| File name: | 123.msi |
| Full analysis: | https://app.any.run/tasks/a6f226de-916c-4696-8984-b2ef66f32816 |
| Verdict: | Malicious activity |
| Analysis date: | April 25, 2019, 12:56:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Orange Heap, Author: Mikalai Kalpinski, Keywords: Installer, Comments: This installer database contains the logic and data required to install Orange Heap., Template: Intel;1049, Revision Number: {78BD0E71-C2C8-4D59-B8A1-312C2113C584}, Create Time/Date: Wed Jun 6 09:32:38 2012, Last Saved Time/Date: Wed Jun 6 09:32:38 2012, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.5.2519.0), Security: 2 |
| MD5: | 5DD480E2FF9FBA53A1ACAD8BCF80A184 |
| SHA1: | B2799D68F70C04E5BDC20684DC29922C215A1E60 |
| SHA256: | 5C5F6A2B329E8EA9CE7EC6FAB25E2DC574FBB817375A057B8999E95FE64C9DD1 |
| SSDEEP: | 49152:d39GHHHDIVPYRnuEMX27gWAaHZBUmVS28:dNGnHDJxZ7UmV |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | Orange Heap |
| Author: | Mikalai Kalpinski |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install Orange Heap. |
| Template: | Intel;1049 |
| RevisionNumber: | {78BD0E71-C2C8-4D59-B8A1-312C2113C584} |
| CreateDate: | 2012:06:06 08:32:38 |
| ModifyDate: | 2012:06:06 08:32:38 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML (3.5.2519.0) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2184 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2320 | "C:\Windows\system32\taskmgr.exe" /1 | C:\Windows\system32\taskmgr.exe | taskmgr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2440 | C:\Windows\system32\MsiExec.exe -Embedding 000F42ADD05196A10A4D349682A4E531 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2724 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2780 | C:\Windows\system32\MsiExec.exe -Embedding E1B7DC18518CC7B1CE0318C48EDF815E C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2956 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\123.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3316 | C:\Windows\system32\MsiExec.exe -Embedding 9FE6C4AD29C0E9A617C03C0E99271C03 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3564 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003A0" "000005BC" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4044 | "C:\Program Files\Orange Heap\OrangeHeap.exe" | C:\Program Files\Orange Heap\OrangeHeap.exe | — | explorer.exe | |||||||||||
User: admin Company: Mikalai Kalpinski Integrity Level: MEDIUM Description: OrangeHeap Exit code: 0 Version: 1.3.29.0 Modules
| |||||||||||||||
| 4056 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000AE251B5B66FBD40188080000000F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000AE251B5B66FBD40188080000000F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000A2356C5B66FBD40188080000000F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000FC976E5B66FBD401880800009C0D0000E80300000100000000000000000000003EAD154BEB8AAB4FB1C7CD2D146918700000000000000000 | |||
| (PID) Process: | (4056) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006421785B66FBD401D80F00001C0A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4056) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006421785B66FBD401D80F0000200A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4056) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006421785B66FBD401D80F0000340E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4056) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000006421785B66FBD401D80F0000200E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4056) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000CCAA815B66FBD401D80F00001C0A0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2956 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI1A32.tmp | — | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3564 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF29352CAEC2795EF8.TMP | — | |
MD5:— | SHA256:— | |||
| 4056 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{4b15ad3e-8aeb-4fab-b1c7-cd2d14691870}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\Windows\Installer\MSI593F.tmp | binary | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\Windows\Installer\135393.ipi | binary | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\Program Files\Orange Heap\Core.dll | executable | |
MD5:2A3069F78D56A669F22E8A5C0A792D6F | SHA256:4C039A23EA70B361C16EE231DA267465B55ECC0D154AD895A66DA2C8EA565BDC | |||