File name:

DirectX-Online-setup.exe

Full analysis: https://app.any.run/tasks/8b80dfba-4eb4-44a3-a78c-2c3c6bcb1967
Verdict: Malicious activity
Analysis date: March 17, 2024, 15:53:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1A98AE36BE4022BFBAEE265EEA1412C1

SHA1:

844C1C40ACF8E8D81D4C6E22A2371AD439F92374

SHA256:

CED3ABC10A60DA7E61AE0E96A0E9D874A10EB4E47BB72D2D383413846A7F5A23

SSDEEP:

98304:zvVTzC7cJrQTh1ry9zBWWy87UDWg/3+i+T69PJqO0ejjh5nXTOhH7fefi9Yw1QF0:h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DirectX-Online-setup.exe (PID: 3996)
      • 7z.exe (PID: 2440)
      • wget.exe (PID: 2152)
      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Changes the autorun value in the registry

      • setup.exe (PID: 2592)
    • Creates a writable file in the system directory

      • dxwsetup.exe (PID: 2484)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DirectX-Online-setup.exe (PID: 3996)
      • 7z.exe (PID: 2440)
      • wget.exe (PID: 2152)
      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Process drops legitimate windows executable

      • DirectX-Online-setup.exe (PID: 3996)
      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Drops 7-zip archiver for unpacking

      • DirectX-Online-setup.exe (PID: 3996)
    • Reads security settings of Internet Explorer

      • DirectX-Online-setup.exe (PID: 3996)
      • dxwsetup.exe (PID: 2484)
    • Reads the Internet Settings

      • DirectX-Online-setup.exe (PID: 3996)
      • mshta.exe (PID: 2208)
      • dxwsetup.exe (PID: 2484)
    • Runs shell command (SCRIPT)

      • mshta.exe (PID: 2208)
    • Starts a Microsoft application from unusual location

      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Reads settings of System Certificates

      • wget.exe (PID: 2152)
      • dxwsetup.exe (PID: 2484)
    • Checks Windows Trust Settings

      • dxwsetup.exe (PID: 2484)
  • INFO

    • Create files in a temporary directory

      • DirectX-Online-setup.exe (PID: 3996)
      • 7z.exe (PID: 2440)
      • wget.exe (PID: 2152)
      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Checks supported languages

      • DirectX-Online-setup.exe (PID: 3996)
      • 7z.exe (PID: 2440)
      • wget.exe (PID: 2152)
      • setup.exe (PID: 2592)
      • dxwsetup.exe (PID: 2484)
    • Reads the computer name

      • DirectX-Online-setup.exe (PID: 3996)
      • wget.exe (PID: 2152)
      • dxwsetup.exe (PID: 2484)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 2208)
    • Checks proxy server information

      • mshta.exe (PID: 2208)
      • dxwsetup.exe (PID: 2484)
    • Reads the machine GUID from the registry

      • wget.exe (PID: 2152)
      • dxwsetup.exe (PID: 2484)
    • Reads the software policy settings

      • dxwsetup.exe (PID: 2484)
    • Creates files or folders in the user directory

      • dxwsetup.exe (PID: 2484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:08:16 11:05:43+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 48640
InitializedDataSize: 128000
UninitializedDataSize: -
EntryPoint: 0x912e
OSVersion: 5
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start directx-online-setup.exe mshta.exe no specs 7z.exe wget.exe setup.exe dxwsetup.exe directx-online-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2152"C:\Users\admin\AppData\Local\Temp\RarSFX0\wget.exe" -O down.exe https://download.yandex.ru/yandex-pack/downloader/downloader.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\wget.exe
mshta.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\wget.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2208"C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX0\start.hta" C:\Windows\System32\mshta.exeDirectX-Online-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2340"C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe" C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\directx-online-setup.exe
c:\windows\system32\ntdll.dll
2440"C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe" x wget.zip -aoaC:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe
mshta.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
4.57
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2484C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX Setup
Exit code:
0
Version:
4.9.0.0904
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2592"C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DirectX 9.0 Web setup
Exit code:
0
Version:
9.29.1974.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3996"C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe" C:\Users\admin\AppData\Local\Temp\DirectX-Online-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\directx-online-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
13 525
Read events
13 453
Write events
59
Delete events
13

Modification events

(PID) Process:(3996) DirectX-Online-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3996) DirectX-Online-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3996) DirectX-Online-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3996) DirectX-Online-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2208) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
Executable files
16
Suspicious files
126
Text files
15
Unknown types
2

Dropped files

PID
Process
Filename
Type
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\7z.dllexecutable
MD5:AACD9B8E5E5E369C3518B86486CFC9D4
SHA256:E876CAB250EB2B0AAB976FF9922A3945E2B4724166B0EFB64690B46FE470CD3C
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\gteb.vbstext
MD5:79582960EA8E7190A156231577AD9DC1
SHA256:B81AFBFEE263BD14F87A7C6BB8B853611E183CDAC17B400CC839503C0145C82F
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\img\logo-offer.pngimage
MD5:072679C20456E6B83EA3707A7C4E7B6F
SHA256:8A0087C2D38FA04F54E2F8A39310EB6FBDC8849C61A55AE235D4B121052A2E6A
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\gtea.vbstext
MD5:84834322F1C96087E391DC6109B7430A
SHA256:E9C7753D760B6F210D42422AE00D79B1EE2884D148A601AF43DFAC7A1E819962
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\last-page.htmlhtml
MD5:3C4D57A85DB135ABAE5B8DB5DCA522F0
SHA256:5F9D15B192B5078386FD506641EB489E243AF47F32A470C4288EA2F5CE756922
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\gam-page.htmlhtml
MD5:4DCFE0BA1B5951F4C07CD1EB27796DCB
SHA256:3FE779A967BD0ECE0FA0F447FDC94070F55D10D20E7FF487613DCFFCF33A8A72
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exeexecutable
MD5:2D1C72072FEC74FB0ECA850EF8F9F93E
SHA256:B93149E44239DBDD5E6705C73AE14EE11285923E963E41E8D142E4171F20F4EB
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\gtec.vbstext
MD5:E1EE479F2602979F43456193BDDFB564
SHA256:7FD02C0E1D8EBF1DAF8F5F4D9E79B85CB5F1CA687CBFECB88D708690F4B96910
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\icon.icoimage
MD5:D5EB89CC40AF2C886D5AA0AB1B1E7C3F
SHA256:65161948F1C0F6C74BAD5C2B9762AC2B490677A54C42D388E9AAFD2760A9EE93
3996DirectX-Online-setup.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Linkf.zipcompressed
MD5:53E6A02CC1A922184E2E360D254310A5
SHA256:FEAD2F25DE0A845ECD6D468DE45A69DA0A197A482EC317FE6B7810EFD501D6DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
43
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_x3daudio_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_xact_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab
unknown
unknown
2484
dxwsetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
unknown
binary
471 b
unknown
2484
dxwsetup.exe
GET
304
184.24.77.174:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?dd4108ad84189a59
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab
unknown
unknown
2484
dxwsetup.exe
GET
302
23.32.101.194:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2152
wget.exe
5.45.205.242:443
download.yandex.ru
YANDEX LLC
RU
whitelisted
2152
wget.exe
185.70.202.15:443
ext-cachev2-itt03.cdn.yandex.net
TELECOM ITALIA SPARKLE S.p.A.
IT
unknown
2484
dxwsetup.exe
23.32.101.194:80
download.microsoft.com
AKAMAI-AS
SE
unknown
2484
dxwsetup.exe
23.32.101.194:443
download.microsoft.com
AKAMAI-AS
SE
unknown
2484
dxwsetup.exe
184.24.77.174:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2484
dxwsetup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
download.yandex.ru
  • 5.45.205.242
  • 5.45.205.243
  • 5.45.205.241
  • 5.45.205.245
  • 5.45.205.244
whitelisted
ext-cachev2-itt03.cdn.yandex.net
  • 185.70.202.15
whitelisted
download.microsoft.com
  • 23.32.101.194
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
ctldl.windowsupdate.com
  • 184.24.77.174
  • 184.24.77.173
  • 184.24.77.191
  • 184.24.77.183
  • 184.24.77.207
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
Process
Message
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH