| File name: | Transwiz.msi |
| Full analysis: | https://app.any.run/tasks/54ac0c39-cdc2-4991-9929-2c0f2976a36a |
| Verdict: | Malicious activity |
| Analysis date: | April 25, 2025, 09:58:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {B034C77C-C017-4926-8EB2-88DF6F1F336B}, Number of Words: 2, Subject: ForensiT Transwiz, Author: ForensiT, Name of Creating Application: Advanced Installer 18.6 build 099b4b9a, Template: ;2057, Comments: This installer database contains the logic and data required to install ForensiT Transwiz., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200 |
| MD5: | CF1DD0006C422C2C85C46A6FE4506406 |
| SHA1: | DA48EC07CEA7407B6B2D38DBB54D2CD472BD7563 |
| SHA256: | 511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801 |
| SSDEEP: | 49152:fx3AY5aeGDcQ8KmLVR97uAHSvVPcAANEoW7SAmEzkGl7KMGzu7dhlwe50Qe2K:GYTGDP8KmHHSVAvW7SAhxQMG67Zwe6rZ |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2009:12:11 11:47:44 |
|---|---|
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2020:09:18 14:06:51 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {B034C77C-C017-4926-8EB2-88DF6F1F336B} |
| Words: | 2 |
| Subject: | ForensiT Transwiz |
| Author: | ForensiT |
| LastModifiedBy: | - |
| Software: | Advanced Installer 18.6 build 099b4b9a |
| Template: | ;2057 |
| Comments: | This installer database contains the logic and data required to install ForensiT Transwiz. |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| Pages: | 200 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1452 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2960 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5400 | "C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" | C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe | explorer.exe | ||||||||||||
User: admin Company: ForensiT Limited Integrity Level: HIGH Description: ForensiT Transwiz Exit code: 0 Version: 1.19.1099.0 Modules
| |||||||||||||||
| 6344 | C:\WINDOWS\system32\profhlp.exe /1 | C:\Windows\System32\profhlp.exe | — | Transwiz.exe | |||||||||||
User: admin Company: ForensiT Integrity Level: HIGH Description: User Profile Migration Helper Exit code: 0 Version: 3.0.0.1 Modules
| |||||||||||||||
| 6436 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Manager Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6512 | "C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" | C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe | — | explorer.exe | |||||||||||
User: admin Company: ForensiT Limited Integrity Level: MEDIUM Description: ForensiT Transwiz Exit code: 3221226540 Version: 1.19.1099.0 Modules
| |||||||||||||||
| 6516 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7244 | C:\Windows\syswow64\MsiExec.exe -Embedding C04134FDD3C266028505478241BB89D2 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7284 | C:\Windows\syswow64\MsiExec.exe -Embedding B6B717DFF7F44ED66A959E83A2F05E0C E Global\MSI0000 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 48000000000000007B27C4A0C8B5DB01401F0000681F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 48000000000000007B27C4A0C8B5DB01401F0000681F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000339823A1C8B5DB01401F0000681F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000339823A1C8B5DB01401F0000681F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 48000000000000006FB02AA1C8B5DB01401F0000681F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 48000000000000001FFE95A1C8B5DB01401F0000681F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 48000000000000008BE925A1C8B5DB01401F0000681F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 11 | |||
| (PID) Process: | (8096) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (8096) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
| Operation: | write | Name: | Element |
Value: 0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8000 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI9317.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI93F5.tmp | binary | |
MD5:D2E9FCDD6FF0C39A07BA8BD866CFD307 | SHA256:13F8AFEF9478397852B466793AC59DD2BCFFA45C26B2DC8D309F84675E49BAFF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI92F7.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI9347.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\inprogressinstallinfo.ipi | binary | |
MD5:CDC8985BA804ED925B393BAE692D2A97 | SHA256:20E715FC3EB819E4135BB232444744C86CD08ACB275707A0FA2FEAEF59065A74 | |||
| 8000 | msiexec.exe | C:\Program Files (x86)\ForensiT\ForensiT Transwiz\Transwiz User Guide.pdf | ||
MD5:4D67C67803BE71AE12FE7EE1482AB646 | SHA256:2AC8C339F26873D2BD369EF6FAC4B098CFD27FE2ECE7DDE40DCAB786BE61AA5B | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI9377.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.config | xml | |
MD5:EF93C2754F599188AF96D1CB2C04AA6C | SHA256:F8CE6F4572B696E7C96E0606C48BA206F2528857A290C8E0B576207CA08E37A6 | |||
| 8000 | msiexec.exe | C:\Windows\Temp\~DF42CD35574A02065C.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||