File name:

Transwiz.msi

Full analysis: https://app.any.run/tasks/54ac0c39-cdc2-4991-9929-2c0f2976a36a
Verdict: Malicious activity
Analysis date: April 25, 2025, 09:58:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {B034C77C-C017-4926-8EB2-88DF6F1F336B}, Number of Words: 2, Subject: ForensiT Transwiz, Author: ForensiT, Name of Creating Application: Advanced Installer 18.6 build 099b4b9a, Template: ;2057, Comments: This installer database contains the logic and data required to install ForensiT Transwiz., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

CF1DD0006C422C2C85C46A6FE4506406

SHA1:

DA48EC07CEA7407B6B2D38DBB54D2CD472BD7563

SHA256:

511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801

SSDEEP:

49152:fx3AY5aeGDcQ8KmLVR97uAHSvVPcAANEoW7SAmEzkGl7KMGzu7dhlwe50Qe2K:GYTGDP8KmHHSVAvW7SAhxQMG67Zwe6rZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • licfldr.exe (PID: 7640)
      • Transwiz.exe (PID: 5400)
      • Transwiz.exe (PID: 6512)
  • SUSPICIOUS

    • Detects AdvancedInstaller (YARA)

      • msiexec.exe (PID: 7412)
      • msiexec.exe (PID: 8000)
    • Executes as Windows Service

      • VSSVC.exe (PID: 8096)
      • ForensiTAppxService.exe (PID: 7324)
    • Executable content was dropped or overwritten

      • Transwiz.exe (PID: 5400)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 7412)
    • Checks proxy server information

      • msiexec.exe (PID: 7412)
    • Reads the software policy settings

      • msiexec.exe (PID: 7412)
    • Checks supported languages

      • msiexec.exe (PID: 8000)
    • Reads the computer name

      • msiexec.exe (PID: 8000)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 8000)
    • Manages system restore points

      • SrTasks.exe (PID: 1452)
    • Manual execution by a user

      • Transwiz.exe (PID: 6512)
      • Transwiz.exe (PID: 5400)
      • Taskmgr.exe (PID: 6436)
      • Taskmgr.exe (PID: 2960)
    • The sample compiled with english language support

      • msiexec.exe (PID: 8000)
      • Transwiz.exe (PID: 5400)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {B034C77C-C017-4926-8EB2-88DF6F1F336B}
Words: 2
Subject: ForensiT Transwiz
Author: ForensiT
LastModifiedBy: -
Software: Advanced Installer 18.6 build 099b4b9a
Template: ;2057
Comments: This installer database contains the logic and data required to install ForensiT Transwiz.
Title: Installation Database
Keywords: Installer, MSI, Database
Pages: 200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
18
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs sppextcomobj.exe no specs slui.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs licfldr.exe no specs rundll32.exe no specs transwiz.exe no specs transwiz.exe slui.exe no specs forensitappxservice.exe no specs profhlp.exe no specs taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1040C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1452C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2960"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\powrprof.dll
5400"C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe
explorer.exe
User:
admin
Company:
ForensiT Limited
Integrity Level:
HIGH
Description:
ForensiT Transwiz
Exit code:
0
Version:
1.19.1099.0
Modules
Images
c:\programdata\forensit\transwiz\deployment files\transwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6344C:\WINDOWS\system32\profhlp.exe /1C:\Windows\System32\profhlp.exeTranswiz.exe
User:
admin
Company:
ForensiT
Integrity Level:
HIGH
Description:
User Profile Migration Helper
Exit code:
0
Version:
3.0.0.1
Modules
Images
c:\windows\system32\profhlp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6436"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
6512"C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exeexplorer.exe
User:
admin
Company:
ForensiT Limited
Integrity Level:
MEDIUM
Description:
ForensiT Transwiz
Exit code:
3221226540
Version:
1.19.1099.0
Modules
Images
c:\programdata\forensit\transwiz\deployment files\transwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6516\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7244C:\Windows\syswow64\MsiExec.exe -Embedding C04134FDD3C266028505478241BB89D2C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7284C:\Windows\syswow64\MsiExec.exe -Embedding B6B717DFF7F44ED66A959E83A2F05E0C E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
16 597
Read events
16 115
Write events
452
Delete events
30

Modification events

(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000007B27C4A0C8B5DB01401F0000681F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000007B27C4A0C8B5DB01401F0000681F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000339823A1C8B5DB01401F0000681F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000339823A1C8B5DB01401F0000681F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000006FB02AA1C8B5DB01401F0000681F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000001FFE95A1C8B5DB01401F0000681F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000008BE925A1C8B5DB01401F0000681F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(8000) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(8096) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(8096) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
14
Suspicious files
33
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
8000msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
8000msiexec.exeC:\Windows\Installer\MSI9317.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\MSI93F5.tmpbinary
MD5:D2E9FCDD6FF0C39A07BA8BD866CFD307
SHA256:13F8AFEF9478397852B466793AC59DD2BCFFA45C26B2DC8D309F84675E49BAFF
8000msiexec.exeC:\Windows\Installer\MSI92F7.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\MSI9347.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:CDC8985BA804ED925B393BAE692D2A97
SHA256:20E715FC3EB819E4135BB232444744C86CD08ACB275707A0FA2FEAEF59065A74
8000msiexec.exeC:\Program Files (x86)\ForensiT\ForensiT Transwiz\Transwiz User Guide.pdfpdf
MD5:4D67C67803BE71AE12FE7EE1482AB646
SHA256:2AC8C339F26873D2BD369EF6FAC4B098CFD27FE2ECE7DDE40DCAB786BE61AA5B
8000msiexec.exeC:\Windows\Installer\MSI9377.tmpexecutable
MD5:36E2EDBDE4F98A27F31FEF1932D51E95
SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF
8000msiexec.exeC:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.configxml
MD5:EF93C2754F599188AF96D1CB2C04AA6C
SHA256:F8CE6F4572B696E7C96E0606C48BA206F2528857A290C8E0B576207CA08E37A6
8000msiexec.exeC:\Windows\Temp\~DF42CD35574A02065C.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info