| File name: | TIFNLAP001_2024-07-30_11_49_30.058.zip |
| Full analysis: | https://app.any.run/tasks/289f4f6b-0d00-49de-be21-399868b6bf94 |
| Verdict: | Malicious activity |
| Analysis date: | July 30, 2024, 11:49:58 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v4.5 to extract, compression method=deflate |
| MD5: | EE5510D595A660321E80D60ECF341B19 |
| SHA1: | C50941EE8ED72EDC61D223368D3BF6B4D4424DB9 |
| SHA256: | 4A565C867EA94442DF641086B5C0134540A0E38B384A7F1F5CD7E3369D0159AF |
| SSDEEP: | 196608:3y82Y+ZSR7Q77zRPi0sN5AMTRBvMWdndyqAqb:3MXZSZQ77U0wPTRRgqb |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0801 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:00:00 00:00:00 |
| ZipCRC: | 0x8d40d106 |
| ZipCompressedSize: | 15951167 |
| ZipUncompressedSize: | 15973364 |
| ZipFileName: | Device/HarddiskVolume3/Users/g.cheneau/Documents/Logiciels PC/LOGICIEL DELTA 256/delt256_outillogiciel_7/Master T?l?Delta256 V2.5048/Install_TeleDelta256_V25048.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 464 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe | WinRAR.exe | ||||||||||||
User: admin Company: SEFI Integrity Level: MEDIUM Description: Installation TeleDelta256 V2.5048 Exit code: 0 Version: 2.0 Modules
| |||||||||||||||
| 1176 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\TIFNLAP001_2024-07-30_11_49_30.058.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 1388 | "C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe" | C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe | — | services.exe | |||||||||||
User: SYSTEM Company: SafeNet, Inc. Integrity Level: SYSTEM Version: 1, 3, 1, 2 Modules
| |||||||||||||||
| 1596 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msxbse35.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" /SPAWNWND=$804B8 /NOTIFYWND=$E027C | C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe | Install_TeleDelta256_V25048.tmp | ||||||||||||
User: admin Company: SEFI Integrity Level: HIGH Description: Installation TeleDelta256 V2.5048 Exit code: 0 Version: 2.0 Modules
| |||||||||||||||
| 2072 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\GAUGE32.OCX" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2088 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdaosp.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2200 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdasc.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2432 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\mspdox35.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2476 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msexcl35.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | Install_TeleDelta256_V25048.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1176) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (5392) Install_TeleDelta256_V25048.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls |
| Operation: | write | Name: | C:\Program Files (x86)\SEFI\Pilotes\Sentinel\SentinelProtectionInstaller7.6.4.exe |
Value: 1 | |||
| (PID) Process: | (5392) Install_TeleDelta256_V25048.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls |
| Operation: | write | Name: | C:\Program Files (x86)\SEFI\Pilotes\BDE\BdeInst.dll |
Value: 1 | |||
| (PID) Process: | (5392) Install_TeleDelta256_V25048.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls |
| Operation: | write | Name: | C:\Program Files (x86)\SEFI\Pilotes\BDE\MiniReg.exe |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1176 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe | executable | |
MD5:6AD179EE1D67C5DC7A56A66BD47E49D8 | SHA256:E4042283A65236E922AC13D32E6E533C2D32D4F39A440E23145E0D17D05F572A | |||
| 464 | Install_TeleDelta256_V25048.exe | C:\Users\admin\AppData\Local\Temp\is-NVU1T.tmp\Install_TeleDelta256_V25048.tmp | executable | |
MD5:34798A4D0811910B1C833A1A5EE2C838 | SHA256:A97E0E9943D6D28EEEE66E4C18709990D5E352C1C97013BE46050736E207E892 | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-S2JE0.tmp | image | |
MD5:6D2E20C7227870C41665EDFF1646A4F3 | SHA256:B21D9EE33340A116D3B27D5869C6BE0C981856B90BB5E385F1F3A211C43554D0 | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\V25048\Data256.exe | executable | |
MD5:196BDB975428FD4EAD1CC72361FE1D05 | SHA256:8782C817C20B79CBB5C17C4A8CCC9679CEF4F9845F44DB714F2FE5EC193A8566 | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Users\admin\AppData\Local\Temp\is-CPDF9.tmp\_isetup\_RegDLL.tmp | executable | |
MD5:C594B792B9C556EA62A30DE541D2FB03 | SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-IATT0.tmp | text | |
MD5:4DC67028DFAAFFC53F8D7FC1501E1132 | SHA256:D1C7BA97AC0974A149508C5490D03636BEF7192975D68F5C1C3215152BDB82DB | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\Commun\is-0N3RE.tmp | — | |
MD5:— | SHA256:— | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\Commun\TELED256.HLP | — | |
MD5:— | SHA256:— | |||
| 5392 | Install_TeleDelta256_V25048.tmp | C:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-1100C.tmp | executable | |
MD5:00E1E507432F10B0089C5F689A330DAD | SHA256:4B6E454F17575A6EE4E2EBB74F878D10F42F4E4EC589867B71FD93AB9A14CFDF | |||
| 1700 | Install_TeleDelta256_V25048.exe | C:\Users\admin\AppData\Local\Temp\is-VATBT.tmp\Install_TeleDelta256_V25048.tmp | executable | |
MD5:34798A4D0811910B1C833A1A5EE2C838 | SHA256:A97E0E9943D6D28EEEE66E4C18709990D5E352C1C97013BE46050736E207E892 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1800 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4424 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4132 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6064 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 131.253.33.254:443 | a-ring-fallback.msedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 2.16.110.169:443 | www.bing.com | Akamai International B.V. | DE | unknown |
— | — | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5692 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6064 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
t-ring-fdv2.msedge.net |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
a-ring-fallback.msedge.net |
| unknown |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
fp-afd-nocache-ccp.azureedge.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |