File name: | EZFN Launcher_1.2.7_x64_en-US.msi |
Full analysis: | https://app.any.run/tasks/2724be4a-ca0f-4a13-b0d7-22d50611b719 |
Verdict: | Malicious activity |
Analysis date: | December 21, 2024, 15:02:00 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: EZFN Launcher, Author: ezfn, Keywords: Installer, Comments: This installer database contains the logic and data required to install EZFN Launcher., Template: x64;0, Revision Number: {8E8ADF67-611A-418A-81D9-A15A7CD2D5D7}, Create Time/Date: Wed Nov 13 21:30:16 2024, Last Saved Time/Date: Wed Nov 13 21:30:16 2024, Number of Pages: 450, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2 |
MD5: | 1425A73D9D6DB003B57BFC2134EA9D70 |
SHA1: | D31866A0CCC44F2DB6A17402F1219BF75E03B8E4 |
SHA256: | B244361E1DAC8D917BE21D8E8453112C461F69FF3EC00E1844F6536379B8CD7F |
SSDEEP: | 98304:QxIWsnjGEXs509D2E4ZlcXZ4qWav6MTvJs6O49zN0BFzdAFX+5UsgoUveJPg8EI2:+eD2Q3DKq//5 |
.msi | | | Microsoft Windows Installer (98.5) |
---|---|---|
.msi | | | Microsoft Installer (100) |
Security: | Read-only recommended |
---|---|
Software: | Windows Installer XML Toolset (3.11.2.4516) |
Words: | 2 |
Pages: | 450 |
ModifyDate: | 2024:11:13 21:30:16 |
CreateDate: | 2024:11:13 21:30:16 |
RevisionNumber: | {8E8ADF67-611A-418A-81D9-A15A7CD2D5D7} |
Template: | x64;0 |
Comments: | This installer database contains the logic and data required to install EZFN Launcher. |
Keywords: | Installer |
Author: | ezfn |
Subject: | EZFN Launcher |
Title: | Installation Database |
CodePage: | Windows Latin 1 (Western European) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
6016 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\EZFN Launcher_1.2.7_x64_en-US.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
6248 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
6340 | C:\Windows\syswow64\MsiExec.exe -Embedding 34E8CED3F4D73F6193B69168DB7A5B57 C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
6764 | C:\WINDOWS\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4516 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
3820 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4540 | powershell.exe -NoProfile -windowstyle hidden try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 } catch {}; Invoke-WebRequest -Uri "https://go.microsoft.com/fwlink/p/?LinkId=2124703" -OutFile "$env:TEMP\MicrosoftEdgeWebview2Setup.exe" ; Start-Process -FilePath "$env:TEMP\MicrosoftEdgeWebview2Setup.exe" -ArgumentList ( '/install') -Wait | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4120 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
7036 | "C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe" /install | C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Version: 1.3.195.39 Modules
| |||||||||||||||
7104 | C:\Users\admin\AppData\Local\Temp\EUCD17.tmp\MicrosoftEdgeUpdate.exe /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers" | C:\Users\admin\AppData\Local\Temp\EUCD17.tmp\MicrosoftEdgeUpdate.exe | MicrosoftEdgeWebview2Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Version: 1.3.195.39 Modules
|
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 48000000000000009D056353B953DB01681800005C1A0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 48000000000000009D056353B953DB01681800005C1A0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000E7E8AC53B953DB01681800005C1A0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000E7E8AC53B953DB01681800005C1A0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 48000000000000000CB1B153B953DB01681800005C1A0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 48000000000000008E78B653B953DB01681800005C1A0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 11 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4800000000000000E8922654B953DB01681800005C1A0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (6248) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 480000000000000015482B54B953DB0168180000CC1A0000E8030000010000000000000000000000425BC922612BC04F93EDE6D8EA1865B700000000000000000000000000000000 | |||
(PID) Process: | (6764) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000E63C3754B953DB016C1A0000F01A0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6248 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
6248 | msiexec.exe | C:\Windows\Installer\13afbb.msi | — | |
MD5:— | SHA256:— | |||
6248 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{22c95b42-2b61-4fc0-93ed-e6d8ea1865b7}_OnDiskSnapshotProp | binary | |
MD5:3C84340AD92B58F6B4B6F39AEFB7421A | SHA256:DCD508016036668B33FC7B13540248E089A5A8E850626D90E6CAD10A8D159B0E | |||
6248 | msiexec.exe | C:\Program Files\EZFN Launcher\_up_\public\season_images\Season11.webp | image | |
MD5:335FB9C70F5039817BF345F77250FBD0 | SHA256:D1ACF91F644BA1877832F3A8315305C6D49A2A140B66CBDED02C5017360786E4 | |||
6248 | msiexec.exe | C:\Windows\Installer\MSIB47E.tmp | binary | |
MD5:230E5857C20C915C931CCB9E2B952978 | SHA256:C9151FEC1A26C98A777686F7FAE35FE9A2392C66FF74DA80E6CCF69FA58D8250 | |||
6248 | msiexec.exe | C:\Program Files\EZFN Launcher\_up_\public\season_images\Season4.webp | image | |
MD5:3AAE2BF0658B3F758401AD902E9DBE95 | SHA256:21DE3019F43DE27146198A3566DC0D4A20F8DA6E5F357BE819D8677B4B48D97E | |||
6248 | msiexec.exe | C:\Program Files\EZFN Launcher\_up_\public\season_images\Season7.webp | image | |
MD5:B112139E396EE16AC6F8D7F5DC5D10F7 | SHA256:1E51EBB0C98EE8CC6A194DC5B08C940573C65BDE2B580E88C0449658C49267F1 | |||
6248 | msiexec.exe | C:\Program Files\EZFN Launcher\_up_\public\season_images\Season6.webp | image | |
MD5:DC8335F69D9DA46E1A71CAFC750B4A1D | SHA256:86E7E0C3F94E9DD442FC1829A42D02A1E152DD3D552B0279B7CD2DADEF949846 | |||
6248 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:3C84340AD92B58F6B4B6F39AEFB7421A | SHA256:DCD508016036668B33FC7B13540248E089A5A8E850626D90E6CAD10A8D159B0E | |||
6248 | msiexec.exe | C:\Windows\Installer\inprogressinstallinfo.ipi | binary | |
MD5:D202356906FC8DC1D91D1421DD0FD9DC | SHA256:0D6D078BD6FB9A7A4A0C6E2066236D75F9714C63506E487FA33979185A510C74 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4912 | svchost.exe | HEAD | 200 | 2.19.198.74:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7d9cd93c-1d5e-449b-9ad7-f1e8d6b90509?P1=1735398165&P2=404&P3=2&P4=bkPX1xLxe2uiskh9mTrFxZY5GbZMRFCt3hbRyTePL7vfLdZ7nYm%2b3oCrYiwEs3vBhOG6uGSObR5Je0ydKAr8xA%3d%3d | unknown | — | — | whitelisted |
4912 | svchost.exe | GET | — | 2.19.198.74:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7d9cd93c-1d5e-449b-9ad7-f1e8d6b90509?P1=1735398165&P2=404&P3=2&P4=bkPX1xLxe2uiskh9mTrFxZY5GbZMRFCt3hbRyTePL7vfLdZ7nYm%2b3oCrYiwEs3vBhOG6uGSObR5Je0ydKAr8xA%3d%3d | unknown | — | — | whitelisted |
3144 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6480 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6480 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
1596 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.23.209.156:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
1176 | svchost.exe | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |