File name:

Unlocker 1.9.2.msi

Full analysis: https://app.any.run/tasks/f5243ab2-6adf-4cc2-b3ec-c4f1b974b5fb
Verdict: Malicious activity
Analysis date: February 11, 2022, 00:31:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {03C0EE01-6D1B-4608-83F0-FE6D05453470}, Number of Words: 2, Subject: Unlocker, Author: ajua Custom Installers, Name of Creating Application: Advanced Installer 10.8 build 54215, Template: ;1033, Comments: This installer database contains the logic and data required to install Unlocker.
MD5:

16BE23C2EBBC5D09F9B6195442E2B8B0

SHA1:

5BAD902B7F4A4B12A41834377BA650AE4903B3A6

SHA256:

D90946212DA87CA31CCF155D55C3057812474F3D8D739D681013CBA79B526DA9

SSDEEP:

3072:wk4R1h9F3DzY5A/Yy+r+GaRJSVhyLCukMcB3RUN46ILJ9+ZB5yOfnA2HXHrBcgEQ:wk4t3DzY5A6iAiLd7rU2HXHrBcgXEH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • msiexec.exe (PID: 3840)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 452)
      • MsiExec.exe (PID: 3360)
  • SUSPICIOUS

    • Executed as Windows Service

      • msiexec.exe (PID: 1940)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
    • Application launched itself

      • msiexec.exe (PID: 1940)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
    • Creates files in the program directory

      • msiexec.exe (PID: 1940)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1940)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 1940)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
      • MsiExec.exe (PID: 452)
      • MsiExec.exe (PID: 3360)
    • Checks supported languages

      • msiexec.exe (PID: 3840)
      • msiexec.exe (PID: 1940)
      • MsiExec.exe (PID: 452)
      • MsiExec.exe (PID: 3360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Comments: This installer database contains the logic and data required to install Unlocker.
Template: ;1033
Software: Advanced Installer 10.8 build 54215
LastModifiedBy: -
Author: ajua Custom Installers
Subject: Unlocker
Words: 2
RevisionNumber: {03C0EE01-6D1B-4608-83F0-FE6D05453470}
CodePage: Windows Latin 1 (Western European)
Security: None
Pages: 200
ModifyDate: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
LastPrinted: 2009:12:11 11:47:44
Keywords: Installer, MSI, Database
Title: Installation Database
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
452C:\Windows\system32\MsiExec.exe -Embedding D9715E86D72081184D85AA53292459CE CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1940C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3360C:\Windows\system32\MsiExec.exe -Embedding A4E8A138422707C027D40356F519A316C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3840"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Unlocker 1.9.2.msi"C:\Windows\System32\msiexec.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 519
Read events
2 426
Write events
81
Delete events
12

Modification events

(PID) Process:(1940) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
94070000263463BEDE1ED801
(PID) Process:(1940) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
5DEFE117A81C26DBF371848B4064705498E63FD685C43A71B032CFED95374791
(PID) Process:(1940) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\12dbb3.ipi
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\12dbb4.rbs
Value:
30940894
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\12dbb4.rbsLow
Value:
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E80FCEE7B89FE894EA29F6E347B62ED7
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files\Unlocker\Unlocker.exe
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1A3EC7766A876A4E9128C8A6078D518
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files\Unlocker\UnlockerDriver5.sys
(PID) Process:(1940) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51BE7D777CD958C4CABC752FDA60008C
Operation:writeName:D52A7755EF4EBFB46A060E7D66CBE4DD
Value:
C:\Program Files\Unlocker\UnlockerInject32.exe
Executable files
11
Suspicious files
4
Text files
1
Unknown types
4

Dropped files

PID
Process
Filename
Type
1940msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF5430CEFF32177C53.TMPgmc
MD5:
SHA256:
1940msiexec.exeC:\Windows\Installer\MSIDF3E.tmpbinary
MD5:
SHA256:
1940msiexec.exeC:\Windows\Installer\12dbb3.ipibinary
MD5:
SHA256:
1940msiexec.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unlocker.lnklnk
MD5:
SHA256:
3840msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC953.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
1940msiexec.exeC:\Windows\Installer\12dbb2.msiexecutable
MD5:16BE23C2EBBC5D09F9B6195442E2B8B0
SHA256:D90946212DA87CA31CCF155D55C3057812474F3D8D739D681013CBA79B526DA9
3840msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICA02.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
3840msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC993.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
1940msiexec.exeC:\Windows\Installer\MSIDED0.tmpexecutable
MD5:8B81E44843E040D453367B14DC6BFF5F
SHA256:FB0FA49DED0077017E58C2C43E7EC60C3E604C763616CE8D198D420261373DFB
1940msiexec.exeC:\Program Files\Unlocker\UnlockerDriver5.sysexecutable
MD5:9DC07E73A4ABB9ACF692113B36A5009F
SHA256:CA7176FC219515D58DCFA66EC61880ECE5617275C9B83701BB74D8B60E733D34
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info