File name:

Transwiz.msi

Full analysis: https://app.any.run/tasks/54ac0c39-cdc2-4991-9929-2c0f2976a36a
Verdict: Malicious activity
Analysis date: April 25, 2025, 09:58:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {B034C77C-C017-4926-8EB2-88DF6F1F336B}, Number of Words: 2, Subject: ForensiT Transwiz, Author: ForensiT, Name of Creating Application: Advanced Installer 18.6 build 099b4b9a, Template: ;2057, Comments: This installer database contains the logic and data required to install ForensiT Transwiz., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

CF1DD0006C422C2C85C46A6FE4506406

SHA1:

DA48EC07CEA7407B6B2D38DBB54D2CD472BD7563

SHA256:

511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801

SSDEEP:

49152:fx3AY5aeGDcQ8KmLVR97uAHSvVPcAANEoW7SAmEzkGl7KMGzu7dhlwe50Qe2K:GYTGDP8KmHHSVAvW7SAhxQMG67Zwe6rZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Transwiz.exe (PID: 6512)
      • licfldr.exe (PID: 7640)
      • Transwiz.exe (PID: 5400)
  • SUSPICIOUS

    • Detects AdvancedInstaller (YARA)

      • msiexec.exe (PID: 7412)
      • msiexec.exe (PID: 8000)
    • Executes as Windows Service

      • VSSVC.exe (PID: 8096)
      • ForensiTAppxService.exe (PID: 7324)
    • Executable content was dropped or overwritten

      • Transwiz.exe (PID: 5400)
  • INFO

    • Reads the software policy settings

      • msiexec.exe (PID: 7412)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7412)
    • Checks supported languages

      • msiexec.exe (PID: 8000)
    • Checks proxy server information

      • msiexec.exe (PID: 7412)
    • Reads the computer name

      • msiexec.exe (PID: 8000)
    • Manages system restore points

      • SrTasks.exe (PID: 1452)
    • The sample compiled with english language support

      • msiexec.exe (PID: 8000)
      • Transwiz.exe (PID: 5400)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 8000)
    • Manual execution by a user

      • Transwiz.exe (PID: 6512)
      • Transwiz.exe (PID: 5400)
      • Taskmgr.exe (PID: 6436)
      • Taskmgr.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {B034C77C-C017-4926-8EB2-88DF6F1F336B}
Words: 2
Subject: ForensiT Transwiz
Author: ForensiT
LastModifiedBy: -
Software: Advanced Installer 18.6 build 099b4b9a
Template: ;2057
Comments: This installer database contains the logic and data required to install ForensiT Transwiz.
Title: Installation Database
Keywords: Installer, MSI, Database
Pages: 200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
18
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs sppextcomobj.exe no specs slui.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs licfldr.exe no specs rundll32.exe no specs transwiz.exe no specs transwiz.exe slui.exe no specs forensitappxservice.exe no specs profhlp.exe no specs taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1040C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1452C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2960"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\powrprof.dll
5400"C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe
explorer.exe
User:
admin
Company:
ForensiT Limited
Integrity Level:
HIGH
Description:
ForensiT Transwiz
Exit code:
0
Version:
1.19.1099.0
Modules
Images
c:\programdata\forensit\transwiz\deployment files\transwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6344C:\WINDOWS\system32\profhlp.exe /1C:\Windows\System32\profhlp.exeTranswiz.exe
User:
admin
Company:
ForensiT
Integrity Level:
HIGH
Description:
User Profile Migration Helper
Exit code:
0
Version:
3.0.0.1
Modules
Images
c:\windows\system32\profhlp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6436"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
6512"C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exeexplorer.exe
User:
admin
Company:
ForensiT Limited
Integrity Level:
MEDIUM
Description:
ForensiT Transwiz
Exit code:
3221226540
Version:
1.19.1099.0
Modules
Images
c:\programdata\forensit\transwiz\deployment files\transwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6516\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7244C:\Windows\syswow64\MsiExec.exe -Embedding C04134FDD3C266028505478241BB89D2C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7284C:\Windows\syswow64\MsiExec.exe -Embedding B6B717DFF7F44ED66A959E83A2F05E0C E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
16 597
Read events
16 115
Write events
452
Delete events
30

Modification events

(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000007B27C4A0C8B5DB01401F0000681F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000007B27C4A0C8B5DB01401F0000681F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000339823A1C8B5DB01401F0000681F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000339823A1C8B5DB01401F0000681F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000006FB02AA1C8B5DB01401F0000681F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000001FFE95A1C8B5DB01401F0000681F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000008BE925A1C8B5DB01401F0000681F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(8096) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(8096) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
14
Suspicious files
33
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
8000msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
8000msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{fe0942fe-97e4-4490-8cfa-52a02d7ca08e}_OnDiskSnapshotPropbinary
MD5:70BA70AABD122C63C72DB94D75821430
SHA256:8A61CDDC24662990BE77B833E463E57E98BFE06CB2F5C2B7D205B78F6FD63D13
8000msiexec.exeC:\Windows\Installer\MSI9434.tmpexecutable
MD5:1AFE13CC96584E1862CA42124785289F
SHA256:91C94656FB4D2B4A9386A4DDAFDA0548F75B09FBB6B6E888578ED4F4F40E28C9
8000msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:70BA70AABD122C63C72DB94D75821430
SHA256:8A61CDDC24662990BE77B833E463E57E98BFE06CB2F5C2B7D205B78F6FD63D13
8000msiexec.exeC:\Windows\Installer\MSI93F5.tmpbinary
MD5:D2E9FCDD6FF0C39A07BA8BD866CFD307
SHA256:13F8AFEF9478397852B466793AC59DD2BCFFA45C26B2DC8D309F84675E49BAFF
8000msiexec.exeC:\Windows\Installer\1154f3.msiexecutable
MD5:CF1DD0006C422C2C85C46A6FE4506406
SHA256:511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801
8000msiexec.exeC:\Windows\Installer\MSI9317.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\MSI92F7.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\MSI918F.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:CDC8985BA804ED925B393BAE692D2A97
SHA256:20E715FC3EB819E4135BB232444744C86CD08ACB275707A0FA2FEAEF59065A74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info