File name:

xnafx40_redist.msi

Full analysis: https://app.any.run/tasks/070e860d-0bc6-455a-a805-86fbccdbc8a0
Verdict: Malicious activity
Analysis date: November 27, 2020, 10:34:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft XNA Framework Redistributable 4.0 Installer, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft XNA Framework Redistributable 4.0., Template: Intel;1033, Revision Number: {DC84B1CC-8305-4856-B0CB-96DBD0DE375A}, Create Time/Date: Mon Aug 23 21:15:54 2010, Last Saved Time/Date: Mon Aug 23 21:15:54 2010, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.0.5419.0), Security: 2
MD5:

97C2EEBB30C5A88C68C8F24F37183F1D

SHA1:

49EFDC29F65FC8263C196338552C7009FC96C5DE

SHA256:

E6C41D692EBCBA854DAD4B1C52BB7DDD05926BAD3105595D6596B8BAB01C25E7

SSDEEP:

98304:wynfL329J1XswfXO6wiBB+4RZg6aENaCZAU5PMO0MntfERyJGH2YPq/:wYD3C1XXfzH+4cLHU5PM/Mnt+YGlq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • DXSETUP.exe (PID: 3220)
    • Application was dropped or rewritten from another process

      • DXSETUP.exe (PID: 3220)
    • Drops executable file immediately after starts

      • DXSETUP.exe (PID: 3220)
    • Loads dropped or rewritten executable

      • DXSETUP.exe (PID: 3220)
      • MsiExec.exe (PID: 2460)
  • SUSPICIOUS

    • Executed as Windows Service

      • vssvc.exe (PID: 528)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 2768)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Drops a file that was compiled in debug mode

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Adds / modifies Windows certificates

      • DXSETUP.exe (PID: 3220)
    • Removes files from Windows directory

      • DXSETUP.exe (PID: 3220)
    • Creates COM task schedule object

      • DXSETUP.exe (PID: 3220)
      • MsiExec.exe (PID: 2460)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 528)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2768)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 2768)
    • Application launched itself

      • msiexec.exe (PID: 2768)
    • Creates files in the program directory

      • msiexec.exe (PID: 2768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Microsoft XNA Framework Redistributable 4.0 Installer
Author: Microsoft Corporation
Keywords: Installer
Comments: This installer database contains the logic and data required to install Microsoft XNA Framework Redistributable 4.0.
Template: Intel;1033
RevisionNumber: {DC84B1CC-8305-4856-B0CB-96DBD0DE375A}
CreateDate: 2010:08:23 20:15:54
ModifyDate: 2010:08:23 20:15:54
Pages: 300
Words: 2
Software: Windows Installer XML (3.0.5419.0)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe vssvc.exe no specs dxsetup.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2372"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\xnafx40_redist.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2460"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Common Files\Microsoft Shared\XNA\Framework\Shared\xnavisualizer.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2768C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3220"C:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\DXSETUP.exe" /silentC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\DXSETUP.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\program files\microsoft xna\xna game studio\v4.0\redist\dx redist\dxsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
980
Read events
582
Write events
381
Delete events
17

Modification events

(PID) Process:(2372) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000A2174EE4A8C4D601D00A00000C090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000FC7950E4A8C4D601D00A00000C090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
43
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000D43B93E4A8C4D601D00A00000C090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000002E9E95E4A8C4D601D00A0000380C0000E803000001000000000000000000000000709391BC04E24594252624179B97570000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000440E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000E80D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D601100200001C0A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000200A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
26
Suspicious files
13
Text files
188
Unknown types
2

Dropped files

PID
Process
Filename
Type
2768msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2768msiexec.exeC:\Windows\Installer\15939e.msi
MD5:
SHA256:
2768msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF055DF9F40828EE7B.TMP
MD5:
SHA256:
2768msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{91937000-04bc-45e2-9425-2624179b9757}_OnDiskSnapshotPropbinary
MD5:FE0233BD2214C11E8EF340D11092E68B
SHA256:B831C466181F4484C42FE3D70BEAD7E4DF299F3433FF1C90F1F6EB6690519F50
2768msiexec.exeC:\Windows\Installer\MSI999A.tmpbinary
MD5:4B345763EA20D83FD799D5530FD54B21
SHA256:60C09F4E5BDAEF58262D6292A2D52F945B7AB838179B62919AFEFAB49D48F01F
2768msiexec.exeC:\Windows\Installer\15939f.ipibinary
MD5:1AA5EF254B0BCEE7005BF862148E9F5A
SHA256:EFFE7A633CB68390F2994969722BDECC14EEB39645382FD1EC95239D97938F23
2768msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:FE0233BD2214C11E8EF340D11092E68B
SHA256:B831C466181F4484C42FE3D70BEAD7E4DF299F3433FF1C90F1F6EB6690519F50
528vssvc.exeC:
MD5:
SHA256:
2768msiexec.exeC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\APR2007_xinput_x86.cabcompressed
MD5:F83F54F45AC15A32DC17614C4F6882D4
SHA256:5AB7BB15394E4ECE850DA5453413AB1DE2EA97D5C93F86482B75073AAA05DA9C
2768msiexec.exeC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\Feb2010_XAudio_x86.cabcompressed
MD5:5DA6E4A80FA53568D2FDDE31CBFF2979
SHA256:281BB0E12F617E9AE7FE3301A7D4A08201B377CAA0311A886E8CDDC2526F734A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3220
DXSETUP.exe
GET
200
2.16.186.120:80
http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl
unknown
der
558 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3220
DXSETUP.exe
2.16.186.120:80
crl.microsoft.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.186.120
  • 2.16.186.74
whitelisted

Threats

No threats detected
Process
Message
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_DETACH
DXSETUP.exe
DLL_PROCESS_DETACH