| File name: | Transwiz.msi |
| Full analysis: | https://app.any.run/tasks/54ac0c39-cdc2-4991-9929-2c0f2976a36a |
| Verdict: | Malicious activity |
| Analysis date: | April 25, 2025, 09:58:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {B034C77C-C017-4926-8EB2-88DF6F1F336B}, Number of Words: 2, Subject: ForensiT Transwiz, Author: ForensiT, Name of Creating Application: Advanced Installer 18.6 build 099b4b9a, Template: ;2057, Comments: This installer database contains the logic and data required to install ForensiT Transwiz., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200 |
| MD5: | CF1DD0006C422C2C85C46A6FE4506406 |
| SHA1: | DA48EC07CEA7407B6B2D38DBB54D2CD472BD7563 |
| SHA256: | 511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801 |
| SSDEEP: | 49152:fx3AY5aeGDcQ8KmLVR97uAHSvVPcAANEoW7SAmEzkGl7KMGzu7dhlwe50Qe2K:GYTGDP8KmHHSVAvW7SAhxQMG67Zwe6rZ |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2009:12:11 11:47:44 |
|---|---|
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2020:09:18 14:06:51 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {B034C77C-C017-4926-8EB2-88DF6F1F336B} |
| Words: | 2 |
| Subject: | ForensiT Transwiz |
| Author: | ForensiT |
| LastModifiedBy: | - |
| Software: | Advanced Installer 18.6 build 099b4b9a |
| Template: | ;2057 |
| Comments: | This installer database contains the logic and data required to install ForensiT Transwiz. |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| Pages: | 200 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1452 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2960 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5400 | "C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" | C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe | explorer.exe | ||||||||||||
User: admin Company: ForensiT Limited Integrity Level: HIGH Description: ForensiT Transwiz Exit code: 0 Version: 1.19.1099.0 Modules
| |||||||||||||||
| 6344 | C:\WINDOWS\system32\profhlp.exe /1 | C:\Windows\System32\profhlp.exe | — | Transwiz.exe | |||||||||||
User: admin Company: ForensiT Integrity Level: HIGH Description: User Profile Migration Helper Exit code: 0 Version: 3.0.0.1 Modules
| |||||||||||||||
| 6436 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Manager Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6512 | "C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe" | C:\ProgramData\ForensiT\Transwiz\Deployment Files\Transwiz.exe | — | explorer.exe | |||||||||||
User: admin Company: ForensiT Limited Integrity Level: MEDIUM Description: ForensiT Transwiz Exit code: 3221226540 Version: 1.19.1099.0 Modules
| |||||||||||||||
| 6516 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7244 | C:\Windows\syswow64\MsiExec.exe -Embedding C04134FDD3C266028505478241BB89D2 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7284 | C:\Windows\syswow64\MsiExec.exe -Embedding B6B717DFF7F44ED66A959E83A2F05E0C E Global\MSI0000 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 48000000000000007B27C4A0C8B5DB01401F0000681F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 48000000000000007B27C4A0C8B5DB01401F0000681F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000339823A1C8B5DB01401F0000681F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000339823A1C8B5DB01401F0000681F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 48000000000000006FB02AA1C8B5DB01401F0000681F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 48000000000000001FFE95A1C8B5DB01401F0000681F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 48000000000000008BE925A1C8B5DB01401F0000681F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (8000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 11 | |||
| (PID) Process: | (8096) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (8096) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001 |
| Operation: | write | Name: | Element |
Value: 0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8000 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 8000 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{fe0942fe-97e4-4490-8cfa-52a02d7ca08e}_OnDiskSnapshotProp | binary | |
MD5:70BA70AABD122C63C72DB94D75821430 | SHA256:8A61CDDC24662990BE77B833E463E57E98BFE06CB2F5C2B7D205B78F6FD63D13 | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI9434.tmp | executable | |
MD5:1AFE13CC96584E1862CA42124785289F | SHA256:91C94656FB4D2B4A9386A4DDAFDA0548F75B09FBB6B6E888578ED4F4F40E28C9 | |||
| 8000 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:70BA70AABD122C63C72DB94D75821430 | SHA256:8A61CDDC24662990BE77B833E463E57E98BFE06CB2F5C2B7D205B78F6FD63D13 | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI93F5.tmp | binary | |
MD5:D2E9FCDD6FF0C39A07BA8BD866CFD307 | SHA256:13F8AFEF9478397852B466793AC59DD2BCFFA45C26B2DC8D309F84675E49BAFF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\1154f3.msi | executable | |
MD5:CF1DD0006C422C2C85C46A6FE4506406 | SHA256:511C2C0908883BC9D05295E5145B767F2633461C93A31D1CB8D765EE09CDD801 | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI9317.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI92F7.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\MSI918F.tmp | executable | |
MD5:36E2EDBDE4F98A27F31FEF1932D51E95 | SHA256:D9A307D175C72EA0922296F0686AB5A2A72F67E3C8C848E6623CB36AEADDF2EF | |||
| 8000 | msiexec.exe | C:\Windows\Installer\inprogressinstallinfo.ipi | binary | |
MD5:CDC8985BA804ED925B393BAE692D2A97 | SHA256:20E715FC3EB819E4135BB232444744C86CD08ACB275707A0FA2FEAEF59065A74 | |||