| File name: | dxwebsetup.exe |
| Full analysis: | https://app.any.run/tasks/8095986b-3301-4119-babc-4f0a0e3157c4 |
| Verdict: | Malicious activity |
| Analysis date: | May 02, 2024, 05:14:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive |
| MD5: | 2CBD6AD183914A0C554F0739069E77D7 |
| SHA1: | 7BF35F2AFCA666078DB35CA95130BEB2E3782212 |
| SHA256: | 2CF71D098C608C56E07F4655855A886C3102553F648DF88458DF616B26FD612F |
| SSDEEP: | 6144:kWK8fc2liXmrLxcdRDLiH1vVRGVOhMp421/7YQV:VcvgLARDI1KIOzO0 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:08:18 01:42:57+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 7 |
| CodeSize: | 34816 |
| InitializedDataSize: | 250368 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5a5e |
| OSVersion: | 5.1 |
| ImageVersion: | 5.1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.0.2600.0 |
| ProductVersionNumber: | 6.0.2600.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | DirectX 9.0 Web setup |
| FileVersion: | 9.29.1974.0 |
| InternalName: | DXWebSetup |
| LegalCopyright: | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFileName: | dxwebsetup.exe |
| ProductName: | Microsoft® Windows® Operating System |
| ProductVersion: | 9.29.1974.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1024 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe | dxwebsetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DirectX Setup Version: 4.9.0.0904 Modules
| |||||||||||||||
| 1772 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3972 | "C:\Users\admin\AppData\Local\Temp\dxwebsetup.exe" | C:\Users\admin\AppData\Local\Temp\dxwebsetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DirectX 9.0 Web setup Exit code: 3221226540 Version: 9.29.1974.0 Modules
| |||||||||||||||
| 4084 | "C:\Users\admin\AppData\Local\Temp\dxwebsetup.exe" | C:\Users\admin\AppData\Local\Temp\dxwebsetup.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DirectX 9.0 Web setup Version: 9.29.1974.0 Modules
| |||||||||||||||
| (PID) Process: | (4084) dxwebsetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | wextract_cleanup0 |
Value: rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\" | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.app.log |
Value: 4096 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (1024) dxwsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1024 | dxwsetup.exe | C:\Windows\Logs\DirectX.log | text | |
MD5:52BBA5D9101DE5F68DFF1BE446F0EAD8 | SHA256:49C7E18EECE4F51205D2D6A8C9B60AEC4F7D7762706BD4C32ECD0638811726C6 | |||
| 4084 | dxwebsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup.dll | executable | |
MD5:984CAD22FA542A08C5D22941B888D8DC | SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308 | |||
| 1024 | dxwsetup.exe | C:\Windows\system32\DirectX\WebSetup\filelist.dat | text | |
MD5:CC85D7649546D3C0B1607F761B73FEC2 | SHA256:E1C85577FEE77B7535AF5918DE16479D5B38F08D7AADBF1B3613D275C7797920 | |||
| 1024 | dxwsetup.exe | C:\Windows\System32\directx\websetup\dsetup32.dll | executable | |
MD5:A5412A144F63D639B47FCC1BA68CB029 | SHA256:8A011DA043A4B81E2B3D41A332E0FF23A65D546BD7636E8BC74885E8746927D6 | |||
| 4084 | dxwebsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.cif | text | |
MD5:7B1FBE9F5F43B2261234B78FE115CF8E | SHA256:762FF640013DB2BD4109D7DF43A867303093815751129BD1E33F16BF02E52CCE | |||
| 4084 | dxwebsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.inf | ini | |
MD5:AD8982EAA02C7AD4D7CDCBC248CAA941 | SHA256:D63C35E9B43EB0F28FFC28F61C9C9A306DA9C9DE3386770A7EB19FAA44DBFC00 | |||
| 4084 | dxwebsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup32.dll | executable | |
MD5:A5412A144F63D639B47FCC1BA68CB029 | SHA256:8A011DA043A4B81E2B3D41A332E0FF23A65D546BD7636E8BC74885E8746927D6 | |||
| 1024 | dxwsetup.exe | C:\Windows\INF\setupapi.app.log | ini | |
MD5:0E6B41E0F65E30DA18F7F84FA6DBC28D | SHA256:0A18E4C2B6D7E602EE8311A6B1AE1FB71318EF35E02C92D41ADF6674F8C032E4 | |||
| 1024 | dxwsetup.exe | C:\Windows\System32\directx\websetup\dsetup.dll | executable | |
MD5:984CAD22FA542A08C5D22941B888D8DC | SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308 | |||
| 1024 | dxwsetup.exe | C:\Windows\system32\directx\websetup\SET39B0.tmp | executable | |
MD5:A5412A144F63D639B47FCC1BA68CB029 | SHA256:8A011DA043A4B81E2B3D41A332E0FF23A65D546BD7636E8BC74885E8746927D6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1024 | dxwsetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 304 | 2.22.242.105:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cfe0a7f8e7962138 | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xact_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x86.cab | unknown | — | — | unknown |
1024 | dxwsetup.exe | GET | 302 | 95.101.197.110:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Oct2006_xact_x86.cab | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1024 | dxwsetup.exe | 95.101.197.110:80 | download.microsoft.com | Akamai International B.V. | NL | unknown |
1024 | dxwsetup.exe | 95.101.197.110:443 | download.microsoft.com | Akamai International B.V. | NL | unknown |
1024 | dxwsetup.exe | 2.22.242.105:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1024 | dxwsetup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
Process | Message |
|---|---|
dxwsetup.exe | DLL_PROCESS_ATTACH |
dxwsetup.exe | DLL_PROCESS_ATTACH |
dxwsetup.exe | Invalid parameter passed to C runtime function.
|
dxwsetup.exe | DLL_PROCESS_DETACH |
dxwsetup.exe | Invalid parameter passed to C runtime function.
|
dxwsetup.exe | DLL_PROCESS_DETACH |