logo

How to Analyze Malicious MSI Installer Files

ID: 9357d429-c69c-5553-b6b6-e9d64102d9ff

STIX ID: report--9357d429-c69c-5553-b6b6-e9d64102d9ff

Feed Name: Intezer Blog

Threat Score
75/100

Date Published: 2024-07-17

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

This report explains how MSI installers are leveraged by attackers to embed and execute malicious binaries via custom actions and embedded binaries, illustrates manual analysis steps (using msitools, msiextract, msidiff) with a worked example of an SSLoad-delivering MSI (including file metadata and a DLL extracted and detected as PhantomLoader), and cites real-world campaigns (DarkGate, IcedID, Maze, MuddyWater/AteraAgent) with example hashes and differences observed between MSI versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.