| File name: | DirectX-Online-setup.exe |
| Full analysis: | https://app.any.run/tasks/8b80dfba-4eb4-44a3-a78c-2c3c6bcb1967 |
| Verdict: | Malicious activity |
| Analysis date: | March 17, 2024, 15:53:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1A98AE36BE4022BFBAEE265EEA1412C1 |
| SHA1: | 844C1C40ACF8E8D81D4C6E22A2371AD439F92374 |
| SHA256: | CED3ABC10A60DA7E61AE0E96A0E9D874A10EB4E47BB72D2D383413846A7F5A23 |
| SSDEEP: | 98304:zvVTzC7cJrQTh1ry9zBWWy87UDWg/3+i+T69PJqO0ejjh5nXTOhH7fefi9Yw1QF0:h |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:08:16 11:05:43+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 48640 |
| InitializedDataSize: | 128000 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x912e |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2152 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\wget.exe" -O down.exe https://download.yandex.ru/yandex-pack/downloader/downloader.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\wget.exe | mshta.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2208 | "C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX0\start.hta" | C:\Windows\System32\mshta.exe | — | DirectX-Online-setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2340 | "C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe" | C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe" x wget.zip -aoa | C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe | mshta.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 4.57 Modules
| |||||||||||||||
| 2484 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe | setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DirectX Setup Exit code: 0 Version: 4.9.0.0904 Modules
| |||||||||||||||
| 2592 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe | mshta.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DirectX 9.0 Web setup Exit code: 0 Version: 9.29.1974.0 Modules
| |||||||||||||||
| 3996 | "C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe" | C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3996) DirectX-Online-setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3996) DirectX-Online-setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3996) DirectX-Online-setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3996) DirectX-Online-setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2208) mshta.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.dll | executable | |
MD5:AACD9B8E5E5E369C3518B86486CFC9D4 | SHA256:E876CAB250EB2B0AAB976FF9922A3945E2B4724166B0EFB64690B46FE470CD3C | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\gteb.vbs | text | |
MD5:79582960EA8E7190A156231577AD9DC1 | SHA256:B81AFBFEE263BD14F87A7C6BB8B853611E183CDAC17B400CC839503C0145C82F | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\img\logo-offer.png | image | |
MD5:072679C20456E6B83EA3707A7C4E7B6F | SHA256:8A0087C2D38FA04F54E2F8A39310EB6FBDC8849C61A55AE235D4B121052A2E6A | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\gtea.vbs | text | |
MD5:84834322F1C96087E391DC6109B7430A | SHA256:E9C7753D760B6F210D42422AE00D79B1EE2884D148A601AF43DFAC7A1E819962 | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\last-page.html | html | |
MD5:3C4D57A85DB135ABAE5B8DB5DCA522F0 | SHA256:5F9D15B192B5078386FD506641EB489E243AF47F32A470C4288EA2F5CE756922 | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\gam-page.html | html | |
MD5:4DCFE0BA1B5951F4C07CD1EB27796DCB | SHA256:3FE779A967BD0ECE0FA0F447FDC94070F55D10D20E7FF487613DCFFCF33A8A72 | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe | executable | |
MD5:2D1C72072FEC74FB0ECA850EF8F9F93E | SHA256:B93149E44239DBDD5E6705C73AE14EE11285923E963E41E8D142E4171F20F4EB | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\gtec.vbs | text | |
MD5:E1EE479F2602979F43456193BDDFB564 | SHA256:7FD02C0E1D8EBF1DAF8F5F4D9E79B85CB5F1CA687CBFECB88D708690F4B96910 | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\icon.ico | image | |
MD5:D5EB89CC40AF2C886D5AA0AB1B1E7C3F | SHA256:65161948F1C0F6C74BAD5C2B9762AC2B490677A54C42D388E9AAFD2760A9EE93 | |||
| 3996 | DirectX-Online-setup.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\Linkf.zip | compressed | |
MD5:53E6A02CC1A922184E2E360D254310A5 | SHA256:FEAD2F25DE0A845ECD6D468DE45A69DA0A197A482EC317FE6B7810EFD501D6DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_x3daudio_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_xact_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D | unknown | binary | 471 b | unknown |
2484 | dxwsetup.exe | GET | 304 | 184.24.77.174:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dd4108ad84189a59 | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab | unknown | — | — | unknown |
2484 | dxwsetup.exe | GET | 302 | 23.32.101.194:80 | http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2152 | wget.exe | 5.45.205.242:443 | download.yandex.ru | YANDEX LLC | RU | whitelisted |
2152 | wget.exe | 185.70.202.15:443 | ext-cachev2-itt03.cdn.yandex.net | TELECOM ITALIA SPARKLE S.p.A. | IT | unknown |
2484 | dxwsetup.exe | 23.32.101.194:80 | download.microsoft.com | AKAMAI-AS | SE | unknown |
2484 | dxwsetup.exe | 23.32.101.194:443 | download.microsoft.com | AKAMAI-AS | SE | unknown |
2484 | dxwsetup.exe | 184.24.77.174:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2484 | dxwsetup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
download.yandex.ru |
| whitelisted |
ext-cachev2-itt03.cdn.yandex.net |
| whitelisted |
download.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
Process | Message |
|---|---|
dxwsetup.exe | DLL_PROCESS_ATTACH |
dxwsetup.exe | DLL_PROCESS_ATTACH |
dxwsetup.exe | Invalid parameter passed to C runtime function.
|
dxwsetup.exe | Invalid parameter passed to C runtime function.
|
dxwsetup.exe | DLL_PROCESS_DETACH |
dxwsetup.exe | DLL_PROCESS_DETACH |