File name: | Idera.SQL.Check.Setup (x64).msi |
Full analysis: | https://app.any.run/tasks/19fd14c9-79bd-4f58-b94d-4965b1134bd1 |
Verdict: | Malicious activity |
Analysis date: | November 22, 2022, 18:03:14 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Idera SQL Check 64-bit, Author: Idera, Keywords: Installer, Comments: This installer database contains the logic and data required to install Idera SQL Check 64-bit., Template: x64;1033, Revision Number: {13DCEA25-0438-4343-B0D4-8B38E9555E0E}, Create Time/Date: Thu Sep 24 11:10:50 2015, Last Saved Time/Date: Thu Sep 24 11:10:50 2015, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.9.1208.0), Security: 2 |
MD5: | 2E5B01E4A17B7023965732C18B67953F |
SHA1: | 3B0F5FDFC719A67A976F05D3C0DB8F7E1159E234 |
SHA256: | BC6C6D980D3CF9530A755285C5FFDC7C538B27EB41F29C8091DFA4269B357FCB |
SSDEEP: | 98304:HBfHPW+xnIay1JmrrjEEE/SzpEEmVp0Gx3uSZW0aAKuwA7rCxxzkr1KO:BlIVJmXz+Vp08Zzb72xax |
.msi | | | Microsoft Windows Installer (98.5) |
---|---|---|
.msi | | | Microsoft Installer (100) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3536 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Idera.SQL.Check.Setup (x64).msi" | C:\Windows\System32\msiexec.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3988 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3536) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US |
PID | Process | Filename | Type | |
---|---|---|---|---|
3536 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIeca4.LOG | text | |
MD5:7C539765D7F35C9E8048340EF2F159DC | SHA256:166F3BE7DD89FF5B7B0D7D348053E0A2327B8D6598B3A791A1CD73F9697291C3 |