File name:

Fraps 3.5.1 by izzedine2001.msi

Full analysis: https://app.any.run/tasks/c16918ec-339c-4e51-b277-61b1ee6b858b
Verdict: Malicious activity
Analysis date: February 24, 2025, 01:01:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Fraps 3.5.1 by izzedine2001, Author: izzedine2001, Keywords: Installer, Comments: This installer database contains the logic and data required to install Fraps 3.5.1 by izzedine2001., Template: x64;1033, Revision Number: {F7780789-91E9-45D2-9605-1BEA0EE40073}, Create Time/Date: Sun Feb 2 13:52:40 2014, Last Saved Time/Date: Sun Feb 2 13:52:40 2014, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.0.5419.0), Security: 2
MD5:

367DFAE030B688DEAE53E89D8C948450

SHA1:

0DC6316CA994C86AE813C2FCFD76391EDFC6E1CC

SHA256:

CF2006C0C991CBA12A6D112C2B8159AED2A69FFDD795F97C30A46FB2EBDDC6EC

SSDEEP:

98304:xmXSvcUL1Yd30Ed9ZdfrTYEMnddj2P39GZGD/lU4lU24TKc1lfTgwD3yLPpH7MqM:tJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • fraps.exe (PID: 4512)
      • fraps.exe (PID: 5236)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 6552)
    • Searches for installed software

      • fraps.exe (PID: 5236)
    • Starts application with an unusual extension

      • fraps.exe (PID: 5236)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6488)
    • Reads the BIOS version

      • fraps.exe (PID: 5236)
  • INFO

    • The sample compiled with english language support

      • msiexec.exe (PID: 6328)
      • msiexec.exe (PID: 6488)
    • Checks supported languages

      • fraps64.dat (PID: 6792)
      • msiexec.exe (PID: 6488)
      • fraps.exe (PID: 5236)
    • Reads the computer name

      • fraps64.dat (PID: 6792)
      • fraps.exe (PID: 5236)
    • Manages system restore points

      • SrTasks.exe (PID: 4872)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6488)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6488)
    • Manual execution by a user

      • fraps.exe (PID: 4512)
      • fraps.exe (PID: 5236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Fraps 3.5.1 by izzedine2001
Author: izzedine2001
Keywords: Installer
Comments: This installer database contains the logic and data required to install Fraps 3.5.1 by izzedine2001.
Template: x64;1033
RevisionNumber: {F7780789-91E9-45D2-9605-1BEA0EE40073}
CreateDate: 2014:02:02 13:52:40
ModifyDate: 2014:02:02 13:52:40
Pages: 200
Words: 2
Software: Windows Installer XML (3.0.5419.0)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs fraps.exe no specs fraps.exe fraps64.dat no specs

Process information

PID
CMD
Path
Indicators
Parent process
4328\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4512"C:\Fraps\fraps.exe" C:\Fraps\fraps.exeexplorer.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
MEDIUM
Description:
Fraps
Exit code:
3221226540
Version:
3, 5, 1, 14962
Modules
Images
c:\fraps\fraps.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4872C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5236"C:\Fraps\fraps.exe" C:\Fraps\fraps.exe
explorer.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
HIGH
Description:
Fraps
Version:
3, 5, 1, 14962
Modules
Images
c:\fraps\fraps.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6328"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Fraps 3.5.1 by izzedine2001.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6488C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wldp.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework64\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework64\v4.0.30319\fusion.dll
6552C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
6792"C:\Fraps\fraps64.dat"C:\Fraps\fraps64.datfraps.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
HIGH
Description:
Fraps
Version:
3, 5, 1, 14962
Modules
Images
c:\fraps\fraps64.dat
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
3 412
Read events
2 277
Write events
1 114
Delete events
21

Modification events

(PID) Process:(6488) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DB1D85A25786DB01981900003C1B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DB1D85A25786DB0198190000441B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DB1D85A25786DB0198190000B8190000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000DB1D85A25786DB0198190000B4190000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6488) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000D0D476A25786DB015819000084190000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6488) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000403879A25786DB0158190000181B0000E803000001000000000000000000000079E9FBA9FAD14240ADFDBE38F524EA4300000000000000000000000000000000
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
48000000000000009DE489A25786DB0198190000441B0000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(6552) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
10
Suspicious files
19
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
6488msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6488msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{a9fbe979-d1fa-4042-adfd-be38f524ea43}_OnDiskSnapshotPropbinary
MD5:419F0604D4895471FE8F74EBE55598A1
SHA256:2CCDA65F5BE6E53D65D88AF1AC5E5C8471A8F071696D09CCCEF31632C534464E
6488msiexec.exeC:\Windows\Installer\139f7f.msiexecutable
MD5:367DFAE030B688DEAE53E89D8C948450
SHA256:CF2006C0C991CBA12A6D112C2B8159AED2A69FFDD795F97C30A46FB2EBDDC6EC
6488msiexec.exeC:\Windows\Installer\MSIA2FA.tmpbinary
MD5:E7A0C648B487CBE7A0F7F97C3E4C763C
SHA256:BA357BC3FA8140C5D0FDC47D288994AE8CCB7163DE3789C4B266B8A2A405D34F
6488msiexec.exeC:\Windows\Temp\~DF68D52E5749B83D20.TMPbinary
MD5:0820D5BFB4DD96F28B3A220DF90030BB
SHA256:3D9B980213AE34E22B95A56F3E2DCEFA31DCCC84B1E6555D59E41D73987F48F7
6488msiexec.exeC:\Fraps\fraps64.datexecutable
MD5:AA210B339558CD4B09693F398075CEA7
SHA256:B63738DDF49032AB73EDF5527ABFF857E30E2C8C7C459FCCC0C77AE2D17D1D68
6488msiexec.exeC:\Fraps\frapslcd.dllexecutable
MD5:95253454DAD464D4E36EF1A0449A8AC4
SHA256:47A1958705781C2A5E47F1B73AD2439F5F3821B2E90F42B16206FFAF32AF1B79
6488msiexec.exeC:\Fraps\fraps64.dllexecutable
MD5:D65788ECA7960492167B1BEC6978D228
SHA256:DABEFA6FDBBFE702264D285EE281EA85904215128EE8C6091B046081A9F268A3
6488msiexec.exeC:\Fraps\fraps32.dllexecutable
MD5:A36E45106C6804572EA63F1A69C08C9A
SHA256:25E4C097E358088BB6A82687192073F7DE2BC05C3E7C6FF963FFD37F04271801
6488msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:0820D5BFB4DD96F28B3A220DF90030BB
SHA256:3D9B980213AE34E22B95A56F3E2DCEFA31DCCC84B1E6555D59E41D73987F48F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1356
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1356
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6700
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2040
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1572
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1356
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1356
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.16.204.161:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1356
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
20.190.160.132:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
  • 23.48.23.166
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
google.com
  • 142.250.186.46
whitelisted
www.bing.com
  • 2.16.204.161
  • 2.16.204.141
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.132
  • 40.126.32.72
  • 20.190.160.131
  • 40.126.32.138
  • 20.190.160.4
  • 20.190.160.67
  • 20.190.160.65
  • 20.190.160.64
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
No debug info