File name:

WindowsPCHealthCheckSetup.msi

Full analysis: https://app.any.run/tasks/327107c9-d657-40bc-bda6-26066c4e541a
Verdict: Malicious activity
Analysis date: October 16, 2024, 12:58:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
generated-doc
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Windows , Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Windows ., Create Time/Date: Wed Feb 14 23:59:36 2024, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 4, Template: x64;1033, Last Saved By: x64;1028, Revision Number: {0B4830D0-7D09-4230-AACD-D5FD555FB76F}3.9.2402.14001;{DFF64957-5873-4325-B0CA-BB0247D0CFC3}3.9.2402.14001;{B66EAEDD-A542-4C86-8C4D-6135868CC47F}, Number of Pages: 400, Number of Characters: 131135
MD5:

A9BF00E6B176E2E9A600E58939A7C088

SHA1:

5D86A8CFC851B0146A33BD5522730176B142B234

SHA256:

F87BF57756049015686B7769B5A8DB32026D310BF853E7D132424F7513FE316C

SSDEEP:

98304:o9h34zvUx3fHoLMuXA54iETFFct+hH9tbuhV4FtUff9UKgtojr5lXMlAZB4j/v3Q:GjyPS42

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 6124)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 3600)
      • msiexec.exe (PID: 6596)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 6596)
  • INFO

    • Creates files or folders in the user directory

      • msiexec.exe (PID: 3600)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 3600)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3600)
      • msiexec.exe (PID: 6596)
    • Reads the software policy settings

      • msiexec.exe (PID: 3600)
    • Manages system restore points

      • SrTasks.exe (PID: 6756)
    • Application launched itself

      • msiexec.exe (PID: 6596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (95.3)
.doc | Microsoft Word document (old ver.) (3.2)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: Windows PC Health Check
Author: Microsoft Corporation
Keywords: Installer
Comments: This installer database contains the logic and data required to install Windows PC Health Check.
RevisionNumber: {D0533BB6-E39F-4F44-9C8A-495E6A298EB0}
CreateDate: 2024:02:14 23:52:18
ModifyDate: 2024:02:14 23:52:18
Pages: 400
Words: 10
Software: Windows Installer XML Toolset (3.11.2.4516)
Security: Read-only recommended
Template: x64;1033,1025,1026,1027,1029,1030,1031,1032,3082,1061,1035,1036,1037,1050,1038,1040,1041,1042,1063,1062,1044,1043,1045,1046,2070,1048,1049,1051,1060,2074,1053,1054,1055,1058,2052,3076,1028
LastModifiedBy: x64;1025
Characters: 131135
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe no specs pchealthcheck.exe

Process information

PID
CMD
Path
Indicators
Parent process
1172\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3600"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\WindowsPCHealthCheckSetup.msiC:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4432C:\Windows\System32\MsiExec.exe -Embedding 51F2C3252096C77709140C5E4CCF1285 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5500C:\Windows\syswow64\MsiExec.exe -Embedding A746E0744E013FCF700A4DFEC4CA45AE CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6124C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6200C:\Windows\System32\MsiExec.exe -Embedding 9D072894370F029FA252858F55DF08E8C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6596C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6756C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7004"C:\Users\admin\AppData\Local\PCHealthCheck\PCHealthCheck.exe" C:\Users\admin\AppData\Local\PCHealthCheck\PCHealthCheck.exe
msiexec.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\pchealthcheck\pchealthcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
15 055
Read events
14 334
Write events
701
Delete events
20

Modification events

(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000B7550B24CB1FDB01C419000090040000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000B7550B24CB1FDB01C419000090040000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000B0018024CB1FDB01C419000090040000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000B0018024CB1FDB01C419000090040000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000061308724CB1FDB01C419000090040000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000A8E98924CB1FDB01C419000090040000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
4800000000000000301D2225CB1FDB01C419000090040000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6596) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000150F2525CB1FDB01C419000090140000E80300000100000000000000000000008D6F497755A8FF40951547D533878DD900000000000000000000000000000000
(PID) Process:(6124) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000B9313325CB1FDB01EC170000D01B0000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
66
Suspicious files
27
Text files
79
Unknown types
18

Dropped files

PID
Process
Filename
Type
6596msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6596msiexec.exeC:\Windows\Installer\959ad.msi
MD5:
SHA256:
3600msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:DC7CF5DEBA840E8D25EB1676493E3302
SHA256:1EB694FB06E8C246C8DE75E7847AC032F7722B00E90511344A55C8EAA9F38485
3600msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C0018BB1B5834735BFA60CD063B31956der
MD5:732CFEB76B91C4D13978A00B8C666ED7
SHA256:9FAB9FC0A1DA813E6DDB93904C1FCFA6546CFBE70747FF8468DDD14D2552DBD2
6596msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{77496f8d-a855-40ff-9515-47d533878dd9}_OnDiskSnapshotPropbinary
MD5:DA5B1BC6533ADD4C8B0AA90799F49238
SHA256:1176391F5C6DB10FA1884B133643A066054A6D7DB579D684B25F1168B306D570
6596msiexec.exeC:\Windows\Installer\MSI5E60.tmpbinary
MD5:EDE94F0D6CFA69827BC5D4E8C9F3DED1
SHA256:6982C4D86E2A5043A21E474CBCF3FF296FACBAC7677B959CF3FC1340DA46E2CA
6596msiexec.exeC:\Windows\Temp\~DF6041856030A201B8.TMPbinary
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
6596msiexec.exeC:\Windows\Installer\MSI6016.tmpexecutable
MD5:E8FEE60F02B4886515A630443BD150A7
SHA256:F504C855A92A154A4857AEE52698996E12B114D0C3027A5BD59925CEDE7B904F
6596msiexec.exeC:\Windows\Temp\~DFB14D00A9C806852D.TMPbinary
MD5:837A8637964231B5DCF921F8BB69AD7C
SHA256:0E201D7DC5861F20F703ECFB5DF83F28EEFF2ACCE0BAFB517B790358B12A4DF1
6596msiexec.exeC:\Users\admin\AppData\Local\PCHealthCheck\zh-hant\PCHealthCheck.exe.muiexecutable
MD5:A10DFDEA9DFDC6238EFF2BF608A6D7AD
SHA256:F8041A4DCBFB596E1F08DBAAD8F7798B4410E8555947BA8BEE519EB3205B599E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
63
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
312 b
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
5232
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
3600
msiexec.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
3600
msiexec.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
DE
binary
1.05 Kb
whitelisted
6200
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
6200
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
3648
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4292
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4360
SearchApp.exe
92.123.104.15:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.bing.com
  • 92.123.104.15
  • 92.123.104.7
  • 92.123.104.5
  • 92.123.104.16
  • 92.123.104.11
  • 92.123.104.18
  • 92.123.104.17
  • 92.123.104.12
  • 92.123.104.19
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.64
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.0
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.75
whitelisted
go.microsoft.com
  • 69.192.162.125
  • 184.28.89.167
whitelisted
th.bing.com
  • 92.123.104.46
  • 92.123.104.61
  • 92.123.104.43
  • 92.123.104.66
  • 92.123.104.53
  • 92.123.104.58
  • 92.123.104.64
  • 92.123.104.60
  • 92.123.104.65
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info