File name:

k.msi

Full analysis: https://app.any.run/tasks/770b3560-2532-4dfc-8e49-a13a1dbdcacb
Verdict: Malicious activity
Analysis date: July 23, 2021, 00:03:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Sushi Power, Author: Sushi Power Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Sushi Power., Template: Intel;1033, Revision Number: {A2207269-F264-4752-94F7-3F0BF04485FA}, Create Time/Date: Thu Jul 15 11:34:22 2021, Last Saved Time/Date: Thu Jul 15 11:34:22 2021, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.0.1528), Security: 2
MD5:

44A099740443D36B767B55875D36EA7D

SHA1:

0301F760D26B8FF3E7D443D5945D0C1F84ED1DD2

SHA256:

84BC754E7F2E69DD889B06EA0EC547C27A43131B7E32559CF2EC89C7C2DA8682

SSDEEP:

49152:Yqrn0/zk6zeDPqxLe1ChOJM92EDZZp5/++OZZe:7QzxS1ChOqYEDHm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SushiSetup.exe (PID: 3520)
      • SushisPower.exe (PID: 4040)
      • SushiSetup.exe (PID: 3684)
      • audacity.exe (PID: 3452)
    • Drops executable file immediately after starts

      • SushisPower.exe (PID: 4040)
    • Loads dropped or rewritten executable

      • audacity.exe (PID: 3452)
  • SUSPICIOUS

    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
      • SushisPower.tmp (PID: 2280)
    • Executed as Windows Service

      • msiexec.exe (PID: 3256)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
      • SushisPower.tmp (PID: 2280)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3256)
      • SushiSetup.exe (PID: 3684)
      • SushisPower.exe (PID: 4040)
      • SushisPower.tmp (PID: 2280)
    • Drops a file with a compile date too recent

      • msiexec.exe (PID: 3256)
    • Checks supported languages

      • SushiSetup.exe (PID: 3520)
      • cmd.exe (PID: 2504)
      • cmd.exe (PID: 1160)
      • cmd.exe (PID: 1920)
      • SushiSetup.exe (PID: 3684)
      • cmd.exe (PID: 3664)
      • SushisPower.exe (PID: 4040)
      • cmd.exe (PID: 1332)
      • SushisPower.tmp (PID: 2280)
      • cmd.exe (PID: 2920)
      • audacity.exe (PID: 3452)
    • Reads the computer name

      • SushiSetup.exe (PID: 3520)
      • SushiSetup.exe (PID: 3684)
      • SushisPower.tmp (PID: 2280)
      • audacity.exe (PID: 3452)
    • Starts CMD.EXE for commands execution

      • SushiSetup.exe (PID: 3520)
      • SushiSetup.exe (PID: 3684)
      • cmd.exe (PID: 1332)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 2504)
      • cmd.exe (PID: 1160)
      • cmd.exe (PID: 3664)
      • cmd.exe (PID: 1920)
    • Application launched itself

      • SushiSetup.exe (PID: 3520)
      • cmd.exe (PID: 1332)
    • Creates a directory in Program Files

      • SushiSetup.exe (PID: 3684)
      • SushisPower.tmp (PID: 2280)
    • Creates files in the program directory

      • SushiSetup.exe (PID: 3684)
    • Changes default file association

      • SushisPower.tmp (PID: 2280)
    • Drops a file that was compiled in debug mode

      • SushisPower.tmp (PID: 2280)
    • Creates files in the user directory

      • audacity.exe (PID: 3452)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
      • sc.exe (PID: 1240)
      • sc.exe (PID: 3816)
      • sc.exe (PID: 3924)
      • sc.exe (PID: 2104)
      • taskmgr.exe (PID: 2816)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
    • Checks supported languages

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
      • sc.exe (PID: 1240)
      • find.exe (PID: 1824)
      • sc.exe (PID: 3924)
      • find.exe (PID: 3132)
      • find.exe (PID: 3784)
      • sc.exe (PID: 3816)
      • sc.exe (PID: 2104)
      • find.exe (PID: 1152)
      • timeout.exe (PID: 1744)
      • taskmgr.exe (PID: 2816)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 2764)
      • msiexec.exe (PID: 3256)
    • Application was dropped or rewritten from another process

      • SushisPower.tmp (PID: 2280)
    • Creates a software uninstall entry

      • SushisPower.tmp (PID: 2280)
    • Manual execution by user

      • taskmgr.exe (PID: 2816)
    • Creates files in the program directory

      • SushisPower.tmp (PID: 2280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: Read-only recommended
Software: Windows Installer XML Toolset (3.11.0.1528)
Words: 10
Pages: 200
ModifyDate: 2021:07:15 10:34:22
CreateDate: 2021:07:15 10:34:22
RevisionNumber: {A2207269-F264-4752-94F7-3F0BF04485FA}
Template: Intel;1033
Comments: This installer database contains the logic and data required to install Sushi Power.
Keywords: Installer
Author: Sushi Power Inc.
Subject: Sushi Power
Title: Installation Database
CodePage: Windows Latin 1 (Western European)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
23
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start msiexec.exe no specs msiexec.exe sushisetup.exe no specs cmd.exe no specs sc.exe no specs find.exe no specs cmd.exe no specs find.exe no specs sc.exe no specs sushisetup.exe cmd.exe no specs sc.exe no specs cmd.exe no specs find.exe no specs find.exe no specs sc.exe no specs sushispower.exe cmd.exe no specs timeout.exe no specs sushispower.tmp cmd.exe no specs taskmgr.exe no specs audacity.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1152FIND /C "RUNNING"C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1160C:\Windows\system32\cmd.exe /c sc query npcap | FIND /C "RUNNING"C:\Windows\system32\cmd.exeSushiSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1240sc query NPF C:\Windows\system32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1332C:\Windows\system32\cmd.exe /d /c timeout 5 & cmd /d /c rd /s /q "C:\Users\admin\AppData\Local\SushiSetupmh"C:\Windows\system32\cmd.exeSushiSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1744timeout 5 C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1824FIND /C "RUNNING"C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\find.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1920C:\Windows\system32\cmd.exe /c sc query npcap | FIND /C "RUNNING"C:\Windows\system32\cmd.exeSushiSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2104sc query npcap C:\Windows\system32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2280"C:\Users\admin\AppData\Local\Temp\is-U7RBB.tmp\SushisPower.tmp" /SL5="$3014A,28665901,295936,C:\Program Files\SushiPowerehfSetup\SushisPower.exe" C:\Users\admin\AppData\Local\Temp\is-U7RBB.tmp\SushisPower.tmp
SushisPower.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-u7rbb.tmp\sushispower.tmp
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2504C:\Windows\system32\cmd.exe /c sc query NPF | FIND /C "RUNNING"C:\Windows\system32\cmd.exeSushiSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
9 913
Read events
9 798
Write events
97
Delete events
18

Modification events

(PID) Process:(2764) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B80C000080FC9E33567FD701
(PID) Process:(3256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
E93687DB4753E431C1FDC92C7C8CB01891AEEF14E227A9DF1C2CDB6A848F180F
(PID) Process:(3256) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\d5824.ipi
(PID) Process:(3256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(3256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\d5825.rbs
Value:
30900062
(PID) Process:(3256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\d5825.rbsLow
Value:
(PID) Process:(3256) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\23B46052A3278F0409708CF9791AD2CE
Operation:writeName:23B46052A3278F0409708CF9FB66D062
Value:
01:\Software\WixSharp\Used\
Executable files
30
Suspicious files
31
Text files
2 939
Unknown types
127

Dropped files

PID
Process
Filename
Type
3256msiexec.exeC:\Windows\Installer\d5823.msiexecutable
MD5:
SHA256:
3256msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF7890891FAA0D3E84.TMPgmc
MD5:
SHA256:
3256msiexec.exeC:\Windows\Installer\MSI59F8.tmpbinary
MD5:
SHA256:
3256msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF972F70BFCE6AB8F0.TMPgmc
MD5:
SHA256:
3256msiexec.exeC:\Config.Msi\d5825.rbsbinary
MD5:
SHA256:
3256msiexec.exeC:\Windows\Installer\SourceHash{25064B32-723A-40F8-9007-C89FBF660D26}binary
MD5:
SHA256:
3520SushiSetup.exeC:\Users\admin\AppData\Local\Temp\~DF336790C111CC5579.TMPbinary
MD5:
SHA256:
3684SushiSetup.exeC:\Program Files\SushiPowerehfSetup\SushisPower.exeexecutable
MD5:B0CE29D2DA93F8EFF5176E4749D369E8
SHA256:6A0CFED327B00CF8FEFEF4BD5C8BA85B5364F3E56345772410572F2D821CA14D
3256msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF646416309FE108D0.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
3256msiexec.exeC:\Users\admin\AppData\Local\SushiSetupmh\SushiSetup.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3684
SushiSetup.exe
104.18.25.117:443
mobileprogramservices.com
Cloudflare Inc
US
unknown

DNS requests

Domain
IP
Reputation
mobileprogramservices.com
  • 104.18.25.117
  • 104.18.24.117
unknown

Threats

No threats detected
No debug info