File name:

xnafx40_redist.msi

Full analysis: https://app.any.run/tasks/070e860d-0bc6-455a-a805-86fbccdbc8a0
Verdict: Malicious activity
Analysis date: November 27, 2020, 10:34:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft XNA Framework Redistributable 4.0 Installer, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft XNA Framework Redistributable 4.0., Template: Intel;1033, Revision Number: {DC84B1CC-8305-4856-B0CB-96DBD0DE375A}, Create Time/Date: Mon Aug 23 21:15:54 2010, Last Saved Time/Date: Mon Aug 23 21:15:54 2010, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.0.5419.0), Security: 2
MD5:

97C2EEBB30C5A88C68C8F24F37183F1D

SHA1:

49EFDC29F65FC8263C196338552C7009FC96C5DE

SHA256:

E6C41D692EBCBA854DAD4B1C52BB7DDD05926BAD3105595D6596B8BAB01C25E7

SSDEEP:

98304:wynfL329J1XswfXO6wiBB+4RZg6aENaCZAU5PMO0MntfERyJGH2YPq/:wYD3C1XXfzH+4cLHU5PM/Mnt+YGlq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • DXSETUP.exe (PID: 3220)
    • Application was dropped or rewritten from another process

      • DXSETUP.exe (PID: 3220)
    • Drops executable file immediately after starts

      • DXSETUP.exe (PID: 3220)
    • Loads dropped or rewritten executable

      • DXSETUP.exe (PID: 3220)
      • MsiExec.exe (PID: 2460)
  • SUSPICIOUS

    • Executed as Windows Service

      • vssvc.exe (PID: 528)
    • Drops a file with too old compile date

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2768)
      • DXSETUP.exe (PID: 3220)
    • Creates a directory in Program Files

      • msiexec.exe (PID: 2768)
    • Creates files in the Windows directory

      • DXSETUP.exe (PID: 3220)
      • msiexec.exe (PID: 2768)
    • Adds / modifies Windows certificates

      • DXSETUP.exe (PID: 3220)
    • Drops a file that was compiled in debug mode

      • DXSETUP.exe (PID: 3220)
      • msiexec.exe (PID: 2768)
    • Removes files from Windows directory

      • DXSETUP.exe (PID: 3220)
    • Creates COM task schedule object

      • MsiExec.exe (PID: 2460)
      • DXSETUP.exe (PID: 3220)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 528)
    • Creates files in the program directory

      • msiexec.exe (PID: 2768)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2768)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 2768)
    • Application launched itself

      • msiexec.exe (PID: 2768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (88.6)
.mst | Windows SDK Setup Transform Script (10)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Microsoft XNA Framework Redistributable 4.0 Installer
Author: Microsoft Corporation
Keywords: Installer
Comments: This installer database contains the logic and data required to install Microsoft XNA Framework Redistributable 4.0.
Template: Intel;1033
RevisionNumber: {DC84B1CC-8305-4856-B0CB-96DBD0DE375A}
CreateDate: 2010:08:23 20:15:54
ModifyDate: 2010:08:23 20:15:54
Pages: 300
Words: 2
Software: Windows Installer XML (3.0.5419.0)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start msiexec.exe no specs msiexec.exe vssvc.exe no specs dxsetup.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2372"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\xnafx40_redist.msi"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2460"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Common Files\Microsoft Shared\XNA\Framework\Shared\xnavisualizer.dll"C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2768C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3220"C:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\DXSETUP.exe" /silentC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\DXSETUP.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\program files\microsoft xna\xna game studio\v4.0\redist\dx redist\dxsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
980
Read events
582
Write events
381
Delete events
17

Modification events

(PID) Process:(2372) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000A2174EE4A8C4D601D00A00000C090000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000FC7950E4A8C4D601D00A00000C090000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
43
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4000000000000000D43B93E4A8C4D601D00A00000C090000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2768) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
40000000000000002E9E95E4A8C4D601D00A0000380C0000E803000001000000000000000000000000709391BC04E24594252624179B97570000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000440E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000E80D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D601100200001C0A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
(PID) Process:(528) vssvc.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000F089A1E4A8C4D60110020000200A0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
Executable files
26
Suspicious files
13
Text files
188
Unknown types
2

Dropped files

PID
Process
Filename
Type
2768msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2768msiexec.exeC:\Windows\Installer\15939e.msi
MD5:
SHA256:
2768msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF055DF9F40828EE7B.TMP
MD5:
SHA256:
2768msiexec.exeC:\Windows\Installer\15939f.ipibinary
MD5:
SHA256:
2768msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{91937000-04bc-45e2-9425-2624179b9757}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2768msiexec.exeC:\Windows\Installer\MSI999A.tmpbinary
MD5:
SHA256:
2768msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
528vssvc.exeC:
MD5:
SHA256:
2768msiexec.exeC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\dsetup32.dllexecutable
MD5:7C7CC9FEB1026678C48BBABE84EA57C2
SHA256:A5C6DF12F9FE2EDAB2A22FE7ABF3CB17EAC110A6FD469F2570BA04AFC88AD767
2768msiexec.exeC:\Program Files\Microsoft XNA\XNA Game Studio\v4.0\Redist\DX Redist\DXSETUP.exeexecutable
MD5:11DD6E8AB9759D1AC91FFE0D0E4949CB
SHA256:16953A202265DB5655B3DD972B855619728DA76545A2F94BCBB6C43262F48D5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3220
DXSETUP.exe
GET
200
2.16.186.120:80
http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl
unknown
der
558 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3220
DXSETUP.exe
2.16.186.120:80
crl.microsoft.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.186.120
  • 2.16.186.74
whitelisted

Threats

No threats detected
Process
Message
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_ATTACH
DXSETUP.exe
DLL_PROCESS_DETACH
DXSETUP.exe
DLL_PROCESS_DETACH