File name:

dxwebsetup.exe

Full analysis: https://app.any.run/tasks/960f224f-b081-42c2-8734-22b1d6259e6b
Verdict: Malicious activity
Analysis date: December 24, 2024, 14:45:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive, 3 sections
MD5:

2CBD6AD183914A0C554F0739069E77D7

SHA1:

7BF35F2AFCA666078DB35CA95130BEB2E3782212

SHA256:

2CF71D098C608C56E07F4655855A886C3102553F648DF88458DF616B26FD612F

SSDEEP:

6144:kWK8fc2liXmrLxcdRDLiH1vVRGVOhMp421/7YQV:VcvgLARDI1KIOzO0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • dxwebsetup.exe (PID: 6428)
    • Executing a file with an untrusted certificate

      • infinst.exe (PID: 6276)
      • infinst.exe (PID: 2612)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 6264)
      • infinst.exe (PID: 5892)
      • infinst.exe (PID: 3584)
      • infinst.exe (PID: 6288)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 1580)
      • infinst.exe (PID: 936)
      • infinst.exe (PID: 4444)
      • infinst.exe (PID: 640)
      • infinst.exe (PID: 5460)
      • infinst.exe (PID: 1400)
      • infinst.exe (PID: 6892)
      • infinst.exe (PID: 2148)
      • infinst.exe (PID: 1076)
      • infinst.exe (PID: 1704)
      • infinst.exe (PID: 5236)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 3812)
      • infinst.exe (PID: 6420)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 6640)
      • infinst.exe (PID: 4944)
      • infinst.exe (PID: 244)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 6560)
      • infinst.exe (PID: 3984)
      • infinst.exe (PID: 6528)
      • infinst.exe (PID: 6720)
      • infinst.exe (PID: 3124)
      • infinst.exe (PID: 2728)
      • infinst.exe (PID: 6844)
      • infinst.exe (PID: 2380)
      • infinst.exe (PID: 6836)
      • infinst.exe (PID: 2996)
      • infinst.exe (PID: 6824)
      • infinst.exe (PID: 644)
      • infinst.exe (PID: 2448)
      • infinst.exe (PID: 3952)
      • infinst.exe (PID: 6704)
      • infinst.exe (PID: 6792)
      • infinst.exe (PID: 4816)
      • infinst.exe (PID: 3772)
      • infinst.exe (PID: 1744)
      • infinst.exe (PID: 5300)
      • infinst.exe (PID: 5208)
      • infinst.exe (PID: 4864)
      • infinst.exe (PID: 4952)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 4308)
      • infinst.exe (PID: 4704)
      • infinst.exe (PID: 5388)
      • infinst.exe (PID: 2132)
      • infinst.exe (PID: 6076)
      • infinst.exe (PID: 1804)
      • infinst.exe (PID: 628)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 1192)
      • infinst.exe (PID: 1328)
      • infinst.exe (PID: 4932)
      • infinst.exe (PID: 2120)
      • infinst.exe (PID: 3920)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 6016)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 5456)
      • infinst.exe (PID: 4640)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 2076)
      • infinst.exe (PID: 6964)
      • infinst.exe (PID: 3824)
    • Registers / Runs the DLL via REGSVR32.EXE

      • dxwsetup.exe (PID: 6464)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • dxwsetup.exe (PID: 6464)
      • dxwebsetup.exe (PID: 6428)
      • infinst.exe (PID: 6276)
      • infinst.exe (PID: 2612)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 5892)
      • infinst.exe (PID: 6264)
      • infinst.exe (PID: 3584)
      • infinst.exe (PID: 6288)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 1580)
      • infinst.exe (PID: 936)
      • infinst.exe (PID: 4444)
      • infinst.exe (PID: 640)
      • infinst.exe (PID: 5460)
      • infinst.exe (PID: 1400)
      • infinst.exe (PID: 2148)
      • infinst.exe (PID: 6892)
      • infinst.exe (PID: 1704)
      • infinst.exe (PID: 1076)
      • infinst.exe (PID: 5236)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 3812)
      • infinst.exe (PID: 6420)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 244)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 6640)
      • infinst.exe (PID: 4944)
      • infinst.exe (PID: 3984)
      • infinst.exe (PID: 6528)
      • infinst.exe (PID: 6560)
      • infinst.exe (PID: 3124)
      • infinst.exe (PID: 6720)
      • infinst.exe (PID: 6836)
      • infinst.exe (PID: 2380)
      • infinst.exe (PID: 2728)
      • infinst.exe (PID: 2996)
      • infinst.exe (PID: 644)
      • infinst.exe (PID: 6844)
      • infinst.exe (PID: 6704)
      • infinst.exe (PID: 2448)
      • infinst.exe (PID: 3952)
      • infinst.exe (PID: 6824)
      • infinst.exe (PID: 6792)
      • infinst.exe (PID: 4816)
      • infinst.exe (PID: 3772)
      • infinst.exe (PID: 1744)
      • infinst.exe (PID: 5300)
      • infinst.exe (PID: 4864)
      • infinst.exe (PID: 4952)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 4308)
      • infinst.exe (PID: 5208)
      • infinst.exe (PID: 5388)
      • infinst.exe (PID: 2132)
      • infinst.exe (PID: 4704)
      • infinst.exe (PID: 6076)
      • infinst.exe (PID: 1804)
      • infinst.exe (PID: 628)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 4932)
      • infinst.exe (PID: 2120)
      • infinst.exe (PID: 1192)
      • infinst.exe (PID: 3920)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 1328)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 5456)
      • infinst.exe (PID: 4640)
      • infinst.exe (PID: 6016)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 2076)
      • infinst.exe (PID: 6964)
      • infinst.exe (PID: 6900)
    • Process drops legitimate windows executable

      • dxwebsetup.exe (PID: 6428)
      • infinst.exe (PID: 6276)
      • infinst.exe (PID: 2612)
      • infinst.exe (PID: 1356)
      • dxwsetup.exe (PID: 6464)
      • infinst.exe (PID: 5892)
      • infinst.exe (PID: 6264)
      • infinst.exe (PID: 3584)
      • infinst.exe (PID: 6288)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 1580)
      • infinst.exe (PID: 936)
      • infinst.exe (PID: 4444)
      • infinst.exe (PID: 640)
      • infinst.exe (PID: 5460)
      • infinst.exe (PID: 6892)
      • infinst.exe (PID: 2148)
      • infinst.exe (PID: 1400)
      • infinst.exe (PID: 1076)
      • infinst.exe (PID: 5236)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 3812)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 6420)
      • infinst.exe (PID: 6640)
      • infinst.exe (PID: 4944)
      • infinst.exe (PID: 244)
      • infinst.exe (PID: 6560)
      • infinst.exe (PID: 3984)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 6720)
      • infinst.exe (PID: 6528)
      • infinst.exe (PID: 3124)
      • infinst.exe (PID: 2380)
      • infinst.exe (PID: 1704)
      • infinst.exe (PID: 2728)
      • infinst.exe (PID: 6836)
      • infinst.exe (PID: 644)
      • infinst.exe (PID: 6844)
      • infinst.exe (PID: 2996)
      • infinst.exe (PID: 6704)
      • infinst.exe (PID: 2448)
      • infinst.exe (PID: 3952)
      • infinst.exe (PID: 6824)
      • infinst.exe (PID: 3772)
      • infinst.exe (PID: 6792)
      • infinst.exe (PID: 4816)
      • infinst.exe (PID: 1744)
      • infinst.exe (PID: 5300)
      • infinst.exe (PID: 4864)
      • infinst.exe (PID: 5208)
      • infinst.exe (PID: 4952)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 2132)
      • infinst.exe (PID: 4704)
      • infinst.exe (PID: 4308)
      • infinst.exe (PID: 5388)
      • infinst.exe (PID: 6076)
      • infinst.exe (PID: 1804)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 4932)
      • infinst.exe (PID: 2120)
      • infinst.exe (PID: 628)
      • infinst.exe (PID: 3920)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 1192)
      • infinst.exe (PID: 1328)
      • infinst.exe (PID: 6016)
      • infinst.exe (PID: 5456)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 4640)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 2076)
      • infinst.exe (PID: 6964)
    • Starts a Microsoft application from unusual location

      • dxwebsetup.exe (PID: 6268)
      • dxwsetup.exe (PID: 6464)
      • dxwebsetup.exe (PID: 6428)
    • Reads security settings of Internet Explorer

      • dxwsetup.exe (PID: 6464)
    • Executes as Windows Service

      • VSSVC.exe (PID: 848)
    • Searches for installed software

      • dllhost.exe (PID: 5028)
    • Checks Windows Trust Settings

      • dxwsetup.exe (PID: 6464)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1876)
      • regsvr32.exe (PID: 236)
      • regsvr32.exe (PID: 4684)
      • dxwsetup.exe (PID: 6464)
      • regsvr32.exe (PID: 6116)
      • regsvr32.exe (PID: 5876)
      • regsvr32.exe (PID: 6776)
      • regsvr32.exe (PID: 396)
      • regsvr32.exe (PID: 5964)
      • regsvr32.exe (PID: 2632)
      • regsvr32.exe (PID: 6772)
      • regsvr32.exe (PID: 2624)
      • regsvr32.exe (PID: 6944)
      • regsvr32.exe (PID: 7088)
      • regsvr32.exe (PID: 5192)
      • regsvr32.exe (PID: 6752)
      • regsvr32.exe (PID: 2804)
      • regsvr32.exe (PID: 2216)
      • regsvr32.exe (PID: 6152)
      • regsvr32.exe (PID: 3688)
      • regsvr32.exe (PID: 6672)
      • regsvr32.exe (PID: 1616)
      • regsvr32.exe (PID: 2424)
      • regsvr32.exe (PID: 6776)
      • regsvr32.exe (PID: 3812)
    • Starts CMD.EXE for commands execution

      • winhlp32.exe (PID: 6196)
  • INFO

    • Checks supported languages

      • dxwebsetup.exe (PID: 6428)
      • dxwsetup.exe (PID: 6464)
      • infinst.exe (PID: 6276)
      • infinst.exe (PID: 2612)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 5892)
      • infinst.exe (PID: 6264)
      • infinst.exe (PID: 3584)
      • infinst.exe (PID: 6288)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 1580)
      • infinst.exe (PID: 936)
      • infinst.exe (PID: 4444)
      • infinst.exe (PID: 640)
      • infinst.exe (PID: 5460)
      • infinst.exe (PID: 1400)
      • infinst.exe (PID: 2148)
      • infinst.exe (PID: 1076)
      • infinst.exe (PID: 6892)
      • infinst.exe (PID: 1704)
      • infinst.exe (PID: 5236)
      • infinst.exe (PID: 3812)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 6420)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 244)
      • infinst.exe (PID: 6640)
      • infinst.exe (PID: 4944)
      • infinst.exe (PID: 6560)
      • infinst.exe (PID: 3984)
      • infinst.exe (PID: 6528)
      • infinst.exe (PID: 3124)
      • infinst.exe (PID: 2728)
      • infinst.exe (PID: 6720)
      • infinst.exe (PID: 6836)
      • infinst.exe (PID: 2380)
      • infinst.exe (PID: 6844)
      • infinst.exe (PID: 2996)
      • infinst.exe (PID: 644)
      • infinst.exe (PID: 6704)
      • infinst.exe (PID: 2448)
      • infinst.exe (PID: 3952)
      • infinst.exe (PID: 6824)
      • infinst.exe (PID: 6792)
      • infinst.exe (PID: 4816)
      • infinst.exe (PID: 3772)
      • infinst.exe (PID: 1744)
      • infinst.exe (PID: 5300)
      • infinst.exe (PID: 4864)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 4308)
      • infinst.exe (PID: 5208)
      • infinst.exe (PID: 5388)
      • infinst.exe (PID: 4704)
      • infinst.exe (PID: 6076)
      • infinst.exe (PID: 1804)
      • infinst.exe (PID: 628)
      • infinst.exe (PID: 1192)
      • infinst.exe (PID: 1328)
      • infinst.exe (PID: 3920)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 5456)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 6016)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 2076)
      • infinst.exe (PID: 6964)
    • Sends debugging messages

      • dxwsetup.exe (PID: 6464)
    • Checks proxy server information

      • dxwsetup.exe (PID: 6464)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 6464)
    • The sample compiled with english language support

      • dxwsetup.exe (PID: 6464)
      • dxwebsetup.exe (PID: 6428)
      • infinst.exe (PID: 6276)
      • infinst.exe (PID: 2612)
      • infinst.exe (PID: 1356)
      • infinst.exe (PID: 5892)
      • infinst.exe (PID: 6264)
      • infinst.exe (PID: 3584)
      • infinst.exe (PID: 6288)
      • infinst.exe (PID: 6676)
      • infinst.exe (PID: 1580)
      • infinst.exe (PID: 936)
      • infinst.exe (PID: 4444)
      • infinst.exe (PID: 640)
      • infinst.exe (PID: 5460)
      • infinst.exe (PID: 1400)
      • infinst.exe (PID: 6892)
      • infinst.exe (PID: 1076)
      • infinst.exe (PID: 2148)
      • infinst.exe (PID: 1704)
      • infinst.exe (PID: 5236)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 6420)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 3812)
      • infinst.exe (PID: 6640)
      • infinst.exe (PID: 4944)
      • infinst.exe (PID: 244)
      • infinst.exe (PID: 3984)
      • infinst.exe (PID: 3620)
      • infinst.exe (PID: 6560)
      • infinst.exe (PID: 6720)
      • infinst.exe (PID: 3124)
      • infinst.exe (PID: 6528)
      • infinst.exe (PID: 2380)
      • infinst.exe (PID: 2728)
      • infinst.exe (PID: 6836)
      • infinst.exe (PID: 2996)
      • infinst.exe (PID: 644)
      • infinst.exe (PID: 6844)
      • infinst.exe (PID: 6704)
      • infinst.exe (PID: 2448)
      • infinst.exe (PID: 6824)
      • infinst.exe (PID: 6792)
      • infinst.exe (PID: 4816)
      • infinst.exe (PID: 3772)
      • infinst.exe (PID: 3952)
      • infinst.exe (PID: 1744)
      • infinst.exe (PID: 4864)
      • infinst.exe (PID: 5300)
      • infinst.exe (PID: 4952)
      • infinst.exe (PID: 5712)
      • infinst.exe (PID: 5208)
      • infinst.exe (PID: 5388)
      • infinst.exe (PID: 2132)
      • infinst.exe (PID: 4704)
      • infinst.exe (PID: 4308)
      • infinst.exe (PID: 6076)
      • infinst.exe (PID: 1804)
      • infinst.exe (PID: 4724)
      • infinst.exe (PID: 2120)
      • infinst.exe (PID: 1192)
      • infinst.exe (PID: 628)
      • infinst.exe (PID: 4932)
      • infinst.exe (PID: 1328)
      • infinst.exe (PID: 3920)
      • infinst.exe (PID: 6460)
      • infinst.exe (PID: 6016)
      • infinst.exe (PID: 3544)
      • infinst.exe (PID: 5456)
      • infinst.exe (PID: 4640)
      • infinst.exe (PID: 6900)
      • infinst.exe (PID: 3824)
      • infinst.exe (PID: 2076)
      • infinst.exe (PID: 6964)
    • Create files in a temporary directory

      • dxwebsetup.exe (PID: 6428)
      • dxwsetup.exe (PID: 6464)
    • Reads the computer name

      • dxwsetup.exe (PID: 6464)
    • Reads the software policy settings

      • dxwsetup.exe (PID: 6464)
    • Reads the machine GUID from the registry

      • dxwsetup.exe (PID: 6464)
    • Manual execution by a user

      • winhlp32.exe (PID: 5788)
      • winhlp32.exe (PID: 4840)
      • winhlp32.exe (PID: 3076)
      • winhlp32.exe (PID: 4640)
      • winhlp32.exe (PID: 1868)
      • winhlp32.exe (PID: 2408)
      • winhlp32.exe (PID: 6584)
      • winhlp32.exe (PID: 6196)
    • Manages system restore points

      • SrTasks.exe (PID: 7124)
    • Gets the hash of the file via CERTUTIL.EXE

      • certutil.exe (PID: 4128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:18 01:42:57+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7
CodeSize: 34816
InitializedDataSize: 250368
UninitializedDataSize: -
EntryPoint: 0x5a5e
OSVersion: 5.1
ImageVersion: 5.1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.0.2600.0
ProductVersionNumber: 6.0.2600.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: DirectX 9.0 Web setup
FileVersion: 9.29.1974.0
InternalName: DXWebSetup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: dxwebsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 9.29.1974.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
261
Monitored processes
126
Malicious processes
77
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dxwebsetup.exe dxwsetup.exe winhlp32.exe no specs winhlp32.exe conhost.exe no specs SPPSurrogate no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs winhlp32.exe no specs winhlp32.exe conhost.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs winhlp32.exe no specs infinst.exe regsvr32.exe no specs winhlp32.exe conhost.exe no specs infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe infinst.exe regsvr32.exe no specs infinst.exe regsvr32.exe no specs SPPSurrogate no specs winhlp32.exe no specs winhlp32.exe conhost.exe no specs cmd.exe no specs certutil.exe no specs find.exe no specs find.exe no specs svchost.exe dxwebsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\xactengine2_1.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
244C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe d3dx9_35_x64.infC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
396C:\WINDOWS\system32\regsvr32.exe /s C:\WINDOWS\system32\xactengine2_6.dllC:\Windows\System32\regsvr32.exedxwsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
628C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe d3dx11_42_x64.infC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
640C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe xinput1_2_x64.inf, Install_DriverC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
644C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe D3DX9_38_x64.infC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
848C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe xinput1_1_x64.inf, Install_DriverC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1076C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe d3dx10_00_x64.infC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1192C:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe XACT3_5_x64.infC:\Users\admin\AppData\Local\Temp\DXF126.tmp\infinst.exe
dxwsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dxf126.tmp\infinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
15 044
Read events
14 725
Write events
299
Delete events
20

Modification events

(PID) Process:(6428) dxwebsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:wextract_cleanup0
Value:
rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
(PID) Process:(6464) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6464) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6464) dxwsetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5028) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
48000000000000000697ACB11256DB01A4130000CC060000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6464) dxwsetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000B432AAB11256DB0140190000A8100000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5028) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
480000000000000084FDECB11256DB01A4130000CC060000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5028) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000004162EFB11256DB01A4130000CC060000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5028) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
48000000000000003FC5F1B11256DB01A4130000CC060000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(5028) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000008BE0F8B11256DB01A4130000CC060000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
655
Suspicious files
1 055
Text files
52
Unknown types
5

Dropped files

PID
Process
Filename
Type
6464dxwsetup.exeC:\Windows\Logs\DirectX.logtext
MD5:654F0F81EE361B8F8FC5A7F520D5F19E
SHA256:9967486237B1DC25DCE4F9D0922A17373E3595C93DD0E9359A314B30D866CBAE
6464dxwsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\DXI6A85.tmptext
MD5:2C4D9E4773084F33092CED15678A2C46
SHA256:ED710D035CCAAB0914810BECF2F5DB2816DBA3A351F3666A38A903C80C16997A
6464dxwsetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:F3C5E9173F6C819001C717CC4251FD0D
SHA256:15CCD7E664F3D12C18BB4BB5F9E5E8736979BED58F163D950D33BC296B84562D
6464dxwsetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:8AF5AAFE6680695C24BD90E2C7FEFECC
SHA256:A45DFC1E1DF40F170045C706DCC2482421B9A2FC1922C64A045A6BE6F29DDBBA
6464dxwsetup.exeC:\Windows\SysWOW64\directx\websetup\SET5518.tmpexecutable
MD5:984CAD22FA542A08C5D22941B888D8DC
SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308
6464dxwsetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\dxupdate[1].cabcompressed
MD5:4AFD7F5C0574A0EFD163740ECB142011
SHA256:6E39B3FDB6722EA8AA0DC8F46AE0D8BD6496DD0F5F56BAC618A0A7DD22D6CFB2
6428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup.dllexecutable
MD5:984CAD22FA542A08C5D22941B888D8DC
SHA256:57BC22850BB8E0BCC511A9B54CD3DA18EEC61F3088940C07D63B9B74E7FE2308
6428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup32.dllexecutable
MD5:A5412A144F63D639B47FCC1BA68CB029
SHA256:8A011DA043A4B81E2B3D41A332E0FF23A65D546BD7636E8BC74885E8746927D6
6464dxwsetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C0018BB1B5834735BFA60CD063B31956binary
MD5:3E3AED1C0BA46C98A8EF6B3BEC083998
SHA256:3FAB079F84B987B1A1E305228BD9D2C7DC9A4033B62D3715073C009391FC949F
6428dxwebsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.inftext
MD5:AD8982EAA02C7AD4D7CDCBC248CAA941
SHA256:D63C35E9B43EB0F28FFC28F61C9C9A306DA9C9DE3386770A7EB19FAA44DBFC00
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
170
TCP/UDP connections
53
DNS requests
28
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6464
dxwsetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x64.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx10_00_x64.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x64.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab
unknown
whitelisted
6464
dxwsetup.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
6464
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2005_d3dx9_27_x86.cab
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
3220
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.137
  • 104.126.37.155
  • 104.126.37.147
  • 104.126.37.153
  • 104.126.37.154
  • 104.126.37.144
  • 104.126.37.161
  • 104.126.37.130
  • 104.126.37.152
  • 104.126.37.163
  • 104.126.37.179
  • 104.126.37.170
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.177
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.4
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.2
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
download.microsoft.com
  • 23.32.101.194
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain in DNS Lookup (keyauth .win)
6196
winhlp32.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
6196
winhlp32.exe
Potentially Bad Traffic
ET INFO KeyAuth Open-source Authentication System Domain (keyauth .win) in TLS SNI
Process
Message
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH