File name:

UDisplay.exe

Full analysis: https://app.any.run/tasks/b96aec2f-8412-4391-abd4-7d7fbfc52252
Verdict: Malicious activity
Analysis date: September 02, 2024, 09:36:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6686CDDB4902B655CB502B9DF5BA3D17

SHA1:

4CE4F85FD56DBE30A6F61D21C35E5FA4BAD943A7

SHA256:

0A9779F2BD49FF1B1867E92B334DE0DE90D41DC8DE72D50B094B37D4FD557DD4

SSDEEP:

98304:8VfWNnk8JWgpukTAjEalth5x35xRDAH/EHfOZ:8cFQoI9t3DAH/E/g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • UDisplay.exe (PID: 1872)
  • SUSPICIOUS

    • Starts itself from another location

      • UDisplay.exe (PID: 1872)
    • Drops the executable file immediately after the start

      • UDisplay.exe (PID: 1872)
    • Executable content was dropped or overwritten

      • UDisplay.exe (PID: 1872)
    • Application launched itself

      • UDisplay.exe (PID: 2484)
  • INFO

    • Checks supported languages

      • UDisplay.exe (PID: 1872)
      • UDisplay.exe (PID: 2484)
      • UDisplay.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2560)
    • Creates files or folders in the user directory

      • UDisplay.exe (PID: 1872)
      • UDisplay.exe (PID: 2484)
    • Reads Environment values

      • UDisplay.exe (PID: 2484)
    • Reads the computer name

      • UDisplay.exe (PID: 2484)
      • UDisplay.exe (PID: 2472)
      • wmpnscfg.exe (PID: 2560)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:12 10:20:42+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.35
CodeSize: 3655680
InitializedDataSize: 23467008
UninitializedDataSize: -
EntryPoint: 0x2f7810
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.1.2563
ProductVersionNumber: 1.0.1.2563
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: SAGE
FileDescription: USB显示扩展客户端
FileVersion: 1.0.1.2563
InternalName: UDisplay.exe
LegalCopyright: Copyright (C) 2023 sageres.com. All Right Reserved.
OriginalFileName: UDisplay.exe
ProductName: UDisplay
ProductVersion: 1.0.1.2563
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start udisplay.exe udisplay.exe no specs udisplay.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1872"C:\Users\admin\AppData\Local\Temp\UDisplay.exe" C:\Users\admin\AppData\Local\Temp\UDisplay.exe
explorer.exe
User:
admin
Company:
SAGE
Integrity Level:
MEDIUM
Description:
USB显示扩展客户端
Exit code:
0
Version:
1.0.1.2563
Modules
Images
c:\users\admin\appdata\local\temp\udisplay.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2472C:\Users\admin\AppData\Local\UDisplay\UDisplay.exe daemonC:\Users\admin\AppData\Local\UDisplay\UDisplay.exeUDisplay.exe
User:
admin
Company:
SAGE
Integrity Level:
MEDIUM
Description:
USB显示扩展客户端
Version:
1.0.1.2563
Modules
Images
c:\users\admin\appdata\local\udisplay\udisplay.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2484C:\Users\admin\AppData\Local\UDisplay\UDisplay.exe mainC:\Users\admin\AppData\Local\UDisplay\UDisplay.exeUDisplay.exe
User:
admin
Company:
SAGE
Integrity Level:
MEDIUM
Description:
USB显示扩展客户端
Version:
1.0.1.2563
Modules
Images
c:\users\admin\appdata\local\udisplay\udisplay.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2560"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
828
Read events
827
Write events
1
Delete events
0

Modification events

(PID) Process:(1872) UDisplay.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:UDisplay
Value:
"C:\Users\admin\AppData\Local\UDisplay\UDisplay.exe" daemon
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2484UDisplay.exeC:\Users\admin\AppData\Local\UDisplay\udisplay.initext
MD5:7A8BDAA7B20EAF41E8FEFECF24ED3C3D
SHA256:BA894327B4F205FF275913CFD7783677FABB5E548E954FA4D547A1B88CDF292B
1872UDisplay.exeC:\Users\admin\AppData\Local\UDisplay\UDisplay.exeexecutable
MD5:6686CDDB4902B655CB502B9DF5BA3D17
SHA256:0A9779F2BD49FF1B1867E92B334DE0DE90D41DC8DE72D50B094B37D4FD557DD4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
23.50.131.200:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1372
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1060
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8f69642324cc87bd
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
1372
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1372
svchost.exe
23.50.131.200:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
1372
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1372
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1060
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.200
  • 23.50.131.216
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted

Threats

No threats detected
No debug info