URL:

https://p12726.therapy.nethealth.com/ROX/GiftRAP.Client.application?url=https://P12726.therapy.nethealth.com/ROX&service=WCF

Full analysis: https://app.any.run/tasks/64b46201-9815-43d4-9f42-4642414686aa
Verdict: Malicious activity
Analysis date: October 18, 2023, 20:16:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

F42C98AFBB4A63ACD8D64145B48208F5CFAB3061

SHA256:

A67F343E34E74AE020C3CD92233BA6363037AB0B14C957EF6B61E4E51A575017

SSDEEP:

3:N8QCBNAFARPXa/LmCeLgYMQbZYNVYTOSDLRNAFARPXaAyTwmjn:2QkA6RPXaMgW6OTpA6RPXaAAwUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GiftRAP.Client.exe (PID: 916)
    • Drops the executable file immediately after the start

      • GiftRAP.Client.exe (PID: 916)
      • dfsvc.exe (PID: 1396)
    • Loads dropped or rewritten executable

      • GiftRAP.Client.exe (PID: 916)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • dfsvc.exe (PID: 1396)
    • Reads Internet Explorer settings

      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Reads settings of System Certificates

      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Reads the Internet Settings

      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Process drops legitimate windows executable

      • dfsvc.exe (PID: 1396)
    • The process drops C-runtime libraries

      • dfsvc.exe (PID: 1396)
    • The process creates files with name similar to system file names

      • dfsvc.exe (PID: 1396)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1884)
    • Checks supported languages

      • dfsvc.exe (PID: 1396)
      • wmpnscfg.exe (PID: 3512)
      • GiftRAP.Client.exe (PID: 916)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3512)
      • explorer.exe (PID: 3248)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3512)
      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3512)
      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Checks proxy server information

      • dfsvc.exe (PID: 1396)
    • Create files in a temporary directory

      • dfsvc.exe (PID: 1396)
    • Creates files or folders in the user directory

      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Reads Environment values

      • dfsvc.exe (PID: 1396)
      • GiftRAP.Client.exe (PID: 916)
    • Process checks are UAC notifies on

      • dfsvc.exe (PID: 1396)
    • Loads dropped or rewritten executable

      • dfsvc.exe (PID: 1396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe no specs iexplore.exe wmpnscfg.exe no specs dfsvc.exe no specs dfsvc.exe explorer.exe no specs giftrap.client.exe

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Users\admin\AppData\Local\Apps\2.0\OQVLXTZK.4P5\AK6KX289.K1P\gift..tion_3b51d6be957d3474_000b.000a_5846ab071efd7ec7\GiftRAP.Client.exe"C:\Users\admin\AppData\Local\Apps\2.0\OQVLXTZK.4P5\AK6KX289.K1P\gift..tion_3b51d6be957d3474_000b.000a_5846ab071efd7ec7\GiftRAP.Client.exe
dfsvc.exe
User:
admin
Company:
Net Health
Integrity Level:
MEDIUM
Description:
Net Health Therapy
Exit code:
0
Version:
11.10.02.914
Modules
Images
c:\users\admin\appdata\local\apps\2.0\oqvlxtzk.4p5\ak6kx289.k1p\gift..tion_3b51d6be957d3474_000b.000a_5846ab071efd7ec7\giftrap.client.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1396"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
ClickOnce
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\dfsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
1884"C:\Program Files\Internet Explorer\iexplore.exe" "https://p12726.therapy.nethealth.com/ROX/GiftRAP.Client.application?url=https://P12726.therapy.nethealth.com/ROX&service=WCF"C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rpcrt4.dll
3248"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\explorer.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3512"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3820"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
ClickOnce
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\microsoft.net\framework\v4.0.30319\dfsvc.exe
3908"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1884 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
21 193
Read events
20 851
Write events
246
Delete events
96

Modification events

(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1884) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
348
Suspicious files
195
Text files
345
Unknown types
0

Dropped files

PID
Process
Filename
Type
1396dfsvc.exeC:\Users\admin\AppData\Local\Temp\Deployment\ERD74KEV.HPO\T45C9OTX.KZH\icudtl.dat
MD5:
SHA256:
3908iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3908iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:9CFC64C4EB99A29DB9613EC4067DDFA4
SHA256:6836DA00BB643327CAE6BB62AB92993433E0E524C5A274319854FFC70DB6C0F2
3908iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_53ABBAEEC270B3FAC67E69C135312DA0binary
MD5:DB4CBD52AAEAA21CD66AB8F873388C41
SHA256:C0BCA908FD436DAF4F70A16A0462F836088DB80029CDA3E0E4A35126C8369102
3908iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:0F8AADB06961BB01E3F45E6C5E04DF38
SHA256:5E0BAFFF6F2229061774F9B945D02F69CA129324B5508594290E716A42107CEC
1884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{3854D70F-6DF3-11EE-B150-12A9866C77DE}.datbinary
MD5:064E03DCF71DE17A5F9927FF846364BF
SHA256:4374EE29571758D2BADF473C2796328182E5F51DD5487F231B2FF72D04AD538E
3908iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_53ABBAEEC270B3FAC67E69C135312DA0binary
MD5:5F2ACE9F4A3AA0750AB9B54E787A6CC2
SHA256:E450EFFA04A23C2A6AD3699B4330400AD6CDEE6309DB78D2BC528ADDE68AE5F8
1884iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{3854D711-6DF3-11EE-B150-12A9866C77DE}.datbinary
MD5:9B0D0CFCA0C8F63CF1BA4F343F6975B2
SHA256:F1FE8AED8261FA808BD64FFE029163BB69BDADDCBEF45D380FDC0FE9807835C5
3908iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\GiftRAP.Client[1].applicationxml
MD5:79432B55FF161F5EF1B0696D9C181F68
SHA256:065D9F957118734CF8135C77D00C62A2EB1818B211BB64C488D187AF4F1D5F22
1396dfsvc.exeC:\Users\admin\AppData\Local\Temp\Deployment\ERD74KEV.HPO\T45C9OTX.KZH\cef.pakbinary
MD5:8FC7B5EDE33BD0C9383E192DD9CD6293
SHA256:5140ABE33C79DED61F11FD2945F5BAEF3D48024CC29E8877B6C571045AB91BAC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
12
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3908
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?44b7f016ec3320f4
unknown
compressed
4.66 Kb
unknown
3908
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEA1lNO%2FAKZllKQD3PWkG1n0%3D
unknown
binary
471 b
unknown
3908
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
binary
471 b
unknown
1396
dfsvc.exe
GET
200
192.229.221.95:80
http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt
unknown
binary
1.30 Kb
unknown
3908
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f96a15a63697bdc6
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3908
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
3908
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1396
dfsvc.exe
52.234.170.35:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1396
dfsvc.exe
18.66.112.73:443
client.therapy.nethealth.com
AMAZON-02
US
unknown
1396
dfsvc.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
916
GiftRAP.Client.exe
52.234.170.35:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.therapy.nethealth.com
  • 18.66.112.73
  • 18.66.112.86
  • 18.66.112.87
  • 18.66.112.51
unknown
cacerts.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
Process
Message
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status Originated: -1073741772 *** Source File: d:\iso_whid\x86fre\base\isolation\win32\isoreg_direct.cpp, line 1127
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: d:\iso_whid\x86fre\base\isolation\hier_hierarchy.cpp, line 230