File name:

MinecraftInstaller.msi

Full analysis: https://app.any.run/tasks/b68ab187-5a20-496a-91b1-a7c17a3a73a4
Verdict: Malicious activity
Analysis date: January 16, 2024, 17:48:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Minecraft Launcher, Author: Mojang, Keywords: Installer, Comments: This installer database contains the logic and data required to install Minecraft Launcher., Template: Intel;1033, Revision Number: {879CAD28-9A81-498B-B7E9-F0255303B8F1}, Create Time/Date: Mon Jun 5 21:44:34 2023, Last Saved Time/Date: Mon Jun 5 21:44:34 2023, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.9.1006.0), Security: 2
MD5:

699FD0CF59C643687883EBBC6512751A

SHA1:

F4CC33359BA26FCD7A3BAC9D283DD614AAEE6785

SHA256:

70119C7DF5E2EE1E553C2CFAD8CF52D3928F22BD3ACBC24AD6069F2DAF068E43

SSDEEP:

24576:XnAStBpHh9unSEpvnRDcM4ophpNDvaXigzNilqT5c+Bt8e7jsMNDkBnE0WTM9Aug:XnA+D+lJcM9h37gzNilqT5rFnDk+0Wv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 120)
      • msiexec.exe (PID: 1356)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 2420)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 1356)
    • Reads the Internet Settings

      • MinecraftLauncher.exe (PID: 148)
      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 2376)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 876)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 3816)
      • msiexec.exe (PID: 2072)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 188)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2072)
      • msiexec.exe (PID: 1560)
      • msiexec.exe (PID: 2440)
      • MinecraftLauncher.exe (PID: 148)
      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 2376)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 876)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 3816)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 188)
    • Reads the computer name

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2072)
      • msiexec.exe (PID: 1560)
      • msiexec.exe (PID: 2440)
      • MinecraftLauncher.exe (PID: 148)
      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 2376)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 876)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3816)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 188)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2072)
      • msiexec.exe (PID: 1560)
      • msiexec.exe (PID: 2440)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 120)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 120)
      • msiexec.exe (PID: 1356)
    • Application launched itself

      • msiexec.exe (PID: 1356)
      • firefox.exe (PID: 3064)
      • firefox.exe (PID: 2844)
      • chrome.exe (PID: 2100)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1356)
    • Reads product name

      • MinecraftLauncher.exe (PID: 148)
      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 2376)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 876)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3816)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 188)
    • Manual execution by a user

      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 2376)
      • firefox.exe (PID: 3064)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 876)
      • chrome.exe (PID: 2100)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 3816)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 188)
    • Creates files in the program directory

      • MinecraftLauncher.exe (PID: 148)
    • Reads Environment values

      • MinecraftLauncher.exe (PID: 2404)
      • MinecraftLauncher.exe (PID: 148)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 2688)
      • MinecraftLauncher.exe (PID: 2260)
      • MinecraftLauncher.exe (PID: 2728)
      • MinecraftLauncher.exe (PID: 1956)
      • MinecraftLauncher.exe (PID: 2540)
      • MinecraftLauncher.exe (PID: 2548)
      • MinecraftLauncher.exe (PID: 2376)
      • MinecraftLauncher.exe (PID: 980)
      • MinecraftLauncher.exe (PID: 876)
      • MinecraftLauncher.exe (PID: 2828)
      • MinecraftLauncher.exe (PID: 3636)
      • MinecraftLauncher.exe (PID: 3504)
      • MinecraftLauncher.exe (PID: 4080)
      • MinecraftLauncher.exe (PID: 3816)
      • MinecraftLauncher.exe (PID: 3808)
      • MinecraftLauncher.exe (PID: 3300)
      • MinecraftLauncher.exe (PID: 3356)
      • MinecraftLauncher.exe (PID: 1784)
      • MinecraftLauncher.exe (PID: 696)
      • MinecraftLauncher.exe (PID: 188)
    • Creates files or folders in the user directory

      • MinecraftLauncher.exe (PID: 148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (95.3)
.doc | Microsoft Word document (old ver.) (3.2)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Minecraft Launcher
Author: Mojang
Keywords: Installer
Comments: This installer database contains the logic and data required to install Minecraft Launcher.
Template: Intel;1033
RevisionNumber: {879CAD28-9A81-498B-B7E9-F0255303B8F1}
CreateDate: 2023:06:05 20:44:34
ModifyDate: 2023:06:05 20:44:34
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.9.1006.0)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
87
Monitored processes
52
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs minecraftlauncher.exe minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs chrome.exe chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs minecraftlauncher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\MinecraftInstaller.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
148"C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe" C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe
msiexec.exe
User:
admin
Company:
Mojang
Integrity Level:
MEDIUM
Description:
Minecraft Launcher
Exit code:
0
Version:
1.0.1.0
Modules
Images
c:\program files\minecraft launcher\minecraftlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
188"C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe" C:\Program Files\Minecraft Launcher\MinecraftLauncher.exeexplorer.exe
User:
admin
Company:
Mojang
Integrity Level:
MEDIUM
Description:
Minecraft Launcher
Exit code:
1
Version:
1.0.1.0
Modules
Images
c:\program files\minecraft launcher\minecraftlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
240"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1608 --field-trial-handle=1176,i,11703916391904185295,5883146582127409740,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
696"C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe" C:\Program Files\Minecraft Launcher\MinecraftLauncher.exeexplorer.exe
User:
admin
Company:
Mojang
Integrity Level:
MEDIUM
Description:
Minecraft Launcher
Exit code:
1
Version:
1.0.1.0
Modules
Images
c:\program files\minecraft launcher\minecraftlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
876"C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe" C:\Program Files\Minecraft Launcher\MinecraftLauncher.exeexplorer.exe
User:
admin
Company:
Mojang
Integrity Level:
MEDIUM
Description:
Minecraft Launcher
Exit code:
1
Version:
1.0.1.0
Modules
Images
c:\program files\minecraft launcher\minecraftlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
980"C:\Program Files\Minecraft Launcher\MinecraftLauncher.exe" C:\Program Files\Minecraft Launcher\MinecraftLauncher.exeexplorer.exe
User:
admin
Company:
Mojang
Integrity Level:
MEDIUM
Description:
Minecraft Launcher
Exit code:
1
Version:
1.0.1.0
Modules
Images
c:\program files\minecraft launcher\minecraftlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1092"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3760 --field-trial-handle=1176,i,11703916391904185295,5883146582127409740,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1356C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1560C:\Windows\system32\MsiExec.exe -Embedding D9B759542285D00FAAC21729814DD7C7C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
23 572
Read events
23 438
Write events
124
Delete events
10

Modification events

(PID) Process:(120) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
73
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
Executable files
8
Suspicious files
117
Text files
42
Unknown types
2

Dropped files

PID
Process
Filename
Type
1356msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
120msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI1827.tmpexecutable
MD5:48EAF9D4CCF75BC06BBC5D33E78B7FFF
SHA256:9AE2608EDD49D2C319BB7BCFC24550BD9FB88B2F100FE90222A6FC55CA43C589
1356msiexec.exeC:\Windows\Installer\MSI3FD4.tmpexecutable
MD5:785EE78478D43F00870E91FA96B94646
SHA256:B8665993CD5F7224E35C122A5C1965F8C4F2B4D9D41F75160B515E66F9AFFC53
1356msiexec.exeC:\Windows\Installer\MSI4033.tmpexecutable
MD5:785EE78478D43F00870E91FA96B94646
SHA256:B8665993CD5F7224E35C122A5C1965F8C4F2B4D9D41F75160B515E66F9AFFC53
1356msiexec.exeC:\Users\Public\Desktop\Minecraft Launcher.lnkbinary
MD5:220B8E4B42640B2AB7F4AE8AA3E6B8E4
SHA256:D44C1E987FD15F45987D89F41ED7A08A0B12AD9097B2A7D11CAD2A21AD53F2FA
1356msiexec.exeC:\Windows\Installer\MSI3FC4.tmpbinary
MD5:1419439595E7454CDB43802DB4820D21
SHA256:06501CFCB5AFEEBA9E4F5AA93A8C09EE2C0815D316A412A7B2F0F20B55FBDCF0
1356msiexec.exeC:\Windows\Installer\MSI4100.tmpexecutable
MD5:785EE78478D43F00870E91FA96B94646
SHA256:B8665993CD5F7224E35C122A5C1965F8C4F2B4D9D41F75160B515E66F9AFFC53
1356msiexec.exeC:\Windows\Installer\{A26EF561-5945-46FD-8094-FA34E44D460F}\minecraft.icoimage
MD5:51BFEB730D48570581188274460D52F7
SHA256:97509B2D85F3C2BB99147EBDBA041F73E4220C9E5F11FCB94B7E665138258E83
1356msiexec.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft Launcher\Minecraft Launcher.lnkbinary
MD5:383B7FCB1F4CE31A5667D68352B59A64
SHA256:C2D80370E4603AE49E816498FE26944A4CFDAC5C9F5A59DB0E43C8984FDB67AD
1356msiexec.exeC:\Program Files\Minecraft Launcher\MinecraftLauncher.exeexecutable
MD5:08F0A3740A8A79FB1237406F124BA18C
SHA256:4B01840FFA24B4834DD40D3E8F8F3AA51B80DB8086C7BB0AADE4379F28261BB6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
81
TCP/UDP connections
50
DNS requests
481
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
404
49.13.77.253:80
http://detectportal.firefox.com/canonical.html
unknown
xml
341 b
unknown
2844
firefox.exe
GET
49.13.77.253:443
https://49.13.77.253/complete/search?client=firefox&q=cornh
unknown
2844
firefox.exe
POST
404
49.13.77.253:443
https://49.13.77.253/spocs
unknown
xml
341 b
2844
firefox.exe
GET
404
49.13.77.253:443
https://49.13.77.253/v1/tiles
unknown
xml
341 b
2844
firefox.exe
GET
404
49.13.77.253:443
https://49.13.77.253/v4/threatListUpdates:fetch?$ct=application/x-protobuf&key=AIzaSyC7jsptDS3am4tPx4r3nxis7IMjBc5Dovo&$httpMethod=POST&$req=ChUKE25hdmNsaWVudC1hdXRvLWZmb3gaCggFEAEiAiACKAEaCggBEAEiAiACKAEaCggDEAEiAiACKAEaCggHEAEiAiACKAEaCggJEAEiAiACKAE=
unknown
xml
341 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
148
MinecraftLauncher.exe
49.13.77.253:443
redstone-launcher.mojang.com
Hetzner Online GmbH
DE
unknown
2844
firefox.exe
49.13.77.253:80
redstone-launcher.mojang.com
Hetzner Online GmbH
DE
unknown
2844
firefox.exe
49.13.77.253:443
redstone-launcher.mojang.com
Hetzner Online GmbH
DE
unknown
2060
chrome.exe
49.13.77.253:443
redstone-launcher.mojang.com
Hetzner Online GmbH
DE
unknown
2100
chrome.exe
239.255.255.250:1900
whitelisted
2100
chrome.exe
224.0.0.251:5353
unknown
2060
chrome.exe
49.13.77.253:80
redstone-launcher.mojang.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
redstone-launcher.mojang.com
  • 49.13.77.253
unknown
detectportal.firefox.com
  • 49.13.77.253
whitelisted
contile.services.mozilla.com
  • 49.13.77.253
whitelisted
spocs.getpocket.com
  • 49.13.77.253
shared
firefox.settings.services.mozilla.com
  • 49.13.77.253
whitelisted
safebrowsing.googleapis.com
  • 49.13.77.253
whitelisted
push.services.mozilla.com
  • 49.13.77.253
whitelisted
dns.msftncsi.com
  • 49.13.77.253
shared
contile-images.services.mozilla.com
  • 49.13.77.253
whitelisted
www.youtube.com
  • 49.13.77.253
whitelisted

Threats

No threats detected
No debug info