| File name: | 7l_css_setup.exe |
| Full analysis: | https://app.any.run/tasks/4b98dde9-9376-43ee-8fff-99ae4fe2ec2e |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 30, 2025, 13:49:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections |
| MD5: | F8AC96DB7E545BF100F63D8EDDD58796 |
| SHA1: | 7C9BB664565F2D26FC9C1B0BCBA505CB5FE07CA7 |
| SHA256: | C935A3FE231FAD5800B348CFF4B88044B17D4DFBCC13307335410D7C9FEEA30B |
| SSDEEP: | 98304:2rq3Bdw8he4FLj2HpU/mA4+FIMWuPBL7hFYrnPhZAlU3bN5PHXLEBlmhuzvQeOGE:dJjgX |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:12 07:26:53+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 685056 |
| InitializedDataSize: | 301056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa83bc |
| OSVersion: | 6.1 |
| ImageVersion: | - |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | SE7EN Solutions |
| FileDescription: | 7Launcher - CS Source Setup |
| FileVersion: | 1.5.6 |
| LegalCopyright: | SE7EN Solutions |
| OriginalFileName: | |
| ProductName: | 7Launcher - CS Source |
| ProductVersion: | 1.5.6 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 660 | "C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe" /SPAWNWND=$50268 /NOTIFYWND=$60256 | C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe | 7l_css_setup.tmp | ||||||||||||
User: admin Company: SE7EN Solutions Integrity Level: HIGH Description: 7Launcher - CS Source Setup Exit code: 0 Version: 1.5.6 Modules
| |||||||||||||||
| 1012 | netsh advfirewall firewall add rule name="7Launcher - CS Source Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source Out" enable=yes profile=any interfacetype=any | C:\Windows\System32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1628 | "C:\Program Files\Counter-Strike Source\Run_CSS.exe" - forceupdate | C:\Program Files\Counter-Strike Source\Run_CSS.exe | 7l_css_setup.tmp | ||||||||||||
User: admin Company: SE7EN Solutions Ltd. Integrity Level: HIGH Description: 7Launcher − CS: Source Version: 1.5.6.0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2288 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3008 | netsh advfirewall firewall add rule name="7Launcher - CS Source In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source In" enable=yes profile=any edge=yes interfacetype=any | C:\Windows\System32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3768 | "cmd.exe" /c netsh advfirewall firewall add rule name="7Launcher P2P In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P In" enable=yes profile=any edge=yes interfacetype=any & netsh advfirewall firewall add rule name="7Launcher P2P Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P Out" enable=yes profile=any interfacetype=any & netsh advfirewall firewall add rule name="7Launcher - CS Source In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source In" enable=yes profile=any edge=yes interfacetype=any & netsh advfirewall firewall add rule name="7Launcher - CS Source Out" dir=out action=allow program="C:\Program Files\Counter-Strike Source\Run_CSS.exe" description="7Launcher - CS Source Out" enable=yes profile=any interfacetype=any | C:\Windows\System32\cmd.exe | — | 7l_css_setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4400 | "taskkill.exe" /f /im "Run_CSS.exe" | C:\Windows\System32\taskkill.exe | — | 7l_css_setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4428 | netsh advfirewall firewall add rule name="7Launcher P2P In" dir=in action=allow program="C:\Program Files\Counter-Strike Source\7launcher\tools\aria2\aria2c.exe" description="7Launcher P2P In" enable=yes profile=any edge=yes interfacetype=any | C:\Windows\System32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4740 | "C:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmp" /SL5="$40260,2262484,987136,C:\Users\admin\AppData\Local\Temp\7l_css_setup.exe" /SPAWNWND=$50268 /NOTIFYWND=$60256 | C:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmp | 7l_css_setup.exe | ||||||||||||
User: admin Company: SE7EN Solutions Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.3.3 | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\Counter-Strike Source | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Counter-Strike Source\ | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: 7Launcher | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: Selected Tasks |
Value: desktopicon | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: Deselected Tasks |
Value: | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | Inno Setup: Language |
Value: English | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | DisplayName |
Value: 7Launcher - CS Source v1.5.6 | |||
| (PID) Process: | (4740) 7l_css_setup.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7Launcher - CS Source_is1 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Counter-Strike Source\Run_CSS.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 660 | 7l_css_setup.exe | C:\Users\admin\AppData\Local\Temp\is-F0II9.tmp\7l_css_setup.tmp | executable | |
MD5:67E07528328DA83C29C98AED97137EF5 | SHA256:73237765D458111FF8C55A8DE093CC44DCDEEFBEFF31FA8B9E1A8F7F2E3253B9 | |||
| 4740 | 7l_css_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-3O14M.tmp\_isetup\_iscrypt.dll | executable | |
MD5:F036861817595C58AE92A6A00FC1CFA8 | SHA256:8623787D415532B869ED0E37B33E2063F974F33A0E366431A59E7DB8B7587F58 | |||
| 4740 | 7l_css_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-3O14M.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 1628 | Run_CSS.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\tg_channel_banner-pls-cat[1].png | image | |
MD5:9F02F4439B5D412B8F18D87FFAD5330C | SHA256:3F904C2741AD152A2C3CD8E27A20C6212FEF888F70A1FCB67A0813B29196E99F | |||
| 4740 | 7l_css_setup.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7Launcher\Counter-Strike Source [7L].lnk | binary | |
MD5:74A190AD848521F5454F37B01BD62D02 | SHA256:F1C44C33FD1ED089F2238BF69F5C74F1F90858ABAEF20C82D23E5E5756786BBE | |||
| 4740 | 7l_css_setup.tmp | C:\Program Files\Counter-Strike Source\7launcher\is-JVGOQ.tmp | image | |
MD5:72048E15A7668A0DB540F02AEC1997B4 | SHA256:43868BD9E6DF64AD0C3840A7D6D02E00831D6439997C92D6B1FBC307BDEB3EED | |||
| 4740 | 7l_css_setup.tmp | C:\Program Files\Counter-Strike Source\Run_CSS.exe | executable | |
MD5:B83646236814B14C263FEFF0745E46F7 | SHA256:0F85C8740A3EDC3255357A0E486DD4583706202DF1FAE95A578D7DC539D3179C | |||
| 4740 | 7l_css_setup.tmp | C:\Program Files\Counter-Strike Source\uninstall7l\is-R50TA.tmp | executable | |
MD5:67E07528328DA83C29C98AED97137EF5 | SHA256:73237765D458111FF8C55A8DE093CC44DCDEEFBEFF31FA8B9E1A8F7F2E3253B9 | |||
| 4740 | 7l_css_setup.tmp | C:\Program Files\Counter-Strike Source\is-OBT3H.tmp | executable | |
MD5:B83646236814B14C263FEFF0745E46F7 | SHA256:0F85C8740A3EDC3255357A0E486DD4583706202DF1FAE95A578D7DC539D3179C | |||
| 4740 | 7l_css_setup.tmp | C:\Program Files\Counter-Strike Source\uninstall7l\unins000.dat | binary | |
MD5:8A71A0781F5E0CCEBEA694020BDF7910 | SHA256:28970FAFAF850F020C043D15ABECABD9D101BCF0FF001186D2255FE860688D51 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.25:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://updater.se7enkills.net/cstrike//en/ | NL | html | 1.04 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://updater.se7enkills.net/cstrike/inf.ini | NL | text | 2.13 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://updater.se7enkills.net/images/7l-cs-source-header.png | NL | image | 93.6 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://updater.se7enkills.net/images/eng/tg_channel_banner-pls-cat.png | NL | image | 8.97 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 142.250.181.227:80 | http://c.pki.goog/r/r4.crl | US | binary | 436 b | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 142.250.181.227:80 | http://c.pki.goog/r/gsr1.crl | US | binary | 1.70 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://updater.se7enkills.net/cstrike/check_css_93up2.dim.lzma | NL | compressed | 18.4 Kb | whitelisted |
1628 | Run_CSS.exe | GET | 200 | 188.114.97.3:80 | http://se7en.pw/c/css/93up2/cstrike.exe.lzma | NL | compressed | 72.8 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.25:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6544 | svchost.exe | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1628 | Run_CSS.exe | 188.114.97.3:80 | updater.se7enkills.net | CLOUDFLARENET | NL | malicious |
1628 | Run_CSS.exe | 142.250.181.232:443 | www.googletagmanager.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
updater.se7enkills.net |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
c.pki.goog |
| whitelisted |
o.pki.goog |
| whitelisted |
se7en.pw |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
1628 | Run_CSS.exe | A Network Trojan was detected | ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
1628 | Run_CSS.exe | A Network Trojan was detected | ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
1628 | Run_CSS.exe | A Network Trojan was detected | ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
1628 | Run_CSS.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |