File name:

AM_Delta_Patch_1.427.23.0.exe

Full analysis: https://app.any.run/tasks/12363fcf-3b2b-4254-b6d8-c2cb41204ee7
Verdict: Malicious activity
Analysis date: April 03, 2025, 03:12:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

638CFA3CC8C59FB5917D366608EF48EC

SHA1:

C46838409FC9C5067CF1BFB6F11BE2FFA6637DBD

SHA256:

02EC070224C166A3A5FDCACC0637ACD5717B28F3E1676944009C015456AA1F41

SSDEEP:

12288:qF88cluRSKtSQywNXVPSCJdBbeNtFC6cByutlK:qtRDSmPSCJDbeNtFUByutlK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • AM_Delta_Patch_1.427.23.0.exe (PID: 6068)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 2384)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6576)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5508)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 2644)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5668)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5072)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6728)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5552)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6620)
    • Process drops legitimate windows executable

      • AM_Delta_Patch_1.427.23.0.exe (PID: 2384)
  • INFO

    • The sample compiled with english language support

      • AM_Delta_Patch_1.427.23.0.exe (PID: 2384)
    • Checks supported languages

      • AM_Delta_Patch_1.427.23.0.exe (PID: 2384)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5072)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 2644)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6728)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6576)
    • Manual execution by a user

      • MpSigStub.exe (PID: 3888)
      • MpSigStub.exe (PID: 6080)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5508)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 2644)
      • MpSigStub.exe (PID: 6668)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5072)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5668)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6728)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 5552)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6620)
      • AM_Delta_Patch_1.427.23.0.exe (PID: 6576)
    • Creates files in the program directory

      • MpSigStub.exe (PID: 3888)
      • MpSigStub.exe (PID: 6080)
      • MpSigStub.exe (PID: 6668)
    • Create files in a temporary directory

      • MpSigStub.exe (PID: 3888)
      • MpSigStub.exe (PID: 6080)
      • MpSigStub.exe (PID: 6668)
    • Checks proxy server information

      • MpSigStub.exe (PID: 3888)
      • MpSigStub.exe (PID: 6080)
      • MpSigStub.exe (PID: 6668)
    • Reads the software policy settings

      • slui.exe (PID: 4724)
      • MpSigStub.exe (PID: 6080)
      • MpSigStub.exe (PID: 3888)
    • Creates files or folders in the user directory

      • MpSigStub.exe (PID: 3888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:04:02 19:08:39+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 180224
InitializedDataSize: 155648
UninitializedDataSize: -
EntryPoint: 0x7770
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.427.26.0
ProductVersionNumber: 1.427.26.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Antimalware WU Stub
InternalName: AM_Delta_Patch_1.427.23.0.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: AM_Delta_Patch_1.427.23.0.exe
ProductName: Microsoft Malware Protection
FileVersion: 1.427.26.0
ProductVersion: 1.427.26.0
StubName: WuStubFinal
StubVersion: 1.1.24010.2001
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
16
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start am_delta_patch_1.427.23.0.exe mpsigstub.exe sppextcomobj.exe no specs slui.exe slui.exe no specs am_delta_patch_1.427.23.0.exe no specs am_delta_patch_1.427.23.0.exe mpsigstub.exe am_delta_patch_1.427.23.0.exe no specs am_delta_patch_1.427.23.0.exe mpsigstub.exe am_delta_patch_1.427.23.0.exe no specs am_delta_patch_1.427.23.0.exe am_delta_patch_1.427.23.0.exe no specs am_delta_patch_1.427.23.0.exe am_delta_patch_1.427.23.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1196C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2384"C:\Users\admin\AppData\Local\Temp\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\AppData\Local\Temp\AM_Delta_Patch_1.427.23.0.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Antimalware WU Stub
Exit code:
2147944048
Version:
1.427.26.0
Modules
Images
c:\users\admin\appdata\local\temp\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2644"C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Antimalware WU Stub
Version:
1.427.26.0
Modules
Images
c:\users\admin\desktop\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3888C:\WINDOWS\system32\MpSigStub.exe /stub 1.1.24010.2001 /payload 1.427.26.0 /MpWUStub /program C:\Users\admin\AppData\Local\Temp\AM_Delta_Patch_1.427.23.0.exeC:\Windows\System32\MpSigStub.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Malware Protection Signature Update Stub
Exit code:
2147944048
Version:
1.1.24010.2001 (7122f19e8a45ed98fbe41ea0bdadf251e45717f9)
Modules
Images
c:\windows\system32\mpsigstub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4724"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5048C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5072"C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Antimalware WU Stub
Version:
1.427.26.0
Modules
Images
c:\users\admin\desktop\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5508"C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Antimalware WU Stub
Exit code:
3221226540
Version:
1.427.26.0
Modules
Images
c:\users\admin\desktop\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
5552"C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Antimalware WU Stub
Exit code:
3221226540
Version:
1.427.26.0
Modules
Images
c:\users\admin\desktop\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
5668"C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exe" C:\Users\admin\Desktop\AM_Delta_Patch_1.427.23.0.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Antimalware WU Stub
Exit code:
3221226540
Version:
1.427.26.0
Modules
Images
c:\users\admin\desktop\am_delta_patch_1.427.23.0.exe
c:\windows\system32\ntdll.dll
Total events
6 575
Read events
6 571
Write events
4
Delete events
0

Modification events

(PID) Process:(2384) AM_Delta_Patch_1.427.23.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MpSigStub
Operation:writeName:LastStartTime
Value:
3EA32C4546A4DB01
(PID) Process:(2384) AM_Delta_Patch_1.427.23.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MpSigStub
Operation:writeName:LastExitCode
Value:
(PID) Process:(6576) AM_Delta_Patch_1.427.23.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MpSigStub
Operation:writeName:LastStartTime
Value:
1575738446A4DB01
(PID) Process:(6576) AM_Delta_Patch_1.427.23.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MpSigStub
Operation:writeName:LastExitCode
Value:
Executable files
0
Suspicious files
17
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3888MpSigStub.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070670_268fbbff2cd5e7a5e2b4bd2e0e19c297153c99_00000000_4133f776-2349-417a-b1cb-e5207068a8e3\Report.wer
MD5:
SHA256:
6080MpSigStub.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_0x80070670_268fbbff2cd5e7a5e2b4bd2e0e19c297153c99_00000000_93882ac4-81d4-4d5f-b00d-e67cb82b3ab7\Report.wer
MD5:
SHA256:
3888MpSigStub.exeC:\Windows\Temp\89EF7771-5657-4047-ABFA-DC2BF3A86325f30.1dba4464544311c\1.427.23.0_to_1.427.26.0_mpasdlta.vdm._pbinary
MD5:C77DEF623CDE8C7DF876B3C19E199949
SHA256:0BABCEA3B595C48FF7CD971648A9DBA9F781EAC6C5B51DB5A48665D6F629B107
3888MpSigStub.exeC:\Users\admin\AppData\Local\Temp\CE93F57C-AEA0-480D-BAF7-E47A2C744486MPTelemetrySubmit\client_manifest.txttext
MD5:78832DCD6FF89BA04F6DC8EEAEA25351
SHA256:FD13D1B3B4DB4D12A6BE71C07FB6536F83EF00782900E919E76BE7726510DB28
3888MpSigStub.exeC:\Users\admin\AppData\Local\Temp\CE93F57C-AEA0-480D-BAF7-E47A2C744486MPTelemetrySubmit\watson_manifest.txtbinary
MD5:C89F26137E0316D69254E7B0B44030E4
SHA256:57A89296B8686A22B249357F6DBB9DB5C11B9BA039EA170E86547658C7472821
3888MpSigStub.exeC:\Users\admin\AppData\Local\Temp\MpSigStub.logbinary
MD5:B730C427E5EF7AC1E277F5F7CA0B281B
SHA256:1DA3F0B34E4198CE9C02291222472E1CAADFB6246F3EC34E0F755D0E4E87A9E7
3888MpSigStub.exeC:\Windows\Temp\89EF7771-5657-4047-ABFA-DC2BF3A86325f30.1dba4464544311c\1.427.23.0_to_1.427.26.0_mpavdlta.vdm._pbinary
MD5:63E563D396E7E0C35DF1C8692275578C
SHA256:603C5CB07462FC9E4AF92808FC8967BFAFCDC0F25BFB3294BBF7ACFE65C9DA61
6080MpSigStub.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER58D7.tmp.xmlxml
MD5:F136B73720F8F17B7691ACB3E7E7BF4A
SHA256:DF5B206AEB8502FD16716137FF1C1D7A6824B4709008911D822C0C7C1820AE34
6668MpSigStub.exeC:\Users\admin\AppData\Local\Temp\7D4E21B5-A6FA-45EB-ACF4-7D9C4C9C1BE8MPTelemetrySubmit\client_manifest.txttext
MD5:78832DCD6FF89BA04F6DC8EEAEA25351
SHA256:FD13D1B3B4DB4D12A6BE71C07FB6536F83EF00782900E919E76BE7726510DB28
6080MpSigStub.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER58A7.tmp.WERInternalMetadata.xmlbinary
MD5:DA3B8807DF74FCA7B6EE5B39A5A96745
SHA256:E2ABA849545C2486F2869ADEA692B87C1D1667D0CD400D82BA3CF8BAC9DC5C08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
26
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.10.249.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3888
MpSigStub.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3888
MpSigStub.exe
GET
200
23.10.249.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.10.249.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3332
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3332
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
23.10.249.24:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
5496
MoUsoCoreWorker.exe
23.10.249.24:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
MpSigStub.exe
20.189.173.21:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3888
MpSigStub.exe
23.10.249.24:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
3216
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3888
MpSigStub.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.10.249.24
whitelisted
watson.events.data.microsoft.com
  • 20.189.173.21
whitelisted
client.wns.windows.com
  • 20.7.2.167
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.160.66
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info