| File name: | SDK320.msi |
| Full analysis: | https://app.any.run/tasks/a8e9e637-08c4-4944-9f85-878065df6b0e |
| Verdict: | Suspicious activity |
| Analysis date: | May 02, 2020, 18:53:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: XFS 3.20 SDK, Author: CEN XFS Workshop, Keywords: Installer, Comments: Version 3.20, Template: Intel;1033, Revision Number: {933C6EF6-D8FE-4020-BB82-E3211F953444}, Create Time/Date: Thu Feb 23 15:54:20 2012, Last Saved Time/Date: Thu Feb 23 15:54:20 2012, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.0.5419.0), Security: 2 |
| MD5: | 32D5CCA418B81E002BB3FDD8E4062BC9 |
| SHA1: | 798D6D8ADB449DE0A3903AF062C8EDD8E401C2E4 |
| SHA256: | 6303EE28660F9D8BFF4A494F96D681A2CEBC72E5ABC1AC3B0FDEBCDDBB7E0B8D |
| SSDEEP: | 6144:RmWfO38XsmuHi8LGK3s+3XN8s5nChu76Gdu8hPt4hAVxNB+j25p2rT:c/38XnQPLGKc+nN8sMuddTPOh0xaj |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | XFS 3.20 SDK |
| Author: | CEN XFS Workshop |
| Keywords: | Installer |
| Comments: | Version 3.20 |
| Template: | Intel;1033 |
| RevisionNumber: | {933C6EF6-D8FE-4020-BB82-E3211F953444} |
| CreateDate: | 2012:02:23 15:54:20 |
| ModifyDate: | 2012:02:23 15:54:20 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML (3.0.5419.0) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3480 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3664 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\SDK320.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3996 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3480) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000BCCA7B15B320D601980D00004C0B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3480) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000BCCA7B15B320D601980D00004C0B0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3480) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 34 | |||
| (PID) Process: | (3480) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000001864D615B320D601980D00004C0B0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3480) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000001864D615B320D601980D00002C0B0000E80300000100000000000000000000005FA551FBFCCAE04DB35615E9A229ECCE0000000000000000 | |||
| (PID) Process: | (3996) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E876E915B320D6019C0F0000900F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3996) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E876E915B320D6019C0F0000300C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3996) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E876E915B320D6019C0F0000780B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3996) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E876E915B320D6019C0F0000840F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3996) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000B889FC15B320D6019C0F0000780B0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3480 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFBFB11088A426CA52.TMP | — | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{fb51a55f-cafc-4de0-b356-15e9a229ecce}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\Windows\Installer\MSI54CA.tmp | binary | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\Windows\Installer\a74d2a.ipi | binary | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 3480 | msiexec.exe | C:\Program Files\Common Files\XFS\SDK\INCLUDE\XFSDEP.H | text | |
MD5:E7DC57D34FE05D383950ECCAA75E3713 | SHA256:AB713A818EF6EB1519CCB4689F617E06784C12BE82A607FA2F8A10ACF079C709 | |||
| 3480 | msiexec.exe | C:\Program Files\Common Files\XFS\SDK\INCLUDE\XFSCIM.H | text | |
MD5:AA1486F00535010B153C43275B75421D | SHA256:563075B386F4D8834B56C1CF6858B0934E1B2206C2CCCAEAB8A39FC5D36E899C | |||
| 3480 | msiexec.exe | C:\Program Files\Common Files\XFS\SDK\DOC\LICENSE.pdf | ||
MD5:AA0F5037BB7F7F1655403E7FBDEDDB77 | SHA256:6EB0091340F1BFAEE42F6224038EB4759ADBED51E04E284ACEC1CA2FCC0D14A0 | |||
| 3480 | msiexec.exe | C:\Program Files\Common Files\XFS\SDK\INCLUDE\XFSADMIN.H | text | |
MD5:477814A946901AD058ABF6B337847E41 | SHA256:24EAE227CD840B0E98C89EF639EEA3442824A2793CDC238CF971CC0CEB0BE72F | |||