URL:

http://a.directfiledl.com/getfile?id=73681

Full analysis: https://app.any.run/tasks/bda1199f-59c8-4c14-97a0-9e142b0568f8
Verdict: Malicious activity
Analysis date: September 05, 2023, 14:09:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

924EDDB449D2EC559FC11766537F1FD2

SHA1:

20101AF85875338FBCBB8C949E07352327877415

SHA256:

5EF81DE6C92E7382C993A5D49E5BEA46688B34C7D9C79EB0F846222EBD926F33

SSDEEP:

3:N1Kf1MXKcd3CARQJAOSUdUn:C9MF3C0QxdUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
  • INFO

    • The process uses the downloaded file

      • iexplore.exe (PID: 3352)
      • WinRAR.exe (PID: 908)
    • Application launched itself

      • iexplore.exe (PID: 3352)
    • Manual execution by a user

      • explorer.exe (PID: 2720)
      • WinRAR.exe (PID: 908)
      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
    • Reads the Internet Settings

      • explorer.exe (PID: 1024)
    • Checks supported languages

      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 908)
    • Reads the computer name

      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
    • Reads the machine GUID from the registry

      • Delta.exe (PID: 688)
      • Delta.exe (PID: 268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe explorer.exe no specs winrar.exe searchprotocolhost.exe no specs delta.exe delta.exe explorer.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\Desktop\Delta V3.60\Delta.exe" C:\Users\admin\Desktop\Delta V3.60\Delta.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Delta
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\delta v3.60\delta.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
532"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3352 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rpcrt4.dll
688"C:\Users\admin\Desktop\Delta V3.60\Delta.exe" C:\Users\admin\Desktop\Delta V3.60\Delta.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Delta
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\windows\system32\mscoree.dll
c:\users\admin\desktop\delta v3.60\delta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Delta V3.60.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
1024C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1312"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1456"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
2720"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3352"C:\Program Files\Internet Explorer\iexplore.exe" "http://a.directfiledl.com/getfile?id=73681"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iertutil.dll
Total events
12 027
Read events
11 781
Write events
242
Delete events
4

Modification events

(PID) Process:(1024) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D0000000002000000000010660000000100002000000075B0D7E28E2E17B576E141128F731FE5320CCA30C35292A435B65D5E91F3150B000000000E80000000020000200000000C791686155A322F498D360901A0BC88A787D4ADF186758AE2D9BB16BE317ECD30000000E07A76BA5A881A8B5FF9F7A7FE5833EB2B96D7A240E8CDC394ED7C494DEC5BF8E13DB07B279185F24F9C8B497FA4E70A400000008D71222A7DB9FE2EAB90303DA35140A5A9A6780343B0FFB0C4B233499C2F0735FA041306AFACB24F5B397960A2D4CBA893F7FF12508B7C84A5AE9013C2C0A092
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3352) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
3
Suspicious files
19
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1312SearchProtocolHost.exeC:\Users\admin\Downloads\Delta V3.60.zip.npxv2q9.partialcompressed
MD5:5FBC10703C4B6446CD05EA069DEEDC54
SHA256:45EE0B8B1DDBA60DF0EB91C8B8D2ECF683FCC987F4041931148F0B47196F1633
3352iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFFACFA04137D7A74B.TMPgmc
MD5:99CB3FCB7E468F6012FC7F69C1DAC797
SHA256:E0846B09D2ABC27163671A3147EE97A4DF3D37D7AAAF7FF2C9A6CEDCCB9E941A
1024explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msbinary
MD5:76E744BF7302B732BF08B014F8861EBB
SHA256:E20A2CB9DA9E0E8A94DB2E80B56FE3E59E6D0A94F9B864456B66E28926AADD15
3352iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:8C26B9BEAB443B164A2A280336FEE4FB
SHA256:921B6EDC6ACA9CC3C0241A3EAE185B364297C7398A7526DB034C5F87D2BED67C
3352iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D93AFBFB-4BF5-11EE-ACBF-12A9866C77DE}.datbinary
MD5:AAE32CE4512F7366FDE6B6093357D5FD
SHA256:4F4CC4E428EA61CBCC9C8FFE4776CF408A36312CED58A3729AE6C90A66B01C32
3352iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{D93AFBFD-4BF5-11EE-ACBF-12A9866C77DE}.datbinary
MD5:38986E1062072F4FBB51B1355259215F
SHA256:C8DCF56FB5CF697F150CA08A8A7DCAE31FE40146E668D441BA17070D7A65B97E
3352iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF594248D40047EEB1.TMPgmc
MD5:E351E5187911B6C5792695DF96346136
SHA256:17FF70C219FDA16C5716ECEB345BCE698EF3B98F28E5F4AB4563F2FF6DD7DA6E
3352iexplore.exeC:\Users\admin\Downloads\Delta V3.60.zipcompressed
MD5:9F2E12DA7BD83AD33BFCFF7D6C9F1F85
SHA256:3C87567E54783E1A9F9320BDAEC0AA25A79EF51AC37FDD6D9AF6CF3FF3F137A9
3352iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:24BE8A92460B5B7A555B1DA559296958
SHA256:77A3CFE6B7EB676AF438D5DE88C7EFCB6ABCC494E0B65DA90201969E6D79B2A3
1024explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Downloads.lnkbinary
MD5:FE5D8928AC26894D6373E1E8C55EFA88
SHA256:464B7C9BB31DE0CC2B7D73AB7D3E21538CDF657CE359D33FC65C8C615881E382
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
8
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
532
iexplore.exe
GET
200
167.235.218.62:80
http://a.directfiledl.com/getfile?id=73681
unknown
compressed
22.1 Mb
unknown
3352
iexplore.exe
GET
200
8.253.95.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?38078b1423850c24
unknown
compressed
4.66 Kb
unknown
3352
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
der
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
532
iexplore.exe
167.235.218.62:80
a.directfiledl.com
Hetzner Online GmbH
DE
unknown
3284
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3352
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3352
iexplore.exe
8.253.95.120:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3352
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
a.directfiledl.com
  • 167.235.218.62
unknown
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 8.253.95.120
  • 8.238.190.126
  • 8.248.139.254
  • 67.27.158.254
  • 8.241.122.126
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info