File name:

Unlocker-1.9.2.msi

Full analysis: https://app.any.run/tasks/197172d4-dbae-46e9-a512-268939bcd25d
Verdict: Malicious activity
Analysis date: April 02, 2025, 05:17:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
unlocker
softmany
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {03C0EE01-6D1B-4608-83F0-FE6D05453470}, Number of Words: 2, Subject: Unlocker, Author: ajua Custom Installers, Name of Creating Application: Advanced Installer 10.8 build 54215, Template: ;1033, Comments: This installer database contains the logic and data required to install Unlocker.
MD5:

16BE23C2EBBC5D09F9B6195442E2B8B0

SHA1:

5BAD902B7F4A4B12A41834377BA650AE4903B3A6

SHA256:

D90946212DA87CA31CCF155D55C3057812474F3D8D739D681013CBA79B526DA9

SSDEEP:

12288:V8/bkWFxtLtOxFVvTkrMAOSDxUzuMrWHl2sqBBp:V8/bkWF+TkrM/znSHl2sqBBp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 5548)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5548)
    • Creates or modifies Windows services

      • Unlocker.exe (PID: 8140)
    • Reads security settings of Internet Explorer

      • Unlocker.exe (PID: 8140)
      • Unlocker.exe (PID: 7600)
    • Executable content was dropped or overwritten

      • Unlocker.exe (PID: 7600)
  • INFO

    • An automatically generated document

      • msiexec.exe (PID: 2284)
    • Checks supported languages

      • msiexec.exe (PID: 4812)
      • msiexec.exe (PID: 5548)
      • msiexec.exe (PID: 7644)
      • Unlocker.exe (PID: 8140)
      • Unlocker.exe (PID: 7600)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2284)
      • msiexec.exe (PID: 5548)
    • Reads the computer name

      • msiexec.exe (PID: 5548)
      • msiexec.exe (PID: 4812)
      • msiexec.exe (PID: 7644)
      • Unlocker.exe (PID: 8140)
      • Unlocker.exe (PID: 7600)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5548)
    • Manual execution by a user

      • Unlocker.exe (PID: 8088)
      • Unlocker.exe (PID: 8140)
      • Unlocker.exe (PID: 7316)
      • Unlocker.exe (PID: 7600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Title: Installation Database
Keywords: Installer, MSI, Database
LastPrinted: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
ModifyDate: 2009:12:11 11:47:44
Pages: 200
Security: None
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {03C0EE01-6D1B-4608-83F0-FE6D05453470}
Words: 2
Subject: Unlocker
Author: ajua Custom Installers
LastModifiedBy: -
Software: Advanced Installer 10.8 build 54215
Template: ;1033
Comments: This installer database contains the logic and data required to install Unlocker.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs sppextcomobj.exe no specs slui.exe no specs msiexec.exe no specs unlocker.exe no specs unlocker.exe unlocker.exe no specs unlocker.exe

Process information

PID
CMD
Path
Indicators
Parent process
2284"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\Unlocker-1.9.2.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4812C:\Windows\syswow64\MsiExec.exe -Embedding 247DCA25E843A9FD198B7A3010653513 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5548C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7316"C:\Program Files (x86)\Unlocker\Unlocker.exe" C:\Program Files (x86)\Unlocker\Unlocker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\program files (x86)\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
7324C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7356"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7600"C:\Program Files (x86)\Unlocker\Unlocker.exe" C:\Program Files (x86)\Unlocker\Unlocker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
7644C:\Windows\syswow64\MsiExec.exe -Embedding B97417C520E188145AE7840FFB8761E3C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
8088"C:\Program Files (x86)\Unlocker\Unlocker.exe" C:\Program Files (x86)\Unlocker\Unlocker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\program files (x86)\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
8140"C:\Program Files (x86)\Unlocker\Unlocker.exe" C:\Program Files (x86)\Unlocker\Unlocker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\program files (x86)\unlocker\unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
Total events
5 620
Read events
5 496
Write events
105
Delete events
19

Modification events

(PID) Process:(5548) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
AC150000BB23C2938EA3DB01
(PID) Process:(5548) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
3EFEB7C422E07DF9B2C093D5D90957082FBE795543A4D3FC07A36ACAADF1CCE7
(PID) Process:(5548) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10d804.rbs
Value:
31171470
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\10d804.rbsLow
Value:
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E80FCEE7B89FE894EA29F6E347B62ED7
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files (x86)\Unlocker\Unlocker.exe
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1A3EC7766A876A4E9128C8A6078D518
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files (x86)\Unlocker\UnlockerDriver5.sys
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51BE7D777CD958C4CABC752FDA60008C
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files (x86)\Unlocker\UnlockerInject32.exe
(PID) Process:(5548) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files (x86)\Unlocker\
Value:
Executable files
12
Suspicious files
33
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
5548msiexec.exeC:\Windows\Installer\10d803.msiexecutable
MD5:16BE23C2EBBC5D09F9B6195442E2B8B0
SHA256:D90946212DA87CA31CCF155D55C3057812474F3D8D739D681013CBA79B526DA9
2284msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIBE50.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
5548msiexec.exeC:\Windows\Installer\MSID9E7.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
2284msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC096.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
2284msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIBF1D.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
5548msiexec.exeC:\Windows\Temp\~DF57190CF7367BE205.TMPbinary
MD5:E8B1FC32F23AA043776AE0794E2D1F9D
SHA256:6761C3503FD7B844F6156585EC2D5CDCFCCD8956CC64A030719C3B515FDAE5E8
5548msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:E8B1FC32F23AA043776AE0794E2D1F9D
SHA256:6761C3503FD7B844F6156585EC2D5CDCFCCD8956CC64A030719C3B515FDAE5E8
5548msiexec.exeC:\Windows\Installer\MSIDB12.tmpbinary
MD5:38271CE4F38EA1268D032B0368B644F4
SHA256:FD3BC5D2B85BE3DF4294870AE51F8C7AF239DE8472011ADD982F2CCC2B72BFE4
2284msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIBFC9.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
5548msiexec.exeC:\Windows\Installer\MSIDAA3.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
35
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6572
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6572
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2924
SearchApp.exe
104.126.37.161:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2924
SearchApp.exe
204.79.197.222:443
fp.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.3
  • 20.190.160.4
  • 40.126.32.138
  • 20.190.160.64
  • 20.190.160.14
  • 20.190.160.17
  • 20.190.160.67
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
www.bing.com
  • 104.126.37.161
  • 104.126.37.131
  • 104.126.37.162
  • 104.126.37.145
  • 104.126.37.153
  • 104.126.37.163
  • 104.126.37.139
  • 104.126.37.137
  • 104.126.37.136
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted
th.bing.com
  • 104.126.37.179
  • 104.126.37.137
  • 104.126.37.130
  • 104.126.37.153
  • 104.126.37.139
  • 104.126.37.145
  • 104.126.37.185
  • 104.126.37.155
  • 104.126.37.123
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info