File name:

PortUp.exe

Full analysis: https://app.any.run/tasks/7c840484-4363-426b-b10a-6f66aa901b6b
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 15, 2025, 15:49:08
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

BB9E17EAA292B8B9FF22AFDAF6F64E1C

SHA1:

AC836A7DE2B9480C7EC9214EC71D21BC6A105952

SHA256:

124575B6EF5CDF3609A8E8200F9EAA55514381259878A31A5E384FB394834D94

SSDEEP:

6144:ckkufsuQtysBLp8ipWM244+ichK0bkTh3p2UFtQj4LAwxuqjh3c/4NKsNFnTwCkF:ckkxyslSPSJWlLzfVWeAWRn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • PortUp.exe (PID: 6460)
    • Reads security settings of Internet Explorer

      • PortUp.exe (PID: 6460)
    • Executable content was dropped or overwritten

      • PortUp.exe (PID: 6460)
    • Process drops legitimate windows executable

      • PortUp.exe (PID: 6460)
    • Process requests binary or script from the Internet

      • PortUp.exe (PID: 6460)
    • Creates/Modifies COM task schedule object

      • PortUp.exe (PID: 6460)
  • INFO

    • The sample compiled with english language support

      • PortUp.exe (PID: 6460)
    • Reads the software policy settings

      • PortUp.exe (PID: 6460)
    • Checks supported languages

      • PortUp.exe (PID: 6460)
    • Reads the computer name

      • PortUp.exe (PID: 6460)
    • Reads the machine GUID from the registry

      • PortUp.exe (PID: 6460)
    • Checks proxy server information

      • PortUp.exe (PID: 6460)
    • Creates files or folders in the user directory

      • PortUp.exe (PID: 6460)
    • Create files in a temporary directory

      • PortUp.exe (PID: 6460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (84.4)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)
.exe | Generic Win/DOS Executable (2)
.exe | DOS Executable Generic (2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:28 15:55:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 675840
InitializedDataSize: 45056
UninitializedDataSize: -
EntryPoint: 0x4960
OSVersion: 4
ImageVersion: 2.5
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.5.0.3
ProductVersionNumber: 2.5.0.3
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Isolated Computer Update Utility - Portable Update is a tool for updating isolated computers
CompanyName: Lorenzo Stilo
FileDescription: Portable Update
LegalCopyright: Lorenzo Stilo 2016-2023
LegalTrademarks: Lorenzo Stilo 2016-2023
ProductName: Portable Update
FileVersion: 2.05.0003
ProductVersion: 2.05.0003
InternalName: PortUp
OriginalFileName: PortUp.exe
OLESelfRegister: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
126
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start portup.exe portup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6260"C:\Users\admin\AppData\Local\Temp\PortUp.exe" C:\Users\admin\AppData\Local\Temp\PortUp.exeexplorer.exe
User:
admin
Company:
Lorenzo Stilo
Integrity Level:
MEDIUM
Description:
Portable Update
Exit code:
3221226540
Version:
2.05.0003
Modules
Images
c:\users\admin\appdata\local\temp\portup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6460"C:\Users\admin\AppData\Local\Temp\PortUp.exe" C:\Users\admin\AppData\Local\Temp\PortUp.exe
explorer.exe
User:
admin
Company:
Lorenzo Stilo
Integrity Level:
HIGH
Description:
Portable Update
Version:
2.05.0003
Modules
Images
c:\users\admin\appdata\local\temp\portup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
1 572
Read events
1 360
Write events
129
Delete events
83

Modification events

(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{00AA9A8A-A069-4DD1-B9F5-BBFBF08EF595}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00AA9A8A-A069-4DD1-B9F5-BBFBF08EF595}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{18DC15AF-ECC1-4839-B489-69655F0A222A}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{18DC15AF-ECC1-4839-B489-69655F0A222A}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{E03A231A-0640-431C-AED5-06FF91151385}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E03A231A-0640-431C-AED5-06FF91151385}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{252ED054-433F-4D79-8CFD-4D233D090D19}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{252ED054-433F-4D79-8CFD-4D233D090D19}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CCFB06DA-1E35-4AD2-968E-874A8DDC1A6D}\LocalServer32
Operation:delete valueName:ThreadingModel
Value:
(PID) Process:(6460) PortUp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20F4B1FB-E106-40CB-86E0-FF5C84510D03}\LocalServer32
Operation:delete valueName:ThreadingModel
Value:
Executable files
4
Suspicious files
15
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
6460PortUp.exeC:\Users\admin\AppData\Local\Temp\PortUp.logtext
MD5:EA078EB53D85CE367881A5F9A892CB91
SHA256:8FD506EA46324D2267A0B959C549F198D1369C15EB95D6ECACBD907F99F14C3E
6460PortUp.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\wuredist[1].cabcompressed
MD5:A2C30B1AB3492E1665108E1AAC2FAAF0
SHA256:DBAF1D9CA1C539EDB66C794F2546C8B2A35E5B1BDD8D32A3353AC4F5111EF0C9
6460PortUp.exeC:\Users\admin\AppData\Local\Temp\Toolbox\wuredist.cabcompressed
MD5:A2C30B1AB3492E1665108E1AAC2FAAF0
SHA256:DBAF1D9CA1C539EDB66C794F2546C8B2A35E5B1BDD8D32A3353AC4F5111EF0C9
6460PortUp.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\MSComCtl[1].htmhtml
MD5:BD2695F4B079C71DBDDDE3436286FB9C
SHA256:2E04A18FF185BA5B16F762A0538339BC4049ACEAEF9738EDD43AF77D2CEB788B
6460PortUp.exeC:\Users\admin\AppData\Local\Temp\Eula.txttext
MD5:5C3AC965A4D72D1F82696DD57117E3FD
SHA256:7CB0F5B14D9C3B27131C1F3083BAAD5BF3A5CBD4C83CE4CB0061CDFB6360D46E
6460PortUp.exeC:\Users\admin\AppData\Local\Temp\PortUp\wuredist.cabcompressed
MD5:A2C30B1AB3492E1665108E1AAC2FAAF0
SHA256:DBAF1D9CA1C539EDB66C794F2546C8B2A35E5B1BDD8D32A3353AC4F5111EF0C9
6460PortUp.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:E192462F281446B5D1500D474FBACC4B
SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60
6460PortUp.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:6CC86BBC1FB3976FBF1013D134361133
SHA256:D40748B618F21531336679DD057F6B488CBE6D61A389AB92D68513BF41EE0246
6460PortUp.exeC:\Users\admin\AppData\Local\Temp\Toolbox\wuredist.xmlxml
MD5:0666C549B25CBC7C20B632A1BBBA6DAD
SHA256:7B966821BA11405D3747FE9C507DFEAA0FC5ECA2124AA9D620E03BE2363E5D46
6460PortUp.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\comctl32[1].htmhtml
MD5:BD2695F4B079C71DBDDDE3436286FB9C
SHA256:2E04A18FF185BA5B16F762A0538339BC4049ACEAEF9738EDD43AF77D2CEB788B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
47
DNS requests
25
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6460
PortUp.exe
GET
302
20.109.209.108:80
http://update.microsoft.com/redist/wuredist.cab
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6460
PortUp.exe
GET
404
184.24.77.160:80
http://activex.microsoft.com/controls/vb6/mscomctl.cab
unknown
whitelisted
6460
PortUp.exe
GET
301
140.238.64.236:80
http://file.portableupdate.com/toolbox/MSComCtl.cab
unknown
unknown
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6460
PortUp.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
6460
PortUp.exe
GET
200
184.24.77.81:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgOZuoTvk%2F5tb8vAG1MAsoKfuw%3D%3D
unknown
whitelisted
6460
PortUp.exe
GET
404
184.24.77.160:80
http://activex.microsoft.com/controls/vb6/comctl32.cab
unknown
whitelisted
6460
PortUp.exe
GET
301
140.238.64.236:80
http://file.portableupdate.com/toolbox/comctl32.cab
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
92.123.104.34:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
440
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 92.123.104.34
  • 92.123.104.26
  • 92.123.104.19
  • 92.123.104.49
  • 92.123.104.32
  • 92.123.104.43
  • 92.123.104.30
  • 92.123.104.31
  • 92.123.104.33
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.68
  • 40.126.31.73
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
update.microsoft.com
  • 20.109.209.108
whitelisted
www.update.microsoft.com
  • 20.109.209.108
whitelisted
fe2.update.microsoft.com
  • 4.154.131.238
  • 52.152.180.158
whitelisted

Threats

PID
Process
Class
Message
6460
PortUp.exe
Misc activity
ET INFO Packed Executable Download
No debug info