File name:

DropboxInstaller.exe

Full analysis: https://app.any.run/tasks/e97fa367-80da-4a35-9a9b-028e4b10b5ad
Verdict: Malicious activity
Analysis date: May 17, 2025, 07:16:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BC201E5911F199EAE5A5855E843C236A

SHA1:

2F98B105BA346E61EC792CB94735DE2079F6F679

SHA256:

1256F3AA5F091AC40A573113FCC1A4D0E320AF5EE363B0ECA79618602CB7DC66

SSDEEP:

24576:+IolN0JKsyMh0RldSE+cbYVegQV+W53cr04YXFftljG8Y62ZUQshwcE3vKDIIM+6:+IolN0IsRh0RldS1cbYVrQV+W53cr04d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Reads security settings of Internet Explorer

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
    • Application launched itself

      • DropboxUpdate.exe (PID: 6028)
    • Disables SEHOP

      • DropboxUpdate.exe (PID: 6032)
    • Starts itself from another location

      • DropboxUpdate.exe (PID: 6032)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 6272)
    • Creates/Modifies COM task schedule object

      • DropboxUpdate.exe (PID: 6944)
    • Potential Corporate Privacy Violation

      • DropboxUpdate.exe (PID: 1324)
    • There is functionality for taking screenshot (YARA)

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6032)
    • The process creates files with name similar to system file names

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Executes as Windows Service

      • DropboxUpdate.exe (PID: 6468)
    • Process drops python dynamic module

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
  • INFO

    • The sample compiled with german language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • Create files in a temporary directory

      • DropboxInstaller.exe (PID: 5544)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The sample compiled with english language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The sample compiled with japanese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with Italian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with korean language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with Indonesian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with french language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • Checks supported languages

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • The sample compiled with portuguese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with polish language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with swedish language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with russian language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • The sample compiled with chinese language support

      • DropboxInstaller.exe (PID: 5544)
      • DropboxUpdate.exe (PID: 6032)
    • Reads the machine GUID from the registry

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 6468)
      • DropboxUpdate.exe (PID: 5008)
    • Creates files in the program directory

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 6468)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Reads the computer name

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
      • DropboxUpdate.exe (PID: 2152)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 6944)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 5008)
      • DropboxUpdate.exe (PID: 6468)
    • Process checks computer location settings

      • DropboxUpdate.exe (PID: 6028)
      • DropboxUpdate.exe (PID: 6032)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxClient_224.4.4811.x64.exe (PID: 7944)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6272)
    • Reads the software policy settings

      • DropboxUpdate.exe (PID: 6032)
      • msiexec.exe (PID: 6272)
      • DropboxUpdate.exe (PID: 1324)
      • DropboxUpdate.exe (PID: 6468)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6272)
    • Checks proxy server information

      • DropboxUpdate.exe (PID: 1324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:09 10:18:51+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 48640
InitializedDataSize: 742400
UninitializedDataSize: -
EntryPoint: 0x4d4d
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.3.983.1
ProductVersionNumber: 1.3.983.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Dropbox, Inc.
FileDescription: Dropbox Update Setup
FileVersion: 1.3.983.1
InternalName: Dropbox Update Setup
LegalCopyright: Copyright: Dropbox, Inc. 2015 (Omaha Copyright Google Inc.)
OriginalFileName: DropboxUpdateSetup.exe
ProductName: Dropbox Update
ProductVersion: 1.3.983.1
LanguageId: en
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
12
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start dropboxinstaller.exe dropboxupdate.exe no specs dropboxupdate.exe sppextcomobj.exe no specs slui.exe no specs dropboxupdate.exe no specs msiexec.exe dropboxupdate.exe no specs dropboxupdate.exe dropboxupdate.exe no specs dropboxupdate.exe dropboxclient_224.4.4811.x64.exe

Process information

PID
CMD
Path
Indicators
Parent process
780C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1324"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBkcm9wYm94X2RhdGE9ImV5SlVRVWRUSWpvaVpVcDVjbFpwY0U5TVV6ZFBlazB0VEhvd2VGSnpiRWwzVFdwSmQwMDNRWGRPYW1NeFRrUk5lazFFV1RKTlRFa3dUVlJqTUUxRVFYbDBWRkV5VGt4QlFYTnJNSFI2UlRCMFJGZHZRbkIzVlU1eVFYNS1RRTFGVkVFaWZRIiBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuOTgzLjEiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7M0RFOEY3RkYtREVFQS00MTc5LUFDOEUtRTUxRDNCNzc4NTQ1fSIgdXNlcmlkPSJ7NkZDRkU2RDEtRjJDOC00OUZGLUExRDctNjY2MUJCMTdGNDk0fSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0ie0E4QzM3RDU2LTg1QzYtNDhFMy1CREM1LUM0NTlDQjQzNTUzRn0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxhcHAgYXBwaWQ9IntEODk2OEZGMi1FMEIxLTRBMTMtQTNFMi1DOUYyOTk1RjNCQzZ9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjMuOTgzLjEiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
DropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Exit code:
0
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2152"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /regsvcC:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exeDropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Exit code:
0
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2236"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5008"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /handoff "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ&nolaunch=0" /installsource taggedmi /sessionid "{3DE8F7FF-DEEA-4179-AC8E-E51D3B778545}"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exeDropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5544"C:\Users\admin\AppData\Local\Temp\DropboxInstaller.exe" C:\Users\admin\AppData\Local\Temp\DropboxInstaller.exe
explorer.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
MEDIUM
Description:
Dropbox Update Setup
Version:
1.3.983.1
Modules
Images
c:\users\admin\appdata\local\temp\dropboxinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6028C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe /installsource taggedmi /install "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ"C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exeDropboxInstaller.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
MEDIUM
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\users\admin\appdata\local\temp\gumb613.tmp\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6032"C:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe" /installsource taggedmi /install "appguid={CC46080E-4C33-4981-859A-BBA2F780F31E}&appname=Dropbox&needsadmin=Prefers&experiments=buildid%3Dmain%7CThu%2C%2031%20Dec%202099%2023%3A59%3A59%20GMT&dropbox_data=eyJUQUdTIjoiZUp5clZpcE9MUzdPek0tTHoweFJzbEl3TWpJd003QXdOamMxTkRNek1EWTJNTEkwTVRjME1EQXl0VFEyTkxBQXNrMHR6RTB0RFdvQnB3VU5yQX5-QE1FVEEifQ" /installelevatedC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exe
DropboxUpdate.exe
User:
admin
Company:
Dropbox, Inc.
Integrity Level:
HIGH
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\users\admin\appdata\local\temp\gumb613.tmp\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6272C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6468"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /svcC:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
services.exe
User:
SYSTEM
Company:
Dropbox, Inc.
Integrity Level:
SYSTEM
Description:
Dropbox Update
Version:
1.3.537.5
Modules
Images
c:\program files (x86)\dropbox\update\dropboxupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
28 858
Read events
28 667
Write events
146
Delete events
45

Modification events

(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update
Operation:writeName:path
Value:
C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\Clients\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:pv
Value:
1.3.983.1
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\Clients\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:name
Value:
Dropbox Update
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\DropboxUpdate\Update\ClientState\{D8968FF2-E0B1-4A13-A3E2-C9F2995F3BC6}
Operation:writeName:pv
Value:
1.3.983.1
(PID) Process:(6032) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DropboxUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\DropboxUpdate.exe
Operation:writeName:AppID
Value:
{96D1EED3-701E-4FE5-B996-A543A8465897}
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:LocalService
Value:
dbupdate
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:ServiceParameters
Value:
/comsvc
(PID) Process:(2152) DropboxUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{96D1EED3-701E-4FE5-B996-A543A8465897}
Operation:writeName:AppID
Value:
{96D1EED3-701E-4FE5-B996-A543A8465897}
Executable files
84
Suspicious files
47
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdate.exeexecutable
MD5:8AD76E0B347BB690697535CE95B1C656
SHA256:7655221B493047C61285E1DE78807D0584920B0D14D150E2487DA9728B1926F3
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxCrashHandler.exeexecutable
MD5:6593CBE28B4DDDF760595AE90A0EEC2E
SHA256:C59A6B27321A0B7B1E71A7419059284A0756864AE42A9892C6F00E3D36B8A043
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\npDropboxUpdate3.dllexecutable
MD5:05EF863E8565B825361C44006474F671
SHA256:C3CFB02C8E26A79BEEBDAD43A6FF22D77EB7D01C87BDCF9641AAA56EC836A4D5
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdate.dllexecutable
MD5:7850315ED466F2CF119AAAC6CF2BB078
SHA256:4DD4FBBE79FCF95492742EA3D494427698425150944527DAE2D2F99A90139BDE
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\DropboxUpdateBroker.exeexecutable
MD5:19409EF4B22E801924DF0AB20BE2D413
SHA256:4F6BBB4E51761BAD085896830231B489BC260CF354A272A5832667D15745868B
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\@PaxHeadertext
MD5:7AAB1349E35300362E6CBAEE08B1F2C2
SHA256:96054F9AC9B8AA9D368B41AD845CA29DFE12810AA0B19A897244EFB77C8DBA5B
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_ja.dllexecutable
MD5:B469981286BACEF95FA6A51A7978B67F
SHA256:75E5C1F1359282953D44DC3EB1F48A1530F44FAD2AA52EA5B2E4A9A06C562383
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_de.dllexecutable
MD5:7EC6DA06AEB47A15B49F91E7F0E1330A
SHA256:1DD6B50FDD9A2FA8E6DABD393A2D129DDB3C37BF7EEABFFACA99F28EE997F96E
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_es.dllexecutable
MD5:7E4A054E4FD54590BD30BDE1C881C81E
SHA256:DB9064B062C3224AF5E4AE33198ACB749061E06A7C1CC489A094F853C468E5DD
5544DropboxInstaller.exeC:\Users\admin\AppData\Local\Temp\GUMB613.tmp\goopdateres_ko.dllexecutable
MD5:6F9A527B9DD8E2F3D450C0BB17299C23
SHA256:121AC95795E7FC8C91D164ACE9AE9CA0691C53653486614DE7B335386E7FB974
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
26
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1324
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAyVRp0LO%2F899HuOUNmwbkY%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7752
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6468
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAyVRp0LO%2F899HuOUNmwbkY%3D
unknown
whitelisted
7752
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6272
msiexec.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
6468
DropboxUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.15:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6272
msiexec.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1324
DropboxUpdate.exe
162.125.66.13:443
client.dropbox.com
DROPBOX
DE
whitelisted
6468
DropboxUpdate.exe
162.125.66.13:443
client.dropbox.com
DROPBOX
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.216.77.15
  • 23.216.77.35
  • 23.216.77.29
  • 23.216.77.43
  • 23.216.77.22
  • 23.216.77.6
  • 23.216.77.37
  • 23.216.77.38
  • 23.216.77.33
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.dropbox.com
  • 162.125.66.13
whitelisted
edge.dropboxstatic.com
  • 162.125.65.22
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.64
  • 40.126.31.0
  • 20.190.159.131
  • 40.126.31.130
  • 40.126.31.3
  • 40.126.31.71
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

PID
Process
Class
Message
1324
DropboxUpdate.exe
Potential Corporate Privacy Violation
ET INFO Dropbox.com Offsite File Backup in Use
No debug info