File name:

FileOpenInstaller64.msi

Full analysis: https://app.any.run/tasks/da1b7efb-98c6-4f9f-a17e-febbeaa3f415
Verdict: Malicious activity
Analysis date: July 23, 2024, 07:43:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: FileOpen Client (x64) B998 - build 998, Author: FileOpen Systems Inc., Keywords: Installer FileOpen, Comments: Copyright 2009-2022 FileOpen Systems Inc. All rights reserved., Template: x64;1033, Revision Number: {2E67C6DA-A9F5-42BE-959D-EC0D2E8F06BF}, Create Time/Date: Tue Jun 7 18:21:58 2022, Last Saved Time/Date: Tue Jun 7 18:21:58 2022, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

05A69EEB6FBB77115BC7CB7C64575F65

SHA1:

6466AEDF409A0DA4C21B913B1196EF09F0E02034

SHA256:

EB1A5F76997B39171A9D812B5F55F681E05F080F34D873FF0B3C4EB9129C6350

SSDEEP:

98304:zjh2lHdzahYgBhC04atc2ysGWxrtyBBF80UjmOR:zjh2PO5fp4n2ystxrtyyqC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 528)
      • msiexec.exe (PID: 5848)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 5848)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 5700)
      • FileOpenManager64.exe (PID: 4016)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 5848)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5848)
    • There is functionality for taking screenshot (YARA)

      • FileOpenBroker64.exe (PID: 6948)
  • INFO

    • Reads the software policy settings

      • msiexec.exe (PID: 528)
      • msiexec.exe (PID: 5848)
      • slui.exe (PID: 532)
    • Checks proxy server information

      • msiexec.exe (PID: 528)
      • slui.exe (PID: 532)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 528)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 528)
      • msiexec.exe (PID: 5848)
    • Reads the computer name

      • msiexec.exe (PID: 5848)
      • msiexec.exe (PID: 6876)
      • FileOpenManager64.exe (PID: 4016)
      • FileOpenBroker64.exe (PID: 6948)
    • Checks supported languages

      • msiexec.exe (PID: 5848)
      • msiexec.exe (PID: 6876)
      • FileOpenManager64.exe (PID: 4016)
      • FileOpenBroker64.exe (PID: 6948)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 5848)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5848)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: FileOpen Client (x64) B998 - build 998
Author: FileOpen Systems Inc.
Keywords: Installer FileOpen
Comments: Copyright © 2009-2022 FileOpen Systems Inc. All rights reserved.
Template: x64;1033
RevisionNumber: {2E67C6DA-A9F5-42BE-959D-EC0D2E8F06BF}
CreateDate: 2022:06:07 18:21:58
ModifyDate: 2022:06:07 18:21:58
Pages: 300
Words: 2
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs slui.exe srtasks.exe no specs conhost.exe no specs msiexec.exe no specs fileopenmanager64.exe no specs THREAT fileopenbroker64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\FileOpenInstaller64.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
532C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4016"C:\Program Files\FileOpen\Services\FileOpenManager64.exe"C:\Program Files\FileOpen\Services\FileOpenManager64.exeservices.exe
User:
SYSTEM
Company:
FileOpen Systems Inc.
Integrity Level:
SYSTEM
Description:
FileOpen Client - Manager Service
Version:
22.06.07.18
Modules
Images
c:\program files\fileopen\services\fileopenmanager64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4584C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4788\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5700C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5848C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6876C:\Windows\syswow64\MsiExec.exe -Embedding 613A6B85E93630EA96F7C848B4F6E881C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6948"C:\Program Files\FileOpen\Services\FileOpenBroker64.exe"C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
msiexec.exe
User:
admin
Company:
FileOpen Systems Inc.
Integrity Level:
MEDIUM
Description:
FileOpen Client - Broker
Version:
22.06.07.18
Modules
Images
c:\program files\fileopen\services\fileopenbroker64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
12 533
Read events
12 225
Write events
289
Delete events
19

Modification events

(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000049816019D4DCDA01D8160000BC0F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000049816019D4DCDA01D8160000BC0F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000E584BD19D4DCDA01D8160000BC0F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000E584BD19D4DCDA01D8160000BC0F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000A249C219D4DCDA01D8160000BC0F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000FBABC419D4DCDA01D8160000BC0F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000033A5D1AD4DCDA01D8160000BC0F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000001D02811AD4DCDA01D81600009C150000E8030000010000000000000000000000DF080551F3FE754DB378759FC591F9FB00000000000000000000000000000000
(PID) Process:(5700) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000F82B881AD4DCDA0144160000B8060000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
5
Suspicious files
21
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
5848msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
5848msiexec.exeC:\Windows\Installer\e748f.msi
MD5:
SHA256:
5848msiexec.exeC:\ProgramData\FileOpen\Updates\L10n\fotk_fr.lcdtext
MD5:02D3A1C956563BA31087EE811BCF1F41
SHA256:E6DCD083958DB6FB9A3FB75A9ED320638C3CBF97B69AA24AAF68E96FB644F9F1
5848msiexec.exeC:\Windows\Installer\inprogressinstallinfo.ipibinary
MD5:D5D73D11E54CFF57356971228C381968
SHA256:562ECDFB2C205E96CE32C0BA60820DA2659404E87D4E441A4473E7AE3A67011A
5848msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:F322455C95131A3B43A0998BF127355C
SHA256:8F55EE5FF02C305B6A2D2C244D53BD816928BE9E135E8229E6C27CC6DEEAFA7A
5848msiexec.exeC:\Windows\Installer\MSI76C2.tmpexecutable
MD5:D97D087BDA45F8F169BFEA007FEBFB0C
SHA256:D0317A841581A88D6C94CDEE0BF84F5C33D0A854B6532964331440FF99F60C56
5848msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{510508df-fef3-4d75-b378-759fc591f9fb}_OnDiskSnapshotPropbinary
MD5:F322455C95131A3B43A0998BF127355C
SHA256:8F55EE5FF02C305B6A2D2C244D53BD816928BE9E135E8229E6C27CC6DEEAFA7A
5848msiexec.exeC:\Program Files\FileOpen\Services\FileOpenBroker64.exeexecutable
MD5:DE1A88EBE38A4EB36E2C88B1A69A0251
SHA256:8741A8BB6FBFED7119C1BDECF8EF5C4E5FAEED79208CA1DD78675AC95492B135
5848msiexec.exeC:\Windows\Installer\MSI77DC.tmpbinary
MD5:768FC088913920E7827FA15F888FBED4
SHA256:09366008067C344163C576E798B658152706505213198DC02223417482A59579
528msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DA3B6E45325D5FFF28CF6BAD6065C907_A784C98748DE3071272E5E8D4651B4F3der
MD5:5A42BAF7D0FC4373E4536052021275F7
SHA256:E29E84DA66D6BE3EC9C4F39E3C5236180911250B88494C32769A188E816D6978
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
43
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
528
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D
unknown
whitelisted
528
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2Fa1XIssT9%2FIBOhypjRRP4%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4016
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6200
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4204
svchost.exe
4.209.33.156:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
184.86.251.13:443
Akamai International B.V.
DE
unknown
528
msiexec.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:137
whitelisted
5072
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 216.58.212.142
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 184.86.251.22
  • 184.86.251.20
  • 184.86.251.14
  • 184.86.251.21
  • 184.86.251.23
  • 184.86.251.16
  • 184.86.251.17
  • 184.86.251.18
  • 184.86.251.15
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
No debug info