File name:

SAMP.zip

Full analysis: https://app.any.run/tasks/6e94dd85-e94a-48eb-9c88-d0dbb0cdcb47
Verdict: Malicious activity
Analysis date: May 27, 2025, 08:20:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
upx
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

7449A37DAD24D57AD05977179258A369

SHA1:

852A9219AB77D2BFF9BF3A09FD626006962363B8

SHA256:

0DDA8EB50126864434EAA8FDD7C5BACACB35E45CE53C9E97FA61E85429F609FD

SSDEEP:

98304:UvtecMXlTUQnOE/YHhUsDsyTl3gy+obcmCAs6jy5RH2suUjV0zt67A/H78p4HuIf:UxInji9RI9AODSUCXXTqKcEoJjENw2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7480)
    • Executing a file with an untrusted certificate

      • dxwebsetup.exe (PID: 7288)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 7288)
    • Registers / Runs the DLL via REGSVR32.EXE

      • dxwsetup.exe (PID: 1116)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
    • The process creates files with name similar to system file names

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
    • Process drops legitimate windows executable

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
      • dxwebsetup.exe (PID: 7288)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
      • infinst.exe (PID: 8176)
    • Starts a Microsoft application from unusual location

      • dxwsetup.exe (PID: 1116)
      • dxwebsetup.exe (PID: 7288)
    • Executable content was dropped or overwritten

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 4212)
      • samp.exe (PID: 5680)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 7668)
    • Reads security settings of Internet Explorer

      • dxwsetup.exe (PID: 1116)
    • Searches for installed software

      • dllhost.exe (PID: 2152)
    • Executes as Windows Service

      • VSSVC.exe (PID: 7352)
    • There is functionality for taking screenshot (YARA)

      • samp.exe (PID: 5680)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7480)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7480)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
      • dxwebsetup.exe (PID: 7288)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 2984)
      • infinst.exe (PID: 208)
      • infinst.exe (PID: 7944)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 8032)
      • infinst.exe (PID: 3332)
      • infinst.exe (PID: 2800)
      • infinst.exe (PID: 8048)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 4740)
      • infinst.exe (PID: 6068)
      • infinst.exe (PID: 7188)
      • infinst.exe (PID: 5744)
      • infinst.exe (PID: 5332)
      • infinst.exe (PID: 6488)
      • infinst.exe (PID: 5116)
      • infinst.exe (PID: 7152)
      • infinst.exe (PID: 7576)
      • infinst.exe (PID: 3024)
      • infinst.exe (PID: 6192)
      • infinst.exe (PID: 7316)
      • infinst.exe (PID: 7260)
      • infinst.exe (PID: 4868)
      • infinst.exe (PID: 3176)
      • infinst.exe (PID: 300)
      • infinst.exe (PID: 4980)
      • infinst.exe (PID: 7448)
      • infinst.exe (PID: 5044)
      • infinst.exe (PID: 6256)
      • infinst.exe (PID: 8084)
      • infinst.exe (PID: 3028)
      • infinst.exe (PID: 3192)
      • infinst.exe (PID: 6656)
      • infinst.exe (PID: 2776)
      • infinst.exe (PID: 2564)
      • infinst.exe (PID: 6300)
      • infinst.exe (PID: 3884)
      • infinst.exe (PID: 240)
      • infinst.exe (PID: 6384)
      • infinst.exe (PID: 3100)
      • infinst.exe (PID: 7328)
      • infinst.exe (PID: 7524)
      • infinst.exe (PID: 960)
      • infinst.exe (PID: 7804)
      • infinst.exe (PID: 3020)
      • infinst.exe (PID: 5324)
      • infinst.exe (PID: 7768)
      • infinst.exe (PID: 7608)
      • infinst.exe (PID: 7740)
      • infinst.exe (PID: 4892)
      • infinst.exe (PID: 7668)
      • infinst.exe (PID: 7640)
      • infinst.exe (PID: 6240)
      • infinst.exe (PID: 6708)
      • infinst.exe (PID: 920)
      • infinst.exe (PID: 5436)
      • infinst.exe (PID: 7372)
      • infinst.exe (PID: 7988)
      • infinst.exe (PID: 6576)
      • infinst.exe (PID: 5228)
      • infinst.exe (PID: 4608)
      • infinst.exe (PID: 7916)
      • infinst.exe (PID: 6340)
      • infinst.exe (PID: 6228)
      • infinst.exe (PID: 7984)
      • infinst.exe (PID: 4212)
      • infinst.exe (PID: 616)
      • infinst.exe (PID: 8172)
      • infinst.exe (PID: 4424)
      • infinst.exe (PID: 8176)
      • infinst.exe (PID: 3676)
      • infinst.exe (PID: 5156)
      • samp.exe (PID: 5680)
    • Manual execution by a user

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8016)
      • samp.exe (PID: 5680)
    • Checks supported languages

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
      • dxwebsetup.exe (PID: 7288)
    • Reads the computer name

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwsetup.exe (PID: 1116)
    • Create files in a temporary directory

      • mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe (PID: 8064)
      • dxwebsetup.exe (PID: 7288)
      • dxwsetup.exe (PID: 1116)
    • Launch of the file from Registry key

      • dxwebsetup.exe (PID: 7288)
    • Checks proxy server information

      • dxwsetup.exe (PID: 1116)
      • slui.exe (PID: 4428)
    • Reads the machine GUID from the registry

      • dxwsetup.exe (PID: 1116)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 1116)
    • Reads the software policy settings

      • dxwsetup.exe (PID: 1116)
    • Manages system restore points

      • SrTasks.exe (PID: 7756)
    • UPX packer has been detected

      • samp.exe (PID: 5680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:05:26 22:37:00
ZipCRC: 0xe6fde320
ZipCompressedSize: 706219
ZipUncompressedSize: 731727
ZipFileName: mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
250
Monitored processes
114
Malicious processes
78
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs mod_sa.v4.4.2.0.sa-mp.v0.3.dl-r1.setup.exe no specs mod_sa.v4.4.2.0.sa-mp.v0.3.dl-r1.setup.exe dxwebsetup.exe dxwsetup.exe slui.exe SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs SPPSurrogate no specs samp.exe

Process information

PID
CMD
Path
Indicators
Parent process
132C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\XAudio2_0.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
208C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx9_26_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
240C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_38_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
300C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx9_35_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
616C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe d3dx10_43_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
920C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_42_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
960C:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe D3DX9_39_x64.infC:\Users\admin\AppData\Local\Temp\DXCB67.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxcb67.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1116C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe /windowsupdateC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
dxwebsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1244C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\XAudio2_3.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2152C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
Total events
20 292
Read events
19 948
Write events
311
Delete events
33

Modification events

(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SAMP.zip
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(7480) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
663
Suspicious files
1 058
Text files
76
Unknown types
7

Dropped files

PID
Process
Filename
Type
7480WinRAR.exeC:\Users\admin\Downloads\gta_sa.exeexecutable
MD5:2B5066BD4097AC2944CE6A9CF8FE5677
SHA256:F01A00CE950FA40CA1ED59DF0E789848C6EDCF6405456274965885D0929343AC
7480WinRAR.exeC:\Users\admin\Downloads\samp.exeexecutable
MD5:F6AE3E5925CD57C20D4F53E727BA9DC1
SHA256:269B3F355E9C6E2869E1C6F4884302405B6AB6C8255BC141B2C3D81F5ABD2EC7
7480WinRAR.exeC:\Users\admin\Downloads\mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeexecutable
MD5:D91CA2164B55501F89F00575A06C7A0B
SHA256:8FC844A3D2A384B424FD49C8D78D317CE7F27AEA1E5E2EABECDF0424DC4FF7C2
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\mod_sa\needle.pngimage
MD5:925F5131220A94570994BBABD3AC2951
SHA256:91488099408A3E6F46CABFEFFC782323EC586BFFDF753DBC53D1E42F88F0C2BC
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\mod_sa\mod_sa.rawabr
MD5:D7C0DEA609BD25249025F0E98CF9C9D2
SHA256:F18E565B2632853D800CCF429E32E02E8AAB0CDC6907611D3DEC5B19A0742638
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\System.dllexecutable
MD5:2AE993A2FFEC0C137EB51C8832691BCB
SHA256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\data\VEHICLES.twotext
MD5:9C2BD18DC1C428D247E118D8E7856ECA
SHA256:4931E68E80C856C0E8AA634F44FFAE2A2D98C6D1CE76815AF64DD81A934811F8
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\data\default.twotext
MD5:9F5C4F4C19464F93F8B3BCE556C66BD2
SHA256:52B3F078B134B23CB577C90CC873C5F12C4A1A0F168C3DDF0891EDE2BC5D622E
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\AppData\Local\Temp\nsmFAEE.tmp\music.modit
MD5:117976177F331C965B39BFB99988859E
SHA256:C272963340C772CCA1955D9507285953E0A80F1729B59ADB8D29288651BAFEE4
8064mod_sa.v4.4.2.0.SA-MP.v0.3.DL-R1.Setup.exeC:\Users\admin\Downloads\data\surface.twotext
MD5:2763746005CE02DDFAFBDB0B2D0C654C
SHA256:FB6D31D3ACEAA41E98BF65632BF2BF8B29A3F85DC0E4240759EB8FB34DDEFB78
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
170
TCP/UDP connections
38
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x64.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x64.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx10_00_x86.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx10_00_x64.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x64.cab
unknown
whitelisted
1116
dxwsetup.exe
GET
302
23.32.97.192:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab
unknown
whitelisted
2104
svchost.exe
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
2104
svchost.exe
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2104
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.136
  • 20.190.160.5
  • 40.126.32.76
  • 20.190.160.3
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
download.microsoft.com
  • 23.32.97.192
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info