| File name: | MouseWithoutBordersSetup.msi |
| Full analysis: | https://app.any.run/tasks/e1978e6a-fb15-41a6-b22d-717a42b13a40 |
| Verdict: | Malicious activity |
| Analysis date: | December 11, 2018, 14:28:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft Garage Mouse without Borders, Author: Microsoft Garage, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders., Template: Intel;1033, Revision Number: {BD0966CC-7CB9-47C8-880D-88171958DEFF}, Create Time/Date: Wed Jan 17 17:44:54 2018, Last Saved Time/Date: Wed Jan 17 17:44:54 2018, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.0.1701), Security: 2 |
| MD5: | 91545812DEBDE8A120378D8D1A076E93 |
| SHA1: | 021869286E3D24FB387974E9A78CAA3A0B8155D6 |
| SHA256: | C73D373275519DE5545824FF20E886E4C2D76770CB77F8B685C0B52A1C07E97D |
| SSDEEP: | 12288:fGqjHGEiyfL5xvW0yUBrkBeONrf5aj0AHiYd4hN+6VFH2anwohwQUv:BjHGuAURxOtfACYg+6VFrhwQUv |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | Microsoft Garage Mouse without Borders |
| Author: | Microsoft Garage |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install Microsoft Garage Mouse without Borders. |
| Template: | Intel;1033 |
| RevisionNumber: | {BD0966CC-7CB9-47C8-880D-88171958DEFF} |
| CreateDate: | 2018:01:17 17:44:54 |
| ModifyDate: | 2018:01:17 17:44:54 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.11.0.1701) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2280 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MousewithoutBordersHelper.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MousewithoutBordersHelper.exe | — | MouseWithoutBorders.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2444 | C:\Windows\system32\MsiExec.exe -Embedding F58943D9AD17A127A49936C049C05186 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2512 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "winlogon" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | MouseWithoutBordersHelper.exe | ||||||||||||
User: SYSTEM Company: Microsoft Integrity Level: SYSTEM Description: Mouse without Borders Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2564 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" "SvcExec" "winlogon" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe | — | MouseWithoutBordersSvc.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2568 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2660 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | MouseWithoutBordersHelper.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: HIGH Description: Mouse without Borders Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2712 | C:\Windows\system32\MsiExec.exe -Embedding 387163F8DC34A3FC86C442DFBBD93B8E M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2784 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe" "SvcExec" "default" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBordersHelper.exe | — | MouseWithoutBordersSvc.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: Mouse Without Borders Helper Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2932 | "C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe" "default" | C:\Program Files\Microsoft Garage\Mouse without Borders\MouseWithoutBorders.exe | MouseWithoutBordersHelper.exe | ||||||||||||
User: SYSTEM Company: Microsoft Integrity Level: SYSTEM Description: Mouse without Borders Exit code: 0 Version: 2.1.8.0105 Modules
| |||||||||||||||
| 2992 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\MouseWithoutBordersSetup.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2992) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2568) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000308E66D95D91D401080A0000600D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2568) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000308E66D95D91D401080A0000600D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2568) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (2568) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000002D8D1D95D91D401080A0000600D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2568) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005C3AD4D95D91D401080A0000E40B0000E8030000010000000000000000000000F086CFF78F8B374995FD921517F560F10000000000000000 | |||
| (PID) Process: | (3612) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2EAE4D95D91D4011C0E000028060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3612) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2EAE4D95D91D4011C0E0000500C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3612) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2EAE4D95D91D4011C0E0000E4030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3612) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D2EAE4D95D91D4011C0E0000580C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2568 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFD7453EA4586481E3.TMP | — | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\Windows\Installer\MSIFA65.tmp | — | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\Windows\Installer\MSIFBAE.tmp | — | |
MD5:— | SHA256:— | |||
| 3612 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{f7cf86f0-8b8f-4937-95fd-921517f560f1}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3780 | DrvInst.exe | C:\Windows\INF\setupapi.dev.log | ini | |
MD5:— | SHA256:— | |||
| 2568 | msiexec.exe | C:\Windows\Installer\19f274.msi | executable | |
MD5:— | SHA256:— | |||
| 3780 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2512 | MouseWithoutBorders.exe | 40.114.241.141:443 | dc.services.visualstudio.com | Microsoft Corporation | NL | whitelisted |
2932 | MouseWithoutBorders.exe | 40.114.241.141:443 | dc.services.visualstudio.com | Microsoft Corporation | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
dc.services.visualstudio.com |
| whitelisted |