| URL: | http://a.directfiledl.com/getfile?id=73681 |
| Full analysis: | https://app.any.run/tasks/bda1199f-59c8-4c14-97a0-9e142b0568f8 |
| Verdict: | Malicious activity |
| Analysis date: | September 05, 2023, 14:09:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 924EDDB449D2EC559FC11766537F1FD2 |
| SHA1: | 20101AF85875338FBCBB8C949E07352327877415 |
| SHA256: | 5EF81DE6C92E7382C993A5D49E5BEA46688B34C7D9C79EB0F846222EBD926F33 |
| SSDEEP: | 3:N1Kf1MXKcd3CARQJAOSUdUn:C9MF3C0QxdUn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Users\admin\Desktop\Delta V3.60\Delta.exe" | C:\Users\admin\Desktop\Delta V3.60\Delta.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Delta Exit code: 3762504530 Version: 1.0.0.0 Modules
| |||||||||||||||
| 532 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3352 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 688 | "C:\Users\admin\Desktop\Delta V3.60\Delta.exe" | C:\Users\admin\Desktop\Delta V3.60\Delta.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Delta Exit code: 3762504530 Version: 1.0.0.0 Modules
| |||||||||||||||
| 908 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Delta V3.60.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1024 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1312 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 1456 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 2720 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3352 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://a.directfiledl.com/getfile?id=73681" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D0000000002000000000010660000000100002000000075B0D7E28E2E17B576E141128F731FE5320CCA30C35292A435B65D5E91F3150B000000000E80000000020000200000000C791686155A322F498D360901A0BC88A787D4ADF186758AE2D9BB16BE317ECD30000000E07A76BA5A881A8B5FF9F7A7FE5833EB2B96D7A240E8CDC394ED7C494DEC5BF8E13DB07B279185F24F9C8B497FA4E70A400000008D71222A7DB9FE2EAB90303DA35140A5A9A6780343B0FFB0C4B233499C2F0735FA041306AFACB24F5B397960A2D4CBA893F7FF12508B7C84A5AE9013C2C0A092 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1312 | SearchProtocolHost.exe | C:\Users\admin\Downloads\Delta V3.60.zip.npxv2q9.partial | compressed | |
MD5:5FBC10703C4B6446CD05EA069DEEDC54 | SHA256:45EE0B8B1DDBA60DF0EB91C8B8D2ECF683FCC987F4041931148F0B47196F1633 | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFFACFA04137D7A74B.TMP | gmc | |
MD5:99CB3FCB7E468F6012FC7F69C1DAC797 | SHA256:E0846B09D2ABC27163671A3147EE97A4DF3D37D7AAAF7FF2C9A6CEDCCB9E941A | |||
| 1024 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | binary | |
MD5:76E744BF7302B732BF08B014F8861EBB | SHA256:E20A2CB9DA9E0E8A94DB2E80B56FE3E59E6D0A94F9B864456B66E28926AADD15 | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:8C26B9BEAB443B164A2A280336FEE4FB | SHA256:921B6EDC6ACA9CC3C0241A3EAE185B364297C7398A7526DB034C5F87D2BED67C | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{D93AFBFB-4BF5-11EE-ACBF-12A9866C77DE}.dat | binary | |
MD5:AAE32CE4512F7366FDE6B6093357D5FD | SHA256:4F4CC4E428EA61CBCC9C8FFE4776CF408A36312CED58A3729AE6C90A66B01C32 | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{D93AFBFD-4BF5-11EE-ACBF-12A9866C77DE}.dat | binary | |
MD5:38986E1062072F4FBB51B1355259215F | SHA256:C8DCF56FB5CF697F150CA08A8A7DCAE31FE40146E668D441BA17070D7A65B97E | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF594248D40047EEB1.TMP | gmc | |
MD5:E351E5187911B6C5792695DF96346136 | SHA256:17FF70C219FDA16C5716ECEB345BCE698EF3B98F28E5F4AB4563F2FF6DD7DA6E | |||
| 3352 | iexplore.exe | C:\Users\admin\Downloads\Delta V3.60.zip | compressed | |
MD5:9F2E12DA7BD83AD33BFCFF7D6C9F1F85 | SHA256:3C87567E54783E1A9F9320BDAEC0AA25A79EF51AC37FDD6D9AF6CF3FF3F137A9 | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:24BE8A92460B5B7A555B1DA559296958 | SHA256:77A3CFE6B7EB676AF438D5DE88C7EFCB6ABCC494E0B65DA90201969E6D79B2A3 | |||
| 1024 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Downloads.lnk | binary | |
MD5:FE5D8928AC26894D6373E1E8C55EFA88 | SHA256:464B7C9BB31DE0CC2B7D73AB7D3E21538CDF657CE359D33FC65C8C615881E382 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
532 | iexplore.exe | GET | 200 | 167.235.218.62:80 | http://a.directfiledl.com/getfile?id=73681 | unknown | compressed | 22.1 Mb | unknown |
3352 | iexplore.exe | GET | 200 | 8.253.95.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?38078b1423850c24 | unknown | compressed | 4.66 Kb | unknown |
3352 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | der | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
532 | iexplore.exe | 167.235.218.62:80 | a.directfiledl.com | Hetzner Online GmbH | DE | unknown |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3352 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | EDGECAST | US | whitelisted |
3352 | iexplore.exe | 8.253.95.120:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3352 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
a.directfiledl.com |
| unknown |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |