| File name: | SkypeMeetingsApp.msi |
| Full analysis: | https://app.any.run/tasks/1776f4a4-aa12-498e-8287-03222023ee7b |
| Verdict: | Malicious activity |
| Analysis date: | December 15, 2021, 15:49:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Skype Meetings App, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Skype Meetings App., Template: Intel;0, Revision Number: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}, Create Time/Date: Sat Aug 3 06:00:26 2019, Last Saved Time/Date: Sat Aug 3 06:00:26 2019, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2 |
| MD5: | 2401C281F6798633B66B2A4A14937354 |
| SHA1: | 632C80EA6699C5A6A4D6247182DAA92A3BF60913 |
| SHA256: | 73FDFB85B80B81C87E78580DC5B46A73C73F7907F8E6CFF0886DCB6493365255 |
| SSDEEP: | 393216:dkRzrZlCLVu8BLhwd0fvt1u3LVazAOGR:dk3lCLVu8z5vvA5OAOw |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| Security: | Read-only recommended |
|---|---|
| Software: | Windows Installer XML Toolset (3.11.1.2318) |
| Words: | 10 |
| Pages: | 300 |
| ModifyDate: | 2019:08:03 05:00:26 |
| CreateDate: | 2019:08:03 05:00:26 |
| RevisionNumber: | {C6C0F413-901C-42A8-A7F1-D03BD40F9B12} |
| Template: | Intel;0 |
| Comments: | This installer database contains the logic and data required to install Skype Meetings App. |
| Keywords: | Installer |
| Author: | Microsoft Corporation |
| Subject: | Skype Meetings App |
| Title: | Installation Database |
| CodePage: | Windows Latin 1 (Western European) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1316 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2908 | "C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe" -autostart | C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Skype Meetings App Exit code: 0 Version: 16.2.0.511 Modules
| |||||||||||||||
| 3208 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\SkypeMeetingsApp.msi" | C:\Windows\System32\msiexec.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4088 | C:\Windows\system32\MsiExec.exe -Embedding 3876718E74E129D0C12EA43385812427 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3208) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress |
| Operation: | write | Name: | (default) |
Value: C:\Windows\Installer\194a8e.ipi | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Config.Msi\ |
Value: | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | write | Name: | C:\Config.Msi\194a8f.rbs |
Value: 30929355 | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | write | Name: | C:\Config.Msi\194a8f.rbsLow |
Value: | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\09DAC598233E9F74CBBD77620BB2AE5D |
| Operation: | write | Name: | 74E9D1CB72981AA48A197736CB42577B |
Value: | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B292FA1EE979F09449473FE50BE44675 |
| Operation: | write | Name: | 74E9D1CB72981AA48A197736CB42577B |
Value: C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\PluginHost.exe | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B9CC14FF144022F4283B53686131CEE9 |
| Operation: | write | Name: | 74E9D1CB72981AA48A197736CB42577B |
Value: C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX.dll | |||
| (PID) Process: | (1316) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\D09D297D2C5539849AD357A3E3596DF3 |
| Operation: | write | Name: | 74E9D1CB72981AA48A197736CB42577B |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1316 | msiexec.exe | C:\Windows\Installer\194a8c.msi | — | |
MD5:— | SHA256:— | |||
| 1316 | msiexec.exe | C:\Windows\Installer\194a8e.ipi | binary | |
MD5:— | SHA256:— | |||
| 1316 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFDC021923132EE1B2.TMP | gmc | |
MD5:— | SHA256:— | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI6693.tmp | binary | |
MD5:— | SHA256:— | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI4CC0.tmp | executable | |
MD5:E4ADC08E8BB63B84431B1E914E05D53D | SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI4C61.tmp | executable | |
MD5:E4ADC08E8BB63B84431B1E914E05D53D | SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI4CB0.tmp | executable | |
MD5:E4ADC08E8BB63B84431B1E914E05D53D | SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI66E2.tmp | executable | |
MD5:D773D9BD091E712DF7560F576DA53DE8 | SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7 | |||
| 1316 | msiexec.exe | C:\Windows\Installer\MSI67AE.tmp | executable | |
MD5:D773D9BD091E712DF7560F576DA53DE8 | SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7 | |||
| 1316 | msiexec.exe | C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F | SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2908 | Skype Meetings App.exe | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/DigiCertGlobalRootG2.crl | US | der | 877 b | whitelisted |
2908 | Skype Meetings App.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9e0f48d7278aa4a1 | US | compressed | 4.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4088 | MsiExec.exe | 52.114.76.17:443 | meet.skype.com | Microsoft Corporation | IE | unknown |
2908 | Skype Meetings App.exe | 52.178.17.3:443 | mobile.pipe.aria.microsoft.com | Microsoft Corporation | NL | suspicious |
2908 | Skype Meetings App.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2908 | Skype Meetings App.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
meet.skype.com |
| unknown |
mobile.pipe.aria.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl3.digicert.com |
| whitelisted |
Process | Message |
|---|---|
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:26.165, TL_INFO, <no file info>, Other, telemetryId:0 |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:27.212, TL_INFO, <no file info>, Other, Sending App Start Event for JLVersion unknown |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:27.275, TL_INFO, <no file info>, Other, MSHTML version: 11.0.9600.19597 |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:27.290, TL_INFO, <no file info>, Other, Setting user agent to "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) SfBShell/16.2.0.511" |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:27.290, TL_ERROR, <no file info>, Other, Unable to open the key for allowed domains |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:27.290, TL_INFO, <no file info>, Other, Autostart, start new thread and wait for websocket |
Skype Meetings App.exe | 2908, 3296, 2021-12-15 15:49:27.306, TL_INFO, <no file info>, Other, Waiting to accept the connections from client |
Skype Meetings App.exe | 2908, 3920, 2021-12-15 15:49:43.290, TL_ERROR, <no file info>, Other, Wait timeout at main thread
|