File name:

AcroPro.msi

Full analysis: https://app.any.run/tasks/c4eb13e8-e95b-485c-8c0b-bb91b1892828
Verdict: Malicious activity
Analysis date: October 21, 2023, 10:55:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Number of Characters: 0, Create Time/Date: Tue Mar 17 01:37:30 2015, Last Printed: Tue Mar 17 01:37:30 2015, Code page: 0, Name of Creating Application: MSI Editor, Title: Adobe Acrobat Installer Project, Subject: Installers, Author: Adobe Systems Incorporated, Keywords: Installer,MSI,Database, Comments: Contact: Your local administrator, Template: Intel;0,1033,1036,1031,2052,1028,1029,1030,1043,1035,1038,1040,1041,1042,1044,1045,1046,1049,1051,1060,1034,1053,1055,1058, Last Saved By: Administrator, Revision Number: {2BD64BE4-DC95-47D3-B274-C500F9C38C20}, Last Saved Time/Date: Wed Mar 18 06:26:59 2020, Number of Pages: 300, Number of Words: 2, Security: 2
MD5:

32D080435936DD4BB951EBB829A99D6B

SHA1:

BD4EA4F9CE16899C969CE02B2C1754E1E51EECDB

SHA256:

DA96E7F934F247E75192C54136C18F3AB0E2E7B7CAF00974B787BF94686D3B65

SSDEEP:

196608:Pld+rSrMlpzEEPjyr/lHsxTwaD56GQtp2kA:ju+IpzEEPOJHNRI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 3464)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 2076)
      • msiexec.exe (PID: 3296)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 2828)
      • spoolsv.exe (PID: 2616)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 3464)
      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 3296)
      • msiexec.exe (PID: 2076)
    • Reads the computer name

      • msiexec.exe (PID: 3464)
      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 3296)
      • msiexec.exe (PID: 2076)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 3464)
      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 3296)
      • msiexec.exe (PID: 2076)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1896)
      • msiexec.exe (PID: 3464)
      • msiexec.exe (PID: 3296)
      • msiexec.exe (PID: 1824)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 1824)
    • Application launched itself

      • msiexec.exe (PID: 3464)
    • Executes as Windows Service

      • SearchIndexer.exe (PID: 576)
    • Creates files in the program directory

      • SearchIndexer.exe (PID: 576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (82)
.mst | Windows SDK Setup Transform Script (9.2)
.ppt | Microsoft PowerPoint document (4.6)
.doc | Microsoft Word document (old ver.) (2.8)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Security: Read-only recommended
Words: 2
Pages: 300
ModifyDate: 2020:03:18 06:26:59
RevisionNumber: {2BD64BE4-DC95-47D3-B274-C500F9C38C20}
LastModifiedBy: Administrator
Template: Intel;0,1033,1036,1031,2052,1028,1029,1030,1043,1035,1038,1040,1041,1042,1044,1045,1046,1049,1051,1060,1034,1053,1055,1058
Comments: Contact: Your local administrator
Keywords: Installer,MSI,Database
Author: Adobe Systems Incorporated
Subject: Installers
Title: Adobe Acrobat Installer Project
Software: MSI Editor
CodePage: Unknown (0)
LastPrinted: 2015:03:17 01:37:30
CreateDate: 2015:03:17 01:37:30
Characters: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
12
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs rundll32.exe no specs searchindexer.exe no specs spoolsv.exe no specs searchprotocolhost.exe no specs searchfilterhost.exe no specs searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
576C:\Windows\system32\SearchIndexer.exe /EmbeddingC:\Windows\System32\SearchIndexer.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Indexer
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\searchindexer.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1824"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\AcroPro.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1896C:\Windows\system32\MsiExec.exe -Embedding 9F20C0BBDC38DF6EFC56C4CE49A7B215 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2076C:\Windows\system32\MsiExec.exe -Embedding CF7DC004DF523F21B75F83DBA0DD85A3 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2616C:\Windows\System32\spoolsv.exeC:\Windows\System32\spoolsv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Spooler SubSystem App
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2828C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3296C:\Windows\system32\MsiExec.exe -Embedding B6ADC759A000424D54F351C9F8B28FDBC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3464C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3500"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528 C:\Windows\System32\SearchFilterHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Search Filter Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchfilterhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
11 897
Read events
9 407
Write events
258
Delete events
2 232

Modification events

(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
72
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3464) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:FirstRun
Value:
0
Executable files
49
Suspicious files
23
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1896msiexec.exeC:\Users\admin\AppData\Local\Temp\{AC76BA86-1033-FFFF-7760-0C0F074E4100}\AcrobatTrial.sifbinary
MD5:2B130B52F04A04D0910F1C9BF77B4265
SHA256:80D899EE87EEBD885E686594522EB12884D2769C01F625FCAB32E59E055047C2
1896msiexec.exeC:\Users\admin\AppData\Local\Temp\{AC76BA86-1033-FFFF-7760-0C0F074E4100}\AcrobatETLA.sifbinary
MD5:BEFBC2FDE21B5160236CBFA13950D906
SHA256:3AEFC9FF93341225EB493B939D995202AC99430F1066F8E8761A939491E77899
3464msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3464msiexec.exeC:\Windows\Installer\1f0047.msi
MD5:
SHA256:
1896msiexec.exeC:\Users\admin\AppData\Local\Temp\{AC76BA86-1033-FFFF-7760-0C0F074E4100}\AcrobatDistiller.sifbinary
MD5:87A7D1E04F32810FEB9B7F25814E1C85
SHA256:5EFA98F4E91654A27F272F7DA31744B0E4E706F5F852451CB81B78C28FDACEA5
1824msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICB0E.tmpexecutable
MD5:C23D4D5A87E08F8A822AD5A8DBD69592
SHA256:6D149866246E79919BDE5A0B45569EA41327C32EE250F37AD8216275A641BB27
1824msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICB8C.tmpexecutable
MD5:EDB88AFFFFD67BCA3523B41D3E2E4810
SHA256:4C3D85E7C49928AF0F43623DCBED474A157EF50AF3CBA40B7FD7AC3FE3DF2F15
1824msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICDA5.tmpexecutable
MD5:E9415999BED44E0DBA8890E0266D001D
SHA256:313E9370C1FB265E6C00B6BE5B18943FDA442F71318A8C7376B587687175848B
1824msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICD37.tmpexecutable
MD5:0A1FF857861E224ABCC9A13F250C2588
SHA256:B32AF71309C32812A0FB7E7583DEB1A2ABF127C7BDF7312B9C326F9555687570
1824msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICE92.tmpexecutable
MD5:0E91605EE2395145D077ADB643609085
SHA256:5472237B0947D129AB6AD89B71D8E007FD5C4624E97AF28CD342919BA0D5F87B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info