| File name: | inSSIDer4-installer.msi |
| Full analysis: | https://app.any.run/tasks/0b6dc617-a392-4a91-a53c-013e4360b5f6 |
| Verdict: | Malicious activity |
| Analysis date: | April 26, 2019, 14:29:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: inSSIDer 4, Author: MetaGeek, LLC, Keywords: Installer, Comments: This installer database contains the logic and data required to install inSSIDer 4., Template: Intel;1033, Revision Number: {37393271-4317-4FA1-A875-A5B7DEA3213D}, Create Time/Date: Mon Jan 19 16:57:28 2015, Last Saved Time/Date: Mon Jan 19 16:57:28 2015, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.6.3303.0), Security: 2 |
| MD5: | F0571E61BFE30431316E3CE7E3070088 |
| SHA1: | D9C560AE5690C266D85CCBC77F57B634FA713907 |
| SHA256: | 936647BA02002DE351CC0DEEF7085520C50CB00F9B17545E2893921E1E237349 |
| SSDEEP: | 98304:4CAnlEjjNSfEYKZ/bXo3XVoaCDuH/zCwv4hTq/rjJzjN9KNNmn96aocAHPUxacMe:4Dl6NclK+3XVoaCVJQjpN9Ym96ao4acK |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | inSSIDer 4 |
| Author: | MetaGeek, LLC |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install inSSIDer 4. |
| Template: | Intel;1033 |
| RevisionNumber: | {37393271-4317-4FA1-A875-A5B7DEA3213D} |
| CreateDate: | 2015:01:19 16:57:28 |
| ModifyDate: | 2015:01:19 16:57:28 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML (3.6.3303.0) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2428 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2992 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\inSSIDer4-installer.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3012 | "C:\Program Files\MetaGeek\inSSIDer 4\inSSIDer4.exe" | C:\Program Files\MetaGeek\inSSIDer 4\inSSIDer4.exe | explorer.exe | ||||||||||||
User: admin Company: MetaGeek, LLC Integrity Level: MEDIUM Description: inSSIDer Exit code: 0 Version: 4.2.0.12 Modules
| |||||||||||||||
| 3212 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3416 | C:\Windows\system32\MsiExec.exe -Embedding A45F5E85DC0E6917513CDC818927D06E C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3480 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000398" "00000574" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2428) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000BE65D57E3CFCD4017C09000048070000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2428) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000BE65D57E3CFCD4017C09000048070000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2428) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (2428) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000003CC5157F3CFCD4017C09000048070000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2428) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000009627187F3CFCD4017C09000038010000E80300000100000000000000000000002446EB1E15FC004DACC2871293B735B60000000000000000 | |||
| (PID) Process: | (3212) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000FEB0217F3CFCD4018C0C000080090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3212) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000FEB0217F3CFCD4018C0C0000280B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3212) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000FEB0217F3CFCD4018C0C0000100A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3212) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000FEB0217F3CFCD4018C0C00009C0B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3212) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000000CD8287F3CFCD4018C0C000080090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2428 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2428 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{1eeb4624-fc15-4d00-acc2-871293b735b6}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3480 | DrvInst.exe | C:\Windows\INF\setupapi.ev1 | binary | |
MD5:— | SHA256:— | |||
| 3480 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 3480 | DrvInst.exe | C:\Windows\INF\setupapi.dev.log | ini | |
MD5:— | SHA256:— | |||
| 2428 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2428 | msiexec.exe | C:\Windows\Installer\10eca4.msi | — | |
MD5:— | SHA256:— | |||
| 2428 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFA39E14F422904F67.TMP | — | |
MD5:— | SHA256:— | |||
| 2992 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIB0C4.tmp | executable | |
MD5:28A9771DEF2F62764786E951DE8AB6C1 | SHA256:5C165E5EAD82EA06047AD5585EFB40E439A6472346033C5528C1F148804328CB | |||
| 2428 | msiexec.exe | C:\Windows\Installer\10eca5.ipi | binary | |
MD5:— | SHA256:— | |||
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| malicious |
Process | Message |
|---|---|
inSSIDer4.exe | inSSIDer4.exe Error: 0 : |
inSSIDer4.exe | The settings property 'lTimerDuration' was not found.
|
inSSIDer4.exe | inSSIDer4.exe Information: 0 : |
inSSIDer4.exe | MetricsCollection is enabled on startup? False
|
inSSIDer4.exe | inSSIDer4.exe Error: 0 : |
inSSIDer4.exe | The settings property '_companyUrl' was not found.
|
inSSIDer4.exe | The settings property '_enableNetworkAliasing' was not found.
|
inSSIDer4.exe | The settings property '_enableNetworkAliasing' was not found.
|
inSSIDer4.exe | inSSIDer4.exe Error: 0 : |
inSSIDer4.exe | The settings property '_enableNetworkAliasing' was not found.
|