File name:

call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe

Full analysis: https://app.any.run/tasks/aa0048ec-b9ec-4dc9-a4cf-4bebfe15dd6e
Verdict: Malicious activity
Analysis date: February 22, 2025, 01:07:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

519323C0BA82598E4304211EE225D998

SHA1:

34488CDA57D1A98ED2B8FB6B65307AD285F16ED4

SHA256:

4BC69ACDBC93F0CFA42B28DBCD51BBA4F2E4347EC84054AB5B3178788BB3C60A

SSDEEP:

98304:7PIRMu5DUrszskSGjKuV3XNr/g4T6Gq+flu+ehce/Unba+O+CB3jD9hlS:k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6564)
      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • There is functionality for taking screenshot (YARA)

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
  • INFO

    • The sample compiled with english language support

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Checks proxy server information

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Checks supported languages

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Reads the computer name

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Reads the software policy settings

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Reads the machine GUID from the registry

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
    • Process checks computer location settings

      • call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe (PID: 6720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (17.3)
.dll | Win32 Dynamic Link Library (generic) (4.1)
.exe | Win32 Executable (generic) (2.8)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:31 15:22:05+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.42
CodeSize: 2143744
InitializedDataSize: 2316288
UninitializedDataSize: -
EntryPoint: 0x1c118b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.11.0
ProductVersionNumber: 3.0.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Softonic
FileDescription: Softonic
FileVersion: 3.0.11.0.0
LegalCopyright: (c) Softonic
ProductName: Softonic
ProductVersion: 3.0.11.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
125
Monitored processes
2
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start call-of-duty-2-mod-tools-mod-installer_l5dz-01.exe call-of-duty-2-mod-tools-mod-installer_l5dz-01.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6564"C:\Users\admin\AppData\Local\Temp\call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe" C:\Users\admin\AppData\Local\Temp\call-of-duty-2-mod-tools-mod-installer_L5dz-01.exeexplorer.exe
User:
admin
Company:
Softonic
Integrity Level:
MEDIUM
Description:
Softonic
Exit code:
3221226540
Version:
3.0.11.0.0
Modules
Images
c:\users\admin\appdata\local\temp\call-of-duty-2-mod-tools-mod-installer_l5dz-01.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6720"C:\Users\admin\AppData\Local\Temp\call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe" C:\Users\admin\AppData\Local\Temp\call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
explorer.exe
User:
admin
Company:
Softonic
Integrity Level:
HIGH
Description:
Softonic
Exit code:
0
Version:
3.0.11.0.0
Modules
Images
c:\users\admin\appdata\local\temp\call-of-duty-2-mod-tools-mod-installer_l5dz-01.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
688
Read events
688
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6720call-of-duty-2-mod-tools-mod-installer_L5dz-01.exeC:\Users\admin\Downloads\call-of-duty-2-mod-tools-mod-installer.execompressed
MD5:97192EA19EE5DD13673220AD642111C2
SHA256:F4E7617A2E98995AA62187C089135399106A608DB2E4E5844FF06D705EB1A513
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
39
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6436
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6436
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7100
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6720
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
18.245.78.185:443
di7e1j5f1plfo.cloudfront.net
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.128
  • 104.126.37.130
  • 104.126.37.136
  • 104.126.37.160
  • 104.126.37.162
  • 104.126.37.131
  • 104.126.37.186
  • 104.126.37.171
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.177
  • 23.48.23.167
  • 23.48.23.145
  • 23.48.23.166
  • 23.48.23.156
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.181.238
whitelisted
di7e1j5f1plfo.cloudfront.net
  • 18.245.78.185
  • 18.245.78.188
  • 18.245.78.145
  • 18.245.78.212
whitelisted
images.sftcdn.net
  • 151.101.1.91
  • 151.101.65.91
  • 151.101.129.91
  • 151.101.193.91
whitelisted
gsf-fl.softonic.com
  • 151.101.129.91
  • 151.101.193.91
  • 151.101.65.91
  • 151.101.1.91
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.1
  • 20.190.159.128
  • 40.126.31.3
  • 20.190.159.129
  • 40.126.31.129
  • 40.126.31.67
  • 20.190.159.73
whitelisted

Threats

No threats detected
Process
Message
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
LoadingPage
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
WelcomePage
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
ProductPage
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
ProductPage
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
DownloadPageDLM
call-of-duty-2-mod-tools-mod-installer_L5dz-01.exe
FinishPageDLM