File name:

DELUX-M800Ultra.exe

Full analysis: https://app.any.run/tasks/367b074a-775b-424e-8f05-272f4c134089
Verdict: Malicious activity
Analysis date: December 18, 2024, 17:06:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

27628BD9EA01355C68AC950732A3BC46

SHA1:

BCFF08A45E9A0D0ABD79742706189EFFF603D9AE

SHA256:

9ED169174752B7619D3E04738B3E39C883C36418DE5ABCD9C688F93E4EED4459

SSDEEP:

98304:dPhClfHMhiygveF+oylDlQNXsaeMHU7cXydU3aDdYjwVkmOwM7XmYl6Zr5QYxcjH:i5HvkVfGpfwpPZUy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DELUX-M800Ultra.exe (PID: 6896)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • DELUX-M800Ultra.exe (PID: 6896)
    • Drops 7-zip archiver for unpacking

      • DELUX-M800Ultra.exe (PID: 6896)
    • Creates a software uninstall entry

      • DELUX-M800Ultra.exe (PID: 6896)
    • Searches for installed software

      • DELUX-M800Ultra.exe (PID: 4932)
  • INFO

    • Reads the computer name

      • DELUX-M800Ultra.exe (PID: 6896)
      • DELUX-M800Ultra.exe (PID: 4932)
    • The sample compiled with chinese language support

      • DELUX-M800Ultra.exe (PID: 6896)
    • Checks supported languages

      • DELUX-M800Ultra.exe (PID: 6896)
      • DELUX-M800Ultra.exe (PID: 4932)
    • Create files in a temporary directory

      • DELUX-M800Ultra.exe (PID: 6896)
    • The sample compiled with english language support

      • DELUX-M800Ultra.exe (PID: 6896)
    • Creates files in the program directory

      • DELUX-M800Ultra.exe (PID: 6896)
    • Sends debugging messages

      • DELUX-M800Ultra.exe (PID: 4932)
    • Creates files or folders in the user directory

      • DELUX-M800Ultra.exe (PID: 4932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:20:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 29696
InitializedDataSize: 489984
UninitializedDataSize: 16896
EntryPoint: 0x38af
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.7
ProductVersionNumber: 1.0.0.7
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Chinese (Simplified)
CompanyName: DELUX
FileDescription: DELUX-M800Ultra
FileVersion: 1.0.0.7
InternalName: DELUX-M800Ultra.exe
LegalCopyright: Copyright (C) 2023
ProductName: DELUX-M800Ultra
ProductVersion: 1.0.0.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start delux-m800ultra.exe delux-m800ultra.exe delux-m800ultra.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4932"C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe"C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe
DELUX-M800Ultra.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\delux-m800ultra\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6728"C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe" C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exeexplorer.exe
User:
admin
Company:
DELUX
Integrity Level:
MEDIUM
Description:
DELUX-M800Ultra
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6896"C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe" C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe
explorer.exe
User:
admin
Company:
DELUX
Integrity Level:
HIGH
Description:
DELUX-M800Ultra
Exit code:
0
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
571
Read events
559
Write events
12
Delete events
0

Modification events

(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\DELUX-M800Ultra
Operation:writeName:LANGUAGE
Value:
1033
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\DELUX-M800Ultra
Operation:writeName:InstPath
Value:
C:\Program Files (x86)\DELUX-M800Ultra
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayName
Value:
DELUX-M800Ultra
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\DELUX-M800Ultra\uninst.exe
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:Publisher
Value:
DELUX
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayVersion
Value:
1.0.0.7
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:HelpLink
Value:
www.deluxworld.com
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:URLInfoAbout
Value:
www.deluxworld.com
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:Comments
Value:
www.deluxworld.com
Executable files
18
Suspicious files
25
Text files
737
Unknown types
0

Dropped files

PID
Process
Filename
Type
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\app.7z
MD5:
SHA256:
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\Font\MiSans-Normal.ttf
MD5:
SHA256:
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\skin.zipcompressed
MD5:B29D4B880C354C24D418921622A6E522
SHA256:6F658667839DC2469E2B5F83CBF9F5EDB64CB6D244977252917E64B60AA750A1
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\Mouse.jsonbinary
MD5:8C961F64FE9BF28302BF43969EA134F0
SHA256:28D8ED9B520D55048E184FB8CEEE5A44A03BEA5B1CBBA0B1FA45E131128B645A
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\logo.icoimage
MD5:2F07E0B664D55BB47BB91AD2352C1837
SHA256:B43FFA56DB1F56F475FEBF6B7A340C5D6770E6460373FEC8A278752585679099
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\AudioFile.jsonbinary
MD5:E5EC2B4D40C00AC0F7DC0916D6C0B54A
SHA256:3B64D0B41D1DE97D25B68B92CF9D8CC76159E1E191F748512F97E8EEBD508C67
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\nsis7zU.dllexecutable
MD5:06A47571AC922F82C098622B2F5F6F63
SHA256:E4AB3064F2E094910AE80104EF9D371CCB74EBBEEED592582CF099ACD83F5FE9
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\ShootData_2.Shootbinary
MD5:5D4264006A1EA73C1B757FAE6231A5B1
SHA256:86DE8B16A69904DD7E1498C8BBEF4CF8DFC81668D1D658C38BC54C1D015200F0
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\color_option_info.configbinary
MD5:BDA2814E5D65589254C92778C0742547
SHA256:59BF7736E328464ABCE7DB3D97586B18C187117B329F482CFF855C8ACDC9C491
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\mouse4K.jsonbinary
MD5:D66D5C847111B951739A20313282FB7C
SHA256:D6B754D2F8E9D2C098155DC36D40384B1DAF45590B9F6A29A1C734C1FA0E5069
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
488
svchost.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6508
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4932
DELUX-M800Ultra.exe
POST
204
47.106.123.88:80
http://acrox.eevision.com/api/updates
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
488
svchost.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.176:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.97
  • 2.16.164.99
  • 2.16.164.34
  • 2.16.164.81
  • 2.16.164.49
  • 2.16.164.106
  • 2.16.164.24
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.bing.com
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.160
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.156
  • 2.23.209.158
  • 2.23.209.181
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.103.156.88
unknown
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
Process
Message
DELUX-M800Ultra.exe
????:49647
DELUX-M800Ultra.exe
InitWindow
DELUX-M800Ultra.exe
windowinit
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
???!
DELUX-M800Ultra.exe
root
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
readjsonFile ???::2
DELUX-M800Ultra.exe
C:\Users\admin\AppData\Local\DELUX-M800Ultra\mouse\ProfileList.ini