| File name: | apkcombovpn-x86-0.1.1.msi |
| Full analysis: | https://app.any.run/tasks/ea5a8186-1830-43d0-8c22-400512db1b3b |
| Verdict: | Malicious activity |
| Analysis date: | May 30, 2020, 01:23:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: APKCombo VPN: Fast, Modern, Secure VPN Tunnel, Author: APKCombo.com, Keywords: Installer, Comments: This installer database contains the logic and data required to install APKCombo VPN., Template: Intel;1033, Revision Number: {B2F6B482-5670-4F7A-B557-94116B5F789A}, Create Time/Date: Thu Apr 9 02:29:58 2020, Last Saved Time/Date: Thu Apr 9 02:29:58 2020, Number of Pages: 400, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 4 |
| MD5: | 3670C1D3595609CCC3DB00404652D8A5 |
| SHA1: | 1F27433DCC8CF58057EC0C8BFA97ABC4992943DE |
| SHA256: | DCC870BA4EB76D1F3B3F3BCC84CF4807709EB4C74BCD5BEC5C94723618A33CB9 |
| SSDEEP: | 98304:lvOFaSszWhQRYhgX6u8MVB6WFbay0bEiklTJPLk:l2FZ2WXhMVBpbaLAiQT |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | APKCombo VPN: Fast, Modern, Secure VPN Tunnel |
| Author: | APKCombo.com |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install APKCombo VPN. |
| Template: | Intel;1033 |
| RevisionNumber: | {B2F6B482-5670-4F7A-B557-94116B5F789A} |
| CreateDate: | 2020:04:09 01:29:58 |
| ModifyDate: | 2020:04:09 01:29:58 |
| Pages: | 400 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Security: | Read-only enforced |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2308 | "C:\Program Files\APKCombo VPN\apkcombovpn.exe" /installmanagerservice | C:\Program Files\APKCombo VPN\apkcombovpn.exe | apkcombovpn.exe | ||||||||||||
User: SYSTEM Company: WireGuard LLC Integrity Level: SYSTEM Description: APKCombo VPN: Fast, Modern, Secure VPN Tunnel Exit code: 0 Version: 0.1.1 Modules
| |||||||||||||||
| 2316 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{0b2f63fb-9158-5dfe-569f-6e1827730219} Global\{10a312e5-be62-5bf9-5cb4-501bf7f59745} C:\Windows\System32\DriverStore\Temp\{5ee22cc9-81e7-1740-ce17-123c2d44f97c}\wintun.inf C:\Windows\System32\DriverStore\Temp\{5ee22cc9-81e7-1740-ce17-123c2d44f97c}\wintun.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2432 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2504 | "C:\Program Files\APKCombo VPN\apkcombovpn.exe" /managerservice | C:\Program Files\APKCombo VPN\apkcombovpn.exe | — | services.exe | |||||||||||
User: SYSTEM Company: WireGuard LLC Integrity Level: SYSTEM Description: APKCombo VPN: Fast, Modern, Secure VPN Tunnel Exit code: 0 Version: 0.1.1 Modules
| |||||||||||||||
| 2576 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2908 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\apkcombovpn-x86-0.1.1.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2980 | C:\Windows\system32\MsiExec.exe -Embedding E1F12751D003A19942CB298118155CAC | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3772 | C:\Windows\system32\MsiExec.exe -Embedding DF03F8310F24B2C7F55700DD38ADCFD9 M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3864 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{39f52aea-c776-3690-a5b6-4f4bd92cb654}\wintun.inf" "0" "634301143" "0000055C" "WinSta0\Default" "00000558" "208" "C:\Windows\Temp\3ef887d2d76d770753025898634439591401c408474a1fc3cb4d027f15876ad4" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3872 | "C:\Program Files\APKCombo VPN\apkcombovpn.exe" /ui 580 576 588 596 | C:\Program Files\APKCombo VPN\apkcombovpn.exe | — | apkcombovpn.exe | |||||||||||
User: admin Company: WireGuard LLC Integrity Level: HIGH Description: APKCombo VPN: Fast, Modern, Secure VPN Tunnel Exit code: 0 Version: 0.1.1 Modules
| |||||||||||||||
| (PID) Process: | (2432) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000D40BD3E62036D6018009000034090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2432) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000D40BD3E62036D6018009000034090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2432) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 37 | |||
| (PID) Process: | (2432) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000060921AE72036D6018009000034090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2432) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000BAF41CE72036D60180090000F00F0000E803000001000000000000000000000075E3EBC592D2E342A71E9295B2721CDC0000000000000000 | |||
| (PID) Process: | (2576) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000227E26E72036D601100A0000B0030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2576) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000227E26E72036D601100A00005C0C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2576) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000227E26E72036D601100A0000600C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2576) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000227E26E72036D601100A00003C020000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2576) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000030A52DE72036D601100A00005C0C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2432 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Windows\Installer\MSI1333.tmp | — | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF7CC59B245A633C4E.TMP | — | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Windows\Installer\MSI14DB.tmp | — | |
MD5:— | SHA256:— | |||
| 2576 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Windows\Installer\MSI14BA.tmp | binary | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Windows\system32\wg.exe | executable | |
MD5:— | SHA256:— | |||
| 2432 | msiexec.exe | C:\Windows\Installer\MSI1598.tmp | executable | |
MD5:— | SHA256:— | |||
| 3772 | MsiExec.exe | C:\Windows\INF\setupapi.app.log | ini | |
MD5:— | SHA256:— | |||