File name:

FileOpenInstaller64.msi

Full analysis: https://app.any.run/tasks/da1b7efb-98c6-4f9f-a17e-febbeaa3f415
Verdict: Malicious activity
Analysis date: July 23, 2024, 07:43:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: FileOpen Client (x64) B998 - build 998, Author: FileOpen Systems Inc., Keywords: Installer FileOpen, Comments: Copyright 2009-2022 FileOpen Systems Inc. All rights reserved., Template: x64;1033, Revision Number: {2E67C6DA-A9F5-42BE-959D-EC0D2E8F06BF}, Create Time/Date: Tue Jun 7 18:21:58 2022, Last Saved Time/Date: Tue Jun 7 18:21:58 2022, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
MD5:

05A69EEB6FBB77115BC7CB7C64575F65

SHA1:

6466AEDF409A0DA4C21B913B1196EF09F0E02034

SHA256:

EB1A5F76997B39171A9D812B5F55F681E05F080F34D873FF0B3C4EB9129C6350

SSDEEP:

98304:zjh2lHdzahYgBhC04atc2ysGWxrtyBBF80UjmOR:zjh2PO5fp4n2ystxrtyyqC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 5848)
      • msiexec.exe (PID: 528)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 5848)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5848)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 5848)
    • Executes as Windows Service

      • VSSVC.exe (PID: 5700)
      • FileOpenManager64.exe (PID: 4016)
    • There is functionality for taking screenshot (YARA)

      • FileOpenBroker64.exe (PID: 6948)
  • INFO

    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 528)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 528)
      • msiexec.exe (PID: 5848)
    • Checks supported languages

      • msiexec.exe (PID: 5848)
      • FileOpenManager64.exe (PID: 4016)
      • msiexec.exe (PID: 6876)
      • FileOpenBroker64.exe (PID: 6948)
    • Reads the software policy settings

      • msiexec.exe (PID: 528)
      • msiexec.exe (PID: 5848)
      • slui.exe (PID: 532)
    • Reads the computer name

      • msiexec.exe (PID: 5848)
      • FileOpenManager64.exe (PID: 4016)
      • msiexec.exe (PID: 6876)
      • FileOpenBroker64.exe (PID: 6948)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 5848)
    • Checks proxy server information

      • msiexec.exe (PID: 528)
      • slui.exe (PID: 532)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 5848)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: FileOpen Client (x64) B998 - build 998
Author: FileOpen Systems Inc.
Keywords: Installer FileOpen
Comments: Copyright © 2009-2022 FileOpen Systems Inc. All rights reserved.
Template: x64;1033
RevisionNumber: {2E67C6DA-A9F5-42BE-959D-EC0D2E8F06BF}
CreateDate: 2022:06:07 18:21:58
ModifyDate: 2022:06:07 18:21:58
Pages: 300
Words: 2
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe vssvc.exe no specs slui.exe srtasks.exe no specs conhost.exe no specs msiexec.exe no specs fileopenmanager64.exe no specs THREAT fileopenbroker64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\FileOpenInstaller64.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
532C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4016"C:\Program Files\FileOpen\Services\FileOpenManager64.exe"C:\Program Files\FileOpen\Services\FileOpenManager64.exeservices.exe
User:
SYSTEM
Company:
FileOpen Systems Inc.
Integrity Level:
SYSTEM
Description:
FileOpen Client - Manager Service
Version:
22.06.07.18
Modules
Images
c:\program files\fileopen\services\fileopenmanager64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4584C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4788\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5700C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5848C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6876C:\Windows\syswow64\MsiExec.exe -Embedding 613A6B85E93630EA96F7C848B4F6E881C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6948"C:\Program Files\FileOpen\Services\FileOpenBroker64.exe"C:\Program Files\FileOpen\Services\FileOpenBroker64.exe
msiexec.exe
User:
admin
Company:
FileOpen Systems Inc.
Integrity Level:
MEDIUM
Description:
FileOpen Client - Broker
Version:
22.06.07.18
Modules
Images
c:\program files\fileopen\services\fileopenbroker64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
12 533
Read events
12 225
Write events
289
Delete events
19

Modification events

(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
480000000000000049816019D4DCDA01D8160000BC0F0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000049816019D4DCDA01D8160000BC0F0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000E584BD19D4DCDA01D8160000BC0F0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000E584BD19D4DCDA01D8160000BC0F0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000A249C219D4DCDA01D8160000BC0F0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000FBABC419D4DCDA01D8160000BC0F0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000033A5D1AD4DCDA01D8160000BC0F0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5848) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
48000000000000001D02811AD4DCDA01D81600009C150000E8030000010000000000000000000000DF080551F3FE754DB378759FC591F9FB00000000000000000000000000000000
(PID) Process:(5700) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\Shadow Copy Optimization Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000F82B881AD4DCDA0144160000B8060000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
5
Suspicious files
21
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
5848msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
5848msiexec.exeC:\Windows\Installer\e748f.msi
MD5:
SHA256:
528msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8890A77645B73478F5B1DED18ACBF795_C090A8C88B266C6FF99A97210E92B44Dbinary
MD5:92A099AADBE9B6E2D5307DD3836EFC9F
SHA256:841B8F38EBE024180A3E232CD85ACCB7AC3C551C641C9FE18141F71A1D2F43F3
5848msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{510508df-fef3-4d75-b378-759fc591f9fb}_OnDiskSnapshotPropbinary
MD5:F322455C95131A3B43A0998BF127355C
SHA256:8F55EE5FF02C305B6A2D2C244D53BD816928BE9E135E8229E6C27CC6DEEAFA7A
528msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8890A77645B73478F5B1DED18ACBF795_C090A8C88B266C6FF99A97210E92B44Dder
MD5:511049B50A66FEF95E321F90F42FCBEF
SHA256:A342795C0C2150138A0B016BD97356CC0D8AD12D82C95E816D4039285D46F4FF
528msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DA3B6E45325D5FFF28CF6BAD6065C907_A784C98748DE3071272E5E8D4651B4F3der
MD5:5A42BAF7D0FC4373E4536052021275F7
SHA256:E29E84DA66D6BE3EC9C4F39E3C5236180911250B88494C32769A188E816D6978
5848msiexec.exeC:\Windows\Temp\~DF03A2725BB1699211.TMPbinary
MD5:D5D73D11E54CFF57356971228C381968
SHA256:562ECDFB2C205E96CE32C0BA60820DA2659404E87D4E441A4473E7AE3A67011A
5848msiexec.exeC:\ProgramData\FileOpen\Updates\L10n\fotk_zh.lcdtext
MD5:03F4D28B17CE89CFE4C288EF7225451F
SHA256:7C7509711730827DA1A713398845A2E09ADDE8ECFCA07DB04B47F34EECE52493
5848msiexec.exeC:\ProgramData\FileOpen\Updates\L10n\fotk_ja.lcdtext
MD5:7DD5A9A2ED2E595E660EAB7B06449720
SHA256:168ED420AB4AC7C5468362EE5804A1EE1BC2304B3A61884ADF1D9E764E66F889
5848msiexec.exeC:\ProgramData\FileOpen\Updates\Lists\fotkCnfs.lcdtext
MD5:CA943A39A4F5DD13E54089690FEC080A
SHA256:FDF6D2CBF65EDCF9E84B66D484BA0FD18FAD427E3EB1BF332C94CADDF1D7EC63
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
43
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
528
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D
unknown
whitelisted
528
msiexec.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2Fa1XIssT9%2FIBOhypjRRP4%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4016
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6200
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4204
svchost.exe
4.209.33.156:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
184.86.251.13:443
Akamai International B.V.
DE
unknown
528
msiexec.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:137
whitelisted
5072
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 216.58.212.142
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 184.86.251.22
  • 184.86.251.20
  • 184.86.251.14
  • 184.86.251.21
  • 184.86.251.23
  • 184.86.251.16
  • 184.86.251.17
  • 184.86.251.18
  • 184.86.251.15
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
No debug info