File name:

Windows Update Blocker.zip

Full analysis: https://app.any.run/tasks/78692660-7f39-4a6b-86f2-a3b7d1d6357a
Verdict: Malicious activity
Analysis date: April 11, 2025, 19:32:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

2A092B4D68D023DB255875CAC30A40A7

SHA1:

6213DA9D476D23FB38FAFF9C16C5C053B9FA28FE

SHA256:

1373A5A5545ADA4B3463CDBE844A07A80096D01081B472DF9900AF4EC7FACBE8

SSDEEP:

49152:QNaVFYZT69EEmXfm6J26a5194CeKOCM+rRq2CmY8quc4Nd8p7A+GTa/xI76feBJy:QwF8TtEmPm6J26a519AKFMq42OadZWWK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1072)
    • Executing a file with an untrusted certificate

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 6192)
      • Wub_x64.exe (PID: 5292)
    • Changes the Windows auto-update feature

      • Wub_x64.exe (PID: 2092)
    • Creates or modifies Windows services

      • Wub_x64.exe (PID: 2092)
    • Changes image file execution options

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 5292)
  • SUSPICIOUS

    • Probably fake Windows Update

      • WinRAR.exe (PID: 1072)
      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 6192)
      • Wub_x64.exe (PID: 5292)
    • Probably fake Windows Update file has been dropped

      • WinRAR.exe (PID: 1072)
    • Creates or modifies Windows services

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 5292)
    • Modifies existing scheduled task

      • schtasks.exe (PID: 2384)
      • schtasks.exe (PID: 4944)
      • schtasks.exe (PID: 4180)
      • schtasks.exe (PID: 6760)
      • schtasks.exe (PID: 5796)
      • schtasks.exe (PID: 5728)
      • schtasks.exe (PID: 5444)
      • schtasks.exe (PID: 6736)
      • schtasks.exe (PID: 4920)
      • schtasks.exe (PID: 4112)
      • schtasks.exe (PID: 496)
      • schtasks.exe (PID: 5588)
      • schtasks.exe (PID: 2908)
      • schtasks.exe (PID: 920)
      • schtasks.exe (PID: 3304)
      • schtasks.exe (PID: 5848)
      • schtasks.exe (PID: 5520)
      • schtasks.exe (PID: 2120)
      • schtasks.exe (PID: 3888)
      • schtasks.exe (PID: 5892)
      • schtasks.exe (PID: 5156)
      • schtasks.exe (PID: 6872)
      • schtasks.exe (PID: 2384)
      • schtasks.exe (PID: 4996)
      • schtasks.exe (PID: 6708)
      • schtasks.exe (PID: 6480)
      • schtasks.exe (PID: 2616)
      • schtasks.exe (PID: 6184)
      • schtasks.exe (PID: 4756)
      • schtasks.exe (PID: 6560)
    • Application launched itself

      • Wub_x64.exe (PID: 2092)
  • INFO

    • Manual execution by a user

      • Wub_x64.exe (PID: 6192)
      • Wub_x64.exe (PID: 2092)
    • Reads mouse settings

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 5292)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1072)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1072)
    • Checks supported languages

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 5292)
    • Create files in a temporary directory

      • Wub_x64.exe (PID: 2092)
    • Reads the computer name

      • Wub_x64.exe (PID: 2092)
      • Wub_x64.exe (PID: 5292)
    • Reads the software policy settings

      • slui.exe (PID: 3300)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:10:21 19:45:04
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Windows Update Blocker/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
201
Monitored processes
68
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs wub_x64.exe no specs wub_x64.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs wub_x64.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" /disableC:\Windows\System32\schtasks.exeWub_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
896\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
920"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\WaaSMedic\PerformRemediation" /disableC:\Windows\System32\schtasks.exeWub_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Windows Update Blocker.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1196\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1532\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1804\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Users\admin\Desktop\Windows Update Blocker\Wub_x64.exe" C:\Users\admin\Desktop\Windows Update Blocker\Wub_x64.exe
explorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Windows Update Blocker
Exit code:
0
Version:
1.8.0.0
Modules
Images
c:\users\admin\desktop\windows update blocker\wub_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
2112\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2120"C:\WINDOWS\System32\schtasks.exe" /change /tn "Microsoft\Windows\WindowsUpdate\Refresh Group Policy Cache" /disableC:\Windows\System32\schtasks.exeWub_x64.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
6 240
Read events
6 161
Write events
67
Delete events
12

Modification events

(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows Update Blocker.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2092) Wub_x64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DoSvc
Operation:writeName:Start
Value:
4
(PID) Process:(2092) Wub_x64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DoSvc
Operation:delete valueName:WubLock
Value:
Executable files
2
Suspicious files
7
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1072.29227\Windows Update Blocker\Wub.exeexecutable
MD5:82AFF8883099CF75462057C4E47E88AC
SHA256:AAC1123F17F8569A36BF93876CEA30E15103FD2379B401A79129A2A6E7285AC2
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1072.29227\Windows Update Blocker\VersionInfo.txttext
MD5:E5316699929D6736E9C0C3B638EC8C2A
SHA256:7E2B60095D07E98C6C827A1047BEB7B2EE649AE84E19ACF3EDDB46911C972FAB
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1072.29227\Windows Update Blocker\Wub_x64.exeexecutable
MD5:9D6778F7F274F7ECD4E7E875A7268B64
SHA256:187EEEE9E518011DE1B87CFB0ED03E12EA551E9011F0C8DEFDD0E4535E672DA2
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1072.29227\Windows Update Blocker\Wub.initext
MD5:F46E5CB49CBA98CE8BCB6CA146855254
SHA256:2354783EFC0CAF965E9C3B72B887B446DA6F08DCAC4FF564AA5FF06C5AF6173E
2092Wub_x64.exeC:\Windows\System32\GroupPolicy\gpt.initext
MD5:617078BCAAA2FF95E4438D83A49CE878
SHA256:42EC7933F10ABA61202B3FC7D3C02D47CFD0C953A8F2CB0E39DF3069697F99EF
2092Wub_x64.exeC:\Users\admin\AppData\Local\Temp\2k0v9v2s.tmptext
MD5:D07C51FCF3074D96B25576375FF8D79B
SHA256:00EB42BC001F881E761C4F8C5B1E49B95A92A9A1E28099DE55DC04F205449FB1
2092Wub_x64.exeC:\Users\admin\AppData\Local\Temp\aut244E.tmpbinary
MD5:6FE605C15470246A5176C30074168DEC
SHA256:8AB8F7D476E811DA1047313CCB73D7A4903551B98C01228E3C4C121E6C67DE30
5292Wub_x64.exeC:\Windows\Temp\5r2c9h2q.tmptext
MD5:D07C51FCF3074D96B25576375FF8D79B
SHA256:00EB42BC001F881E761C4F8C5B1E49B95A92A9A1E28099DE55DC04F205449FB1
5292Wub_x64.exeC:\Windows\Temp\aut46DB.tmpbinary
MD5:4D7B8032915CD9DAAC1038612FDD3339
SHA256:F30D620F1C56D117B01BE387547F705DFE9BE3F2BC470166F1AE60028E9BC739
2092Wub_x64.exeC:\Users\admin\AppData\Local\Temp\aut245E.tmpbinary
MD5:4D7B8032915CD9DAAC1038612FDD3339
SHA256:F30D620F1C56D117B01BE387547F705DFE9BE3F2BC470166F1AE60028E9BC739
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
17
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.169:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.169:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
616
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.169:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.169:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.48.23.169
  • 23.48.23.194
  • 23.48.23.164
  • 23.48.23.147
  • 23.48.23.162
  • 23.48.23.177
  • 23.48.23.158
  • 23.48.23.145
  • 23.48.23.156
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.64
  • 20.190.160.67
  • 20.190.160.130
  • 20.190.160.3
  • 40.126.32.134
  • 20.190.160.131
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.23
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info