File name:

DropboxInstaller.exe

Full analysis: https://app.any.run/tasks/e97fa367-80da-4a35-9a9b-028e4b10b5ad
Verdict: Malicious activity
Analysis date: May 17, 2025, 07:16:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BC201E5911F199EAE5A5855E843C236A

SHA1:

2F98B105BA346E61EC792CB94735DE2079F6F679

SHA256:

1256F3AA5F091AC40A573113FCC1A4D0E320AF5EE363B0ECA79618602CB7DC66

SSDEEP:

24576:+IolN0JKsyMh0RldSE+cbYVegQV+W53cr04YXFftljG8Y62ZUQshwcE3vKDIIM+6:+IolN0IsRh0RldS1cbYVrQV+W53cr04d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Reads security settings of Internet Explorer

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
    • Application launched itself

      • DropboxUpdate.exe (PID: 6028)
    • Starts itself from another location

      • DropboxUpdate.exe (PID: 6032)
    • Disables SEHOP

      • DropboxUpdate.exe (PID: 6032)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6272)
    • Creates/Modifies COM task schedule object

      • DropboxUpdate.exe (PID: 6944)
    • Executes as Windows Service

      • DropboxUpdate.exe (PID: 6468)
    • There is functionality for taking screenshot (YARA)

      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 5008)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The process creates files with name similar to system file names

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Process drops python dynamic module

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Potential Corporate Privacy Violation

      • DropboxUpdate.exe (PID: 1324)
  • INFO

    • Create files in a temporary directory

      • DropboxInstaller.exe (PID: 5544)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Checks supported languages

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The sample compiled with english language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The sample compiled with german language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with Italian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with Indonesian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with japanese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with korean language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with polish language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with portuguese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with french language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with swedish language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with russian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with chinese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • Reads the machine GUID from the registry

      • DropboxUpdate.exe (PID: 6028)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 2152)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
    • Creates files in the program directory

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Reads the computer name

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
    • Process checks computer location settings

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Reads the software policy settings

      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 6468)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6272)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6272)
    • Checks proxy server information

      • DropboxUpdate.exe (PID: 1324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:09 10:18:51+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 48640
InitializedDataSize: 742400
UninitializedDataSize: -
EntryPoint: 0x4d4d
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.3.983.1
ProductVersionNumber: 1.3.983.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Dropbox, Inc.
FileDescription: Dropbox Update Setup
FileVersion: 1.3.983.1
InternalName: Dropbox Update Setup
LegalCopyright: Copyright: Dropbox, Inc. 2015 (Omaha Copyright Google Inc.)
OriginalFileName: DropboxUpdateSetup.exe
ProductName: Dropbox Update
ProductVersion: 1.3.983.1
LanguageId: en
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
12
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start dropboxinstaller.exe dropboxupdate.exe no specs dropboxupdate.exe sppextcomobj.exe no specs slui.exe no specs dropboxupdate.exe no specs msiexec.exe dropboxupdate.exe no specs dropboxupdate.exe dropboxupdate.exe no specs dropboxupdate.exe dropboxclient_224.4.4811.x64.exe

Process information

PID
CMD
Path
Indicators
Parent process
780C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1324"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBkcm9wYm94X2RhdGE9ImV5SlVRVWRUSWpvaVpVcDVjbFpwY0U5TVV6ZFBlazB0VEhvd2VGSnpiRWwzVFdwSmQwMDNRWGRPYW1NeFRrUk5lazFFV1RKTlRFa3dUVlJqTUUxRVFYbDBWRkV5VGt4QlFYTnJNSFI2UlRCMFJGZHZRbkIzVlU1eVFYNS1RRTFGVkVFaWZRIiBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuOTgzLjEiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7M0RFOEY3RkYtREVFQS00MTc5LUFDOEUtRTUxRDNCNzc4NTQ1fSIgdXNlcmlkPSJ7NkZDRkU2RDEtRjJDOC00OUZGLUExRDctNjY2MUJCMTdGNDk0fSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0ie0E4QzM3RDU2LTg1QzYtNDhFMy1CREM1LUM0NTlDQjQzNTUzRn0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxhcHAgYXBwaWQ9IntEODk2OEZGMi1FMEIxLTRBMTMtQTNFMi1DOUYyOTk1RjNCQzZ9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjMuOTgzLjEiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
DropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Exit code:
0
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2152"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /regsvcC:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exeDropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Exit code:
0
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2236"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5008"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /handoff "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ&nolaunch=0" /installsource taggedmi /sessionid "{3DE8F7FF-DEEA-4179-AC8E-E51D3B778545}"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exeDropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5544"C:\Users\admin\AppData\Local\Temp\DropboxInstaller.exe" C:\Users\admin\AppData\Local\Temp\DropboxInstaller.exe
explorer.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
MEDIUM
Description:
Dropbox Update Setup
Version:
1.3.983.1
Modules
Images
c:\users\admin\appdata\local\temp\dropboxinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6028C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe /installsource taggedmi /install "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ"C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exeDropboxInstaller.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
MEDIUM
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\users\admin\appdata\local\temp\gumb613.tmp\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6032"C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe" /installsource taggedmi /install "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ" /installelevatedC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe
DropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\users\admin\appdata\local\temp\gumb613.tmp\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6272C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6468"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /svcC:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
services.exe
User:
SYSTEM
Company:
Dropbox, Inc.
Integrity Level:
SYSTEM
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
28 858
Read events
28 667
Write events
146
Delete events
45

Modification events

(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update
Operation:writeName:path
Value:
C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\Clients\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:pv
Value:
1.3.983.1
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\Clients\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:name
Value:
Dropbox Update
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\ClientState\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:pv
Value:
1.3.983.1
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DropboxUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\DropboxUpdate.exe
Operation:writeName:AppID
Value:
{96D1EED3-701E-4FE5-B996-A543A8465897}
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:LocalService
Value:
dbupdate
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:ServiceParameters
Value:
/comsvc
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:AppID
Value:
{96D1EED3-701E-4FE5-B996-A543A8465897}
Executable files
84
Suspicious files
47
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_da.dllexecutable
MD5:404FDE9C1036B2203DAABC4635F3B570
SHA256:3C42EE21356D06D472960377BE43C1257D16BDA3461B4A712C932901FE4AD586
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\@PaxHeadertext
MD5:7AAB1349E35300362E6CBAEE08B1F2C2
SHA256:96054F9AC9B8AA9D368B41AD845CA29DFE12810AA0B19A897244EFB77C8DBA5B
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_es.dllexecutable
MD5:7E4A054E4FD54590BD30BDE1C881C81E
SHA256:DB9064B062C3224AF5E4AE33198ACB749061E06A7C1CC489A094F853C468E5DD
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdateOnDemand.exeexecutable
MD5:C1B15C6B3159EE58C9147D2C59BC6D19
SHA256:4C5EEFB55977506C18EB27CC01CCF7773DFB050D93240B5959822061753F4A97
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxCrashHandler.exeexecutable
MD5:6593CBE28B4DDDF760595AE90A0EEC2E
SHA256:C59A6B27321A0B7B1E71A7419059284A0756864AE42A9892C6F00E3D36B8A043
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdate.dllexecutable
MD5:7850315ED466F2CF119AAAC6CF2BB078
SHA256:4DD4FBBE79FCF95492742EA3D494427698425150944527DAE2D2F99A90139BDE
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdateBroker.exeexecutable
MD5:19409EF4B22E801924DF0AB20BE2D413
SHA256:4F6BBB4E51761BAD085896830231B489BC260CF354A272A5832667D15745868B
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdateHelper.msiexecutable
MD5:7E7BCD010731A002F292C2F9A2C03C05
SHA256:7D53451933C9EEF1A722D9A285D91112418DB30415B3B4009DB0CE88195FC615
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\psuser.dllexecutable
MD5:CC060AE910C05B0CFE92307EF098795E
SHA256:9BB4B0449F899593F815C89C44253A06D8FB08AB9906F6EF11D81CB9E8C35550
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exeexecutable
MD5:8AD76E0B347BB690697535CE95B1C656
SHA256:7655221B493047C61285E1DE78807D0584920B0D14D150E2487DA9728B1926F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
26
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6272
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6272
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
6272
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAOKSkxNqmqtTGS8Y78ILE0%3D
unknown
whitelisted
1324
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
6468
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
1324
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAyVRp0LO%2F899HuOUNmwbkY%3D
unknown
whitelisted
6468
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAyVRp0LO%2F899HuOUNmwbkY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.15:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6272
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1324
DropboxUpdate.exe
162.125.66.13:443
client.dropbox.com
DROPBOX
DE
whitelisted
6468
DropboxUpdate.exe
162.125.66.13:443
client.dropbox.com
DROPBOX
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.15
  • 23.216.77.35
  • 23.216.77.29
  • 23.216.77.43
  • 23.216.77.22
  • 23.216.77.6
  • 23.216.77.37
  • 23.216.77.38
  • 23.216.77.33
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.dropbox.com
  • 162.125.66.13
whitelisted
edge.dropboxstatic.com
  • 162.125.65.22
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.64
  • 40.126.31.0
  • 20.190.159.131
  • 40.126.31.130
  • 40.126.31.3
  • 40.126.31.71
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

PID
Process
Class
Message
1324
DropboxUpdate.exe
Potential Corporate Privacy Violation
ET INFO Dropbox.com Offsite File Backup in Use
No debug info