File name:

SafeNet-Minidriver-x32-10.2.msi

Full analysis: https://app.any.run/tasks/53c78f88-18ee-4fc6-81b1-291ba52f27ee
Verdict: Malicious activity
Analysis date: April 22, 2019, 11:27:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: [ProductName] Setup, Comments: 10.2.28, Keywords: eToken MSI Installer Database, Subject: SafeNet Minidriver 10.2, Author: Gemalto, Security: 1, Number of Pages: 500, Name of Creating Application: InstallShield 2014 - Professional Edition 21, Last Saved Time/Date: Sun Aug 5 16:50:45 2018, Create Time/Date: Sun Aug 5 16:50:45 2018, Last Printed: Sun Aug 5 16:50:45 2018, Revision Number: {1508A9BF-DEBB-4005-B4E7-D269B5FB51AA}, Code page: 1252, Template: Intel;1033
MD5:

EC3D8DCFB059B641FAED90D7DCC31B5A

SHA1:

A23AE126FAFF6EBA684C53EC573CA3EB48537A35

SHA256:

CD59C8A3C563922FE70B5FA6B9E6C8B57B71E4086A6FC77E2696A3C82422A442

SSDEEP:

49152:Mn3FQyP8T0hAX2OPjtNoH7PX2xP/tN4YyQtFuOPn8BlbG9QeE:OQy02OMHr2dsYycuOgUZE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1720)
      • msiexec.exe (PID: 1900)
      • MsiExec.exe (PID: 1812)
      • DrvInst.exe (PID: 2104)
      • DrvInst.exe (PID: 2044)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 1900)
      • DrvInst.exe (PID: 2104)
      • DrvInst.exe (PID: 2044)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 2104)
      • DrvInst.exe (PID: 2044)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 2104)
      • DrvInst.exe (PID: 2044)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 1900)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2384)
    • Searches for installed software

      • msiexec.exe (PID: 1900)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2384)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3888)
    • Creates files in the program directory

      • msiexec.exe (PID: 1900)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1900)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (84.2)
.mst | Windows SDK Setup Transform Script (9.5)
.flo | iGrafx FlowCharter document (5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Characters: -
LastModifiedBy: InstallShield
Words: -
Title: [ProductName] Setup
Comments: 10.2.28
Keywords: eToken MSI Installer Database
Subject: SafeNet Minidriver 10.2
Author: Gemalto
Security: Password protected
Pages: 500
Software: InstallShield? 2014 - Professional Edition 21
ModifyDate: 2018:08:05 15:50:45
CreateDate: 2018:08:05 15:50:45
LastPrinted: 2018:08:05 15:50:45
RevisionNumber: {1508A9BF-DEBB-4005-B4E7-D269B5FB51AA}
CodePage: Windows Latin 1 (Western European)
Template: Intel;1033
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
9
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe drvinst.exe drvinst.exe

Process information

PID
CMD
Path
Indicators
Parent process
1720"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\SafeNet-Minidriver-x32-10.2.msi"C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1812C:\Windows\system32\MsiExec.exe -Embedding 81BAA79776479038245E33B4DF74DEB6 M Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1900C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2044DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{583db1ce-4013-2680-3a3d-470821050075}\SafeNet.Minidriver.inf" "0" "6df673323" "000004C0" "WinSta0\Default" "000003C4" "208" "C:\Program Files\Gemalto\SafeNet Minidriver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2104DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{1ae921f8-75a2-7830-6fc1-14343c34c871}\SafeNet.Minidriver.IDPrime.inf" "0" "6b7ee42c7" "000005A0" "WinSta0\Default" "000004C0" "208" "C:\Program Files\Gemalto\IDGo 800 Minidriver"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2384DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000004C0" "000004AC"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3664C:\Windows\system32\MsiExec.exe -Embedding D0968581A3864405912ECEADD08F99FCC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3888C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3900C:\Windows\system32\MsiExec.exe -Embedding 520FC95EB727BB0E46F3C12049511CAD CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
885
Read events
385
Write events
482
Delete events
18

Modification events

(PID) Process:(1720) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F0754680FEF8D4016C0700006C0B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F0754680FEF8D4016C0700006C0B0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
20
(PID) Process:(1900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000EC34C780FEF8D4016C0700006C0B0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000004697C980FEF8D4016C070000D8040000E8030000010000000000000000000000760BD2F948788043B21C31A3A41034410000000000000000
(PID) Process:(3888) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000CA6EE180FEF8D401300F000030010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3888) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000CA6EE180FEF8D401300F0000BC080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3888) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000CA6EE180FEF8D401300F000060030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3888) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000CA6EE180FEF8D401300F000028080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
22
Suspicious files
24
Text files
227
Unknown types
11

Dropped files

PID
Process
Filename
Type
1900msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1900msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{f9d20b76-7848-4380-b21c-31a3a4103441}_OnDiskSnapshotPropbinary
MD5:
SHA256:
1900msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFD13649D30A88635D.TMP
MD5:
SHA256:
3888vssvc.exeC:
MD5:
SHA256:
1900msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
2384DrvInst.exeC:\Windows\INF\setupapi.ev3binary
MD5:
SHA256:
2384DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:
SHA256:
2384DrvInst.exeC:\Windows\INF\setupapi.ev1binary
MD5:
SHA256:
1900msiexec.exeC:\Windows\system32\axaltocm.dllexecutable
MD5:
SHA256:
1900msiexec.exeC:\Windows\Installer\ecabf.ipibinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info