File name:

SkypeMeetingsApp.msi

Full analysis: https://app.any.run/tasks/1776f4a4-aa12-498e-8287-03222023ee7b
Verdict: Malicious activity
Analysis date: December 15, 2021, 15:49:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Skype Meetings App, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Skype Meetings App., Template: Intel;0, Revision Number: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}, Create Time/Date: Sat Aug 3 06:00:26 2019, Last Saved Time/Date: Sat Aug 3 06:00:26 2019, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

2401C281F6798633B66B2A4A14937354

SHA1:

632C80EA6699C5A6A4D6247182DAA92A3BF60913

SHA256:

73FDFB85B80B81C87E78580DC5B46A73C73F7907F8E6CFF0886DCB6493365255

SSDEEP:

393216:dkRzrZlCLVu8BLhwd0fvt1u3LVazAOGR:dk3lCLVu8z5vvA5OAOw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 4088)
      • Skype Meetings App.exe (PID: 2908)
    • Application was dropped or rewritten from another process

      • Skype Meetings App.exe (PID: 2908)
  • SUSPICIOUS

    • Executed as Windows Service

      • msiexec.exe (PID: 1316)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
    • Application launched itself

      • msiexec.exe (PID: 1316)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 1316)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1316)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 1316)
    • Drops a file with a compile date too recent

      • msiexec.exe (PID: 1316)
    • Creates files in the user directory

      • msiexec.exe (PID: 1316)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 1316)
    • Changes default file association

      • msiexec.exe (PID: 1316)
    • Checks supported languages

      • Skype Meetings App.exe (PID: 2908)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1316)
    • Reads the computer name

      • Skype Meetings App.exe (PID: 2908)
  • INFO

    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
      • Skype Meetings App.exe (PID: 2908)
    • Checks supported languages

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
      • MsiExec.exe (PID: 4088)
    • Reads the computer name

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
      • MsiExec.exe (PID: 4088)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3208)
      • msiexec.exe (PID: 1316)
      • Skype Meetings App.exe (PID: 2908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: Read-only recommended
Software: Windows Installer XML Toolset (3.11.1.2318)
Words: 10
Pages: 300
ModifyDate: 2019:08:03 05:00:26
CreateDate: 2019:08:03 05:00:26
RevisionNumber: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}
Template: Intel;0
Comments: This installer database contains the logic and data required to install Skype Meetings App.
Keywords: Installer
Author: Microsoft Corporation
Subject: Skype Meetings App
Title: Installation Database
CodePage: Windows Latin 1 (Western European)
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start msiexec.exe no specs msiexec.exe msiexec.exe skype meetings app.exe

Process information

PID
CMD
Path
Indicators
Parent process
1316C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2908"C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe" -autostartC:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Skype Meetings App
Exit code:
0
Version:
16.2.0.511
Modules
Images
c:\users\admin\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\skype meetings app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
3208"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\SkypeMeetingsApp.msi"C:\Windows\System32\msiexec.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4088C:\Windows\system32\MsiExec.exe -Embedding 3876718E74E129D0C12EA43385812427C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
12 767
Read events
12 372
Write events
387
Delete events
8

Modification events

(PID) Process:(3208) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1316) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\194a8e.ipi
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\194a8f.rbs
Value:
30929355
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\194a8f.rbsLow
Value:
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\09DAC598233E9F74CBBD77620BB2AE5D
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B292FA1EE979F09449473FE50BE44675
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\PluginHost.exe
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B9CC14FF144022F4283B53686131CEE9
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX.dll
(PID) Process:(1316) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\D09D297D2C5539849AD357A3E3596DF3
Operation:writeName:74E9D1CB72981AA48A197736CB42577B
Value:
Executable files
87
Suspicious files
703
Text files
3
Unknown types
6

Dropped files

PID
Process
Filename
Type
1316msiexec.exeC:\Windows\Installer\194a8c.msi
MD5:
SHA256:
1316msiexec.exeC:\Windows\Installer\194a8e.ipibinary
MD5:
SHA256:
1316msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFDC021923132EE1B2.TMPgmc
MD5:
SHA256:
1316msiexec.exeC:\Windows\Installer\MSI6693.tmpbinary
MD5:
SHA256:
1316msiexec.exeC:\Windows\Installer\MSI4CC0.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
1316msiexec.exeC:\Windows\Installer\MSI4C61.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
1316msiexec.exeC:\Windows\Installer\MSI4CB0.tmpexecutable
MD5:E4ADC08E8BB63B84431B1E914E05D53D
SHA256:280C1AC6326078393A389F122A5EED88C1A29E33E787A2CC0BC9BEB04F43E90F
1316msiexec.exeC:\Windows\Installer\MSI66E2.tmpexecutable
MD5:D773D9BD091E712DF7560F576DA53DE8
SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7
1316msiexec.exeC:\Windows\Installer\MSI67AE.tmpexecutable
MD5:D773D9BD091E712DF7560F576DA53DE8
SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7
1316msiexec.exeC:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F
SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2908
Skype Meetings App.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertGlobalRootG2.crl
US
der
877 b
whitelisted
2908
Skype Meetings App.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9e0f48d7278aa4a1
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4088
MsiExec.exe
52.114.76.17:443
meet.skype.com
Microsoft Corporation
IE
unknown
2908
Skype Meetings App.exe
52.178.17.3:443
mobile.pipe.aria.microsoft.com
Microsoft Corporation
NL
suspicious
2908
Skype Meetings App.exe
93.184.221.240:80
ctldl.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2908
Skype Meetings App.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
meet.skype.com
  • 52.114.76.17
unknown
mobile.pipe.aria.microsoft.com
  • 52.178.17.3
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
Process
Message
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:26.165, TL_INFO, <no file info>, Other, telemetryId:0
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:27.212, TL_INFO, <no file info>, Other, Sending App Start Event for JLVersion unknown
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:27.275, TL_INFO, <no file info>, Other, MSHTML version: 11.0.9600.19597
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:27.290, TL_INFO, <no file info>, Other, Setting user agent to "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) SfBShell/16.2.0.511"
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:27.290, TL_ERROR, <no file info>, Other, Unable to open the key for allowed domains
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:27.290, TL_INFO, <no file info>, Other, Autostart, start new thread and wait for websocket
Skype Meetings App.exe
2908, 3296, 2021-12-15 15:49:27.306, TL_INFO, <no file info>, Other, Waiting to accept the connections from client
Skype Meetings App.exe
2908, 3920, 2021-12-15 15:49:43.290, TL_ERROR, <no file info>, Other, Wait timeout at main thread