309888467AAC70C3C7EF6A2E

SHA256:

4E77E303BBA6CF84588BDB6DA91F7A875D406F7930CBE9F4D2AAE0B643C0C928

SSDEEP:

393216:Hc2Ryzq2+0lkPEezmlMUH9n0sEf0/c++oLw525IgfLJ5pz3:azHPKmVB0MUzMw525ljpz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • makecert.exe (PID: 2424)
      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • signtool.exe (PID: 1256)
    • Application was dropped or rewritten from another process

      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • signtool.exe (PID: 1256)
      • makecert.exe (PID: 2424)
      • signtool.exe (PID: 3292)
  • SUSPICIOUS

    • Executed as Windows Service

      • vssvc.exe (PID: 2892)
    • Executed via COM

      • DrvInst.exe (PID: 3536)
      • DrvInst.exe (PID: 2832)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2320)
      • UniversalAdbDriverInstaller.exe (PID: 3868)
      • DrvInst.exe (PID: 2832)
    • Creates files in the program directory

      • makecert.exe (PID: 2424)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2832)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2832)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 2832)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 2320)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 3536)
      • DrvInst.exe (PID: 2832)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2320)
    • Searches for installed software

      • msiexec.exe (PID: 2320)
    • Creates files in the program directory

      • msiexec.exe (PID: 2320)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2892)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 3536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {6B6AEE4D-046A-41C9-BF62-B092D307049D}
Title: UniversalAdbDriverSetup
Subject: -
Author: ClockworkMod
Keywords: -
Comments: -
Words: 2
ModifyDate: 2015:08:31 23:09:28
LastPrinted: 2015:08:31 23:09:28
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs universaladbdriverinstaller.exe makecert.exe signtool.exe signtool.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1256"C:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe" sign /v /s PrivateCertStore /n UniversalADB /t http://timestamp.verisign.com/scripts/timstamp.dll usb_driver\androidwinusb86.catC:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Authenticode(R) - signing and verifying tool
Exit code:
0
Version:
4.00 (th1.150709-1700)
Modules
Images
c:\program files\clockworkmod\universal adb driver\signtool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\user32.dll
1572C:\Windows\system32\MsiExec.exe -Embedding 812438A8180E2046B21534A354867417C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2320C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2424"C:\Program Files\ClockworkMod\Universal Adb Driver\makecert.exe" -r -pe -ss PrivateCertStore -n CN=UniversalADB "C:\Program Files\ClockworkMod\Universal Adb Driver\UniversalADB.cer"C:\Program Files\ClockworkMod\Universal Adb Driver\makecert.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
ECM MakeCert
Exit code:
0
Version:
10.0.10240.16384 (th1.150709-1700)
Modules
Images
c:\program files\clockworkmod\universal adb driver\makecert.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mssign32.dll
c:\windows\system32\user32.dll
2816C:\Windows\system32\MsiExec.exe -Embedding CFE9AAA7158C9953ADB5F8C2DE51F55D CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2832DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{52c20bc4-73fd-6d3c-ab54-9855fd733c6d}\android_winusb.inf" "0" "6b892493b" "000003D4" "WinSta0\Default" "000005AC" "208" "C:\Program Files\ClockworkMod\Universal Adb Driver\usb_driver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2892C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3184"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\UniversalAdbDriverSetup.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3292"C:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe" sign /v /s PrivateCertStore /n UniversalADB /t http://timestamp.verisign.com/scripts/timstamp.dll usb_driver\androidwinusba64.catC:\Program Files\ClockworkMod\Universal Adb Driver\signtool.exe
UniversalAdbDriverInstaller.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Authenticode(R) - signing and verifying tool
Exit code:
0
Version:
4.00 (th1.150709-1700)
Modules
Images
c:\program files\clockworkmod\universal adb driver\signtool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\user32.dll
3536DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000580" "00000388"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
840
Read events
452
Write events
376
Delete events
12

Modification events

(PID) Process:(2320) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000E608799B430FD50110090000580D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2320) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000E608799B430FD50110090000580D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000042A2D39B430FD5014C0B0000A4060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000042A2D39B430FD5014C0B000008080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000042A2D39B430FD5014C0B00000C070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
400000000000000042A2D39B430FD5014C0B00003C080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000F666D89B430FD5014C0B00000C070000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
400000000000000050C9DA9B430FD5014C0B00003C080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000AA2BDD9B430FD5014C0B000008080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000048EDF9B430FD5014C0B0000A4060000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
Executable files
29
Suspicious files
21
Text files
268
Unknown types
10

Dropped files

PID
Process
Filename
Type
3184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI4AB8.tmp
MD5:
SHA256:
3184msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI4B46.tmp
MD5:
SHA256:
2320msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2320msiexec.exeC:\Windows\Installer\13ab85.msi
MD5:
SHA256:
2320msiexec.exeC:\Windows\Installer\MSIAF5E.tmp
MD5:
SHA256:
2320msiexec.exeC:\Windows\Installer\MSIB059.tmp
MD5:
SHA256:
2320msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFB2493CAFFCF2160E.TMP
MD5:
SHA256:
2892vssvc.exeC:
MD5:
SHA256:
2320msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{aee004d3-91cb-41ac-aaaa-c4d4177c7522}_OnDiskSnapshotPropbinary
MD5:
SHA256:
3536DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3292
signtool.exe
POST
200
216.168.246.38:80
http://timestamp.verisign.com/scripts/timstamp.dll
US
text
4.07 Kb
unknown
1256
signtool.exe
POST
200
216.168.246.38:80
http://timestamp.verisign.com/scripts/timstamp.dll
US
text
4.07 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3292
signtool.exe
216.168.246.38:80
timestamp.verisign.com
US
unknown
1256
signtool.exe
216.168.246.38:80
timestamp.verisign.com
US
unknown

DNS requests

Domain
IP
Reputation
timestamp.verisign.com
  • 216.168.246.38
unknown

Threats

No threats detected
No debug info