File name:

SAMP.zip

Full analysis: https://app.any.run/tasks/6e94dd85-e94a-48eb-9c88-d0dbb0cdcb47
Verdict: Malicious activity
Analysis date: May 27, 2025, 08:20:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
upx
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

7449A37DAD24D57AD05977179258A369

SHA1:

852A9219AB77D2BFF9BF3A09FD626006962363B8

SHA256:

0DDA8EB50126864434EAA8FDD7C5BACACB35E45CE53C9E97FA61E85429F609FD

SSDEEP:

98304:UvtecMXlTUQnOE/YHhUsDsyTl3gy+obcmCAs6jy5RH2suUjV0zt67A/H78p4HuIf:UxInji9RI9AODSUCXXTqKcEoJjENw2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7480)
    • Executing a file with an untrusted certificate

      • dxwebsetup.exe (PID: 7288)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 7288)
    • Registers / Runs the DLL via REGSVR32.EXE

      • dxwsetup.exe (PID: 1116)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
    • The process creates files with name similar to system file names

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
    • Executable content was dropped or overwritten

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
      • samp.exe (PID: 5680)
    • Process drops legitimate windows executable

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
    • Starts a Microsoft application from unusual location

      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
    • Reads security settings of Internet Explorer

      • dxwsetup.exe (PID: 1116)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7352)
    • Searches for installed software

      • dllhost.exe (PID: 2152)
    • There is functionality for taking screenshot (YARA)

      • samp.exe (PID: 5680)
  • INFO

    • Manual execution by a user

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8016)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • samp.exe (PID: 5680)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7480)
    • Checks supported languages

      • dxwebsetup.exe (PID: 7288)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
    • Create files in a temporary directory

      • dxwebsetup.exe (PID: 7288)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7480)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 3676)
      • samp.exe (PID: 5680)
      • infinst.exe (PID: 5156)
    • Reads the computer name

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
    • Launch of the file from Registry key

      • dxwebsetup.exe (PID: 7288)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 1116)
    • Reads the software policy settings

      • dxwsetup.exe (PID: 1116)
    • Checks proxy server information

      • dxwsetup.exe (PID: 1116)
      • slui.exe (PID: 4428)
    • Reads the machine GUID from the registry

      • dxwsetup.exe (PID: 1116)
    • Manages system restore points

      • SrTasks.exe (PID: 7756)
    • UPX packer has been detected

      • samp.exe (PID: 5680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:05:26 22:37:00
ZipCRC: 0xe6fde320
ZipCompressedSize: 706219
ZipUncompressedSize: 731727
ZipFileName: mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
250
Monitored processes
114
Malicious processes
78
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs mod_sa.v4.4.2.0.sa-mp.v0.3.dl-r1.setup.exe no specs mod_sa.v4.4.2.0.sa-mp.v0.3.dl-r1.setup.exe dxwebsetup.exe dxwsetup.exe slui.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs SPPSurrogate no specs samp.exe

Process information

PID
CMD
Path
Indicators
Parent process
132C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\XAudio2_0.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
208C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx9_26_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
240C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_38_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
300C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx9_35_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
616C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx10_43_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
920C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_42_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
960C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_39_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1116C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe /windowsupdateC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
dxwebsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1244C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\XAudio2_3.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2152C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
Total events
20 292
Read events
19 948
Write events
311
Delete events
33

Modification events

(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SAMP.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
663
Suspicious files
1 058
Text files
76
Unknown types
7

Dropped files

PID
Process
Filename
Type
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\mod_sa\mod_sa.initext
MD5:DA2C50B0C67CFC441F13430F8D524B7B
SHA256:F937607C682B49648EAB16B17BBD1F07DFCD27EA7CBC0D8C84715AE25F2C9283
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\mod_sa\speedo.pngimage
MD5:F9C48019B3A20EA04C9E93E998F5AB9A
SHA256:DE7E7BA31FF3FD56878CF4736801EF4237F5B287B85B64463B0CA68BC7479650
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\mod_sa\needle.pngimage
MD5:925F5131220A94570994BBABD3AC2951
SHA256:91488099408A3E6F46CABFEFFC782323EC586BFFDF753DBC53D1E42F88F0C2BC
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\d3d9.dllexecutable
MD5:77F418E25B44035AE00C3EFF6271FB2C
SHA256:8E9638372C00754AE8FA13F699350EB7E6170C4B3981ED1B2B1E9E957ADAC1CE
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\music.modit
MD5:117976177F331C965B39BFB99988859E
SHA256:C272963340C772CCA1955D9507285953E0A80F1729B59ADB8D29288651BAFEE4
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\bassmod.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\brandingurl.dllexecutable
MD5:028857EE4BF29E5379B19027DF010071
SHA256:798CE85390508959953B55D966EE3AD8FAE938CB107233876566A5823D339A66
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\System.dllexecutable
MD5:2AE993A2FFEC0C137EB51C8832691BCB
SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59
7480WinRAR.exeC:\Users\admin\Downloads\samp.exeexecutable
MD5:F6AE3E5925CD57C20D4F53E727BA9DC1
SHA256:269B3F355E9C6E2869E1C6F4884302405B6AB6C8255BC141B2C3D81F5ABD2EC7
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\data\SHOPPING.twotext
MD5:19FF65162EAA59000DB59AC1FD88D3D9
SHA256:35E9CBB2363ABECDC46F913BF60E8A5166F02A7F243EB53B7FE75B37B5776BD7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
170
TCP/UDP connections
38
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1116
dxwsetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7172
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x64.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
2104
svchost.exe
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2104
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.136
  • 20.190.160.5
  • 40.126.32.76
  • 20.190.160.3
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
download.microsoft.com
  • 23.32.97.192
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info