File name: | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe |
Full analysis: | https://app.any.run/tasks/d2969c5e-2e39-4ad0-9e5c-09332398cb7f |
Verdict: | Malicious activity |
Analysis date: | May 01, 2024, 07:41:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 6B0996924A1FF0DF14223B378C8E4FB8 |
SHA1: | C491EB345F1CC3A701E7ACE9ED3E4662830AFA55 |
SHA256: | 1E67C3AE6C79FB0768A19BE602116008C06D396A81A5B206345EDAD34061882B |
SSDEEP: | 98304:7+cD4dn1qApW3FjIzbg5fd+nGopWKJmq3REIwu3cuH7Kqur90xg3YlKy44gEkgFk:TKec9Lxc |
.exe | | | Inno Setup installer (65.1) |
---|---|---|
.exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
.dll | | | Win32 Dynamic Link Library (generic) (3.9) |
.exe | | | Win32 Executable (generic) (2.6) |
.exe | | | Win16/32 Executable Delphi generic (1.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2023:02:15 14:54:16+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 741888 |
InitializedDataSize: | 50688 |
UninitializedDataSize: | - |
EntryPoint: | 0xb5eec |
OSVersion: | 6.1 |
ImageVersion: | 6 |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.2.0.0 |
ProductVersionNumber: | 1.2.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | Dell, Inc. |
FileDescription: | DellDockFW_UPGRADE_UTILITY Setup |
FileVersion: | 1.2 |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | DellDockFW_UPGRADE_UTILITY |
ProductVersion: | 1.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
864 | "C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$2013A,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
2108 | "C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: HIGH Description: DellDockFW_UPGRADE_UTILITY Setup Exit code: 0 Version: 1.2 Modules
| |||||||||||||||
3976 | "C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" | C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | explorer.exe | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: MEDIUM Description: DellDockFW_UPGRADE_UTILITY Setup Exit code: 0 Version: 1.2 Modules
| |||||||||||||||
3992 | "C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$20138,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" | C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | — | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | |||||||||||
User: admin Company: Dell, Inc. Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
|
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: 60030000ACEE60F69A9BDA01 | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: 50F4204EBD87179067A14B84148230461B3122CF6D19071BA3B9A97645E705FA | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 963E9592648478E28EEE007B3943F28BDD85E7E408727C50B2457FCB919E22EC | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\OpenWithProgids |
Operation: | write | Name: | DellDockFW_UPGRADE_UTILITYFile.exe |
Value: | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe\SupportedTypes |
Operation: | write | Name: | .myp |
Value: | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.2 | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY | |||
(PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY\ |
PID | Process | Filename | Type | |
---|---|---|---|---|
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-HR4HF.tmp | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\unins000.exe | executable | |
MD5:8E793246AF4897C6C84F6CC4C536FC8E | SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107 | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-P7E02.tmp | executable | |
MD5:8E793246AF4897C6C84F6CC4C536FC8E | SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107 | |||
3976 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | executable | |
MD5:832E804AB463815164C8D19D9A98A79B | SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB | |||
2108 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | executable | |
MD5:832E804AB463815164C8D19D9A98A79B | SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Users\admin\AppData\Local\Temp\is-7GQ27.tmp\_isetup\_isdecmp.dll | executable | |
MD5:077CB4461A2767383B317EB0C50F5F13 | SHA256:8287D0E287A66EE78537C8D1D98E426562B95C50F569B92CEA9CE36A9FA57E64 | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\ec_89.01.03.05.bin | binary | |
MD5:F0A5EC75809558A243FD8D24E6048FC0 | SHA256:BDBAB2971411C8CFF5543E22EBA1A4B9E2BE584A84E279F53FB7B2B1936FA648 | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-ISNDI.tmp | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\ec_01.01.00.07.bin | binary | |
MD5:DDD2686AE6794A2C9E1A14F4B3C2C18C | SHA256:BC28B6EF4BC18D41CD599A42EE14F8EC125F6C287259B1F45A9FC4C55E98261B |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |