File name:

TIFNLAP001_2024-07-30_11_49_30.058.zip

Full analysis: https://app.any.run/tasks/289f4f6b-0d00-49de-be21-399868b6bf94
Verdict: Malicious activity
Analysis date: July 30, 2024, 11:49:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

EE5510D595A660321E80D60ECF341B19

SHA1:

C50941EE8ED72EDC61D223368D3BF6B4D4424DB9

SHA256:

4A565C867EA94442DF641086B5C0134540A0E38B384A7F1F5CD7E3369D0159AF

SSDEEP:

196608:3y82Y+ZSR7Q77zRPi0sN5AMTRBvMWdndyqAqb:3MXZSZQ77U0wPTRRgqb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • MiniReg.exe (PID: 3580)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1176)
      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Executable content was dropped or overwritten

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • MiniReg.exe (PID: 3580)
    • Reads the date of Windows installation

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Reads the Windows owner or organization settings

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6328)
      • regsvr32.exe (PID: 5832)
      • regsvr32.exe (PID: 3056)
      • MiniReg.exe (PID: 3580)
    • The process checks if it is being run in the virtual environment

      • msiexec.exe (PID: 7156)
    • Process drops legitimate windows executable

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 6716)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3796)
      • sntlkeyssrvr.exe (PID: 1388)
      • spnsrvnt.exe (PID: 2908)
      • sntlsrtsrvr.exe (PID: 6704)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4752)
      • SentinelDriverInstallSupport.exe (PID: 6484)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 4752)
    • Creates or modifies Windows services

      • SentinelDriverInstallSupport.exe (PID: 6484)
    • Suspicious use of NETSH.EXE

      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • There is functionality for taking screenshot (YARA)

      • Data256.exe (PID: 3820)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1176)
      • msiexec.exe (PID: 6720)
      • msiexec.exe (PID: 6716)
    • Checks supported languages

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • msiexec.exe (PID: 7156)
      • msiexec.exe (PID: 6716)
      • spnsrvnt.exe (PID: 2908)
      • sntlkeyssrvr.exe (PID: 1388)
      • sntlsrtsrvr.exe (PID: 6704)
      • msiexec.exe (PID: 3608)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
      • MiniReg.exe (PID: 3580)
      • TeleDelta.exe (PID: 6412)
      • Data256.exe (PID: 3820)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1176)
      • msiexec.exe (PID: 6720)
    • Create files in a temporary directory

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
      • MiniReg.exe (PID: 3580)
    • Reads the computer name

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • msiexec.exe (PID: 6716)
      • msiexec.exe (PID: 7156)
      • sntlkeyssrvr.exe (PID: 1388)
      • spnsrvnt.exe (PID: 2908)
      • sntlsrtsrvr.exe (PID: 6704)
      • msiexec.exe (PID: 3608)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • SHKSrvSupport.exe (PID: 6572)
      • SPNSrvSupport.exe (PID: 3668)
      • MiniReg.exe (PID: 3580)
      • TeleDelta.exe (PID: 6412)
      • Data256.exe (PID: 3820)
    • Process checks computer location settings

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Creates files in the program directory

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • spnsrvnt.exe (PID: 2908)
      • MiniReg.exe (PID: 3580)
    • Creates a software uninstall entry

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Reads the software policy settings

      • slui.exe (PID: 2492)
      • drvinst.exe (PID: 4752)
    • Checks proxy server information

      • slui.exe (PID: 2492)
    • Reads the machine GUID from the registry

      • sntlsrtsrvr.exe (PID: 6704)
      • spnsrvnt.exe (PID: 2908)
      • drvinst.exe (PID: 4752)
    • Manual execution by a user

      • TeleDelta.exe (PID: 6412)
      • Data256.exe (PID: 3820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x8d40d106
ZipCompressedSize: 15951167
ZipUncompressedSize: 15973364
ZipFileName: Device/HarddiskVolume3/Users/g.cheneau/Documents/Logiciels PC/LOGICIEL DELTA 256/delt256_outillogiciel_7/Master T?l?Delta256 V2.5048/Install_TeleDelta256_V25048.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
199
Monitored processes
52
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe install_teledelta256_v25048.exe install_teledelta256_v25048.tmp no specs install_teledelta256_v25048.exe install_teledelta256_v25048.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs sentinelprotectioninstaller7.6.4.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs spnsrvnt.exe no specs sntlkeyssrvr.exe no specs sntlsrtsrvr.exe no specs msiexec.exe no specs sentineldriverinstallsupport.exe conhost.exe no specs drvinst.exe spnsrvsupport.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs shksrvsupport.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs minireg.exe teledelta.exe no specs THREAT data256.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
464"C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe
WinRAR.exe
User:
admin
Company:
SEFI
Integrity Level:
MEDIUM
Description:
Installation TeleDelta256 V2.5048
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1176.3248\device\harddiskvolume3\users\g.cheneau\documents\logiciels pc\logiciel delta 256\delt256_outillogiciel_7\master télédelta256 v2.5048\install_teledelta256_v25048.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1176"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\TIFNLAP001_2024-07-30_11_49_30.058.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1388"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exeservices.exe
User:
SYSTEM
Company:
SafeNet, Inc.
Integrity Level:
SYSTEM
Version:
1, 3, 1, 2
Modules
Images
c:\program files (x86)\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1596"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msxbse35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1700"C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" /SPAWNWND=$804B8 /NOTIFYWND=$E027C C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe
Install_TeleDelta256_V25048.tmp
User:
admin
Company:
SEFI
Integrity Level:
HIGH
Description:
Installation TeleDelta256 V2.5048
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1176.3248\device\harddiskvolume3\users\g.cheneau\documents\logiciels pc\logiciel delta 256\delt256_outillogiciel_7\master télédelta256 v2.5048\install_teledelta256_v25048.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2072"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\GAUGE32.OCX"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2088"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdaosp.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2200"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdasc.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2432"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\mspdox35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2476"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msexcl35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
32 917
Read events
31 879
Write events
1 012
Delete events
26

Modification events

(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\Sentinel\SentinelProtectionInstaller7.6.4.exe
Value:
1
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\BDE\BdeInst.dll
Value:
1
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\BDE\MiniReg.exe
Value:
1
Executable files
138
Suspicious files
228
Text files
52
Unknown types
6

Dropped files

PID
Process
Filename
Type
1176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exeexecutable
MD5:6AD179EE1D67C5DC7A56A66BD47E49D8
SHA256:E4042283A65236E922AC13D32E6E533C2D32D4F39A440E23145E0D17D05F572A
464Install_TeleDelta256_V25048.exeC:\Users\admin\AppData\Local\Temp\is-NVU1T.tmp\Install_TeleDelta256_V25048.tmpexecutable
MD5:34798A4D0811910B1C833A1A5EE2C838
SHA256:A97E0E9943D6D28EEEE66E4C18709990D5E352C1C97013BE46050736E207E892
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-S2JE0.tmpimage
MD5:6D2E20C7227870C41665EDFF1646A4F3
SHA256:B21D9EE33340A116D3B27D5869C6BE0C981856B90BB5E385F1F3A211C43554D0
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\Data256.exeexecutable
MD5:196BDB975428FD4EAD1CC72361FE1D05
SHA256:8782C817C20B79CBB5C17C4A8CCC9679CEF4F9845F44DB714F2FE5EC193A8566
5392Install_TeleDelta256_V25048.tmpC:\Users\admin\AppData\Local\Temp\is-CPDF9.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-IATT0.tmptext
MD5:4DC67028DFAAFFC53F8D7FC1501E1132
SHA256:D1C7BA97AC0974A149508C5490D03636BEF7192975D68F5C1C3215152BDB82DB
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\Commun\is-0N3RE.tmp
MD5:
SHA256:
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\Commun\TELED256.HLP
MD5:
SHA256:
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-1100C.tmpexecutable
MD5:00E1E507432F10B0089C5F689A330DAD
SHA256:4B6E454F17575A6EE4E2EBB74F878D10F42F4E4EC589867B71FD93AB9A14CFDF
1700Install_TeleDelta256_V25048.exeC:\Users\admin\AppData\Local\Temp\is-VATBT.tmp\Install_TeleDelta256_V25048.tmpexecutable
MD5:34798A4D0811910B1C833A1A5EE2C838
SHA256:A97E0E9943D6D28EEEE66E4C18709990D5E352C1C97013BE46050736E207E892
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
53
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1800
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6064
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2.16.110.169:443
www.bing.com
Akamai International B.V.
DE
unknown
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5692
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6064
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 2.16.110.169
  • 2.16.110.137
  • 2.16.110.170
  • 2.16.110.168
  • 2.16.110.177
  • 2.16.110.152
  • 2.16.110.195
  • 2.16.110.200
  • 2.16.110.147
  • 2.16.110.123
  • 2.16.110.131
  • 2.16.110.136
  • 2.16.110.130
  • 2.23.209.160
  • 2.23.209.152
  • 2.23.209.151
  • 2.23.209.155
  • 2.23.209.156
  • 2.23.209.161
  • 2.23.209.157
  • 2.23.209.154
  • 2.23.209.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.60
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.73
  • 20.190.159.68
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.75
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info