| File name: | ishredder-windows.msi |
| Full analysis: | https://app.any.run/tasks/04dba4ad-0d74-40d2-95f5-651fed225bab |
| Verdict: | Malicious activity |
| Analysis date: | December 31, 2023, 10:30:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Protectstar(TM) iShredder 7, Author: Protectstar Inc., Comments: iShredder, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Template: Intel;1033, Last Saved By: Intel;1031, Revision Number: {D7D7E52F-49B3-476D-AAB0-BA32E2594E9D}7.0.2107;{D7D7E52F-49B3-476D-AAB0-BA32E2594E9D}7.0.2107;{84EF3185-4BC8-4114-A3A5-52DF78AE2BDF}, Number of Pages: 200, Number of Characters: 0 |
| MD5: | E0C23E46138A0013B3FD2F210C409C64 |
| SHA1: | 3F9282746E08BAC196D02200234085B944621FA2 |
| SHA256: | BD0F7593EF4A126B8DB980A773799B14125A2C798B40772C41C53582B8911EA0 |
| SSDEEP: | 98304:uZXZ9ZVZJZ5Z6DXAOw/n9MD6fIZRLtXifrJAIAytVk01Lcv4BBGv11G5l/+c15TJ:CDi4dt0 |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Pages: | 200 |
| RevisionNumber: | {05682DB8-1DE5-4EAD-B1E0-075165A16FFF} |
| Title: | Protectstar(TM) iShredder 7 |
| Subject: | - |
| Author: | Protectstar Inc. |
| Keywords: | - |
| Comments: | iShredder |
| Words: | 2 |
| ModifyDate: | 2021:08:15 08:58:40 |
| LastPrinted: | 2021:08:15 08:58:40 |
| Template: | Intel;1033,1031 |
| LastModifiedBy: | Intel;1031 |
| Characters: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | "C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\ProtectStar\DataShredder\DataShredderShellExt.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 552 | "C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe" | C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 900 | "C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe" | C:\Users\admin\Desktop\(x64bit.)_v7.0.21.01.09_patch.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225547 Modules
| |||||||||||||||
| 984 | "C:\Windows\system32\MsiExec.exe" /Z "C:\Program Files\ProtectStar\DataShredder\DataShredderShellExt.dll" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1196 | C:\Windows\system32\MsiExec.exe -Embedding D010711122C447D46D18DCA5E952E26E C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1288 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1572 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\ishredder-windows.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2016 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2080 | C:\Windows\system32\MsiExec.exe -Embedding C92474A88581BA033C4391B263D0031B C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2184 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\ishredder-windows.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2184) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 73 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1288) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1288 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 1288 | msiexec.exe | C:\Windows\Installer\e2c8a.msi | — | |
MD5:— | SHA256:— | |||
| 2184 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI172E.tmp | executable | |
MD5:612E28BA3A3B49EA7453E0866082638E | SHA256:27011F19145E33D9770CDF53E860A0CDD9A98933612D7A99619039CEC722CCFB | |||
| 2184 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIFC42.tmp | executable | |
MD5:612E28BA3A3B49EA7453E0866082638E | SHA256:27011F19145E33D9770CDF53E860A0CDD9A98933612D7A99619039CEC722CCFB | |||
| 1288 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFACA35129DAA0E768.TMP | binary | |
MD5:4D96CEA4DFBBFF7EB571B0C528DCF7F3 | SHA256:8AFC7DFD06553C3C7D07A6FF34E1583639D6EDB975DFC884B865C85418F4F9CC | |||
| 1288 | msiexec.exe | C:\Windows\Installer\MSI31F8.tmp | binary | |
MD5:08A7ECBC7C9425B9B9641D09B4FD0153 | SHA256:8B76C3D06588C07C6E57148D0E2BBA74C1472BCE183BAEC77AC8AAC3A10A5286 | |||
| 1288 | msiexec.exe | C:\Windows\Installer\e2c8d.msi | — | |
MD5:— | SHA256:— | |||
| 1288 | msiexec.exe | C:\Program Files\ProtectStar\DataShredder\AppIco.ico | image | |
MD5:7A94D4D9F4FB1E38B3113AB4A7EFD803 | SHA256:0F5A59CF93408DE7C6F1E968F35BC13DFF26658AF1605516F5A06FD6D3433AEC | |||
| 1288 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:DE211DB5A94888A9AC70E85B262709DA | SHA256:25ED927584188FB16888F77AF781E6D1C9D0E5FB101CBA56EA1E39666F990029 | |||
| 1288 | msiexec.exe | C:\Windows\Installer\e2c8b.ipi | binary | |
MD5:9F527763AA4CDD1C63D8656371C94CF5 | SHA256:12B6930CCC50AA14FB167E6FEF5E62D283E7396290069C0578A1E7CB80749B95 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3388 | DataShredderGUI6.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?65b8d6cb9b90a22f | unknown | compressed | 65.2 Kb | unknown |
3388 | DataShredderGUI6.exe | GET | 200 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?127d542563002f94 | unknown | compressed | 4.66 Kb | unknown |
3388 | DataShredderGUI6.exe | GET | 200 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
3388 | DataShredderGUI6.exe | GET | 200 | 184.24.77.45:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNUJFKAFSI3aY62xPtxREpHnw%3D%3D | unknown | binary | 503 b | unknown |
1080 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?503c317279212ca4 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3388 | DataShredderGUI6.exe | 217.160.175.246:443 | www.protectstar.com | IONOS SE | DE | unknown |
3388 | DataShredderGUI6.exe | 184.24.77.194:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3388 | DataShredderGUI6.exe | 69.192.161.44:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
3388 | DataShredderGUI6.exe | 184.24.77.45:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
1080 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3272 | DataShredderGUI6.exe | 217.160.175.246:443 | www.protectstar.com | IONOS SE | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.protectstar.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |