| File name: | AdRapPublic_ENU.msi |
| Full analysis: | https://app.any.run/tasks/eeee9fe9-bb37-4aaf-b7a7-259bdcdd3b78 |
| Verdict: | Malicious activity |
| Analysis date: | November 05, 2019, 22:13:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: ADST 5.8, Author: Microsoft Corporation, Keywords: Installer, Comments: Active Directory Risk Assesment Program, Template: ;1033, Revision Number: {605230E8-3827-4E50-83C2-471AE038CFDE}, Number of Pages: 200, Number of Words: 2, Security: 2, Create Time/Date: Fri Sep 26 01:50:33 2008, Last Saved Time/Date: Fri Sep 26 01:50:33 2008, Name of Creating Application: Windows Installer XML v2.0.4701.0 (candle/light) |
| MD5: | A63B2B55280B8197E7D0B046763116C9 |
| SHA1: | AD6C860E67733808B462C1D178FD589212A6C379 |
| SHA256: | 68FA75DB61060028A8CD96806C702BEA17A1C867B8D60107FABD31C657217B7B |
| SSDEEP: | 196608:xb6MOh40jrm2IifldwZ7dpGCUky7L86nMACkATXMV3Dl+pEX:AdfjaGldwZ7qCBy75bCvO |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | ADST 5.8 |
| Author: | Microsoft Corporation |
| Keywords: | Installer |
| Comments: | Active Directory Risk Assesment Program |
| Template: | ;1033 |
| RevisionNumber: | {605230E8-3827-4E50-83C2-471AE038CFDE} |
| Pages: | 200 |
| Words: | 2 |
| Security: | Read-only recommended |
| CreateDate: | 2008:09:26 00:50:33 |
| ModifyDate: | 2008:09:26 00:50:33 |
| Software: | Windows Installer XML v2.0.4701.0 (candle/light) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2232 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2700 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AdRapPublic_ENU.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3336 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3876 | "C:\ADRAP\Public\RapidClient.exe" | C:\ADRAP\Public\RapidClient.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: RapidClient Exit code: 0 Version: 01.02.0062.01_RAPIDFull Modules
| |||||||||||||||
| (PID) Process: | (2232) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000CE8395632694D501B8080000F00F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2232) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000CE8395632694D501B8080000F00F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2232) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 33 | |||
| (PID) Process: | (2232) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000005A0ADD632694D501B8080000F00F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2232) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000B46CDF632694D501B80800000C0F0000E803000001000000000000000000000037E1ABA44AF8BB41A6F4A0D129B144680000000000000000 | |||
| (PID) Process: | (3336) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D0BAED632694D501080D0000E4060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3336) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D0BAED632694D501080D00002C0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3336) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D0BAED632694D501080D0000A8050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3336) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D0BAED632694D501080D0000700F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3336) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000092A6F9632694D501080D0000A8050000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2232 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\Windows\Installer\3a0ecb.msi | — | |
MD5:— | SHA256:— | |||
| 3336 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF1059EFC429EDA1FF.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\Keyoti.RapidSpellMDict.dll | executable | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\Schema\BestPracticeText.xsd | xml | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\Schema\BaseTypes.xsd | xml | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\RapidClient.exe | executable | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\Schema\Rules.xsd | xml | |
MD5:— | SHA256:— | |||
| 2232 | msiexec.exe | C:\ADRAP\Public\Schema\EngagementManifest.xsd | xml | |
MD5:— | SHA256:— | |||