File name:

TIFNLAP001_2024-07-30_11_49_30.058.zip

Full analysis: https://app.any.run/tasks/289f4f6b-0d00-49de-be21-399868b6bf94
Verdict: Malicious activity
Analysis date: July 30, 2024, 11:49:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

EE5510D595A660321E80D60ECF341B19

SHA1:

C50941EE8ED72EDC61D223368D3BF6B4D4424DB9

SHA256:

4A565C867EA94442DF641086B5C0134540A0E38B384A7F1F5CD7E3369D0159AF

SSDEEP:

196608:3y82Y+ZSR7Q77zRPi0sN5AMTRBvMWdndyqAqb:3MXZSZQ77U0wPTRRgqb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • MiniReg.exe (PID: 3580)
    • Registers / Runs the DLL via REGSVR32.EXE

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1176)
      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Executable content was dropped or overwritten

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • MiniReg.exe (PID: 3580)
    • Reads the date of Windows installation

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Reads the Windows owner or organization settings

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5832)
      • regsvr32.exe (PID: 3056)
      • regsvr32.exe (PID: 6328)
      • MiniReg.exe (PID: 3580)
    • Process drops legitimate windows executable

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3796)
      • spnsrvnt.exe (PID: 2908)
      • sntlkeyssrvr.exe (PID: 1388)
      • sntlsrtsrvr.exe (PID: 6704)
    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 6716)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
    • The process checks if it is being run in the virtual environment

      • msiexec.exe (PID: 7156)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4752)
      • SentinelDriverInstallSupport.exe (PID: 6484)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 4752)
    • Creates or modifies Windows services

      • SentinelDriverInstallSupport.exe (PID: 6484)
    • Suspicious use of NETSH.EXE

      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • There is functionality for taking screenshot (YARA)

      • Data256.exe (PID: 3820)
  • INFO

    • Checks supported languages

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • msiexec.exe (PID: 7156)
      • msiexec.exe (PID: 6716)
      • spnsrvnt.exe (PID: 2908)
      • sntlkeyssrvr.exe (PID: 1388)
      • sntlsrtsrvr.exe (PID: 6704)
      • msiexec.exe (PID: 3608)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
      • MiniReg.exe (PID: 3580)
      • TeleDelta.exe (PID: 6412)
      • Data256.exe (PID: 3820)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1176)
      • msiexec.exe (PID: 6720)
      • msiexec.exe (PID: 6716)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1176)
      • msiexec.exe (PID: 6720)
    • Create files in a temporary directory

      • Install_TeleDelta256_V25048.exe (PID: 464)
      • Install_TeleDelta256_V25048.exe (PID: 1700)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
      • MiniReg.exe (PID: 3580)
    • Reads the computer name

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • SentinelProtectionInstaller7.6.4.exe (PID: 4788)
      • msiexec.exe (PID: 6716)
      • msiexec.exe (PID: 7156)
      • spnsrvnt.exe (PID: 2908)
      • sntlkeyssrvr.exe (PID: 1388)
      • sntlsrtsrvr.exe (PID: 6704)
      • msiexec.exe (PID: 3608)
      • SentinelDriverInstallSupport.exe (PID: 6484)
      • drvinst.exe (PID: 4752)
      • SHKSrvSupport.exe (PID: 6572)
      • SPNSrvSupport.exe (PID: 3668)
      • MiniReg.exe (PID: 3580)
      • TeleDelta.exe (PID: 6412)
      • Data256.exe (PID: 3820)
    • Process checks computer location settings

      • Install_TeleDelta256_V25048.tmp (PID: 6624)
      • msiexec.exe (PID: 3608)
      • SPNSrvSupport.exe (PID: 3668)
      • SHKSrvSupport.exe (PID: 6572)
    • Creates files in the program directory

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • spnsrvnt.exe (PID: 2908)
      • MiniReg.exe (PID: 3580)
    • Creates a software uninstall entry

      • Install_TeleDelta256_V25048.tmp (PID: 5392)
      • msiexec.exe (PID: 6716)
    • Reads the software policy settings

      • slui.exe (PID: 2492)
      • drvinst.exe (PID: 4752)
    • Checks proxy server information

      • slui.exe (PID: 2492)
    • Reads the machine GUID from the registry

      • sntlsrtsrvr.exe (PID: 6704)
      • spnsrvnt.exe (PID: 2908)
      • drvinst.exe (PID: 4752)
    • Manual execution by a user

      • Data256.exe (PID: 3820)
      • TeleDelta.exe (PID: 6412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x8d40d106
ZipCompressedSize: 15951167
ZipUncompressedSize: 15973364
ZipFileName: Device/HarddiskVolume3/Users/g.cheneau/Documents/Logiciels PC/LOGICIEL DELTA 256/delt256_outillogiciel_7/Master T?l?Delta256 V2.5048/Install_TeleDelta256_V25048.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
199
Monitored processes
52
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe install_teledelta256_v25048.exe install_teledelta256_v25048.tmp no specs install_teledelta256_v25048.exe install_teledelta256_v25048.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs sentinelprotectioninstaller7.6.4.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs spnsrvnt.exe no specs sntlkeyssrvr.exe no specs sntlsrtsrvr.exe no specs msiexec.exe no specs sentineldriverinstallsupport.exe conhost.exe no specs drvinst.exe spnsrvsupport.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs shksrvsupport.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs minireg.exe teledelta.exe no specs THREAT data256.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
464"C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe
WinRAR.exe
User:
admin
Company:
SEFI
Integrity Level:
MEDIUM
Description:
Installation TeleDelta256 V2.5048
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1176.3248\device\harddiskvolume3\users\g.cheneau\documents\logiciels pc\logiciel delta 256\delt256_outillogiciel_7\master télédelta256 v2.5048\install_teledelta256_v25048.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1176"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\TIFNLAP001_2024-07-30_11_49_30.058.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1388"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exeservices.exe
User:
SYSTEM
Company:
SafeNet, Inc.
Integrity Level:
SYSTEM
Version:
1, 3, 1, 2
Modules
Images
c:\program files (x86)\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1596"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msxbse35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1700"C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe" /SPAWNWND=$804B8 /NOTIFYWND=$E027C C:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\Device\HarddiskVolume3\Users\g.cheneau\Documents\Logiciels PC\LOGICIEL DELTA 256\delt256_outillogiciel_7\Master TéléDelta256 V2.5048\Install_TeleDelta256_V25048.exe
Install_TeleDelta256_V25048.tmp
User:
admin
Company:
SEFI
Integrity Level:
HIGH
Description:
Installation TeleDelta256 V2.5048
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1176.3248\device\harddiskvolume3\users\g.cheneau\documents\logiciels pc\logiciel delta 256\delt256_outillogiciel_7\master télédelta256 v2.5048\install_teledelta256_v25048.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2072"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\GAUGE32.OCX"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2088"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdaosp.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2200"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msdasc.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2432"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\mspdox35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2476"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\msexcl35.dll"C:\Windows\SysWOW64\regsvr32.exeInstall_TeleDelta256_V25048.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
32 917
Read events
31 879
Write events
1 012
Delete events
26

Modification events

(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1176) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\Sentinel\SentinelProtectionInstaller7.6.4.exe
Value:
1
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\BDE\BdeInst.dll
Value:
1
(PID) Process:(5392) Install_TeleDelta256_V25048.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls
Operation:writeName:C:\Program Files (x86)\SEFI\Pilotes\BDE\MiniReg.exe
Value:
1
Executable files
138
Suspicious files
228
Text files
52
Unknown types
6

Dropped files

PID
Process
Filename
Type
1176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1176.3248\manifest.jsontext
MD5:07AB563DA79ED941B47CBAC104670503
SHA256:231ED0971BB25EA109556964ABC0EBC2F7C092ACB38A8F2F9667BDA523B931CF
5392Install_TeleDelta256_V25048.tmpC:\Users\admin\AppData\Local\Temp\is-CPDF9.tmp\_isetup\_setup64.tmpexecutable
MD5:B4604F8CD050D7933012AE4AA98E1796
SHA256:B50B7AC03EC6DA865BF4504C7AC1E52D9F5B67C7BCB3EC0DB59FAB24F1B471C5
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\ASD1632.icoimage
MD5:6D2E20C7227870C41665EDFF1646A4F3
SHA256:B21D9EE33340A116D3B27D5869C6BE0C981856B90BB5E385F1F3A211C43554D0
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-S2JE0.tmpimage
MD5:6D2E20C7227870C41665EDFF1646A4F3
SHA256:B21D9EE33340A116D3B27D5869C6BE0C981856B90BB5E385F1F3A211C43554D0
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\V25048\is-1100C.tmpexecutable
MD5:00E1E507432F10B0089C5F689A330DAD
SHA256:4B6E454F17575A6EE4E2EBB74F878D10F42F4E4EC589867B71FD93AB9A14CFDF
5392Install_TeleDelta256_V25048.tmpC:\Users\admin\AppData\Local\Temp\is-CPDF9.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\Commun\is-0N3RE.tmp
MD5:
SHA256:
5392Install_TeleDelta256_V25048.tmpC:\Program Files (x86)\SEFI\TeleDelta256\Commun\TELED256.HLP
MD5:
SHA256:
5392Install_TeleDelta256_V25048.tmpC:\Users\admin\AppData\Local\Temp\is-CPDF9.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
1700Install_TeleDelta256_V25048.exeC:\Users\admin\AppData\Local\Temp\is-VATBT.tmp\Install_TeleDelta256_V25048.tmpexecutable
MD5:34798A4D0811910B1C833A1A5EE2C838
SHA256:A97E0E9943D6D28EEEE66E4C18709990D5E352C1C97013BE46050736E207E892
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
53
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
1800
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6064
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2.16.110.169:443
www.bing.com
Akamai International B.V.
DE
unknown
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5692
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6064
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 2.16.110.169
  • 2.16.110.137
  • 2.16.110.170
  • 2.16.110.168
  • 2.16.110.177
  • 2.16.110.152
  • 2.16.110.195
  • 2.16.110.200
  • 2.16.110.147
  • 2.16.110.123
  • 2.16.110.131
  • 2.16.110.136
  • 2.16.110.130
  • 2.23.209.160
  • 2.23.209.152
  • 2.23.209.151
  • 2.23.209.155
  • 2.23.209.156
  • 2.23.209.161
  • 2.23.209.157
  • 2.23.209.154
  • 2.23.209.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.60
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.73
  • 20.190.159.68
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.75
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info