File name:

SkypeMeetingsApp.msi

Full analysis: https://app.any.run/tasks/1cfdf67d-5013-4569-96da-32183662baed
Verdict: Malicious activity
Analysis date: May 11, 2020, 10:24:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Skype Meetings App, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Skype Meetings App., Template: Intel;0, Revision Number: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}, Create Time/Date: Sat Aug 3 06:00:26 2019, Last Saved Time/Date: Sat Aug 3 06:00:26 2019, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

2401C281F6798633B66B2A4A14937354

SHA1:

632C80EA6699C5A6A4D6247182DAA92A3BF60913

SHA256:

73FDFB85B80B81C87E78580DC5B46A73C73F7907F8E6CFF0886DCB6493365255

SSDEEP:

393216:dkRzrZlCLVu8BLhwd0fvt1u3LVazAOGR:dk3lCLVu8z5vvA5OAOw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Skype Meetings App.exe (PID: 1492)
      • opera.exe (PID: 4064)
    • Application was dropped or rewritten from another process

      • Skype Meetings App.exe (PID: 1492)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • Skype Meetings App.exe (PID: 1492)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 376)
    • Manual execution by user

      • iexplore.exe (PID: 2160)
      • opera.exe (PID: 4064)
    • Changes internet zones settings

      • iexplore.exe (PID: 2160)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2160)
      • iexplore.exe (PID: 3836)
    • Application launched itself

      • iexplore.exe (PID: 2160)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3836)
    • Dropped object may contain Bitcoin addresses

      • Skype Meetings App.exe (PID: 1492)
    • Creates files in the user directory

      • opera.exe (PID: 4064)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2160)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2160)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Skype Meetings App
Author: Microsoft Corporation
Keywords: Installer
Comments: This installer database contains the logic and data required to install Skype Meetings App.
Template: Intel;0
RevisionNumber: {C6C0F413-901C-42A8-A7F1-D03BD40F9B12}
CreateDate: 2019:08:03 05:00:26
ModifyDate: 2019:08:03 05:00:26
Pages: 300
Words: 10
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe skype meetings app.exe iexplore.exe iexplore.exe no specs opera.exe

Process information

PID
CMD
Path
Indicators
Parent process
376C:\Windows\system32\MsiExec.exe -Embedding 46DDC0E985E1DC51FCC77D547191248FC:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1352"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\SkypeMeetingsApp.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1492"C:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe" -autostartC:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\Skype Meetings App.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Skype Meetings App
Exit code:
0
Version:
16.2.0.511
Modules
Images
c:\users\admin\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\skype meetings app.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
2160"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3836"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2160 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
4064"C:\Program Files\Opera\opera.exe" C:\Program Files\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\rpcrt4.dll
Total events
4 617
Read events
483
Write events
2 815
Delete events
1 319

Modification events

(PID) Process:(1352) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(376) MsiExec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\SkypeForBusinessPlugin\16.2
Operation:writeName:LAUNCHSTATUS
Value:
1
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1492) Skype Meetings App.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2160) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
2325501620
(PID) Process:(2160) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30812030
Executable files
0
Suspicious files
1 241
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
1492Skype Meetings App.exeC:\Users\admin\AppData\Local\Temp\502b78874477486695e9334dfbf03e4a.db.session-journal
MD5:
SHA256:
1492Skype Meetings App.exeC:\Users\admin\AppData\Local\Temp\502b78874477486695e9334dfbf03e4a.db-journal
MD5:
SHA256:
4064opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\oprEC33.tmp
MD5:
SHA256:
4064opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\oprEC63.tmp
MD5:
SHA256:
2160iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
4064opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00001.tmp
MD5:
SHA256:
4064opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\EPTD58ZU795POB9B4U3F.temp
MD5:
SHA256:
1492Skype Meetings App.exeC:\Users\admin\AppData\Local\Temp\502b78874477486695e9334dfbf03e4a.db.sessionsqlite
MD5:
SHA256:
1492Skype Meetings App.exeC:\Users\admin\AppData\Local\Microsoft\SkypeForBusinessPlugin\Tracing\ShellApp_2020-05-11_10-25-04.logtext
MD5:
SHA256:
1492Skype Meetings App.exeC:\Users\admin\AppData\Local\Temp\502b78874477486695e9334dfbf03e4a.dbsqlite
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
8
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4064
opera.exe
GET
200
93.184.220.29:80
http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
564 b
whitelisted
2160
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
376
MsiExec.exe
52.114.74.21:443
meet.skype.com
Microsoft Corporation
NL
unknown
1492
Skype Meetings App.exe
52.114.132.22:443
mobile.pipe.aria.microsoft.com
Microsoft Corporation
US
whitelisted
4064
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
93.184.220.29:80
crl4.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
4064
opera.exe
185.26.182.93:443
certs.opera.com
Opera Software AS
whitelisted
2160
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
meet.skype.com
  • 52.114.74.21
unknown
mobile.pipe.aria.microsoft.com
  • 52.114.132.22
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
certs.opera.com
  • 185.26.182.94
  • 185.26.182.93
whitelisted
crl4.digicert.com
  • 93.184.220.29
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
Process
Message
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:04.637, TL_INFO, <no file info>, Other, telemetryId:0
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:05.684, TL_INFO, <no file info>, Other, Sending App Start Event for JLVersion unknown
Skype Meetings App.exe
1492, 1296, 2020-05-11 11:25:05.731, TL_INFO, <no file info>, Other, Waiting to accept the connections from client
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:05.731, TL_ERROR, <no file info>, Other, Unable to open the key for allowed domains
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:05.731, TL_INFO, <no file info>, Other, Setting user agent to "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) SfBShell/16.2.0.511"
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:05.731, TL_INFO, <no file info>, Other, Autostart, start new thread and wait for websocket
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:05.731, TL_INFO, <no file info>, Other, MSHTML version: 11.0.9600.17842
Skype Meetings App.exe
1492, 3016, 2020-05-11 11:25:21.731, TL_ERROR, <no file info>, Other, Wait timeout at main thread