File name:

32bit.msi

Full analysis: https://app.any.run/tasks/342acc4f-6bc5-4ae7-8c0a-9f7749280e76
Verdict: Malicious activity
Analysis date: May 14, 2021, 18:50:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Code page: 1252, Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Wed Feb 1 11:10:38 2006, Name of Creating Application: Windows Installer, Security: 0, Template: ;1033, Last Saved By: ;1033, Revision Number: {54B6B76F-570F-49AE-BC06-02D926303CF2}1.4.8;{8B282CB8-D6CA-4638-BDD6-9E15F46FF245}1.4.8;{ED37058B-0A2C-4338-9045-7F8098234AF7}, Number of Pages: 200, Number of Characters: 63
MD5:

3C2D39BE92EE6C7BDFD94FD31848FFCF

SHA1:

8A9AA9334D601FFCCA64526B727F37C4F23C3493

SHA256:

52E13A75E8E7371B43D18E4B8E52E9BF6310A3436624317EEEC6BD2BE6E09847

SSDEEP:

98304:2YQ2GBGyAIRJtJlZrHrcNRh/tDeZUL3j80ODWtvvmQLRTZSS1kCbJt8cfP/M:KS+RjnZbrEJeZULT80ODWtfLR31p1hXM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • MsiExec.exe (PID: 1712)
      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
  • SUSPICIOUS

    • Removes files from Windows directory

      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
    • Creates files in the Windows directory

      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
    • Executed via COM

      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
    • Executable content was dropped or overwritten

      • DrvInst.exe (PID: 1276)
      • MsiExec.exe (PID: 1712)
      • DrvInst.exe (PID: 2820)
    • Drops a file with too old compile date

      • DrvInst.exe (PID: 1276)
      • MsiExec.exe (PID: 1712)
      • DrvInst.exe (PID: 2820)
    • Drops a file that was compiled in debug mode

      • DrvInst.exe (PID: 1276)
      • DrvInst.exe (PID: 2820)
      • MsiExec.exe (PID: 1712)
    • Drops a file with a compile date too recent

      • DrvInst.exe (PID: 1276)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 1712)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 1276)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 1276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Characters: 63
Comments: This installer database contains the logic and data required to install MVCI Driver for TOYOTA TIS.
Template: ;1033,1028,2052,1036,1031,1040,1049
Software: Advanced Installer 7.2.1
LastModifiedBy: -
Author: XHorse Electronics
Subject: MVCI Driver for TOYOTA TIS
Words: 2
RevisionNumber: {DA698F43-F3D0-4CB3-AA1D-D48FB96B90F9}
CodePage: Windows Latin 1 (Western European)
Security: None
Pages: 200
ModifyDate: 2009:07:27 15:08:27
Keywords: Installer, MSI, Database
Title: Installation Database
CreateDate: 2006:02:01 11:10:36
LastPrinted: 2006:02:01 11:10:36
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs drvinst.exe msiexec.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1276DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\ftdibus.inf" "0" "64bb5824b" "0000054C" "WinSta0\Default" "000003F4" "208" "C:\Program Files\XHorse Electronics\MVCI Driver for TOYOTA TIS\ftdibus"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1712C:\Windows\system32\MsiExec.exe -Embedding 5E63463E15096FF82056C12EA7E929D0 M Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2280"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\32bit.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2820DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{6c5c9dec-49f9-21dd-30e7-6e78d117fa5c}\ftdiport.inf" "0" "65723a11b" "000003F4" "WinSta0\Default" "000004D4" "208" "C:\Program Files\XHorse Electronics\MVCI Driver for TOYOTA TIS\ftdiport"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
173
Read events
130
Write events
43
Delete events
0

Modification events

(PID) Process:(1712) MsiExec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\DIFxApp\Components\{5E279225-28C9-42A7-BF38-004A6A761ABC}
Operation:writeName:CleanupNeeded
Value:
1
(PID) Process:(1712) MsiExec.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1712) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(1276) DrvInst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1276) DrvInst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
Operation:writeName:Blob
Value:
0400000001000000100000002A954ECA79B2874573D92D90BAF99FB61400000001000000140000004A5C7522AA46BFA4089D39974EBDB4A360F7A01D030000000100000014000000A43489159A520F0D93D032CCAF37E7FE20A8B4190B00000001000000320000004D006900630072006F0073006F0066007400200052006F006F007400200041007500740068006F007200690074007900000069000000010000000E000000300C060A2B0601040182373C03020F00000001000000100000008B3C3087B7056F5EC5DDBA91A1B901F01900000001000000100000003FC8CB0BC05241E58D65E9448B2D07C220000000010000001604000030820412308202FAA003020102020F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D01010405003070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479301E170D3937303131303037303030305A170D3230313233313037303030305A3070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100A902BDC170E63BF24E1B289F97785E30EAA2A98D255FF8FE954CA3B7FE9DA2203E7C51A29BA28F60326BD1426479EEAC76C954DAF2EB9C861C8F9F8466B3C56B7A6223D61D3CDE0F0192E896C4BF2D669A9A682699D03A2CBF0CB55826C146E70A3E38962CA92839A8EC498342E3840FBB9A6C5561AC827CA1602D774CE999B4643B9A501C310824149FA9E7912B18E63D986314605805659F1D375287F7A7EF9402C61BD3BF5545B38980BF3AEC54944EAEFDA77A6D744EAF18CC96092821005790606937BB4B12073C56FF5BFBA4660A08A6D2815657EFB63B5E16817704DAF6BEAE8095FEB0CD7FD6A71A725C3CCABCF008A32230B30685C9B320771385DF0203010001A381A83081A53081A20603551D0104819A30819780105BD070EF69729E23517E14B24D8EFFCBA1723070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479820F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D0101040500038201010095E80BC08DF3971835EDB80124D87711F35C60329F9E0BCB3E0591888FC93AE621F2F057932CB5A047C862EFFCD7CC3B3B5AA9365469FE246D3FC9CCAADE057CDD318D3D9F10706ABBFE124F1869C0FCD043E3115A204FEA627BAFAA19C82B37252DBE65A1128A250F63A3F7541CF921C9D615F352AC6E433207FD8217F8E5676C0D51F6BDF152C7BDE7C430FC203109881D95291A4DD51D02A5F180E003B45BF4B1DDC857EE6549C75254B6B4032812FF90D6F0088F7EB897C5AB372CE47AE4A877E376A000D06A3FC1D2368AE04112A8356A1B6ADB35E1D41C04E4A84504C85A33386E4D1C0D62B70AA28CD3D5543F46CD1C55A670DB123A8793759FA7D2A0
(PID) Process:(1276) DrvInst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
Operation:writeName:Blob
Value:
0400000001000000100000002A954ECA79B2874573D92D90BAF99FB60F00000001000000100000008B3C3087B7056F5EC5DDBA91A1B901F0030000000100000014000000A43489159A520F0D93D032CCAF37E7FE20A8B4196800000001000000080000000000DC6F269AD30169000000010000000E000000300C060A2B0601040182373C03021D00000001000000100000006C6FE103005E9DDA7F0D5B92F8CA4A401400000001000000140000004A5C7522AA46BFA4089D39974EBDB4A360F7A01D620000000100000020000000F38406E540D7A9D90CB4A9479299640FFB6DF9E224ECC7A01C0D9558D8DAD77D0B00000001000000320000004D006900630072006F0073006F0066007400200052006F006F007400200041007500740068006F00720069007400790000001900000001000000100000003FC8CB0BC05241E58D65E9448B2D07C220000000010000001604000030820412308202FAA003020102020F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D01010405003070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479301E170D3937303131303037303030305A170D3230313233313037303030305A3070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100A902BDC170E63BF24E1B289F97785E30EAA2A98D255FF8FE954CA3B7FE9DA2203E7C51A29BA28F60326BD1426479EEAC76C954DAF2EB9C861C8F9F8466B3C56B7A6223D61D3CDE0F0192E896C4BF2D669A9A682699D03A2CBF0CB55826C146E70A3E38962CA92839A8EC498342E3840FBB9A6C5561AC827CA1602D774CE999B4643B9A501C310824149FA9E7912B18E63D986314605805659F1D375287F7A7EF9402C61BD3BF5545B38980BF3AEC54944EAEFDA77A6D744EAF18CC96092821005790606937BB4B12073C56FF5BFBA4660A08A6D2815657EFB63B5E16817704DAF6BEAE8095FEB0CD7FD6A71A725C3CCABCF008A32230B30685C9B320771385DF0203010001A381A83081A53081A20603551D0104819A30819780105BD070EF69729E23517E14B24D8EFFCBA1723070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479820F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D0101040500038201010095E80BC08DF3971835EDB80124D87711F35C60329F9E0BCB3E0591888FC93AE621F2F057932CB5A047C862EFFCD7CC3B3B5AA9365469FE246D3FC9CCAADE057CDD318D3D9F10706ABBFE124F1869C0FCD043E3115A204FEA627BAFAA19C82B37252DBE65A1128A250F63A3F7541CF921C9D615F352AC6E433207FD8217F8E5676C0D51F6BDF152C7BDE7C430FC203109881D95291A4DD51D02A5F180E003B45BF4B1DDC857EE6549C75254B6B4032812FF90D6F0088F7EB897C5AB372CE47AE4A877E376A000D06A3FC1D2368AE04112A8356A1B6ADB35E1D41C04E4A84504C85A33386E4D1C0D62B70AA28CD3D5543F46CD1C55A670DB123A8793759FA7D2A0
(PID) Process:(1712) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DIFx\DriverStore\ftdibus.inf_x86_neutral_196728ceed198527
Operation:writeName:DependentInstaller
Value:
{5E279225-28C9-42A7-BF38-004A6A761ABC}
(PID) Process:(1712) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DIFx\DriverStore\ftdibus.inf_x86_neutral_196728ceed198527
Operation:writeName:DependentInstallerName
Value:
MVCI Driver for TOYOTA TIS
(PID) Process:(1712) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DIFxApp\Components\{5E279225-28C9-42A7-BF38-004A6A761ABC}
Operation:writeName:DriverStore
Value:
C:\Windows\System32\DriverStore\FileRepository\ftdibus.inf_x86_neutral_196728ceed198527\ftdibus.inf
(PID) Process:(1712) MsiExec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\DIFxApp\Components\{5E279225-28C9-42A7-BF38-004A6A761ABC}
Operation:writeName:Reboot
Value:
0
Executable files
14
Suspicious files
15
Text files
63
Unknown types
7

Dropped files

PID
Process
Filename
Type
2280msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIF9FC.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\i386\SET5EA1.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\i386\SET5EB2.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\i386\SET5EC2.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\i386\SET5EC3.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\SET5ED4.tmp
MD5:
SHA256:
1712MsiExec.exeC:\Users\admin\AppData\Local\Temp\{691a7e22-bfa0-0070-6453-505230e76e78}\SET5EE5.tmp
MD5:
SHA256:
1276DrvInst.exeC:\Windows\System32\DriverStore\Temp\{0ec71b1f-8ef9-16a3-380b-a118b8dfe338}\i386\SET6057.tmp
MD5:
SHA256:
1276DrvInst.exeC:\Windows\System32\DriverStore\Temp\{0ec71b1f-8ef9-16a3-380b-a118b8dfe338}\i386\SET6067.tmp
MD5:
SHA256:
1276DrvInst.exeC:\Windows\System32\DriverStore\Temp\{0ec71b1f-8ef9-16a3-380b-a118b8dfe338}\i386\SET6088.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info