| File name: | Printer DCA 4.3.0.25513.msi |
| Full analysis: | https://app.any.run/tasks/6de637bd-2a03-4007-b9df-bc66cf585ba4 |
| Verdict: | Malicious activity |
| Analysis date: | February 22, 2019, 15:05:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {EA22128A-BB2E-4CA0-A407-8BAEA8C1BCF7}, Number of Words: 2, Subject: Printer DCA, Author: PrintFleet Inc., Name of Creating Application: Advanced Installer 10.7 build 53797, Template: ;1033, Comments: This installer database contains the logic and data required to install Printer DCA. |
| MD5: | 32CF8EE588787E3F5979FEBDA6E05F53 |
| SHA1: | C9DF930D8779FBA1B345455937ECEE099BA5A466 |
| SHA256: | DAB8D98FC22E0B68EEF4CBC69F3A637522C9DE1558C76CC562636AB1F1E79736 |
| SSDEEP: | 196608:RXvBbSceEMjphT1giNvY/GmGSSzbxnqTACgRw5X2e5N8VsfnWYD2BE:BvBmcRMjphLdYVGhbJqT4KX2OrWR |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| Title: | Installation Database |
|---|---|
| Keywords: | Installer, MSI, Database |
| LastPrinted: | 2009:12:11 11:47:44 |
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2009:12:11 11:47:44 |
| Pages: | 200 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {EA22128A-BB2E-4CA0-A407-8BAEA8C1BCF7} |
| Words: | 2 |
| Subject: | Printer DCA |
| Author: | PrintFleet Inc. |
| LastModifiedBy: | - |
| Software: | Advanced Installer 10.7 build 53797 |
| Template: | ;1033 |
| Comments: | This installer database contains the logic and data required to install Printer DCA. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1016 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\yhpelyej.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | — | PrinterDCA.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 1148 | C:\Windows\system32\MsiExec.exe -Embedding 49B1B6C75652C00E0329A833BBA07410 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2128 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES8896.tmp" "c:\Users\admin\AppData\Local\Temp\CSC8895.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 2148 | "C:\Program Files\Printer DCA\PrinterDCA.exe" | C:\Program Files\Printer DCA\PrinterDCA.exe | — | MsiExec.exe | |||||||||||
User: admin Company: PrintFleet Inc Integrity Level: MEDIUM Description: Printer DCA Exit code: 3221226540 Version: 4.3.0.25513 Modules
| |||||||||||||||
| 2276 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003E4" "000004A4" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2696 | C:\Windows\system32\MsiExec.exe -Embedding AA15461F5186C56E4DC12E27C95CD9B1 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2820 | C:\Windows\system32\wbem\WmiApSrv.exe | C:\Windows\system32\wbem\WmiApSrv.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: WMI Performance Reverse Adapter Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3052 | "C:\Program Files\Printer DCA\PrinterDCA.exe" | C:\Program Files\Printer DCA\PrinterDCA.exe | MsiExec.exe | ||||||||||||
User: admin Company: PrintFleet Inc Integrity Level: HIGH Description: Printer DCA Exit code: 0 Version: 4.3.0.25513 Modules
| |||||||||||||||
| 3252 | C:\Windows\system32\MsiExec.exe -Embedding D0D4A7F3E9D0245E5903BB43A417B2DC C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3536 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3632) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3632) msiexec.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA |
| Operation: | write | Name: | Blob |
Value: 0300000001000000140000008AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8040000000100000010000000FF5FBC4290FA389E798467EBD7AE940B0F0000000100000014000000C45627B5584BF62327DF60D6185744A2D2F2BCBF190000000100000010000000E843AC3B52EC8C297FA948C9B1FB281918000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C200000000100000088040000308204843082036CA0030201020210421AF2940984191F520A4BC62426A74B300D06092A864886F70D0101050500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3035303630373038303931305A170D3230303533303130343833385A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D8300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D010105050003820101004D422FA6C18AEB07809058468CF81939662A3C5A2C6DCFD4D987558D790B12887B408FD5C7F84B8D551663ADB757DC3B2BBDD3C14F1E03874B449BE3E2404526F326492B6A84F1547AD442DAFCD36ABB667ECA9EEAE9BBDC07C7C3924E833C81499F92D53209EA492EA111719A36D2C54E68B6CB0E1B2516AF6CDE5D76D81F72B193268617DB18DEAF45E9DFFB98AF1418EDA45EF6899445F055044ADDFF27DD064A40F6B4BCF1E40F9902BBFD5D0E2E28C1BE3B5F1A3F971084BC163ED8A39C631D66CB5C5FDA3EF30F0A093522DBDBC03F00F9E60D5D67D1FDA01E032BD940F7BECC87665480A6A3B8F51962D5D226B19826EE9ACB44A7455A8195151AF551 | |||
| (PID) Process: | (3536) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009442B80FC0CAD401D00D0000740E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3536) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009442B80FC0CAD401D00D0000740E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3536) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (3536) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000020C9FF0FC0CAD401D00D0000740E0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3536) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007A2B0210C0CAD401D00D0000F40C0000E80300000100000000000000000000001865D39718F325469110D88AD9EDD8A00000000000000000 | |||
| (PID) Process: | (3572) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A4A01710C0CAD401F40D000078090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A4A01710C0CAD401F40D0000640D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3572) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A4A01710C0CAD401F40D0000680D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEDFB.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEE69.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEEA9.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEEC9.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEEE9.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI33D.tmp | — | |
MD5:— | SHA256:— | |||
| 3632 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI34E.tmp | — | |
MD5:— | SHA256:— | |||
| 3536 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3536 | msiexec.exe | C:\Windows\Installer\1b3768.msi | — | |
MD5:— | SHA256:— | |||
| 3536 | msiexec.exe | C:\Windows\Installer\MSI3F58.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3632 | msiexec.exe | GET | 200 | 91.199.212.52:80 | http://crt.usertrust.com/UTNAddTrustObject_CA.crt | GB | der | 1.13 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3632 | msiexec.exe | 91.199.212.52:80 | crt.usertrust.com | Comodo CA Ltd | GB | suspicious |
Domain | IP | Reputation |
|---|---|---|
crt.usertrust.com |
| whitelisted |
Process | Message |
|---|---|
PrinterDCA.exe | 2019-02-22 15:06:04.3415 STARTUP **** C:\Program Files\Printer DCA\PrinterDCA.exe running on USER-PC as USER-PC\admin, PID 3052 ****
|
PrinterDCA.exe | 2019-02-22 15:06:04.3415 STARTUP **** C:\Program Files\Printer DCA\PrinterDCA.exe running on USER-PC as USER-PC\admin, PID 3052 ****
|
PrinterDCA.exe |