| File name: | IPCMultiViewSetup.msi |
| Full analysis: | https://app.any.run/tasks/3732e1d0-caa4-40cc-8976-7ee6530612a8 |
| Verdict: | Malicious activity |
| Analysis date: | April 22, 2019, 05:03:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;0, Number of Pages: 200, Revision Number: {CBA649EA-3FB4-4BCB-A2DA-E1EED1973192}, Title: IPCMultiViewSetup, Author: IPCamera, Comments: IPCamera IPCMultiView, Number of Words: 2, Last Saved Time/Date: Tue Oct 31 10:39:23 2017, Last Printed: Tue Oct 31 10:39:23 2017 |
| MD5: | B1EE5740A3B963115D455D742AE147BE |
| SHA1: | 28ABB306E585D934DDEE5AB99B0E4C428D1CBE05 |
| SHA256: | F099F8C8107809AD4E5BCE4580727486946105B8DF730CBCF9F6F7B6235A4410 |
| SSDEEP: | 24576:RGfBSagCfvodPA0Qif6N2SFeV3CzzeuaqK:RGfBiCgdXQm6prveu |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CreateDate: | 1999:06:21 07:00:00 |
|---|---|
| Software: | Windows Installer |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| Template: | Intel;0 |
| Pages: | 200 |
| RevisionNumber: | {CBA649EA-3FB4-4BCB-A2DA-E1EED1973192} |
| Title: | IPCMultiViewSetup |
| Subject: | - |
| Author: | IPCamera |
| Keywords: | - |
| Comments: | IPCamera IPCMultiView |
| Words: | 2 |
| ModifyDate: | 2017:10:31 10:39:23 |
| LastPrinted: | 2017:10:31 10:39:23 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2112 | "C:\Program Files\IPCamera\IPCMultiViewSetup\IPCMultiView.exe" | C:\Program Files\IPCamera\IPCMultiViewSetup\IPCMultiView.exe | explorer.exe | ||||||||||||
User: admin Company: ESNTD Integrity Level: MEDIUM Description: IPCamera Viewer Exit code: 0 Version: 1.8.0.1 Modules
| |||||||||||||||
| 2468 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3864 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000005C0" "000005B8" | C:\Windows\system32\DrvInst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3868 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\IPCMultiViewSetup.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (332) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000B6D67BC8C8F8D4014C010000840F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (332) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000B6D67BC8C8F8D4014C010000840F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (332) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 20 | |||
| (PID) Process: | (332) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000009CBFC5C8C8F8D4014C010000840F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (332) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000F621C8C8C8F8D4014C01000044080000E8030000010000000000000000000000A1DB8FE703901D4393E6AC54214A394A0000000000000000 | |||
| (PID) Process: | (2468) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005EABD1C8C8F8D401A4090000780D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2468) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005EABD1C8C8F8D401A4090000C00D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2468) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005EABD1C8C8F8D401A40900008C0B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2468) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000005EABD1C8C8F8D401A409000030010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2468) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000001270D6C8C8F8D401A40900008C0B0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 332 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 332 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF0B9D0DE7935D2A85.TMP | — | |
MD5:— | SHA256:— | |||
| 332 | msiexec.exe | C:\Windows\Installer\MSI8A99.tmp | — | |
MD5:— | SHA256:— | |||
| 2468 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 332 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF9068E6A27E0D0273.TMP | — | |
MD5:— | SHA256:— | |||
| 3864 | DrvInst.exe | C:\Windows\INF\setupapi.ev3 | binary | |
MD5:— | SHA256:— | |||
| 332 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{e78fdba1-9003-431d-93e6-ac54214a394a}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3864 | DrvInst.exe | C:\Windows\INF\setupapi.dev.log | ini | |
MD5:— | SHA256:— | |||
| 3864 | DrvInst.exe | C:\Windows\INF\setupapi.ev1 | binary | |
MD5:— | SHA256:— | |||
| 332 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 54.200.199.150:10200 | p2pcam.P2PLiveCam.com | Amazon.com, Inc. | US | unknown |
2112 | IPCMultiView.exe | 112.124.40.254:10200 | mycamdns.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
mycamdns.com |
| malicious |
p2pcam.P2PLiveCam.com |
| unknown |