File name:

MM26_ENU.msi

Full analysis: https://app.any.run/tasks/3ca063bf-00d0-4b60-a982-4139a20ed541
Verdict: Malicious activity
Analysis date: July 19, 2018, 02:00:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Windows Movie Maker 2.6 Setup Package, Author: Microsoft Corporation, Keywords: Installer, Comments: WIXfile to create Movie Maker Installer, Template: ;1033, Revision Number: {95C677F7-FFD3-47F1-9A04-A6F4F66EF27A}, Number of Pages: 300, Number of Words: 2, Security: 2, Create Time/Date: Fri Mar 30 17:38:04 2007, Last Saved Time/Date: Fri Mar 30 17:38:04 2007, Name of Creating Application: Windows Installer XML v2.0.3620.0 (candle/light)
MD5:

50CA8D5F89C21B815C2F8A444B6FE2D9

SHA1:

D245030388F61F39030B20932B8F086A6C990D04

SHA256:

C3D463551528FEC6B8B9A9DFC26DDC265B41F6FCBD4197732E10D864DD6BFFD9

SSDEEP:

196608:3KF9iOay7JhtAKeEFGXQqRHhv93coUpcE3Gdxxf0:3k9iOvVhsHHLcTiR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • MOVIEMK.exe (PID: 996)
    • Application was dropped or rewritten from another process

      • MOVIEMK.exe (PID: 996)
  • SUSPICIOUS

    • Reads internet explorer settings

      • MOVIEMK.exe (PID: 996)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (79)
.mst | Windows SDK Setup Transform Script (8.9)
.mswmm | Windows Movie Maker project (6.6)
.xls | Microsoft Excel sheet (4.2)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Windows Movie Maker 2.6 Setup Package
Author: Microsoft Corporation
Keywords: Installer
Comments: WIXfile to create Movie Maker Installer
Template: ;1033
RevisionNumber: {95C677F7-FFD3-47F1-9A04-A6F4F66EF27A}
Pages: 300
Words: 2
Security: Read-only recommended
CreateDate: 2007:03:30 16:38:04
ModifyDate: 2007:03:30 16:38:04
Software: Windows Installer XML v2.0.3620.0 (candle/light)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs drvinst.exe no specs moviemk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
192DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot19" "" "" "61530dda3" "00000000" "000005C0" "0000055C"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
996"C:\Program Files\Movie Maker 2.6\MOVIEMK.exe" C:\Program Files\Movie Maker 2.6\MOVIEMK.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Movie Maker
Exit code:
0
Version:
2, 6, 4037, 0
Modules
Images
c:\program files\movie maker 2.6\moviemk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1860"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\MM26_ENU.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
930
Read events
569
Write events
361
Delete events
0

Modification events

(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
(PID) Process:(1860) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-844
Value:
BitLocker Data Recovery Agent
(PID) Process:(192) DrvInst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(996) MOVIEMK.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MM20
Operation:writeName:AutoSaveProject
Value:
{A698A454-0615-44E5-B05D-77C6F1365D6D}.AutoSave
(PID) Process:(996) MOVIEMK.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MM20
Operation:writeName:RanMM1xUpgrade
Value:
1
(PID) Process:(996) MOVIEMK.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MM20
Operation:writeName:MediaTabViewState
Value:
2
Executable files
0
Suspicious files
1
Text files
61
Unknown types
1

Dropped files

PID
Process
Filename
Type
996MOVIEMK.exeC:\Users\admin\AppData\Local\Microsoft\Movie Maker\MEDIATAB.DAT
MD5:
SHA256:
192DrvInst.exeC:\Windows\INF\setupapi.ev3abr
MD5:
SHA256:
192DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:
SHA256:
192DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info