| File name: | N-.428270.msi |
| Full analysis: | https://app.any.run/tasks/43eaa667-14c0-45a2-83b6-7c90087c47fc |
| Verdict: | Malicious activity |
| Threats: | Danabot is an advanced banking Trojan malware that was designed to steal financial information from victims. Out of the Trojans in the wild, this is one of the most advanced thanks to the modular design and a complex delivery method. |
| Analysis date: | December 11, 2023, 16:55:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {40484CC9-6F70-4035-AC8C-C3866325D025}, Number of Words: 10, Subject: msedge, Author: msedge, Name of Creating Application: Advanced Installer 12.3 build 64631, Template: ;1033, Comments: This installer database contains the logic and data required to install msedge. |
| MD5: | C9C6DB0BF85A6E3B3021F7F86C32F0AC |
| SHA1: | 90797382CA79EE40ABDEAC09D4A334BB1326DEB7 |
| SHA256: | E7D5D59A61EC599175866BD863CAB56233C722E4B6637901CC0108CB52B419C5 |
| SSDEEP: | 98304:pMvn40ykSxzwBWCs6GUo/eS5l7EskJbNJkh3j2hMRi1sOlNE0OvdPVnPdND4v+ij:HR3 |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| Title: | Installation Database |
|---|---|
| Keywords: | Installer, MSI, Database |
| LastPrinted: | 2009:12:11 11:47:44 |
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2009:12:11 11:47:44 |
| Pages: | 200 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {40484CC9-6F70-4035-AC8C-C3866325D025} |
| Words: | 10 |
| Subject: | msedge |
| Author: | msedge |
| LastModifiedBy: | - |
| Software: | Advanced Installer 12.3 build 64631 |
| Template: | ;1033 |
| Comments: | This installer database contains the logic and data required to install msedge. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | C:\Windows\syswow64\MsiExec.exe -Embedding 38A32403523415D05B5C29711259BB51 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1828 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2852 | "C:\Users\admin\AppData\Roaming\CDrex\E8B5488BF90A4B94A2AADB597A00375A\c4u2-CDrex.exe" | C:\Users\admin\AppData\Roaming\CDrex\E8B5488BF90A4B94A2AADB597A00375A\c4u2-CDrex.exe | identity_helper.exe | ||||||||||||
User: admin Company: The CDex Project - http://cdex.mu/ Integrity Level: MEDIUM Description: CDex - Open Source Digital Audio CD Extractor Exit code: 0 Version: 2.05 Modules
| |||||||||||||||
| 2868 | "C:\Users\admin\Documents\identity_helper.exe" | C:\Users\admin\Documents\identity_helper.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 105.0.1343.50 Modules
| |||||||||||||||
| 2932 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\N-.428270.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2868) identity_helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2868) identity_helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2868) identity_helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2868) identity_helper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2852) c4u2-CDrex.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Skype.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2868 | identity_helper.exe | C:\Users\admin\AppData\Roaming\CDrex\E8B5488BF90A4B94A2AADB597A00375A\wnaspi32.dll | — | |
MD5:— | SHA256:— | |||
| 1828 | msiexec.exe | C:\Windows\Installer\22ba32.msi | executable | |
MD5:C9C6DB0BF85A6E3B3021F7F86C32F0AC | SHA256:E7D5D59A61EC599175866BD863CAB56233C722E4B6637901CC0108CB52B419C5 | |||
| 2852 | c4u2-CDrex.exe | C:\Users\admin\AppData\Roaming\CDrex\E8B5488BF90A4B94A2AADB597A00375A\.pdf | — | |
MD5:— | SHA256:— | |||
| 1828 | msiexec.exe | C:\Users\admin\Documents\msedge_elf.dll | executable | |
MD5:84DF8D4579B6FAFFFFD44B840448C341 | SHA256:C8A5573952F3D16D1681FBC8F4FEEA946F99B7209C70D3A0B22D43563EB173D8 | |||
| 1828 | msiexec.exe | C:\Users\admin\Pictures\download.jfif | image | |
MD5:4802E0EDA69AC9BDD0C92602576872EA | SHA256:AECAF53404FF690198FD47BA9965945754883311791668E46A935CDA30120762 | |||
| 1828 | msiexec.exe | C:\Users\admin\Pictures\download (1).jfif | image | |
MD5:8F1C3C676DED12086617FDA43DCFAC76 | SHA256:AF4861D752A31E2B21F80D6D0446B7CD30094E680855E0F6793A6C12FD751871 | |||
| 1828 | msiexec.exe | C:\Users\admin\Pictures\festadenatal.jpeg | image | |
MD5:E2CA62603A876D957D3FA2319D855ADE | SHA256:57EE94BAD9450259635884050937A6A50E77330BA38CD59F5D6EA48754E39B02 | |||
| 1828 | msiexec.exe | C:\Users\admin\Documents\identity_helper.exe | executable | |
MD5:8FA972B96F978BB206E91BCFF398E758 | SHA256:DC5BB39844056CF9F967BE503246934998404B37F6A4DF7A0408DA4B87DCE02F | |||
| 2868 | identity_helper.exe | C:\Users\admin\AppData\Roaming\CDrex\E8B5488BF90A4B94A2AADB597A00375A\libmusicbrainz.dll | executable | |
MD5:95D7788FA5B5A07B353609A010BE9F81 | SHA256:73A01A986C608B985374075864AF2612B7BBBE2C55EF0ACD2EECFF34F648FFD1 | |||
| 2868 | identity_helper.exe | C:\Users\admin\AppData\Roaming\CDrex\c4u2.zip | compressed | |
MD5:F000E74442CB23DD036C6071D6AEE115 | SHA256:68FAB280D701FF81B4D3F0886FE9D1DD0727360409C2D3C345DDF30D015F675D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2852 | c4u2-CDrex.exe | POST | 200 | 69.10.43.175:80 | http://69.10.43.175/1/zip.php | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2868 | identity_helper.exe | 216.238.118.19:48082 | — | AS-CHOOPA | BR | unknown |
2852 | c4u2-CDrex.exe | 69.10.43.175:80 | — | IS-AS-1 | US | unknown |
PID | Process | Class | Message |
|---|---|---|---|
2868 | identity_helper.exe | Malware Command and Control Activity Detected | ET MALWARE [eSentire] Win32/Spy.Banker CnC Command (DOWNLOAD) |