File name:

9D8AA271.msi

Full analysis: https://app.any.run/tasks/a051f562-5b79-469f-850d-ada3c8bfff7b
Verdict: Malicious activity
Analysis date: June 14, 2021, 05:32:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Security: 0, Code page: 936, Revision Number: {E7685123-7C7F-4AA4-B355-2D9B02653510}, Number of Words: 2, Subject: F4RaF, Author: F4RaF, Name of Creating Application: Advanced Installer 16.5 build 8df7ad95, Template: ;2052, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5:

46614F3C20662D3DC83479421C022F92

SHA1:

81D6C22C0E97EC46566747D0AA6ADED289422FC0

SHA256:

DD5A03ED5C86516BC202CC0DE9EB995C97B46CB5E73CA4CECB3590FD55FBC622

SSDEEP:

24576:FUuDXXNoe04BMeRocDP1Nz4lDhkPTG4Mcgiwkew8vroUQGDXDNSnf6BlMRUT:FdXdgi5oo+FeBRSw8vlQIzNSnf6y4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • msiexec.exe (PID: 3128)
  • SUSPICIOUS

    • Executed as Windows Service

      • msiexec.exe (PID: 3128)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 1904)
      • msiexec.exe (PID: 3128)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 1904)
      • msiexec.exe (PID: 3128)
    • Application launched itself

      • msiexec.exe (PID: 3128)
    • Reads Environment values

      • netsh.exe (PID: 2660)
      • netsh.exe (PID: 1020)
      • netsh.exe (PID: 1936)
      • netsh.exe (PID: 1244)
      • netsh.exe (PID: 2692)
      • netsh.exe (PID: 2356)
      • netsh.exe (PID: 1624)
      • netsh.exe (PID: 3632)
      • netsh.exe (PID: 1852)
      • netsh.exe (PID: 2820)
      • netsh.exe (PID: 4040)
      • netsh.exe (PID: 1020)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3128)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 3128)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3128)
    • Uses NETSH.EXE for network configuration

      • MsiExec.exe (PID: 2696)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 3128)
    • Creates or modifies windows services

      • netsh.exe (PID: 1020)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 1904)
      • msiexec.exe (PID: 3128)
      • MsiExec.exe (PID: 1320)
      • MsiExec.exe (PID: 2696)
      • netsh.exe (PID: 2660)
      • netsh.exe (PID: 1244)
      • netsh.exe (PID: 2692)
      • netsh.exe (PID: 1020)
      • netsh.exe (PID: 1936)
      • netsh.exe (PID: 2356)
      • netsh.exe (PID: 1624)
      • netsh.exe (PID: 3632)
      • netsh.exe (PID: 1852)
      • netsh.exe (PID: 2820)
      • netsh.exe (PID: 4040)
      • netsh.exe (PID: 1020)
    • Checks supported languages

      • msiexec.exe (PID: 1904)
      • msiexec.exe (PID: 3128)
      • netsh.exe (PID: 2660)
      • netsh.exe (PID: 1020)
      • MsiExec.exe (PID: 1320)
      • MsiExec.exe (PID: 2696)
      • netsh.exe (PID: 2692)
      • netsh.exe (PID: 1936)
      • netsh.exe (PID: 1244)
      • netsh.exe (PID: 2356)
      • netsh.exe (PID: 1624)
      • netsh.exe (PID: 3632)
      • netsh.exe (PID: 1852)
      • netsh.exe (PID: 2820)
      • netsh.exe (PID: 4040)
      • netsh.exe (PID: 1020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.mst | Windows SDK Setup Transform Script (88.7)
.msi | Microsoft Installer (100)

EXIF

FlashPix

Pages: 200
Keywords: Installer, MSI, Database
Title: Installation Database
Comments: -
Template: ;2052
Software: Advanced Installer 16.5 build 8df7ad95
LastModifiedBy: -
Author: F4RaF
Subject: F4RaF
Words: 2
RevisionNumber: {E7685123-7C7F-4AA4-B355-2D9B02653510}
CodePage: Windows Simplified Chinese (PRC, Singapore)
Security: None
ModifyDate: 2009:12:11 11:47:44
CreateDate: 2009:12:11 11:47:44
LastPrinted: 2009:12:11 11:47:44
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
16
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020"C:\Windows\System32\netsh.exe" ipsec static add policy name=qianyeC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1020"C:\Windows\System32\netsh.exe" ipsec static set policy name=qianye assign=yC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1244"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=445 protocol=TCPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1320C:\Windows\system32\MsiExec.exe -Embedding D9FC57AD49A7223251C0E95E3EA0B717C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1624"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=445 protocol=UDPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1852"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=139 protocol=UDPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\credui.dll
1904"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\9D8AA271.msi.mst"C:\Windows\System32\msiexec.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
3010
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1936"C:\Windows\System32\netsh.exe" ipsec static add filterlist name=Filter1C:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2356"C:\Windows\System32\netsh.exe" ipsec static add filter filterlist=Filter1 srcaddr=any dstaddr=Me dstport=139 protocol=TCPC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\gdi32.dll
2660"C:\Windows\System32\netsh.exe" interface ipv6 installC:\Windows\System32\netsh.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\credui.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
8 598
Read events
7 907
Write events
677
Delete events
14

Modification events

(PID) Process:(3128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
380C0000EBB235ACDE60D701
(PID) Process:(3128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9827B3B81309CFEF9FDC105CF1A423C18C6B182AA7BB4ED97EF3E1DCAED0973D
(PID) Process:(3128) msiexec.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
Operation:writeName:(default)
Value:
C:\Windows\Installer\2b4249.ipi
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\2b424a.rbs
Value:
30892263
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\2b424a.rbsLow
Value:
241829152
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B7B00AA4731E2647AAC15042EA5873C
Operation:writeName:230593080361B4C49A79A0C7BC277CB5
Value:
C:\Windows\AppPatch\Custom\
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files\F4RaF\F4RaF\
Value:
1
(PID) Process:(3128) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Program Files\F4RaF\
Value:
1
Executable files
6
Suspicious files
5
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
3128msiexec.exeC:\Windows\Installer\2b4249.ipibinary
MD5:
SHA256:
3128msiexec.exeC:\Windows\Installer\2b4247.msiexecutable
MD5:
SHA256:
3128msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF592318740EFC8E1A.TMPgmc
MD5:
SHA256:
3128msiexec.exeC:\Windows\Installer\MSI4430.tmpbinary
MD5:
SHA256:
3128msiexec.exeC:\Config.Msi\2b424a.rbsbinary
MD5:
SHA256:
3128msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFBC88464A50CEA378.TMPgmc
MD5:
SHA256:
3128msiexec.exeC:\Windows\Installer\SourceHash{80395032-1630-4C4B-A997-0A7CCB72C75B}binary
MD5:
SHA256:
3128msiexec.exeC:\Windows\Installer\MSI4373.tmpexecutable
MD5:4BA8EF50CE73395AD623C770C10E35A7
SHA256:6094C813CA4BD0C647B950BA286BD338EF3623FA953B3BCF1A359B88F7296E55
3128msiexec.exeC:\Windows\Installer\MSI4353.tmpexecutable
MD5:4B49C57CBEFA1D2773DA1F95338E294D
SHA256:68C66657B569CAD9CC6E1F5ADF0795B5DF444EC9945C0D86C62C5ABC8AADDC08
3128msiexec.exeC:\Windows\Installer\MSI42E3.tmpexecutable
MD5:4BA8EF50CE73395AD623C770C10E35A7
SHA256:6094C813CA4BD0C647B950BA286BD338EF3623FA953B3BCF1A359B88F7296E55
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info