| File name: | IsoCreator.msi |
| Full analysis: | https://app.any.run/tasks/5cb928bd-0167-417e-8484-0112d9733962 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2019, 13:27:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Last Printed: Wed Feb 1 11:10:36 2006, Create Time/Date: Wed Feb 1 11:10:36 2006, Title: Installation Database, Keywords: Installer, MSI, Database, Last Saved Time/Date: Mon Jul 27 16:08:27 2009, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {566077F7-9B2C-4BB2-89D1-8370AE5387B6}, Number of Words: 2, Subject: ISO Creator 1.0, Author: Bunny-Wabbit, Name of Creating Application: Advanced Installer 7.2.1, Template: ;1033, Comments: This installer database contains the logic and data required to install ISO Creator 1.0. |
| MD5: | 79F30247BD797ACE6160F9C8B0D08217 |
| SHA1: | 6802C3CD115C79C1DBB0CFB26E7A79FD3CC35289 |
| SHA256: | F01A0A824DDEEB46ADE73E2BFC3141A0FEE650089A6C4522AB38895D97351634 |
| SSDEEP: | 12288:z4uNqYgAZhdlO1cgRxsPWjUg2kY4zs57D:z4uNqYgAVlq5xZUg2Yzs53 |
| .msi | | | Microsoft Windows Installer (88.6) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (10) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2006:02:01 11:10:36 |
|---|---|
| CreateDate: | 2006:02:01 11:10:36 |
| Title: | Installation Database |
| Keywords: | Installer, MSI, Database |
| ModifyDate: | 2009:07:27 15:08:27 |
| Pages: | 200 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {566077F7-9B2C-4BB2-89D1-8370AE5387B6} |
| Words: | 2 |
| Subject: | ISO Creator 1.0 |
| Author: | Bunny-Wabbit |
| LastModifiedBy: | - |
| Software: | Advanced Installer 7.2.1 |
| Template: | ;1033 |
| Comments: | This installer database contains the logic and data required to install ISO Creator 1.0. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1156 | C:\Windows\system32\MsiExec.exe -Embedding 0EF17456A738D9A08E76C01B3CB28643 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2924 | "C:\Program Files\Bunny-Wabbit\ISO Creator 1.0\IsoCreator.exe" | C:\Program Files\Bunny-Wabbit\ISO Creator 1.0\IsoCreator.exe | — | explorer.exe | |||||||||||
User: admin Company: Epurasu Designs Integrity Level: MEDIUM Description: IsoCreator Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3000 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\IsoCreator.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3080 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000538" "000005BC" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3872 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2328) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009809ED3357D3D40118090000680E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2328) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009809ED3357D3D40118090000680E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2328) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (2328) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000E67B403457D3D40118090000680E0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2328) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000040DE423457D3D40118090000280D0000E8030000010000000000000000000000F580B840F0C5C64B8F0F3B0FC4F408760000000000000000 | |||
| (PID) Process: | (3872) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000B68E533457D3D401200F0000A00D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000B68E533457D3D401200F000078090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000B68E533457D3D401200F00006C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000B68E533457D3D401200F0000AC0D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3872) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000C4B55A3457D3D401200F0000AC0D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3000 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIEA25.tmp | — | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFD00F9F011CB27867.TMP | — | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\Windows\Installer\MSI32B7.tmp | — | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\Config.Msi\212dc8.rbs | — | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF3958CD60C8FBEB08.TMP | — | |
MD5:— | SHA256:— | |||
| 3872 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 3080 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 2328 | msiexec.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO Creator 1.0\IsoCreator.exe.lnk | lnk | |
MD5:— | SHA256:— | |||