download: | eLectaScreenRecorder.msi |
Full analysis: | https://app.any.run/tasks/2e2be08b-0a78-4965-9575-ce320ef32d05 |
Verdict: | Malicious activity |
Analysis date: | December 06, 2019, 22:35:39 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-msi |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {C3535290-965D-449B-B839-6B9647BA15B5}, Title: Electa Live Screen Recorder Setup, Author: ELECTA COMMUNICATIONS LTD, Comments: Electa Live Screen Recorder is a tool for creating screen movies and tutorials., Number of Words: 2, Last Saved Time/Date: Mon Dec 2 07:39:40 2013, Last Printed: Mon Dec 2 07:39:40 2013 |
MD5: | C657E186FEE3AE3096899E83547A6BBF |
SHA1: | 0EFAC38BB4D7B23B131579A283C7F744ADD4FFD9 |
SHA256: | E2D16FE6BEBA1B4D83016F1368C5713F528ACD052CDBB775593421C947DA3E44 |
SSDEEP: | 393216:Ogv0C8xV2Y5xCPBaS0Cw/WwpKKEfryNtZEw/WwpKKEfwq0u5n8k8QUc:T8/2YgaS19wpKKSrsTE9wpKKSD1qQl |
.msi | | | Microsoft Windows Installer (98.5) |
---|---|---|
.msi | | | Microsoft Installer (100) |
LastPrinted: | 2013:12:02 07:39:40 |
---|---|
ModifyDate: | 2013:12:02 07:39:40 |
Words: | 2 |
Comments: | Electa Live Screen Recorder is a tool for creating screen movies and tutorials. |
Keywords: | - |
Author: | ELECTA COMMUNICATIONS LTD |
Subject: | - |
Title: | Electa Live Screen Recorder Setup |
RevisionNumber: | {C3535290-965D-449B-B839-6B9647BA15B5} |
Pages: | 200 |
Template: | Intel;1033 |
CodePage: | Windows Latin 1 (Western European) |
Security: | Password protected |
Software: | Windows Installer |
CreateDate: | 1999:06:21 07:00:00 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2764 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\eLectaScreenRecorder.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
1744 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) | ||||
4072 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2112 | "C:\Program Files\ELECTA COMMUNICATIONS LTD\Electa Live Screen Recorder\eLectaRecorder.exe" | C:\Program Files\ELECTA COMMUNICATIONS LTD\Electa Live Screen Recorder\eLectaRecorder.exe | — | explorer.exe |
User: admin Company: eLecta Integrity Level: MEDIUM Description: eLectaRecorder Version: 1.0.0.1 | ||||
352 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
716 | "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\1.avi" | C:\Program Files\VideoLAN\VLC\vlc.exe | explorer.exe | |
User: admin Company: VideoLAN Integrity Level: MEDIUM Description: VLC media player Version: 2.2.6 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1744 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Windows\Installer\3a0ef9.msi | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF68A5B4ABA79FB6E3.TMP | — | |
MD5:— | SHA256:— | |||
4072 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Windows\Installer\3a0efc.msi | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Config.Msi\3a0efb.rbs | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF45E80B7CA114FB14.TMP | — | |
MD5:— | SHA256:— | |||
1744 | msiexec.exe | C:\Windows\Installer\MSI163D.tmp | binary | |
MD5:1BB7F0EFF1CCEA57B2B5A3929B6AB075 | SHA256:EE5C57C4EF9F9F0EC4960D8C41B0052BA549736F3391A7F094EDAA8E625FDDB9 | |||
1744 | msiexec.exe | C:\Program Files\ELECTA COMMUNICATIONS LTD\Electa Live Screen Recorder\film.ico | image | |
MD5:B6B77CC40F7BDBBFB9D7B8960FBB9851 | SHA256:C45FD52FA81CF121827CC167C47A97191763B3E406AAF9E0743D4DEA1BE24714 | |||
1744 | msiexec.exe | C:\Program Files\ELECTA COMMUNICATIONS LTD\Electa Live Screen Recorder\film32.ico | image | |
MD5:149F659A522059115167B54AEE25B0C9 | SHA256:8C4A6A5D4B703E4EF530A65B30872664649612E703D1A2FB82CB85032FEDF11A |
Process | Message |
---|---|
vlc.exe | core libvlc: one instance mode ENABLED
|
vlc.exe | core libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
|
vlc.exe | direct3d vout display error: Could not read adapter capabilities. (hr=0x8876086A)
|
vlc.exe | direct3d vout display error: Direct3D could not be initialized
|