File name:

SSCERuntime-ENU.msi

Full analysis: https://app.any.run/tasks/5ce2a0ed-a42b-4759-8d4e-ff5086dd170a
Verdict: Malicious activity
Analysis date: December 04, 2024, 15:36:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft SQL Server Compact, Author: Microsoft Corporation, Keywords: Installer, MSI, Database, Intel, Comments: This installer database contains the logic and data required to install Microsoft SQL Server Compact 3.5 SP2 ENU., Template: Intel;1033, Revision Number: {84395861-2117-43CE-9029-6D1A73F6929A}, Create Time/Date: Fri Feb 12 03:19:10 2010, Last Saved Time/Date: Fri Feb 12 03:19:10 2010, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML v3.0.2921.0, Security: 2
MD5:

86AF6D36DFF214718DCD35D851249D3D

SHA1:

286A78FAAE68FCBA8FBA4EDCD9FA201DE1F25D12

SHA256:

99B5F0C1CC7FE40120A36FB760CC7C646EDEF5916695D6ECD8D41E8BBA9B1C60

SSDEEP:

49152:zfii8t59kIUvtcaLotZgA0fRHCUsmZ/Aus1e7J/VoNxvrIQ2pjEQpFV:zfii8t59QzotZp/oZCG9oNZIHV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6484)
      • msiexec.exe (PID: 6768)
      • TiWorker.exe (PID: 444)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6340)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6484)
      • msiexec.exe (PID: 6768)
      • TiWorker.exe (PID: 444)
    • Executable content was dropped or overwritten

      • TiWorker.exe (PID: 444)
  • INFO

    • Manages system restore points

      • SrTasks.exe (PID: 6132)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Microsoft SQL Server Compact
Author: Microsoft Corporation
Keywords: Installer, MSI, Database, Intel
Comments: This installer database contains the logic and data required to install Microsoft SQL Server Compact 3.5 SP2 ENU.
Template: Intel;1033
RevisionNumber: {84395861-2117-43CE-9029-6D1A73F6929A}
CreateDate: 2010:02:12 03:19:10
ModifyDate: 2010:02:12 03:19:10
Pages: 200
Words: 2
Software: Windows Installer XML v3.0.2921.0
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs tiworker.exe

Process information

PID
CMD
Path
Indicators
Parent process
444C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
3848C:\Windows\syswow64\MsiExec.exe -Embedding BC7ABA818DFD54EDB29CB3B1C6165FE7 E Global\MSI0000C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5240C:\Windows\syswow64\MsiExec.exe -Embedding D19AC84A95810A7F32ABCF7A8382DC7AC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5576\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6132C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6340C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6484"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\SSCERuntime-ENU.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6768C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
12 446
Read events
11 982
Write events
426
Delete events
38

Modification events

(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
48000000000000006EBE25496246DB01701A000018080000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000006EBE25496246DB01701A000018080000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000021C063496246DB01701A000018080000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
480000000000000021C063496246DB01701A000018080000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000292466496246DB01701A000018080000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
480000000000000019ED6A496246DB01701A000018080000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000B823E2496246DB01701A000018080000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000002B87E4496246DB01701A000068180000E8030000010000000000000000000000573C5B4F8F0D234897C9066815621FC300000000000000000000000000000000
(PID) Process:(6340) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000002F67F0496246DB01C4180000641A0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
36
Suspicious files
24
Text files
20
Unknown types
2

Dropped files

PID
Process
Filename
Type
6768msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6768msiexec.exeC:\Windows\Installer\MSIBF4E.tmpexecutable
MD5:00C3F5CA474A20C4A8DFB263A3950DAD
SHA256:9D849A8F5B39941EA32D47F0529977B1870F648736A483D86682436E3D3DB748
6768msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{4f5b3c57-0d8f-4823-97c9-066815621fc3}_OnDiskSnapshotPropbinary
MD5:8EB72DB1A0B05F81EDD73DFD93935C1B
SHA256:67E8AC5648827EB514C5C45EED3BC8AFD2066D8FBDA013D33555EBC3A38A1AF8
6484msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9der
MD5:A26DCBB948DA05EC8AF97885DBD149B0
SHA256:3CEB4A8069B2B9E5FDF508EF67D5AF5B9D3E6A7B417919953A89FA9773E16440
6768msiexec.exeC:\Windows\Installer\MSIBD19.tmpexecutable
MD5:85221B3BCBA8DBE4B4A46581AA49F760
SHA256:F6E34A4550E499346F5AB1D245508F16BF765FF24C4988984B89E049CA55737F
6768msiexec.exeC:\Windows\Temp\~DF726FCEC5C2487EAC.TMPbinary
MD5:3174516C770B1A67BB41F54A9E17F3D9
SHA256:59F0DF2553FF2EC8638877F714378B8423B6CBBF672030A2BCCF0DB6842D8942
6768msiexec.exeC:\Windows\Installer\13b8b4.msiexecutable
MD5:86AF6D36DFF214718DCD35D851249D3D
SHA256:99B5F0C1CC7FE40120A36FB760CC7C646EDEF5916695D6ECD8D41E8BBA9B1C60
6768msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:8EB72DB1A0B05F81EDD73DFD93935C1B
SHA256:67E8AC5648827EB514C5C45EED3BC8AFD2066D8FBDA013D33555EBC3A38A1AF8
6768msiexec.exeC:\Windows\Installer\MSIBEDF.tmpbinary
MD5:76F469AA831850DF909EB0DB0DE75875
SHA256:76D12295F3DD73D3A568474DB7A88D1B32B9E336E5A87D15622E5FF0FF9B00AA
6768msiexec.exeC:\Windows\assembly\tmp\SKNXN439\SDDXI61Otext
MD5:728C41A6BE9A4A809F7E063FFA2F56D1
SHA256:9782EC0A23145FF2CAB56496DE4F6C9AF6130A0E3C654A0F3A9C93860A2054AC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6484
msiexec.exe
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/CSPCA.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6648
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4716
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4716
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4992
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.16.204.160:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6484
msiexec.exe
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.173
  • 23.48.23.169
  • 23.48.23.162
  • 23.48.23.183
  • 23.48.23.164
  • 23.48.23.190
  • 23.48.23.177
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.bing.com
  • 2.16.204.160
  • 2.16.204.135
  • 2.16.204.155
  • 2.16.204.157
  • 2.16.204.142
  • 2.16.204.153
  • 2.16.204.139
  • 2.16.204.134
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.68
  • 40.126.31.73
  • 20.190.159.0
  • 40.126.31.71
  • 40.126.31.69
  • 20.190.159.23
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info