| download: | /MSI.msi |
| Full analysis: | https://app.any.run/tasks/56cafb5b-f5bb-45c3-8abc-d17993a489c9 |
| Verdict: | Malicious activity |
| Analysis date: | May 11, 2024, 04:49:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {5079DED0-A577-44C9-A041-A291BC53658D}, Number of Words: 10, Subject: DavinciSoft, Author: Ciguru LLC, Name of Creating Application: DavinciSoft, Template: ;1033, Comments: This installer database contains the logic and data required to install DavinciSoft., Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200 |
| MD5: | B4A482A7E96CFDEF632A7AF286120156 |
| SHA1: | 73E3639A9388AF84B9C0F172B3AEAF3823014596 |
| SHA256: | EAD5EBF464C313176174FF0FDC3360A3477F6361D0947221D31287EEB04691B3 |
| SSDEEP: | 49152:K449IfHgoHxmbqD+/GKIikt698ta5Q1FTeor8trZe96S2gzgdDcAmEYpbNMZWlMV:o9IIoHWkt698tPTeorH6IzghNmEYpbNs |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2009:12:11 11:47:44 |
|---|---|
| CreateDate: | 2009:12:11 11:47:44 |
| ModifyDate: | 2020:09:18 14:06:51 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {5079DED0-A577-44C9-A041-A291BC53658D} |
| Words: | 10 |
| Subject: | DavinciSoft |
| Author: | Ciguru LLC |
| LastModifiedBy: | - |
| Software: | DavinciSoft |
| Template: | ;1033 |
| Comments: | This installer database contains the logic and data required to install DavinciSoft. |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| Pages: | 200 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1588 | C:\Windows\system32\MsiExec.exe -Embedding FD8153A8AAA727A8E974C72ED7E1DCCC | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1800 | "C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Roaming\upfilles.dll, stow | C:\Windows\System32\rundll32.exe | — | MSI5F3C.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | "C:\Windows\Installer\MSI5F3C.tmp" C:/Windows/System32/rundll32.exe C:\Users\admin\AppData\Roaming\upfilles.dll, stow | C:\Windows\Installer\MSI5F3C.tmp | — | msiexec.exe | |||||||||||
User: admin Company: Caphyon LTD Integrity Level: MEDIUM Description: File that launches another file Exit code: 0 Version: 19.1.0.0 Modules
| |||||||||||||||
| 2108 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3976 | "C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\MSI.msi | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4012 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4056 | C:\Windows\system32\MsiExec.exe -Embedding 0086B6120381CF1CAD57A7DFF451B25E C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (4012) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000E23D8FA95EA3DA01AC0F000060040000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4012) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000E23D8FA95EA3DA01AC0F000060040000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4012) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 75 | |||
| (PID) Process: | (4012) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000C4E559AA5EA3DA01AC0F000060040000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4012) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000001E485CAA5EA3DA01AC0F000074010000E80300000100000000000000000000007533668F9B99C64DB66399535A48C6B30000000000000000 | |||
| (PID) Process: | (2108) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E03368AA5EA3DA013C08000090060000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2108) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E03368AA5EA3DA013C08000084080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2108) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E03368AA5EA3DA013C0800000C040000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2108) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000E03368AA5EA3DA013C08000060030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2108) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000094F86CAA5EA3DA013C0800000C040000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4012 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{8f663375-999b-4dc6-b663-99535a48c6b3}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 4012 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3976 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI3A5C.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 4012 | msiexec.exe | C:\Windows\Installer\105882.msi | executable | |
MD5:B4A482A7E96CFDEF632A7AF286120156 | SHA256:EAD5EBF464C313176174FF0FDC3360A3477F6361D0947221D31287EEB04691B3 | |||
| 4012 | msiexec.exe | C:\Windows\Installer\MSI5F3C.tmp | executable | |
MD5:B9545ED17695A32FACE8C3408A6A3553 | SHA256:1E0E63B446EECF6C9781C7D1CAE1F46A3BB31654A70612F71F31538FB4F4729A | |||
| 4012 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:9E4AFE95F887695308758E961B6DA307 | SHA256:B5C53463CF3190B25084510A434C2B35D3904B1D6556081921D17E8C08CBAE38 | |||
| 3976 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI3A7C.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 3976 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI3ABD.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 4012 | msiexec.exe | C:\Windows\Installer\MSI594D.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 4012 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF3980774851C71C93.TMP | gmc | |
MD5:3E7877412860E83A99415F4F6CEE0FBB | SHA256:AD0B5C1B0C72FD4D7A6E2727487A0D9819540F1808613B3DC6C7CB1B62109E77 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |