File name:

DELUX-M800Ultra.exe

Full analysis: https://app.any.run/tasks/367b074a-775b-424e-8f05-272f4c134089
Verdict: Malicious activity
Analysis date: December 18, 2024, 17:06:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

27628BD9EA01355C68AC950732A3BC46

SHA1:

BCFF08A45E9A0D0ABD79742706189EFFF603D9AE

SHA256:

9ED169174752B7619D3E04738B3E39C883C36418DE5ABCD9C688F93E4EED4459

SSDEEP:

98304:dPhClfHMhiygveF+oylDlQNXsaeMHU7cXydU3aDdYjwVkmOwM7XmYl6Zr5QYxcjH:i5HvkVfGpfwpPZUy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • DELUX-M800Ultra.exe (PID: 6896)
    • Drops 7-zip archiver for unpacking

      • DELUX-M800Ultra.exe (PID: 6896)
    • Executable content was dropped or overwritten

      • DELUX-M800Ultra.exe (PID: 6896)
    • Creates a software uninstall entry

      • DELUX-M800Ultra.exe (PID: 6896)
    • Searches for installed software

      • DELUX-M800Ultra.exe (PID: 4932)
  • INFO

    • Checks supported languages

      • DELUX-M800Ultra.exe (PID: 6896)
      • DELUX-M800Ultra.exe (PID: 4932)
    • The sample compiled with chinese language support

      • DELUX-M800Ultra.exe (PID: 6896)
    • Reads the computer name

      • DELUX-M800Ultra.exe (PID: 6896)
      • DELUX-M800Ultra.exe (PID: 4932)
    • Create files in a temporary directory

      • DELUX-M800Ultra.exe (PID: 6896)
    • The sample compiled with english language support

      • DELUX-M800Ultra.exe (PID: 6896)
    • Creates files in the program directory

      • DELUX-M800Ultra.exe (PID: 6896)
    • Sends debugging messages

      • DELUX-M800Ultra.exe (PID: 4932)
    • Creates files or folders in the user directory

      • DELUX-M800Ultra.exe (PID: 4932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:20:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 29696
InitializedDataSize: 489984
UninitializedDataSize: 16896
EntryPoint: 0x38af
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.7
ProductVersionNumber: 1.0.0.7
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Chinese (Simplified)
CompanyName: DELUX
FileDescription: DELUX-M800Ultra
FileVersion: 1.0.0.7
InternalName: DELUX-M800Ultra.exe
LegalCopyright: Copyright (C) 2023
ProductName: DELUX-M800Ultra
ProductVersion: 1.0.0.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start delux-m800ultra.exe delux-m800ultra.exe delux-m800ultra.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4932"C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe"C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe
DELUX-M800Ultra.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\delux-m800ultra\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6728"C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe" C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exeexplorer.exe
User:
admin
Company:
DELUX
Integrity Level:
MEDIUM
Description:
DELUX-M800Ultra
Exit code:
3221226540
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6896"C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe" C:\Users\admin\AppData\Local\Temp\DELUX-M800Ultra.exe
explorer.exe
User:
admin
Company:
DELUX
Integrity Level:
HIGH
Description:
DELUX-M800Ultra
Exit code:
0
Version:
1.0.0.7
Modules
Images
c:\users\admin\appdata\local\temp\delux-m800ultra.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
571
Read events
559
Write events
12
Delete events
0

Modification events

(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\DELUX-M800Ultra
Operation:writeName:LANGUAGE
Value:
1033
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\DELUX-M800Ultra
Operation:writeName:InstPath
Value:
C:\Program Files (x86)\DELUX-M800Ultra
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayName
Value:
DELUX-M800Ultra
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\DELUX-M800Ultra\uninst.exe
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\DELUX-M800Ultra\DELUX-M800Ultra.exe
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:Publisher
Value:
DELUX
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:DisplayVersion
Value:
1.0.0.7
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:HelpLink
Value:
www.deluxworld.com
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:URLInfoAbout
Value:
www.deluxworld.com
(PID) Process:(6896) DELUX-M800Ultra.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DELUX-M800Ultra
Operation:writeName:Comments
Value:
www.deluxworld.com
Executable files
18
Suspicious files
25
Text files
737
Unknown types
0

Dropped files

PID
Process
Filename
Type
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\app.7z
MD5:
SHA256:
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\Font\MiSans-Normal.ttf
MD5:
SHA256:
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\nsis7zU.dllexecutable
MD5:06A47571AC922F82C098622B2F5F6F63
SHA256:E4AB3064F2E094910AE80104EF9D371CCB74EBBEEED592582CF099ACD83F5FE9
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\skin.zipcompressed
MD5:B29D4B880C354C24D418921622A6E522
SHA256:6F658667839DC2469E2B5F83CBF9F5EDB64CB6D244977252917E64B60AA750A1
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\Skin\.idea\modules.xmlxml
MD5:61BFA2D0D24B314F6F4DDCDEA4FE86E0
SHA256:1DC3CE383CC12FA88132A886BC7AC3B8DC3EF01FF5472F6B857813D9B0E480D3
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\nsNiuniuSkin.dllexecutable
MD5:1834FD72E6A7387749D014A30B53D6AC
SHA256:148CB136FF5AE9711DDB869B5F22065EE89E13EAF5081CE39C07DBE89CCD97B7
6896DELUX-M800Ultra.exeC:\Users\admin\AppData\Local\Temp\nsm5C9B.tmp\System.dllexecutable
MD5:BF712F32249029466FA86756F5546950
SHA256:7851CB12FA4131F1FEE5DE390D650EF65CAC561279F1CFE70AD16CC9780210AF
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\logo.icoimage
MD5:2F07E0B664D55BB47BB91AD2352C1837
SHA256:B43FFA56DB1F56F475FEBF6B7A340C5D6770E6460373FEC8A278752585679099
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\AudioFile.jsonbinary
MD5:E5EC2B4D40C00AC0F7DC0916D6C0B54A
SHA256:3B64D0B41D1DE97D25B68B92CF9D8CC76159E1E191F748512F97E8EEBD508C67
6896DELUX-M800Ultra.exeC:\Program Files (x86)\DELUX-M800Ultra\DefaultData\color_option_info.configbinary
MD5:BDA2814E5D65589254C92778C0742547
SHA256:59BF7736E328464ABCE7DB3D97586B18C187117B329F482CFF855C8ACDC9C491
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
488
svchost.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.97:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6508
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6360
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4932
DELUX-M800Ultra.exe
POST
204
47.106.123.88:80
http://acrox.eevision.com/api/updates
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
488
svchost.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.97:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.176:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.97
  • 2.16.164.99
  • 2.16.164.34
  • 2.16.164.81
  • 2.16.164.49
  • 2.16.164.106
  • 2.16.164.24
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.bing.com
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.160
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.185
  • 2.23.209.156
  • 2.23.209.158
  • 2.23.209.181
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.74
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.103.156.88
unknown
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
Process
Message
DELUX-M800Ultra.exe
????:49647
DELUX-M800Ultra.exe
InitWindow
DELUX-M800Ultra.exe
windowinit
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
???!
DELUX-M800Ultra.exe
root
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
readjsonFile ???::0
DELUX-M800Ultra.exe
readjsonFile ???::2
DELUX-M800Ultra.exe
C:\Users\admin\AppData\Local\DELUX-M800Ultra\mouse\ProfileList.ini