File name:

C:\Windows\Installer\1982d2.msi

Full analysis: https://app.any.run/tasks/28a3d11c-275f-48e6-a06b-139a748a393d
Verdict: Malicious activity
Analysis date: July 01, 2021, 14:46:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Security: 0, Code page: 936, Revision Number: {F06F846D-D684-47A6-923C-C7631CE2BA6B}, Number of Words: 2, Subject: VKBjD, Author: VKBjD, Name of Creating Application: Advanced Installer 16.5 build 8df7ad95, Template: ;2052, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

8708D160001B08B232090C4C7D2A9D4E

SHA1:

D242EF894B4C8C2E2CC187C2CF53942353FB79E6

SHA256:

5F062D034DFDF7AC36B391DD6DA1304B68574C65757673896CBA13374551CAFA

SSDEEP:

24576:p6uDXXN0e04BMeRocDP1NadWsvF4e1LpDhkPTG4Mcgiwkew8vroUQGDXDNSnf6Bv:p/Xdci5ooOWyLpFeBRSw8vlQIzNSnf6l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • msiexec.exe (PID: 2256)
  • SUSPICIOUS

    • Executed as Windows Service

      • msiexec.exe (PID: 2256)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3808)
      • msiexec.exe (PID: 2256)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3808)
      • msiexec.exe (PID: 2256)
    • Application launched itself

      • msiexec.exe (PID: 2256)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2256)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 2256)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 2256)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 2256)
    • Reads Environment values

      • netsh.exe (PID: 2116)
      • netsh.exe (PID: 3124)
      • netsh.exe (PID: 1236)
      • netsh.exe (PID: 2124)
      • netsh.exe (PID: 2496)
      • netsh.exe (PID: 3120)
      • netsh.exe (PID: 2100)
      • netsh.exe (PID: 3100)
      • netsh.exe (PID: 2096)
      • netsh.exe (PID: 2116)
      • netsh.exe (PID: 556)
      • netsh.exe (PID: 1568)
    • Uses NETSH.EXE for network configuration

      • MsiExec.exe (PID: 2272)
    • Creates or modifies windows services

      • netsh.exe (PID: 556)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 3808)
      • msiexec.exe (PID: 2256)
      • MsiExec.exe (PID: 2808)
      • netsh.exe (PID: 2116)
      • MsiExec.exe (PID: 2272)
      • netsh.exe (PID: 3124)
      • netsh.exe (PID: 1236)
      • netsh.exe (PID: 2124)
      • netsh.exe (PID: 2496)
      • netsh.exe (PID: 3120)
      • netsh.exe (PID: 2100)
      • netsh.exe (PID: 3100)
      • netsh.exe (PID: 556)
      • netsh.exe (PID: 2096)
      • netsh.exe (PID: 2116)
      • netsh.exe (PID: 1568)
    • Checks supported languages

      • msiexec.exe (PID: 3808)
      • msiexec.exe (PID: 2256)
      • MsiExec.exe (PID: 2808)
      • MsiExec.exe (PID: 2272)
      • netsh.exe (PID: 2116)
      • netsh.exe (PID: 2100)
      • netsh.exe (PID: 1568)
      • netsh.exe (PID: 3124)
      • netsh.exe (PID: 1236)
      • netsh.exe (PID: 2124)
      • netsh.exe (PID: 2496)
      • netsh.exe (PID: 3120)
      • netsh.exe (PID: 3100)
      • netsh.exe (PID: 2096)
      • netsh.exe (PID: 556)
      • netsh.exe (PID: 2116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.mst | Windows SDK Setup Transform Script (88.7)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Pages: 200
Keywords: Installer, MSI, Database
Title: Installation Database
Comments: -
Template: ;2052
Software: Advanced Installer 16.5 build 8df7ad95
LastModifiedBy: -
Author: VKBjD
Subject: VKBjD
Words: 2
RevisionNumber: {F06F846D-D684-47A6-923C-C7631CE2BA6B}
CodePage: Windows Simplified Chinese (PRC, Singapore)
Security: None
ModifyDate: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
LastPrinted: 2009:12:11 11:47:44
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
16
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
556"C:\Windows\System32\netsh.exe" ipsec static set policy name=qianye assign=yC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1236"C:\Windows\System32\netsh.exe" ipsec static add policy name=qianyeC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1568"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=135 protocol=UDPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2096"C:\Windows\System32\netsh.exe" ipsec static add filteraction name=FilteraAtion1 action=blockC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2100"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=445 protocol=UDPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2116"C:\Windows\System32\netsh.exe" interface ipv6 installC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2116"C:\Windows\System32\netsh.exe" ipsec static add rule name=Rule1 policy=qianye filterlist=Filter1 filteraction=FilteraAtion1C:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2124"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=445 protocol=TCPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\gdi32.dll
2256C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2272C:\Windows\system32\MsiExec.exe -Embedding 0E6347298617DCF381A1FC0C2BB15988 E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
8 597
Read events
7 906
Write events
677
Delete events
14

Modification events

(PID) Process:(2256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
D0080000845859DF876ED701
(PID) Process:(2256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
02BA8F44DDB3CED61E21610DC2D12950C0D5CF1B9AD665E5277C1FBB4BFD6121
(PID) Process:(2256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\198fb5.ipi
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\198fb6.rbs
Value:
30895760
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\198fb6.rbsLow
Value:
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B7B00AA4731E2647AAC15042EA5873C
Operation:writeName:230593080361B4C49A79A0C7BC277CB5
Value:
C:\Windows\AppPatch\Custom\
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files\VKBjD\VKBjD\
Value:
1
(PID) Process:(2256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files\VKBjD\
Value:
1
Executable files
6
Suspicious files
5
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
2256msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF50D58D58651B8ED0.TMPgmc
MD5:
SHA256:
2256msiexec.exeC:\Windows\Installer\MSI918C.tmpbinary
MD5:
SHA256:
2256msiexec.exeC:\Windows\Installer\198fb5.ipibinary
MD5:
SHA256:
2256msiexec.exeC:\Windows\Installer\MSI90BF.tmpexecutable
MD5:4B49C57CBEFA1D2773DA1F95338E294D
SHA256:68C66657B569CAD9CC6E1F5ADF0795B5DF444EC9945C0D86C62C5ABC8AADDC08
2256msiexec.exeC:\Windows\Installer\198fb3.msiexecutable
MD5:8708D160001B08B232090C4C7D2A9D4E
SHA256:5F062D034DFDF7AC36B391DD6DA1304B68574C65757673896CBA13374551CAFA
2256msiexec.exeC:\Windows\Installer\MSI90DF.tmpexecutable
MD5:4BA8EF50CE73395AD623C770C10E35A7
SHA256:6094C813CA4BD0C647B950BA286BD338EF3623FA953B3BCF1A359B88F7296E55
2256msiexec.exeC:\Windows\Installer\MSI908F.tmpexecutable
MD5:4BA8EF50CE73395AD623C770C10E35A7
SHA256:6094C813CA4BD0C647B950BA286BD338EF3623FA953B3BCF1A359B88F7296E55
2256msiexec.exeC:\Windows\Installer\MSI9040.tmpexecutable
MD5:4BA8EF50CE73395AD623C770C10E35A7
SHA256:6094C813CA4BD0C647B950BA286BD338EF3623FA953B3BCF1A359B88F7296E55
2256msiexec.exeC:\Config.Msi\198fb6.rbsbinary
MD5:
SHA256:
2256msiexec.exeC:\Windows\Installer\SourceHash{80395032-1630-4C4B-A997-0A7CCB72C75B}binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info