| download: | DualMonitorTools-2.7.msi |
| Full analysis: | https://app.any.run/tasks/18dccb54-2ace-4f96-bd7c-e6421cc63d37 |
| Verdict: | Malicious activity |
| Analysis date: | February 03, 2019, 05:58:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Dual Monitor Tools, Author: GNE, Keywords: Installer, Comments: This installer database contains the logic and data required to install Dual Monitor Tools., Template: Intel;1033, Revision Number: {7FF98FB7-C39E-4860-9F3E-A012BD7D7C61}, Create Time/Date: Tue Jun 5 11:30:10 2018, Last Saved Time/Date: Tue Jun 5 11:30:10 2018, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.3.3007), Security: 2 |
| MD5: | F20F84F66373C0C0A5E2CB537E80372E |
| SHA1: | 666B2832B6F8E9C0F3F12385581B7AC0A6218E2C |
| SHA256: | EFE4130EF57407712A7B71B99780ED7268D51C027678DCE2AAFFAEB78FF0A722 |
| SSDEEP: | 12288:aBIdw7Q24CYdoowWQ5Np4q2P5TE62whOuQ4M6ZNLbp:aBWw024FdooSN+95T1QQnv |
| .msi | | | Microsoft Installer (100) |
|---|
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | Dual Monitor Tools |
| Author: | GNE |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install Dual Monitor Tools. |
| Template: | Intel;1033 |
| RevisionNumber: | {7FF98FB7-C39E-4860-9F3E-A012BD7D7C61} |
| CreateDate: | 2018:06:05 10:30:10 |
| ModifyDate: | 2018:06:05 10:30:10 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.10.3.3007) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2456 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2748 | "C:\Program Files\Internet Explorer\iexplore.exe" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2832 | "C:\Program Files\Opera\opera.exe" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
| 3016 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\DualMonitorTools-2.7.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3212 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2748 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3768 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3864 | "C:\Program Files\Dual Monitor Tools\DMT.exe" | C:\Program Files\Dual Monitor Tools\DMT.exe | msiexec.exe | ||||||||||||
User: admin Company: GNE Integrity Level: MEDIUM Description: Dual Monitor Tools Exit code: 0 Version: 2.7.0.0 Modules
| |||||||||||||||
| 3980 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000538" "000005BC" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2456) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000000C84429885BBD40198090000000E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2456) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000000C84429885BBD40198090000000E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2456) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (2456) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000000094939885BBD40198090000000E0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2456) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005AF6959885BBD40198090000840C0000E8030000010000000000000000000000AC89D7DC22033343AA15ECFBA19E6E830000000000000000 | |||
| (PID) Process: | (3768) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000C27F9F9885BBD401B80E0000040D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3768) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000C27F9F9885BBD401B80E00000C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3768) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000C27F9F9885BBD401B80E0000180D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3768) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000C27F9F9885BBD401B80E000004090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3768) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000D0A6A69885BBD401B80E000004090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2456 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2456 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF2C87B7171CD7444B.TMP | — | |
MD5:— | SHA256:— | |||
| 2456 | msiexec.exe | C:\Config.Msi\215313.rbs | — | |
MD5:— | SHA256:— | |||
| 3768 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2456 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF0DC8A52021C73E4C.TMP | — | |
MD5:— | SHA256:— | |||
| 3864 | DMT.exe | C:\Users\admin\AppData\Roaming\Dual Monitor Tools\DmtSettings.tmp | — | |
MD5:— | SHA256:— | |||
| 3980 | DrvInst.exe | C:\Windows\INF\setupapi.dev.log | ini | |
MD5:— | SHA256:— | |||
| 3980 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 2748 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2456 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{dcd789ac-0322-4333-aa15-ecfba19e6e83}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2832 | opera.exe | GET | 200 | 66.225.197.197:80 | http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 543 b | whitelisted |
3212 | iexplore.exe | GET | 301 | 216.105.38.13:80 | http://www.sourceforge.net/ | US | html | 186 b | malicious |
2832 | opera.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAOXQPQlVpLtFek%2BmcpabOk%3D | US | der | 471 b | whitelisted |
2748 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2748 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3212 | iexplore.exe | 87.121.121.2:443 | netix.dl.sourceforge.net | NetIX Communications Ltd. | BG | suspicious |
3212 | iexplore.exe | 216.105.38.13:443 | downloads.sourceforge.net | American Internet Services, LLC. | US | malicious |
3212 | iexplore.exe | 216.105.38.13:80 | downloads.sourceforge.net | American Internet Services, LLC. | US | malicious |
— | — | 216.105.38.13:443 | downloads.sourceforge.net | American Internet Services, LLC. | US | malicious |
2832 | opera.exe | 82.145.215.40:443 | certs.opera.com | Opera Software AS | — | whitelisted |
2832 | opera.exe | 66.225.197.197:80 | crl4.digicert.com | CacheNetworks, Inc. | US | whitelisted |
2832 | opera.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
netix.dl.sourceforge.net |
| suspicious |
downloads.sourceforge.net |
| whitelisted |
sourceforge.net |
| whitelisted |
www.sourceforge.net |
| malicious |
certs.opera.com |
| whitelisted |
crl4.digicert.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
Process | Message |
|---|---|
DMT.exe | DMT.exe Error: 0 : |
DMT.exe | 05:59:36|Controller|Info|DMT Starting
|
DMT.exe | DMT.exe Error: 0 : |
DMT.exe | 05:59:36|Controller|Info|O/S Version Major:6, Minor:1
|