File name:

PHM Plus! for Windows XP.msi

Full analysis: https://app.any.run/tasks/9f4ddf69-5005-4b5f-93e9-1cf077fc90d6
Verdict: Malicious activity
Analysis date: June 04, 2025, 19:16:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {900E90D0-06EF-46D0-9DC3-BC7D472A5B71}, Title: PHM Plus! for Windows XP, Author: Philippe Majerus, Keywords: PHM Plus! utilities system, Comments: Customization and enhancement utilities for Windows XP, Number of Words: 2, Last Saved Time/Date: Sun Apr 17 14:01:55 2005, Last Printed: Sun Apr 17 14:01:55 2005
MD5:

B0B2EB75E33B29D17A7CB5CAF047FCBE

SHA1:

16A1606EA4704A1B88B398D325E181BFBBC8C9BD

SHA256:

A1DC182F56FF411FE185DDEC21761D9DAE845E3773228B8B10667CB0C0176AE5

SSDEEP:

98304:p9awrh81meNS9HcAqDwahN7YP9octET+nfCuJ/KreqdhczcrI2EBmc1LYZGaHvR+:CdMzfZhcQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 3656)
      • msiexec.exe (PID: 3868)
      • msiexec.exe (PID: 3344)
      • msiexec.exe (PID: 3776)
      • msiexec.exe (PID: 3836)
      • msiexec.exe (PID: 3676)
      • msiexec.exe (PID: 2608)
      • msiexec.exe (PID: 120)
      • msiexec.exe (PID: 2044)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3492)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3572)
    • Application launched itself

      • msiexec.exe (PID: 3492)
  • INFO

    • The sample compiled with french language support

      • msiexec.exe (PID: 3492)
    • The sample compiled with english language support

      • msiexec.exe (PID: 3492)
    • Checks supported languages

      • msiexec.exe (PID: 3492)
      • Ntoskrnl2bmp.exe (PID: 1740)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3492)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3492)
    • Reads the computer name

      • msiexec.exe (PID: 3492)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 3492)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3492)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3492)
    • Manual execution by a user

      • Ntoskrnl2bmp.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {900E90D0-06EF-46D0-9DC3-BC7D472A5B71}
Title: PHM Plus! for Windows XP
Subject: -
Author: Philippe Majerus
Keywords: PHM Plus! utilities system
Comments: Customization and enhancement utilities for Windows XP
Words: 2
ModifyDate: 2005:04:17 14:01:55
LastPrinted: 2005:04:17 14:01:55
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
13
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs ntoskrnl2bmp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandNote.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1740"C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exe" C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exeexplorer.exe
User:
admin
Company:
Majerus.net
Integrity Level:
MEDIUM
Description:
PHM Plus! Ntoskrnl to BMP Converter
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\program files\phm plus!\ntoskrnl2bmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2044"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemCustomize.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2608"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemFlags.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3344"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandClock.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3492C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3508"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\PHM Plus! for Windows XP.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3572C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3656"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\ShellFolderCustomize.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3676"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FolderAppearance.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
4 475
Read events
4 154
Write events
309
Delete events
12

Modification events

(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
400000000000000098B2F23985D5DB01A40D0000300F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
400000000000000098B2F23985D5DB01A40D0000300F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000004836783A85D5DB01F40D0000D80C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000004836783A85D5DB01F40D000008090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000A2987A3A85D5DB01F40D0000C40D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000A2987A3A85D5DB01F40D0000B0030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
75
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000007823653A85D5DB01A40D0000300F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D285673A85D5DB01A40D000078060000E8030000010000000000000000000000338C2B31DB676A4297B780EAFE89AF4F0000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000003A0F713A85D5DB01F40D0000B0030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
12
Suspicious files
6
Text files
11
Unknown types
15

Dropped files

PID
Process
Filename
Type
3492msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3492msiexec.exeC:\Windows\Installer\198860.msi
MD5:
SHA256:
3492msiexec.exeC:\Windows\System32\PHMWeb.chmchm
MD5:363B8E2D7D5F132E53381437908841E3
SHA256:7822522CEC3F4F3D53BDE22F46464986511F636A3B70D665A9F95B1858BC012C
3492msiexec.exeC:\Program Files\PHM Plus!\Utilities\Boot Media Center.bmpimage
MD5:13686AAF1C994EE66E03AF54AE467B25
SHA256:A6FD4B54620F21D6A4500E0839877FC9E4F4D0BFE654F8411C3A245FB099B514
3492msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF9753BB54408089A9.TMPgmc
MD5:6EC783528657F8C653D656BA5E88BB7B
SHA256:1F838138D7A3F826E896F312C7F76189F94327555F912B68853408F2FE95B85F
3492msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:41DD53B970F1C2C7086695800491CC54
SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783
3492msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{312b8c33-67db-426a-97b7-80eafe89af4f}_OnDiskSnapshotPropbinary
MD5:41DD53B970F1C2C7086695800491CC54
SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783
3492msiexec.exeC:\Windows\Installer\198861.ipibinary
MD5:41C030A94BDDA690A184E4A025251EF5
SHA256:09962BAED65D611AF370F328B6F15B4965A2D781C2A4989B886EBF56951F77F2
3492msiexec.exeC:\Windows\Installer\MSI8DBF.tmpbinary
MD5:17A1028C063E7287DC3FC820CCA9E967
SHA256:9A2C8F4D829BC1B85B7F3D5172AA6A3FC15A0A21D524F19EE0C4EF9EAFB24B65
3492msiexec.exeC:\Program Files\PHM Plus!\ShellFolderCustomize.dllexecutable
MD5:FAD33547C5B13CCFECEA9280B03B3100
SHA256:7F7E7B29F0062D130AD86450B0C7EECF3962911FB95B048F92F3E43E89FC977E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted

Threats

No threats detected
No debug info