| File name: | MacroGamer_v275_Setup.msi |
| Full analysis: | https://app.any.run/tasks/1b4851f0-dc9e-445c-b12f-37e533b38a76 |
| Verdict: | Malicious activity |
| Analysis date: | July 17, 2021, 08:35:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {A454F692-B52F-409A-88C4-05F22CABB303}, Title: Macro Gamer Setup, Author: iToady, Comments: MacroGamer is the free alternative to macro-enabled keyboards or hardware , Number of Words: 2, Last Saved Time/Date: Sat May 23 21:44:48 2020, Last Printed: Sat May 23 21:44:48 2020 |
| MD5: | F7A9D1BF05F8F0E2A1CC6CAFD0985070 |
| SHA1: | A9F931E9F7C8A7964D19AF9B5F938C2DBFCB44E4 |
| SHA256: | D82A1CFFC6E982B07C0AEF61B96B4C36EBD921949C9D4C45A31781539AE443E8 |
| SSDEEP: | 12288:mjDGPXXktIro8FAPUxv9gvIp2z92NFttMDWEzpS6P:mjDGPnkqc8FAM32z92TtwFS6P |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2020:05:23 20:44:48 |
|---|---|
| ModifyDate: | 2020:05:23 20:44:48 |
| Words: | 2 |
| Comments: | MacroGamer is the free alternative to macro-enabled keyboards or hardware |
| Keywords: | - |
| Author: | iToady |
| Subject: | - |
| Title: | Macro Gamer Setup |
| RevisionNumber: | {A454F692-B52F-409A-88C4-05F22CABB303} |
| Pages: | 200 |
| Template: | Intel;1033 |
| CodePage: | Windows Latin 1 (Western European) |
| Security: | Password protected |
| Software: | Windows Installer |
| CreateDate: | 1999:06:21 07:00:00 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2140 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\MacroGamer_v275_Setup.msi" | C:\Windows\System32\msiexec.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2316 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3796 | "C:\Users\admin\Documents\MacroGamer\MacroGamer.exe" | C:\Users\admin\Documents\MacroGamer\MacroGamer.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3, 2, 4, 9 Modules
| |||||||||||||||
| 4028 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (4028) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009864FCC3E67AD701BC0F0000D40B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4028) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009864FCC3E67AD701BC0F0000D40B0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4028) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 67 | |||
| (PID) Process: | (4028) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000403952C4E67AD701BC0F0000D40B0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4028) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000009A9B54C4E67AD701BC0F00005C0B0000E803000001000000000000000000000098C7173854B8274CA157927646857A7D0000000000000000 | |||
| (PID) Process: | (2316) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8C25BC4E67AD7010C090000740D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2316) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8C25BC4E67AD7010C090000B4090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2316) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8C25BC4E67AD7010C09000090090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2316) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A8C25BC4E67AD7010C090000BC0D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2316) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000002255EC4E67AD7010C090000740D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4028 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{3817c798-b854-4c27-a157-927646857a7d}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Windows\Installer\135111.msi | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFB0DFCDA1376F936F.TMP | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Windows\Installer\135112.ipi | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Windows\Installer\MSI547C.tmp | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Users\admin\Documents\MacroGamer\scancodes.dat | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Users\admin\Documents\MacroGamer\mgconfig.dat | — | |
MD5:— | SHA256:— | |||
| 4028 | msiexec.exe | C:\Users\admin\Documents\MacroGamer\MacrosEnabled.wav | — | |
MD5:— | SHA256:— | |||