| File name: | Wireless_AutoSwitch_XPV.1.5.7.4.msi |
| Full analysis: | https://app.any.run/tasks/4ae87b0a-94fd-4c70-a272-948278f249bb |
| Verdict: | Malicious activity |
| Analysis date: | August 08, 2023, 13:30:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Keywords: Installer,MSI,Database, Code page: 1252, Name of Creating Application: MakeMsi version 22.121, a free tool by Dennis Bareis (http://dennisbareis.com/makemsi.htm), Security: 0, Revision Number: {3C5F3653-7418-4BB7-88F4-B05F964C129C}, Template: Intel;1033, Number of Pages: 110, Title: Wireless AutoSwitch XPV, Subject: 1.5.7.4 (created Tue Jan 24 2023 at 11:41:53am), Number of Words: 2, Create Time/Date: Tue Jan 24 16:42:01 2023, Total Editing Time: Tue Jan 24 16:42:01 2023, Comments: Wireless AutoSwitch XPV, Author: Sase Sham, Inc., Last Saved By: Sase Sham, Inc. |
| MD5: | 36C443162D63A82070AA3E3B2C5BF7B5 |
| SHA1: | 0D79047D6D530EDF6A0E70AA8754612E640D85BF |
| SHA256: | 8C841EB4C765E8BD71CEAFFCD618A275B5DC3FCB48C65DDCC77CFE9BC73C9BB3 |
| SSDEEP: | 49152:J/PXtY5Akhd0LVSUl3zaYQNQiJx4YD6pdfFl7YTAiWl:ZtY5Ae0hS0aOgxVD2fFl7X |
| .msi | | | Microsoft Windows Installer (79.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9) |
| .msp | | | Windows Installer Patch (7.4) |
| .doc | | | Microsoft Word document (old ver.) (2.7) |
| .msi | | | Microsoft Installer (100) |
| LastModifiedBy: | Sase Sham, Inc. |
|---|---|
| Author: | Sase Sham, Inc. |
| Comments: | Wireless AutoSwitch XPV |
| TotalEditTime: | 2023:01:24 16:42:01 |
| CreateDate: | 2023:01:24 16:42:01 |
| Words: | 2 |
| Subject: | 1.5.7.4 (created Tue Jan 24 2023 at 11:41:53am) |
| Title: | Wireless AutoSwitch XPV |
| Pages: | 110 |
| Template: | Intel;1033 |
| RevisionNumber: | {3C5F3653-7418-4BB7-88F4-B05F964C129C} |
| Security: | None |
| Software: | MakeMsi version 22.121, a free tool by Dennis Bareis (http://dennisbareis.com/makemsi.htm) |
| CodePage: | Windows Latin 1 (Western European) |
| Keywords: | Installer,MSI,Database |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1000 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1872 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Wireless_AutoSwitch_XPV.1.5.7.4.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3200 | "C:\Program Files\Wireless AutoSwitch\WrlsAutoSW.exs" | C:\Program Files\Wireless AutoSwitch\WrlsAutoSW.exs | — | services.exe | |||||||||||
User: SYSTEM Company: Sase Sham, Inc. Integrity Level: SYSTEM Description: WrlsAutoSW XPV Exit code: 0 Version: 1.5.7.4 Modules
| |||||||||||||||
| 3572 | "C:\Program Files\Wireless AutoSwitch\WrlsAutoSW Toggle.exe" | C:\Program Files\Wireless AutoSwitch\WrlsAutoSW Toggle.exe | — | explorer.exe | |||||||||||
User: admin Company: Sase Sham, Inc. Integrity Level: MEDIUM Description: WrlsAutoSW Toggle Exit code: 0 Version: 1.3.2 Modules
| |||||||||||||||
| 3736 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Wireless AutoSwitch\IsLicense30.dll" | C:\Windows\System32\regsvr32.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1040) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9E28AE6A-1FA4-494D-83E9-35F4866C35E3}\{554C5F18-D668-4AC6-AE2B-7CD6C3833FB7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1040) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9E28AE6A-1FA4-494D-83E9-35F4866C35E3} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1040) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{8D86A374-2CEB-4BD0-BC9F-E9C5646581D1} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 72 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1000) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1000 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 1000 | msiexec.exe | C:\Program Files\Wireless AutoSwitch\WrlsAutoSWLog.txt | — | |
MD5:— | SHA256:— | |||
| 1000 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{ea91580e-0fa8-49f5-b329-82de949d7af5}_OnDiskSnapshotProp | binary | |
MD5:57C4739F1BE21496E70D57C304518B68 | SHA256:38612E569AA9F3F68764035972765EC1F2C2F918415D3634E8259D5B987D1CCF | |||
| 1000 | msiexec.exe | C:\Windows\Installer\fd141.msi | executable | |
MD5:36C443162D63A82070AA3E3B2C5BF7B5 | SHA256:8C841EB4C765E8BD71CEAFFCD618A275B5DC3FCB48C65DDCC77CFE9BC73C9BB3 | |||
| 1000 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:57C4739F1BE21496E70D57C304518B68 | SHA256:38612E569AA9F3F68764035972765EC1F2C2F918415D3634E8259D5B987D1CCF | |||
| 1000 | msiexec.exe | C:\Program Files\Wireless AutoSwitch\WrlsOn.exe | executable | |
MD5:27E6162FD067D4945465E09D0F380832 | SHA256:244D710AB3F450E723EDF6CA528C61C5C3542BD02EAADAF85E01334387BB2D7E | |||
| 1000 | msiexec.exe | C:\Program Files\Wireless AutoSwitch\wbdLA44I.dll | executable | |
MD5:161CF63E4C819B1F111D8A1A067BA397 | SHA256:B127E2920C64B5BFA855D426DA6AB42F67EE2154DB0294EB3C50496FED3D184D | |||
| 1000 | msiexec.exe | C:\Windows\Installer\MSID410.tmp | binary | |
MD5:A53FFF4513C5499D03346F1405084232 | SHA256:4083E65573A668558C5AF812C13112BB6169E4FCC4AC6839096A185CBD8460B8 | |||
| 1000 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF25815A9BC682AE9E.TMP | binary | |
MD5:E04BE6D40CFDD12ACC2FCBE1ABE55DBC | SHA256:1C997B3767D910E493E6544E2445589B7745112E1215059A5D2267D4E0CCF9E0 | |||
| 1000 | msiexec.exe | C:\Program Files\Wireless AutoSwitch\wrlsswV64.exe | executable | |
MD5:CDBAE64001AC9838AF57792D4065A00C | SHA256:0EB71D235CD74CB66171FB0C8736D5BF76A5FDCC84A6542C411F2FD70D2132F4 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |