File name:

Install Security for Windows.exe

Full analysis: https://app.any.run/tasks/a1ed9131-87d6-4849-897d-f25ab9cb3183
Verdict: Malicious activity
Analysis date: December 03, 2024, 05:29:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

FF53BE9D3A6EF83F47279552867DA686

SHA1:

9F3DE77E60A8F2168BEF77D8E35C99C764944239

SHA256:

B81C651CB7440F9FB24D1D99F025E45EB51EFF3EAE5E72CE9D1FB2861CB8C4A6

SSDEEP:

98304:s6TQ4jFC4tlFMXagCdvGbXwJolD3X2Rd59YF/z3uop94vH0xtB9GCsBLOMQ4JGOJ:5gLY9TEBJLfSnBv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Install Security for Windows.exe (PID: 6092)
      • SanDiskSecuritySetup.exe (PID: 6436)
      • drvinst.exe (PID: 6708)
    • The process creates files with name similar to system file names

      • Install Security for Windows.exe (PID: 6092)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 6512)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 6512)
      • drvinst.exe (PID: 6708)
    • Executes as Windows Service

      • WDDriveService.exe (PID: 6784)
  • INFO

    • Checks supported languages

      • Install Security for Windows.exe (PID: 6092)
    • Reads the computer name

      • Install Security for Windows.exe (PID: 6092)
    • Create files in a temporary directory

      • Install Security for Windows.exe (PID: 6092)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6512)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 6512)
    • Reads the machine GUID from the registry

      • Install Security for Windows.exe (PID: 6092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:09:03 13:44:40+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 10
CodeSize: 318976
InitializedDataSize: 52736
UninitializedDataSize: -
EntryPoint: 0x474b
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.17
ProductVersionNumber: 1.0.0.17
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Western Digital Technologies, Inc.
FileDescription: SanDisk Security
FileVersion: 1.0.0.17
InternalName: setup
LegalCopyright: © 2020 Western Digital Technologies, Inc. All rights reserved.
OriginalFileName: SanDiskSecuritySetup.exe
ProductName: SanDisk Security
ProductVersion: 1.0.0.17
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start install security for windows.exe sandisksecuritysetup.exe msiexec.exe msiexec.exe no specs msi3f.tmp no specs drvinst.exe msi34d.tmp no specs wddriveservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6092"C:\Users\admin\AppData\Local\Temp\Install Security for Windows.exe" C:\Users\admin\AppData\Local\Temp\Install Security for Windows.exe
explorer.exe
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
MEDIUM
Description:
SanDisk Security
Exit code:
0
Version:
1.0.0.17
Modules
Images
c:\users\admin\appdata\local\temp\install security for windows.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6436"C:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.be\SanDiskSecuritySetup.exe" -q -burn.elevated BurnPipe.{5473FDDC-F8E7-4C68-8724-1DA8A1E70340} {1BA45F71-BF30-4E05-9F1F-FA474B105A52} 6092C:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.be\SanDiskSecuritySetup.exe
Install Security for Windows.exe
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
HIGH
Description:
SanDisk Security
Exit code:
0
Version:
1.0.0.17
Modules
Images
c:\users\admin\appdata\local\temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.be\sandisksecuritysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6512C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6600C:\Windows\syswow64\MsiExec.exe -Embedding E593F616E7C1FB101F4E92D0534C5787C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6644"C:\WINDOWS\Installer\MSI3F.tmp" /SW /SA /Q /PATH "C:\Program Files (x86)\Western Digital\WDCSAM\\"C:\Windows\Installer\MSI3F.tmpmsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
2147549184
Version:
2.1
Modules
Images
c:\windows\installer\msi3f.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6708DrvInst.exe "4" "9" "c:\program files (x86)\western digital\wdcsam\wdcsam.inf" "9" "4ca998ccf" "00000000000001D8" "WinSta0\Default" "00000000000001D0" "208" "c:\program files (x86)\western digital\wdcsam"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096971
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
6756"C:\WINDOWS\Installer\MSI34D.tmp" /rescanC:\Windows\Installer\MSI34D.tmpmsiexec.exe
User:
admin
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
HIGH
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\windows\installer\msi34d.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6784"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exeservices.exe
User:
SYSTEM
Company:
Western Digital Technologies, Inc.
Integrity Level:
SYSTEM
Description:
WD Drive Service
Version:
2.4.2.79
Modules
Images
c:\program files (x86)\western digital\wd drive manager\wddriveservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\setupapi.dll
Total events
18 388
Read events
17 853
Write events
520
Delete events
15

Modification events

(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{189ff347-b978-4c66-88b6-30214ecb87a9}\SanDiskSecuritySetup.exe
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleUpgradeCode
Value:
{D532BBE5-8B77-4809-A311-5106CB48B865}
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleVersion
Value:
1.0.0.17
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleProviderKey
Value:
{189ff347-b978-4c66-88b6-30214ecb87a9}
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:BundleTag
Value:
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:EngineVersion
Value:
3.6.3303.0
(PID) Process:(6436) SanDiskSecuritySetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{189ff347-b978-4c66-88b6-30214ecb87a9}
Operation:writeName:DisplayIcon
Value:
C:\ProgramData\Package Cache\{189ff347-b978-4c66-88b6-30214ecb87a9}\SanDiskSecuritySetup.exe,0
Executable files
42
Suspicious files
27
Text files
160
Unknown types
2

Dropped files

PID
Process
Filename
Type
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\DriveSecuritySetup
MD5:
SHA256:
6436SanDiskSecuritySetup.exeC:\ProgramData\Package Cache\.unverified\DriveSecuritySetup
MD5:
SHA256:
6436SanDiskSecuritySetup.exeC:\ProgramData\Package Cache\{3C6EE362-358C-41AB-8B54-0BBBE7DE837F}v1.0.0.17\SanDiskSecuritySetup.msi
MD5:
SHA256:
6512msiexec.exeC:\Windows\Installer\13efd2.msi
MD5:
SHA256:
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.ba1\MVVM.dllexecutable
MD5:496FA0255E34508357D948762799958F
SHA256:6EEF17E30DE543507E26068A43AB469EEB6CC819A353593C6E2FB8DFE862EFAF
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.ba1\mbahost.dllexecutable
MD5:8A26C827E7DD4B0EF452BEA4200049E2
SHA256:0C378211674601436A9DB7150C01836170BDE0B7B14E7D15F6DB9BD381D2D0FD
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.ba1\mbapreq.wxlxml
MD5:16D2BD521AC2ACD7BD590A9B35F843DF
SHA256:84D8C544A8E320BD4EB3472A582326142D7CA86794B930FE983C3822A6ACF263
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.ba1\WDUtilities.dllexecutable
MD5:B4A32EC57117B2444C2703CE7F978968
SHA256:6325C85F39349F770F9250A8A32E4D6409B9B5956A124A6E43D8577E842FC95E
6092Install Security for Windows.exeC:\Users\admin\AppData\Local\Temp\{189ff347-b978-4c66-88b6-30214ecb87a9}\.ba1\mbapreq.pngimage
MD5:8CF3013C469DD229A8268C070024564A
SHA256:52B375270AC82296F49FB0C68AF35E0BF5A854722F390ED71AEB54CEB40D2532
6512msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_E6095CD2AECC9011BCD0D7B421356B17binary
MD5:2BB52EBAF6051FBD37C65BB1465D9C1E
SHA256:F24550A287441BC64E83AB3E0D8D21688A9D6F0A84D96B1D6B82F0F8149B2768
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
34
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2484
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6260
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6260
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6512
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEB2iSDBvmyYY0ILgln0z02o%3D
unknown
whitelisted
6512
msiexec.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQ5suEceKjAJbxseAmHFkQ9FrhTWQQUDuE6qFM6MdWKvsG7rWcaA4WtNA4CEQCNp1dyCzc48Th5ne0MQhgL
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2736
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
776
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.209.140:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1176
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 172.217.18.110
whitelisted
www.bing.com
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.189
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.149
  • 2.23.209.158
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.23
  • 20.190.159.71
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info