File name:

PHM Plus! for Windows XP.msi

Full analysis: https://app.any.run/tasks/9f4ddf69-5005-4b5f-93e9-1cf077fc90d6
Verdict: Malicious activity
Analysis date: June 04, 2025, 19:16:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Create Time/Date: Mon Jun 21 07:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {900E90D0-06EF-46D0-9DC3-BC7D472A5B71}, Title: PHM Plus! for Windows XP, Author: Philippe Majerus, Keywords: PHM Plus! utilities system, Comments: Customization and enhancement utilities for Windows XP, Number of Words: 2, Last Saved Time/Date: Sun Apr 17 14:01:55 2005, Last Printed: Sun Apr 17 14:01:55 2005
MD5:

B0B2EB75E33B29D17A7CB5CAF047FCBE

SHA1:

16A1606EA4704A1B88B398D325E181BFBBC8C9BD

SHA256:

A1DC182F56FF411FE185DDEC21761D9DAE845E3773228B8B10667CB0C0176AE5

SSDEEP:

98304:p9awrh81meNS9HcAqDwahN7YP9octET+nfCuJ/KreqdhczcrI2EBmc1LYZGaHvR+:CdMzfZhcQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 3572)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 3492)
    • Creates/Modifies COM task schedule object

      • msiexec.exe (PID: 3656)
      • msiexec.exe (PID: 3868)
      • msiexec.exe (PID: 3836)
      • msiexec.exe (PID: 3344)
      • msiexec.exe (PID: 3776)
      • msiexec.exe (PID: 3676)
      • msiexec.exe (PID: 2608)
      • msiexec.exe (PID: 120)
      • msiexec.exe (PID: 2044)
    • Application launched itself

      • msiexec.exe (PID: 3492)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 3492)
    • Checks supported languages

      • msiexec.exe (PID: 3492)
      • Ntoskrnl2bmp.exe (PID: 1740)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3492)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 3492)
    • The sample compiled with french language support

      • msiexec.exe (PID: 3492)
    • The sample compiled with english language support

      • msiexec.exe (PID: 3492)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3492)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3492)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3492)
    • Manual execution by a user

      • Ntoskrnl2bmp.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CreateDate: 1999:06:21 07:00:00
Software: Windows Installer
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
Pages: 200
RevisionNumber: {900E90D0-06EF-46D0-9DC3-BC7D472A5B71}
Title: PHM Plus! for Windows XP
Subject: -
Author: Philippe Majerus
Keywords: PHM Plus! utilities system
Comments: Customization and enhancement utilities for Windows XP
Words: 2
ModifyDate: 2005:04:17 14:01:55
LastPrinted: 2005:04:17 14:01:55
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
13
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs ntoskrnl2bmp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandNote.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1740"C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exe" C:\Program Files\PHM Plus!\Ntoskrnl2bmp.exeexplorer.exe
User:
admin
Company:
Majerus.net
Integrity Level:
MEDIUM
Description:
PHM Plus! Ntoskrnl to BMP Converter
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\program files\phm plus!\ntoskrnl2bmp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2044"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemCustomize.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2608"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FilesystemFlags.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3344"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\DeskBandClock.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3492C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3508"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\PHM Plus! for Windows XP.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3572C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3656"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\ShellFolderCustomize.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3676"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\PHM Plus!\FolderAppearance.dll"C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
4 475
Read events
4 154
Write events
309
Delete events
12

Modification events

(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
400000000000000098B2F23985D5DB01A40D0000300F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
400000000000000098B2F23985D5DB01A40D0000300F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000004836783A85D5DB01F40D0000D80C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Leave)
Value:
40000000000000004836783A85D5DB01F40D000008090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000A2987A3A85D5DB01F40D0000C40D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4000000000000000A2987A3A85D5DB01F40D0000B0030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
75
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000007823653A85D5DB01A40D0000300F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3492) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000D285673A85D5DB01A40D000078060000E8030000010000000000000000000000338C2B31DB676A4297B780EAFE89AF4F0000000000000000
(PID) Process:(3572) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000003A0F713A85D5DB01F40D0000B0030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
12
Suspicious files
6
Text files
11
Unknown types
15

Dropped files

PID
Process
Filename
Type
3492msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3492msiexec.exeC:\Windows\Installer\198860.msi
MD5:
SHA256:
3492msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:41DD53B970F1C2C7086695800491CC54
SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783
3492msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{312b8c33-67db-426a-97b7-80eafe89af4f}_OnDiskSnapshotPropbinary
MD5:41DD53B970F1C2C7086695800491CC54
SHA256:39FBCFAD680905C7BE2754BFBAE7F29427BFC2748F8FFA3E032302D2D2A97783
3492msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF9753BB54408089A9.TMPgmc
MD5:6EC783528657F8C653D656BA5E88BB7B
SHA256:1F838138D7A3F826E896F312C7F76189F94327555F912B68853408F2FE95B85F
3492msiexec.exeC:\Windows\Installer\198861.ipibinary
MD5:41C030A94BDDA690A184E4A025251EF5
SHA256:09962BAED65D611AF370F328B6F15B4965A2D781C2A4989B886EBF56951F77F2
3492msiexec.exeC:\Program Files\PHM Plus!\BootLogo.dllexecutable
MD5:A5C5B7EEA4B80B20A9EB01FADDF9FC6E
SHA256:B64BB5BFDE6F0DDA3297150FB9F7F6DFD0601B912442245F7B1900BEB2AF3804
3492msiexec.exeC:\Program Files\PHM Plus!\DeskBandSlideshow.dllexecutable
MD5:2496D9CFC59E67CF4AFC1548EE8C2B19
SHA256:D77D9D39F0F74A37F5D200C1C9F69EFB8D82EF174B30D2C3FA19D5D29DB583F1
3492msiexec.exeC:\Program Files\PHM Plus!\Utilities\Boot Bliss.bmpimage
MD5:9C04649EF0953CC0E15013551E38E784
SHA256:CF22FEA34B2B97713F0F830B78238571019159AD447044668545CACF63A0467B
3492msiexec.exeC:\Windows\System32\PHMWeb.chmchm
MD5:363B8E2D7D5F132E53381437908841E3
SHA256:7822522CEC3F4F3D53BDE22F46464986511F636A3B70D665A9F95B1858BC012C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted

Threats

No threats detected
No debug info