| File name: | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe |
| Full analysis: | https://app.any.run/tasks/d2969c5e-2e39-4ad0-9e5c-09332398cb7f |
| Verdict: | Malicious activity |
| Analysis date: | May 01, 2024, 07:41:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6B0996924A1FF0DF14223B378C8E4FB8 |
| SHA1: | C491EB345F1CC3A701E7ACE9ED3E4662830AFA55 |
| SHA256: | 1E67C3AE6C79FB0768A19BE602116008C06D396A81A5B206345EDAD34061882B |
| SSDEEP: | 98304:7+cD4dn1qApW3FjIzbg5fd+nGopWKJmq3REIwu3cuH7Kqur90xg3YlKy44gEkgFk:TKec9Lxc |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 50688 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.0 |
| ProductVersionNumber: | 1.2.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Dell, Inc. |
| FileDescription: | DellDockFW_UPGRADE_UTILITY Setup |
| FileVersion: | 1.2 |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | DellDockFW_UPGRADE_UTILITY |
| ProductVersion: | 1.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 864 | "C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$2013A,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2108 | "C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: HIGH Description: DellDockFW_UPGRADE_UTILITY Setup Exit code: 0 Version: 1.2 Modules
| |||||||||||||||
| 3976 | "C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" | C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | explorer.exe | ||||||||||||
User: admin Company: Dell, Inc. Integrity Level: MEDIUM Description: DellDockFW_UPGRADE_UTILITY Setup Exit code: 0 Version: 1.2 Modules
| |||||||||||||||
| 3992 | "C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$20138,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" | C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | — | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | |||||||||||
User: admin Company: Dell, Inc. Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 60030000ACEE60F69A9BDA01 | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 50F4204EBD87179067A14B84148230461B3122CF6D19071BA3B9A97645E705FA | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 963E9592648478E28EEE007B3943F28BDD85E7E408727C50B2457FCB919E22EC | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\OpenWithProgids |
| Operation: | write | Name: | DellDockFW_UPGRADE_UTILITYFile.exe |
Value: | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe\SupportedTypes |
| Operation: | write | Name: | .myp |
Value: | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.2 | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY | |||
| (PID) Process: | (864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\DellDockFW_UPGRADE_UTILITY\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | executable | |
MD5:832E804AB463815164C8D19D9A98A79B | SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-HR4HF.tmp | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\cfg.dat | text | |
MD5:37E0B86058D6F62830849F66C49D5912 | SHA256:C4F874E42E872DFD14A50A51C029A5ECAF396325A7F7102AF223D5FCA0244211 | |||
| 2108 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | executable | |
MD5:832E804AB463815164C8D19D9A98A79B | SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-0ERLP.tmp | text | |
MD5:37E0B86058D6F62830849F66C49D5912 | SHA256:C4F874E42E872DFD14A50A51C029A5ECAF396325A7F7102AF223D5FCA0244211 | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-ISNDI.tmp | executable | |
MD5:9C953B8F51C128897ABCE0FB9AC21D93 | SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\unins000.exe | executable | |
MD5:8E793246AF4897C6C84F6CC4C536FC8E | SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107 | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\is-P7E02.tmp | executable | |
MD5:8E793246AF4897C6C84F6CC4C536FC8E | SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107 | |||
| 864 | 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp | C:\Program Files\DellDockFW_UPGRADE_UTILITY\ec_01.01.00.05.bin | binary | |
MD5:008935D60A53640F51F270E375564CED | SHA256:A7DDEEEFF7B5F1A704FA7781F30A77BB5DC7B1050FA8A0F303949A2C39940D1B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |