| File name: | AutodeskScanWin-EMEA.msi |
| Full analysis: | https://app.any.run/tasks/66243951-40fe-4d5a-ba61-e6fbd13081ff |
| Verdict: | Malicious activity |
| Analysis date: | October 30, 2019, 21:32:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: ScanWin, Author: Autodesk, Keywords: Installer, Comments: This installer database contains the logic and data required to install ScanWin., Template: Intel;1033, Revision Number: {9B6695B1-D416-4A29-A532-D951C38DD690}, Create Time/Date: Fri Oct 25 13:29:36 2019, Last Saved Time/Date: Fri Oct 25 13:29:36 2019, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2 |
| MD5: | A6033B6BC4B997EC75E4076816C336D9 |
| SHA1: | FC1CED31BD34495B6D3A34A966D072514A3071F4 |
| SHA256: | 632F57137480192E2067ACEA4801C829513578C9ECF926BEC095E2154E6D27ED |
| SSDEEP: | 49152:czRt0UjO43frZBC1/t1iskdASsuInkQyHxtkup:4T0UJ3D7C9t1YABJ1up |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | ScanWin |
| Author: | Autodesk |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install ScanWin. |
| Template: | Intel;1033 |
| RevisionNumber: | {9B6695B1-D416-4A29-A532-D951C38DD690} |
| CreateDate: | 2019:10:25 12:29:36 |
| ModifyDate: | 2019:10:25 12:29:36 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.11.1.2318) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1400 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1876 | cmd /c C:\Windows\Temp\User_Subscriptions.cmd | C:\Windows\system32\cmd.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2256 | "C:\Windows\system32\cmd.exe" | C:\Windows\system32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2620 | "ScanWin.exe" /cred="EAAAANFTX6tYUSIaJFQx25sGED18dY7snDO/7yrdEMnYAkhRZ6dWqukeQV9HnxB7VjgVpw==" /iprange=192.168.100.1-192.168.100.30 /rp /fp /sl /output="C:\ProgramData\Autodesk\ScanWin\Output" | C:\Program Files\Autodesk\ScanWin\ScanWin.exe | — | ScanWinViewer.exe | |||||||||||
User: admin Company: License Dashboard Integrity Level: MEDIUM Description: ScanWin Exit code: 0 Version: 2.0.7.0 Modules
| |||||||||||||||
| 2764 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2960 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AutodeskScanWin-EMEA.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3340 | "C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exe" | C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exe | — | explorer.exe | |||||||||||
User: admin Company: License Dashboard Integrity Level: MEDIUM Description: ScanWin Viewer Exit code: 0 Version: 2.0.7.0 Modules
| |||||||||||||||
| 3604 | cmd /c C:\Windows\Temp\Installer_Helper.cmd | C:\Windows\system32\cmd.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3704 | ipconfig | C:\Windows\system32\ipconfig.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IP Configuration Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
| (PID) Process: | (2960) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-844 |
Value: BitLocker Data Recovery Agent | |||
| (PID) Process: | (1400) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 400000000000000038A0B0AB698FD5017805000034030000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1400) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 400000000000000038A0B0AB698FD5017805000034030000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1400) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 33 | |||
| (PID) Process: | (1400) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000003AD708AC698FD5017805000034030000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CabE71E.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\TarE71F.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CabE740.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\TarE741.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\CabE7DE.tmp | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\TarE7DF.tmp | — | |
MD5:— | SHA256:— | |||
| 1400 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 1400 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFFD7161106D6092E6.TMP | — | |
MD5:— | SHA256:— | |||
| 2764 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2960 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2960 | msiexec.exe | GET | 200 | 8.241.122.254:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.0 Kb | whitelisted |
2960 | msiexec.exe | GET | 200 | 8.241.122.254:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E.crt | US | der | 1.47 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2960 | msiexec.exe | 8.241.122.254:80 | www.download.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
2960 | msiexec.exe | 91.199.212.52:80 | crt.usertrust.com | Comodo CA Ltd | GB | suspicious |
Domain | IP | Reputation |
|---|---|---|
crt.usertrust.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
2.100.168.192.in-addr.arpa |
| whitelisted |