File name:

Cofense Reporter for Outlook v5.0.1 Setup - Smurfit Kappa Group.msi

Full analysis: https://app.any.run/tasks/3d868b41-5d07-4883-a9ed-233b78b2bd8e
Verdict: Malicious activity
Analysis date: August 14, 2020, 07:55:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Cofense Reporter, Author: Cofense Inc., Keywords: Installer, Comments: Cofense Reporter, Template: Intel;1033, Last Saved By: AutoBuilder, Revision Number: {567EFE5E-97BA-4311-81DB-EF2134D481D6}, Create Time/Date: Tue Mar 31 17:20:56 2020, Last Saved Time/Date: Wed Aug 5 15:30:35 2020, Number of Pages: 200, Number of Words: 6, Name of Creating Application: InstEd, Security: 0
MD5:

B700B34DAE9EB747C7D7797EC272B0CB

SHA1:

D67AF749233945EC855BA75B897A3F6F4BAED60C

SHA256:

CD5CB8CA681A4FA84EEAB3F1D98D687A5F6E0393754345E38302CCF6EC7769AC

SSDEEP:

393216:l8ELDXQTP2trrBfPvXRtvM6cvyxZxib/WIsfi:XLDqP2trNTBc2Sb/WIv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • rundll32.exe (PID: 2256)
      • OUTLOOK.EXE (PID: 2724)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • rundll32.exe (PID: 2256)
    • Creates COM task schedule object

      • MSI2CC8.tmp (PID: 3692)
    • Creates files in the user directory

      • OUTLOOK.EXE (PID: 2724)
  • INFO

    • Loads dropped or rewritten executable

      • MSI2CC8.tmp (PID: 3692)
    • Application was dropped or rewritten from another process

      • MSI2CC8.tmp (PID: 3692)
    • Reads Microsoft Office registry keys

      • MSI2CC8.tmp (PID: 3692)
      • OUTLOOK.EXE (PID: 2724)
    • Manual execution by user

      • OUTLOOK.EXE (PID: 2724)
    • Reads internet explorer settings

      • OUTLOOK.EXE (PID: 2724)
    • Reads Internet Cache Settings

      • OUTLOOK.EXE (PID: 2724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Cofense Reporter
Author: Cofense Inc.
Keywords: Installer
Comments: Cofense Reporter
Template: Intel;1033
LastModifiedBy: AutoBuilder
RevisionNumber: {567EFE5E-97BA-4311-81DB-EF2134D481D6}
CreateDate: 2020:04:30 16:20:56
ModifyDate: 2020:08:05 14:30:35
Pages: 200
Words: 6
Software: InstEd
Security: None
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs rundll32.exe msi2cc8.tmp no specs outlook.exe

Process information

PID
CMD
Path
Indicators
Parent process
2256rundll32.exe "C:\Windows\Installer\MSI2516.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_927187 1 CustomAction!CustomAction.CustomActions.CreateCofenseReporterWindowsEventLogC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2724"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2988"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Cofense Reporter for Outlook v5.0.1 Setup - Smurfit Kappa Group.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3692"C:\Windows\Installer\MSI2CC8.tmp" /install="C:\Program Files\Cofense\Cofense Reporter\5.0.1\bin\CofenseOutlookReporter.dll" /privileges=admin /logFileLocation=%LocalAppDataFolder%\Temp\5.0.1 - CofenseOutlookReporter_ADXRegistrator_Install.logC:\Windows\Installer\MSI2CC8.tmpmsiexec.exe
User:
admin
Company:
Add-in Express Ltd.
Integrity Level:
MEDIUM
Description:
Add-in Express .NET Registrator
Exit code:
0
Version:
9.4.4644.0
Modules
Images
c:\windows\installer\msi2cc8.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
Total events
1 400
Read events
1 086
Write events
283
Delete events
31

Modification events

(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
(PID) Process:(2988) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-844
Value:
BitLocker Data Recovery Agent
(PID) Process:(2256) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Cofense Reporter
Operation:writeName:MaxSize
Value:
524288
(PID) Process:(2256) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Cofense Reporter
Operation:writeName:AutoBackupLogFiles
Value:
0
(PID) Process:(2256) rundll32.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Cofense Reporter\Cofense Reporter
Operation:writeName:EventMessageFile
Value:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\EventLogMessages.dll
(PID) Process:(3692) MSI2CC8.tmpKey:HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
8
Suspicious files
2
Text files
40
Unknown types
1

Dropped files

PID
Process
Filename
Type
2988msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIE39A.tmp
MD5:
SHA256:
2724OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR6945.tmp.cvr
MD5:
SHA256:
2724OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WWTL2GN1DOWW7OJ5JUTA.temp
MD5:
SHA256:
2256rundll32.exeC:\Windows\Installer\MSI2516.tmp-\CRfO.Common.dllexecutable
MD5:
SHA256:
2724OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.logtext
MD5:
SHA256:
3692MSI2CC8.tmpC:\users\admin\appdata\local\temp\5.0.1 - cofenseoutlookreporter_adxregistrator_install.logtext
MD5:
SHA256:
3692MSI2CC8.tmpC:\Users\admin\AppData\Local\Temp\5.0.1 - CofenseOutlookReporter_ADXRegistrator_Install.logtext
MD5:
SHA256:
2724OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnklnk
MD5:
SHA256:
2724OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\be71009ff8bb02a2.customDestinations-ms~RFe7088.TMPbinary
MD5:
SHA256:
2256rundll32.exeC:\Windows\Installer\MSI2516.tmp-\CustomAction.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2724
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2724
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted

Threats

No threats detected
No debug info