| File name: | usb-monitor-pro.msi |
| Full analysis: | https://app.any.run/tasks/c312f7db-a861-4bae-804e-34f16117965f |
| Verdict: | Malicious activity |
| Analysis date: | January 06, 2024, 18:06:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: USB Monitor Pro Installation Package, Author: FabulaTech, Keywords: Installer, MSI, Database, USB Monitor Pro, Comments: Installs USB Monitor Pro, Template: ;1033, Number of Pages: 200, Number of Words: 2, Security: 2, Revision Number: {4AF34099-447C-4215-89EA-EC00EA9DA18C}, Create Time/Date: Mon Sep 19 11:45:03 2016, Last Saved Time/Date: Mon Sep 19 11:45:03 2016, Name of Creating Application: Windows Installer XML v2.0.5325.0 (candle/light) |
| MD5: | 15C1F148AAC00A482302072B72B19A3E |
| SHA1: | 6F19E2B52ED3F45E0D719E4D30E063452D6B39DC |
| SHA256: | C159778451F3E15F0FCE95607B9ECA3D21958F33D7D0BBB4D513E6D904BE4D08 |
| SSDEEP: | 98304:dfKLzn9DK5N67i3GcfszjBawwb50MMdmsywwE6p4LssTD71pq+GQpKN+zFof48YP:z3JuGwx9PkJWJ9GR+8TsuE |
| .msi | | | Microsoft Installer (100) |
|---|
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | USB Monitor Pro Installation Package |
| Author: | FabulaTech |
| Keywords: | Installer, MSI, Database, USB Monitor Pro |
| Comments: | Installs USB Monitor Pro |
| Template: | ;1033 |
| Pages: | 200 |
| Words: | 2 |
| Security: | Read-only recommended |
| RevisionNumber: | {4AF34099-447C-4215-89EA-EC00EA9DA18C} |
| CreateDate: | 2016:09:19 10:45:03 |
| ModifyDate: | 2016:09:19 10:45:03 |
| Software: | Windows Installer XML v2.0.5325.0 (candle/light) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Downloads\usb-monitor-pro.msi" | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 316 | "C:\Windows\System32\cmd.exe" /C del C:\Users\admin\AppData\Local\Temp\setup-usbmon-Intel.msi | C:\Windows\System32\cmd.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1608 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1924 | "msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\setup-usbmon-Intel.msi" | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2416 | C:\Windows\system32\MsiExec.exe -Embedding CF5EC0DCC02E27037DFC27F6D0FA56DE C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2436 | "C:\Program Files\USB Monitor Pro\usbmonitor.exe" /first | C:\Program Files\USB Monitor Pro\usbmonitor.exe | msiexec.exe | ||||||||||||
User: admin Company: FabulaTech Integrity Level: MEDIUM Description: USB Monitor Pro GUI Exit code: 0 Version: 2.8.0.1 Modules
| |||||||||||||||
| 2632 | C:\Windows\system32\MsiExec.exe -Embedding 71513CDCD9DF73EEA718E14DF8FC47DD | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2800 | "C:\Program Files\USB Monitor Pro\ftusbmon.exe" | C:\Program Files\USB Monitor Pro\ftusbmon.exe | — | services.exe | |||||||||||
User: SYSTEM Company: FabulaTech Integrity Level: SYSTEM Description: USB Monitor Pro Service Exit code: 0 Version: 2.8.0.1 Modules
| |||||||||||||||
| 2828 | C:\Windows\system32\MsiExec.exe -Embedding D00F5789178EDF86071227860E9F917A E Global\MSI0000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (128) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2416) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2416) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2416) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2416) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2068) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2068) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2068) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 73 | |||
| (PID) Process: | (2068) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2068) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2068 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2068 | msiexec.exe | C:\Windows\Installer\e1ccb.msi | — | |
MD5:— | SHA256:— | |||
| 2068 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\setup-usbmon-Intel.msi | — | |
MD5:— | SHA256:— | |||
| 2068 | msiexec.exe | C:\Windows\Installer\e1cce.msi | — | |
MD5:— | SHA256:— | |||
| 2068 | msiexec.exe | C:\Windows\Installer\e1ccf.msi | — | |
MD5:— | SHA256:— | |||
| 128 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 128 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\Cab3D4.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 2068 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{b5431b7e-e487-44a2-af76-cdf69edd0f30}_OnDiskSnapshotProp | binary | |
MD5:F764E1D86785484B5405BD3C7C18BD7D | SHA256:1E770137A02E3F2F248789341CD03988978975319E9E8726CE27AE9B2B2D3187 | |||
| 128 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:4A3050D2223059163B41B6E347E156D7 | SHA256:210FF8D6723E6283917BB005CE6ADDABE9185EB2B4F003DEBD1039FA8C10099A | |||
| 2068 | msiexec.exe | C:\Windows\Installer\e1ccc.ipi | binary | |
MD5:E47A52052A969A4E73A4543E57C3C7B0 | SHA256:EDE73FC3F4A53333EF946BC380D06D90D79BC8E1EE61D983FCEBD34BF673C65B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?67c7103e6bf462aa | unknown | compressed | 65.2 Kb | unknown |
2436 | usbmonitor.exe | GET | 301 | 74.84.144.110:80 | http://www.usb-monitor.com/usbmon.xml?random-value=9527342.8 | unknown | html | 269 b | unknown |
2968 | iexplore.exe | GET | 301 | 74.84.144.110:80 | http://www.usb-monitor.com/usbmon-start/?rf=usbmon&ver=2.8 | unknown | html | 271 b | unknown |
2844 | iexplore.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4ed8e041b1b09be7 | unknown | compressed | 4.66 Kb | unknown |
2968 | iexplore.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?335dbfba1f3d6e55 | unknown | compressed | 4.66 Kb | unknown |
2968 | iexplore.exe | GET | 200 | 72.246.169.163:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
2844 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 312 b | unknown |
2968 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | unknown | binary | 1.47 Kb | unknown |
2968 | iexplore.exe | GET | 200 | 95.101.54.195:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNWCn0cEFwmkzCKx8u04odWUw%3D%3D | unknown | binary | 503 b | unknown |
1080 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?68d075f71f4fb981 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
128 | msiexec.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2436 | usbmonitor.exe | 74.84.144.110:80 | www.usb-monitor.com | HOPONE-GLOBAL | US | unknown |
2436 | usbmonitor.exe | 74.84.144.110:443 | www.usb-monitor.com | HOPONE-GLOBAL | US | unknown |
2968 | iexplore.exe | 74.84.144.110:80 | www.usb-monitor.com | HOPONE-GLOBAL | US | unknown |
2968 | iexplore.exe | 74.84.144.110:443 | www.usb-monitor.com | HOPONE-GLOBAL | US | unknown |
2968 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2968 | iexplore.exe | 72.246.169.163:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
www.usb-monitor.com |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r3.o.lencr.org |
| shared |
cdnjs.cloudflare.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2436 | usbmonitor.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent Possible Trojan Downloader Shell |