| File name: | DS4Windows_3.3.3_x64.zip |
| Full analysis: | https://app.any.run/tasks/95d5c88a-7a86-4de1-9bc9-4c05f3df60fe |
| Verdict: | Malicious activity |
| Analysis date: | September 22, 2024, 14:26:20 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | B35E3AAEB5FFCA32D4B426474A755361 |
| SHA1: | E869C8164400E1801E48C561B608E84A91515109 |
| SHA256: | CF5619BCB51B82E4E1765276E9F67FB1E2D23DFF968A653657ACF35BAFFF8BF4 |
| SSDEEP: | 98304:nRUMju2G1q+/k+iyBMQ01wvxOF8w9Tgb6+1+eO26oDjNzJ6voA3BwKcoTmEZRHXK:gUrrE2r8 |
| .zip | | | ZIP compressed archive (36.3) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:12:31 12:33:30 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | DS4Windows/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.0&gui=true | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | DS4Windows.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 888 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7356 --field-trial-handle=2304,i,3952500264422951371,10978135667354793991,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1344 | "C:\Users\admin\AppData\Local\Temp\{7E55F0EE-0F4C-423D-90F5-E6B56253AC78}\.be\windowsdesktop-runtime-8.0.8-win-x64.exe" -q -burn.elevated BurnPipe.{94909765-CEF3-406E-92E1-9D17C13097B6} {ECD78915-45CC-4113-8280-42FD27CBCDC8} 7560 | C:\Users\admin\AppData\Local\Temp\{7E55F0EE-0F4C-423D-90F5-E6B56253AC78}\.be\windowsdesktop-runtime-8.0.8-win-x64.exe | windowsdesktop-runtime-8.0.8-win-x64.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Windows Desktop Runtime - 8.0.8 (x64) Version: 8.0.8.33916 | |||||||||||||||
| 1860 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3560 --field-trial-handle=2304,i,3952500264422951371,10978135667354793991,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2476 | C:\Windows\syswow64\MsiExec.exe -Embedding 86C83C8EC5E44C1816E6E7B412282CDC | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) | |||||||||||||||
| 3936 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7520 --field-trial-handle=2304,i,3952500264422951371,10978135667354793991,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 | |||||||||||||||
| 4024 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3580 --field-trial-handle=2304,i,3952500264422951371,10978135667354793991,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 4088 | "C:\Users\admin\Downloads\windowsdesktop-runtime-8.0.8-win-x64.exe" | C:\Users\admin\Downloads\windowsdesktop-runtime-8.0.8-win-x64.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Desktop Runtime - 8.0.8 (x64) Version: 8.0.8.33916 | |||||||||||||||
| 4224 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4288 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2648 --field-trial-handle=2304,i,3952500264422951371,10978135667354793991,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\DS4Windows_3.3.3_x64.zip | |||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6112) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (7052) GameBar.exe | Key: | \REGISTRY\A\{27d6af2e-3ba7-f1d9-255a-cf6397a47463}\LocalState |
| Operation: | write | Name: | InstalledVersionMajor |
Value: 0200B342896FFB0CDB01 | |||
| (PID) Process: | (7052) GameBar.exe | Key: | \REGISTRY\A\{27d6af2e-3ba7-f1d9-255a-cf6397a47463}\LocalState |
| Operation: | write | Name: | InstalledVersionMinor |
Value: 2200D3A68B6FFB0CDB01 | |||
| (PID) Process: | (7052) GameBar.exe | Key: | \REGISTRY\A\{27d6af2e-3ba7-f1d9-255a-cf6397a47463}\LocalState |
| Operation: | write | Name: | InstalledVersionBuild |
Value: 616DD3A68B6FFB0CDB01 | |||
| (PID) Process: | (7052) GameBar.exe | Key: | \REGISTRY\A\{27d6af2e-3ba7-f1d9-255a-cf6397a47463}\LocalState |
| Operation: | write | Name: | InstalledVersionRevision |
Value: 0000D3A68B6FFB0CDB01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\DS4Updater.exe | executable | |
MD5:E86B6BA53CA8462BAEAEE561AE187E9F | SHA256:622C770E622DAF9E08C06E203C982613EC9CC2CF73E0EFEE68461B7A2E7646A5 | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\DS4Windows.dll | executable | |
MD5:12EF7AB3E301423C7CD6ED95B52360DE | SHA256:D89C4D3D0F45187283A2D71FF22623D0F871D59A34754065A81EA98C7A6E1FDA | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\FakerInputDll.dll | executable | |
MD5:7C87A11E5C2BBD4E2414C568EA4F4360 | SHA256:7E3D67A3E6B4EF2ABA039A3B1E079ACDE3AD95E0286A87623949AD74607D1A50 | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\DotNetProjects.Wpf.Extended.Toolkit.dll | executable | |
MD5:8983F161391AB632B9D2AEA51A69C4CE | SHA256:8038EEAA3483C1A751F04F5ACD1CBE5D01C772F9049D04E3BF0D07D04F5723BF | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\BezierCurveEditor\index.html | html | |
MD5:B7F3E0AEC1E9905B2706285819AD8627 | SHA256:FBD5E846237145AAA4B1D5275EAF95013A31D41E9CDAAAD032D583245DE54A7E | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\Lang\de\DS4Windows.resources.dll | executable | |
MD5:CF84BF5A4834CE4DABE93A299148C71E | SHA256:B85914D3DB0AA76B04871B6A893C4A79D5AAD328D8587E0E90E8FA40EF1D4FB2 | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\HttpProgress.dll | executable | |
MD5:E97FB25CB7D477D5C3116F3ADD7C060E | SHA256:A6C28242C760DB5713F12A292A87C470E39E42AEF8663D02AF8E72A3658B97BA | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\ICSharpCode.AvalonEdit.dll | executable | |
MD5:7CA104C3E98D3CBD162FDEF84EDD3B8F | SHA256:2417E116ED23B3CB7DED9759BDF7DBDCFAE0F7D58D71B1DD5E264F5510D3EEA1 | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\Lang\ar\DS4Windows.resources.dll | executable | |
MD5:A9B68E0C6A30FD6A12C6C2B463CB9711 | SHA256:7C7B59283F43107CB7094FA534DB00EC4A2DD350DDE7B04CC14555BD4474E26C | |||
| 6112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\Lang\es\DS4Windows.resources.dll | executable | |
MD5:373A1E357AB1840419B742B54B5B2271 | SHA256:DEA05A23469A91B8D88F3AE576A51C3713E5813BE7D340C671B8C399E0EF5CAE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | HEAD | 200 | 152.199.19.161:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727462871&P2=404&P3=2&P4=Nea%2fc%2bPKPvRS35DlrGF3zO8BJisCPFqqAez0DveTO9om5nzcZ1gqhjl3ad8SjmR8d08M5ob3o274HZ8h5XtkRw%3d%3d | unknown | — | — | whitelisted |
7404 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7404 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
368 | msedge.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown | — | — | whitelisted |
— | — | GET | 206 | 152.199.19.161:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727462871&P2=404&P3=2&P4=Nea%2fc%2bPKPvRS35DlrGF3zO8BJisCPFqqAez0DveTO9om5nzcZ1gqhjl3ad8SjmR8d08M5ob3o274HZ8h5XtkRw%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 206 | 152.199.19.161:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727462871&P2=404&P3=2&P4=Nea%2fc%2bPKPvRS35DlrGF3zO8BJisCPFqqAez0DveTO9om5nzcZ1gqhjl3ad8SjmR8d08M5ob3o274HZ8h5XtkRw%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 206 | 152.199.19.161:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/45cb24f0-52b6-4958-85f8-37fa5e4fde6b?P1=1727462871&P2=404&P3=2&P4=Nea%2fc%2bPKPvRS35DlrGF3zO8BJisCPFqqAez0DveTO9om5nzcZ1gqhjl3ad8SjmR8d08M5ob3o274HZ8h5XtkRw%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6032 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2452 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
7072 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
aka.ms |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
business.bing.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
Process | Message |
|---|---|
DS4Windows.exe | You must install .NET to run this application.
App: C:\Users\admin\AppData\Local\Temp\Rar$EXa6112.639\DS4Windows\DS4Windows.exe
Architecture: x64
App host version: 8.0.0
.NET location: Not found
Learn more:
https://aka.ms/dotnet/app-launch-failed
Download the .NET runtime:
https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.0 |