File name:

7l_css_setup.exe

Full analysis: https://app.any.run/tasks/4b98dde9-9376-43ee-8fff-99ae4fe2ec2e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 30, 2025, 13:49:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

F8AC96DB7E545BF100F63D8EDDD58796

SHA1:

7C9BB664565F2D26FC9C1B0BCBA505CB5FE07CA7

SHA256:

C935A3FE231FAD5800B348CFF4B88044B17D4DFBCC13307335410D7C9FEEA30B

SSDEEP:

98304:2rq3Bdw8he4FLj2HpU/mA4+FIMWuPBL7hFYrnPhZAlU3bN5PHXLEBlmhuzvQeOGE:dJjgX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 7l_css_setup.tmp (PID: 4776)
      • 7l_css_setup.tmp (PID: 4740)
      • Run_CSS.exe (PID: 1628)
    • Executable content was dropped or overwritten

      • 7l_css_setup.exe (PID: 5072)
      • 7l_css_setup.exe (PID: 660)
      • Run_CSS.exe (PID: 1628)
      • 7l_css_setup.tmp (PID: 4740)
    • Starts CMD.EXE for commands execution

      • 7l_css_setup.tmp (PID: 4740)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 3768)
    • Reads Microsoft Outlook installation path

      • Run_CSS.exe (PID: 1628)
    • Reads Internet Explorer settings

      • Run_CSS.exe (PID: 1628)
    • Process requests binary or script from the Internet

      • Run_CSS.exe (PID: 1628)
    • The process drops C-runtime libraries

      • Run_CSS.exe (PID: 1628)
    • Process drops legitimate windows executable

      • Run_CSS.exe (PID: 1628)
    • There is functionality for taking screenshot (YARA)

      • Run_CSS.exe (PID: 1628)
    • The process creates files with name similar to system file names

      • Run_CSS.exe (PID: 1628)
    • Uses TASKKILL.EXE to kill process

      • 7l_css_setup.tmp (PID: 4740)
    • Reads the Windows owner or organization settings

      • 7l_css_setup.tmp (PID: 4740)
  • INFO

    • Checks supported languages

      • 7l_css_setup.tmp (PID: 4776)
      • 7l_css_setup.exe (PID: 5072)
      • 7l_css_setup.exe (PID: 660)
      • 7l_css_setup.tmp (PID: 4740)
      • Run_CSS.exe (PID: 1628)
    • Create files in a temporary directory

      • 7l_css_setup.exe (PID: 5072)
      • 7l_css_setup.exe (PID: 660)
      • 7l_css_setup.tmp (PID: 4740)
    • Detects InnoSetup installer (YARA)

      • 7l_css_setup.exe (PID: 5072)
      • 7l_css_setup.tmp (PID: 4776)
    • Compiled with Borland Delphi (YARA)

      • 7l_css_setup.exe (PID: 5072)
      • 7l_css_setup.tmp (PID: 4776)
      • Run_CSS.exe (PID: 1628)
      • slui.exe (PID: 2288)
    • Process checks computer location settings

      • 7l_css_setup.tmp (PID: 4776)
      • 7l_css_setup.tmp (PID: 4740)
    • Reads the computer name

      • 7l_css_setup.tmp (PID: 4776)
      • 7l_css_setup.exe (PID: 660)
      • Run_CSS.exe (PID: 1628)
      • 7l_css_setup.tmp (PID: 4740)
    • The sample compiled with english language support

      • 7l_css_setup.tmp (PID: 4740)
      • Run_CSS.exe (PID: 1628)
    • Creates a software uninstall entry

      • 7l_css_setup.tmp (PID: 4740)
    • Process checks whether UAC notifications are on

      • Run_CSS.exe (PID: 1628)
    • Checks proxy server information

      • Run_CSS.exe (PID: 1628)
      • slui.exe (PID: 2288)
    • Reads the machine GUID from the registry

      • Run_CSS.exe (PID: 1628)
    • Creates files or folders in the user directory

      • Run_CSS.exe (PID: 1628)
    • The sample compiled with russian language support

      • Run_CSS.exe (PID: 1628)
    • Reads the software policy settings

      • slui.exe (PID: 5544)
      • Run_CSS.exe (PID: 1628)
      • slui.exe (PID: 2288)
    • Creates files in the program directory

      • Run_CSS.exe (PID: 1628)
      • 7l_css_setup.tmp (PID: 4740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:12 07:26:53+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 685056
InitializedDataSize: 301056
UninitializedDataSize: -
EntryPoint: 0xa83bc
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: SE7EN Solutions
FileDescription: 7Launcher - CS Source Setup
FileVersion: 1.5.6
LegalCopyright: SE7EN Solutions
OriginalFileName:
ProductName: 7Launcher - CS Source
ProductVersion: 1.5.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
17
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 7l_css_setup.exe 7l_css_setup.tmp no specs 7l_css_setup.exe 7l_css_setup.tmp sppextcomobj.exe no specs slui.exe taskkill.exe no specs conhost.exe no specs run_css.exe cmd.exe no specs conhost.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs slui.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe" /SPAWNWND=$50268 /NOTIFYWND=$60256 C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe
7l_css_setup.tmp
User:
admin
Company:
SE7EN Solutions
Integrity Level:
HIGH
Description:
7Launcher - CS Source Setup
Exit code:
0
Version:
1.5.6
Modules
Images
c:\users\admin\appdata\local\temp\7l_css_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1012netsh advfirewall firewall add rule name="7Launcher - CS Source Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source Out" enable=yes profile=any interfacetype=anyC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1628"C:\Program Files\Counter-Strike Source\Run_CSS.exe" - forceupdateC:\Program Files\Counter-Strike Source\Run_CSS.exe
7l_css_setup.tmp
User:
admin
Company:
SE7EN Solutions Ltd.
Integrity Level:
HIGH
Description:
7Launcher − CS: Source
Version:
1.5.6.0
Modules
Images
c:\program files\counter-strike source\run_css.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2288C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3008netsh advfirewall firewall add rule name="7Launcher - CS Source In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source In" enable=yes profile=any edge=yes interfacetype=any C:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3768"cmd.exe" /c netsh advfirewall firewall add rule name="7Launcher P2P In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P In" enable=yes profile=any edge=yes interfacetype=any & netsh advfirewall firewall add rule name="7Launcher P2P Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P Out" enable=yes profile=any interfacetype=any & netsh advfirewall firewall add rule name="7Launcher - CS Source In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source In" enable=yes profile=any edge=yes interfacetype=any & netsh advfirewall firewall add rule name="7Launcher - CS Source Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source Out" enable=yes profile=any interfacetype=anyC:\Windows\System32\cmd.exe7l_css_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
4400"taskkill.exe" /f /im "Run_CSS.exe"C:\Windows\System32\taskkill.exe7l_css_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4428netsh advfirewall firewall add rule name="7Launcher P2P In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P In" enable=yes profile=any edge=yes interfacetype=any C:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4740"C:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmp" /SL5="$40260,2262484,987136,C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe" /SPAWNWND=$50268 /NOTIFYWND=$60256 C:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmp
7l_css_setup.exe
User:
admin
Company:
SE7EN Solutions
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-f0ii9.tmp\7l_css_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
4 675
Read events
4 642
Write events
33
Delete events
0

Modification events

(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.3.3
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\Counter-Strike Source
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Counter-Strike Source\
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: Icon Group
Value:
7Launcher
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:Inno Setup: Language
Value:
English
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:DisplayName
Value:
7Launcher - CS Source v1.5.6
(PID) Process:(4740) 7l_css_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Counter-Strike Source\Run_CSS.exe
Executable files
248
Suspicious files
339
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
6607l_css_setup.exeC:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmpexecutable
MD5:67E07528328DA83C29C98AED97137EF5
SHA256:73237765D458111FF8C55A8DE093CC44DCDEEFBEFF31FA8B9E1A8F7F2E3253B9
47407l_css_setup.tmpC:\Users\admin\AppData\Local\Temp\is-3O14M.tmp\_isetup\_iscrypt.dllexecutable
MD5:F036861817595C58AE92A6A00FC1CFA8
SHA256:8623787D415532B869ED0E37B33E2063F974F33A0E366431A59E7DB8B7587F58
47407l_css_setup.tmpC:\Users\admin\AppData\Local\Temp\is-3O14M.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
1628Run_CSS.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\tg_channel_banner-pls-cat[1].pngimage
MD5:9F02F4439B5D412B8F18D87FFAD5330C
SHA256:3F904C2741AD152A2C3CD8E27A20C6212FEF888F70A1FCB67A0813B29196E99F
47407l_css_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\7Launcher\Counter-Strike Source [7L].lnkbinary
MD5:74A190AD848521F5454F37B01BD62D02
SHA256:F1C44C33FD1ED089F2238BF69F5C74F1F90858ABAEF20C82D23E5E5756786BBE
47407l_css_setup.tmpC:\Program Files\Counter-Strike Source\7launcher\is-JVGOQ.tmpimage
MD5:72048E15A7668A0DB540F02AEC1997B4
SHA256:43868BD9E6DF64AD0C3840A7D6D02E00831D6439997C92D6B1FBC307BDEB3EED
47407l_css_setup.tmpC:\Program Files\Counter-Strike Source\Run_CSS.exeexecutable
MD5:B83646236814B14C263FEFF0745E46F7
SHA256:0F85C8740A3EDC3255357A0E486DD4583706202DF1FAE95A578D7DC539D3179C
47407l_css_setup.tmpC:\Program Files\Counter-Strike Source\uninstall7l\is-R50TA.tmpexecutable
MD5:67E07528328DA83C29C98AED97137EF5
SHA256:73237765D458111FF8C55A8DE093CC44DCDEEFBEFF31FA8B9E1A8F7F2E3253B9
47407l_css_setup.tmpC:\Program Files\Counter-Strike Source\is-OBT3H.tmpexecutable
MD5:B83646236814B14C263FEFF0745E46F7
SHA256:0F85C8740A3EDC3255357A0E486DD4583706202DF1FAE95A578D7DC539D3179C
47407l_css_setup.tmpC:\Program Files\Counter-Strike Source\uninstall7l\unins000.datbinary
MD5:8A71A0781F5E0CCEBEA694020BDF7910
SHA256:28970FAFAF850F020C043D15ABECABD9D101BCF0FF001186D2255FE860688D51
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
351
TCP/UDP connections
30
DNS requests
22
Threats
405

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://updater.se7enkills.net/cstrike//en/
NL
html
1.04 Kb
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://updater.se7enkills.net/cstrike/inf.ini
NL
text
2.13 Kb
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://updater.se7enkills.net/images/7l-cs-source-header.png
NL
image
93.6 Kb
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://updater.se7enkills.net/images/eng/tg_channel_banner-pls-cat.png
NL
image
8.97 Kb
whitelisted
1628
Run_CSS.exe
GET
200
142.250.181.227:80
http://c.pki.goog/r/r4.crl
US
binary
436 b
whitelisted
1628
Run_CSS.exe
GET
200
142.250.181.227:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://updater.se7enkills.net/cstrike/check_css_93up2.dim.lzma
NL
compressed
18.4 Kb
whitelisted
1628
Run_CSS.exe
GET
200
188.114.97.3:80
http://se7en.pw/c/css/93up2/cstrike.exe.lzma
NL
compressed
72.8 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.25:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1628
Run_CSS.exe
188.114.97.3:80
updater.se7enkills.net
CLOUDFLARENET
NL
malicious
1628
Run_CSS.exe
142.250.181.232:443
www.googletagmanager.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.12
  • 23.216.77.21
  • 23.216.77.15
  • 23.216.77.8
  • 23.216.77.11
  • 23.216.77.27
  • 23.216.77.28
  • 23.216.77.29
whitelisted
google.com
  • 216.58.212.142
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.72
  • 20.190.160.2
  • 20.190.160.66
  • 40.126.32.136
  • 20.190.160.5
  • 40.126.32.134
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
updater.se7enkills.net
  • 188.114.97.3
  • 188.114.96.3
whitelisted
www.googletagmanager.com
  • 142.250.181.232
whitelisted
c.pki.goog
  • 142.250.181.227
whitelisted
o.pki.goog
  • 142.250.186.99
whitelisted
se7en.pw
  • 188.114.97.3
  • 188.114.96.3
malicious

Threats

PID
Process
Class
Message
2196
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.pw domain - Likely Hostile
1628
Run_CSS.exe
A Network Trojan was detected
ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1628
Run_CSS.exe
A Network Trojan was detected
ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1628
Run_CSS.exe
A Network Trojan was detected
ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
1628
Run_CSS.exe
Misc activity
ET INFO HTTP Request to a *.pw domain
No debug info