File name:

AutodeskScanWin.msi

Full analysis: https://app.any.run/tasks/027cb8b7-f84c-4fea-bd6f-7c792f1e80fb
Verdict: Malicious activity
Analysis date: May 21, 2020, 04:30:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: ScanWin, Author: Autodesk, Keywords: Installer, Comments: This installer database contains the logic and data required to install ScanWin., Template: Intel;1033, Revision Number: {90B94755-1D21-4EDF-A3FD-2347D63D9D91}, Create Time/Date: Fri Apr 24 14:22:40 2020, Last Saved Time/Date: Fri Apr 24 14:22:40 2020, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2
MD5:

F8E07CAC7A5A3B631DBE7821667A4A2F

SHA1:

2F406F70CCA8B3B42D6639F4DEC6B72058DE6F74

SHA256:

D52430FB7805AE2D43ADDB1618F08A7AC859C2B6A9BDC8BF164A9927465D550C

SSDEEP:

49152:lzRtJ4eJyViUdQyHKHwIu4oHEEbvncQyH7tkz2:ZTJ4YyViPqKHru4oHEEvtz2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ScanWinViewer.exe (PID: 3728)
      • ScanWinViewer.exe (PID: 2880)
      • ScanWin.exe (PID: 312)
      • ScanWin.exe (PID: 3424)
    • Loads dropped or rewritten executable

      • ScanWinViewer.exe (PID: 2880)
      • ScanWin.exe (PID: 3424)
      • ScanWin.exe (PID: 312)
  • SUSPICIOUS

    • Executed via WMI

      • cmd.exe (PID: 2776)
      • cmd.exe (PID: 1604)
    • Creates files in the program directory

      • cmd.exe (PID: 2776)
      • ScanWin.exe (PID: 312)
  • INFO

    • Manual execution by user

      • ScanWinViewer.exe (PID: 3728)
      • ScanWinViewer.exe (PID: 2880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: ScanWin
Author: Autodesk
Keywords: Installer
Comments: This installer database contains the logic and data required to install ScanWin.
Template: Intel;1033
RevisionNumber: {90B94755-1D21-4EDF-A3FD-2347D63D9D91}
CreateDate: 2020:04:24 13:22:40
ModifyDate: 2020:04:24 13:22:40
Pages: 200
Words: 2
Software: Windows Installer XML Toolset (3.11.1.2318)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs scanwinviewer.exe no specs scanwinviewer.exe scanwin.exe no specs cmd.exe no specs cmd.exe no specs scanwin.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"ScanWin.exe" /iprange=127.0.0.1-127.0.0.1 /rp /fp /sl /lu /output="C:\ProgramData\Autodesk\ScanWin\Output"C:\Program Files\Autodesk\ScanWin\ScanWin.exeScanWinViewer.exe
User:
admin
Company:
License Dashboard
Integrity Level:
HIGH
Description:
ScanWin
Exit code:
0
Version:
2.0.8.7
Modules
Images
c:\program files\autodesk\scanwin\scanwin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1464"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AutodeskScanWin.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1604cmd /c C:\ProgramData\User_Subscriptions.cmdC:\Windows\system32\cmd.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2776cmd /c C:\ProgramData\Installer_Helper.cmdC:\Windows\system32\cmd.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2880"C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exe" C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exe
explorer.exe
User:
admin
Company:
License Dashboard
Integrity Level:
HIGH
Description:
ScanWin Viewer
Exit code:
0
Version:
2.0.8.7
Modules
Images
c:\program files\autodesk\scanwin\scanwinviewer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3424"ScanWin.exe" /output="C:\Users\admin\Documents\AutodeskProducts.csv" /exportC:\Program Files\Autodesk\ScanWin\ScanWin.exeScanWinViewer.exe
User:
admin
Company:
License Dashboard
Integrity Level:
HIGH
Description:
ScanWin
Exit code:
0
Version:
2.0.8.7
Modules
Images
c:\program files\autodesk\scanwin\scanwin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3728"C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exe" C:\Program Files\Autodesk\ScanWin\ScanWinViewer.exeexplorer.exe
User:
admin
Company:
License Dashboard
Integrity Level:
MEDIUM
Description:
ScanWin Viewer
Exit code:
3221226540
Version:
2.0.8.7
Modules
Images
c:\program files\autodesk\scanwin\scanwinviewer.exe
c:\systemroot\system32\ntdll.dll
Total events
770
Read events
708
Write events
59
Delete events
3

Modification events

(PID) Process:(1464) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
ScanWinViewer.exe
(PID) Process:(312) ScanWin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(312) ScanWin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
Operation:writeName:1
Value:
5300630061006E00570069006E005600690065007700650072002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0200000001000000000000000A00000007000000090000000800000006000000030000000500000004000000FFFFFFFF
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
Operation:writeName:MRUListEx
Value:
0000000001000000FFFFFFFF
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg
Operation:writeName:TV_FolderType
Value:
{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}
(PID) Process:(2880) ScanWinViewer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg
Operation:writeName:TV_TopViewID
Value:
{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
Executable files
0
Suspicious files
1
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
312ScanWin.exeC:\ProgramData\User_Subscriptions.cmdtext
MD5:
SHA256:
3424ScanWin.exeC:\Users\admin\Documents\AutodeskProducts.csv-NFO.txttext
MD5:
SHA256:
312ScanWin.exeC:\ProgramData\Autodesk\ScanWin\DataStore.xml.md5text
MD5:
SHA256:
312ScanWin.exeC:\ProgramData\Autodesk\ScanWin\DataStore.xmlxml
MD5:
SHA256:
312ScanWin.exeC:\ProgramData\Autodesk\ScanWin\Output-NFO.txttext
MD5:
SHA256:
3424ScanWin.exeC:\Users\admin\Documents\AutodeskProducts.xlsxdocument
MD5:
SHA256:
2776cmd.exeC:\ProgramData\ScanWin_AdskLicenseHelper.jsontext
MD5:06CDBF01E1FF209EE054FA3F3C88B1C7
SHA256:6002E5EEEFC5B695E753A51F24A04C550EE5789FF49E6A8F9AA87CC3D2C1034F
312ScanWin.exeC:\ProgramData\Installer_Helper.cmdtext
MD5:6647A0865DFBB1F54ABDC9821817D8B9
SHA256:51EE9920146190810CB9BEC1AD8812A78DF1CDAE2F17FC0A910E737054A90E05
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info