File name:

24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe

Full analysis: https://app.any.run/tasks/d2969c5e-2e39-4ad0-9e5c-09332398cb7f
Verdict: Malicious activity
Analysis date: May 01, 2024, 07:41:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6B0996924A1FF0DF14223B378C8E4FB8

SHA1:

C491EB345F1CC3A701E7ACE9ED3E4662830AFA55

SHA256:

1E67C3AE6C79FB0768A19BE602116008C06D396A81A5B206345EDAD34061882B

SSDEEP:

98304:7+cD4dn1qApW3FjIzbg5fd+nGopWKJmq3REIwu3cuH7Kqur90xg3YlKy44gEkgFk:TKec9Lxc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 3976)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 2108)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 3976)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 2108)
    • Reads the Windows owner or organization settings

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
    • Process drops legitimate windows executable

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
  • INFO

    • Create files in a temporary directory

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 3976)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 2108)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
    • Checks supported languages

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 3976)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe (PID: 2108)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 3992)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
    • Reads the computer name

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 3992)
      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
    • Creates files in the program directory

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
    • Creates a software uninstall entry

      • 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp (PID: 864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 50688
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.0
ProductVersionNumber: 1.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Dell, Inc.
FileDescription: DellDockFW_UPGRADE_UTILITY Setup
FileVersion: 1.2
LegalCopyright:
OriginalFileName:
ProductName: DellDockFW_UPGRADE_UTILITY
ProductVersion: 1.2
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 24314_dellfw_upgrade_dock_utility_v1.2.exe 24314_dellfw_upgrade_dock_utility_v1.2.tmp no specs 24314_dellfw_upgrade_dock_utility_v1.2.exe 24314_dellfw_upgrade_dock_utility_v1.2.tmp

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$2013A,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp
24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe
User:
admin
Company:
Dell, Inc.
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-uucb8.tmp\24314_dellfw_upgrade_dock_utility_v1.2.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2108"C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe
24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp
User:
admin
Company:
Dell, Inc.
Integrity Level:
HIGH
Description:
DellDockFW_UPGRADE_UTILITY Setup
Exit code:
0
Version:
1.2
Modules
Images
c:\users\admin\appdata\local\temp\24314_dellfw_upgrade_dock_utility_v1.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3976"C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe
explorer.exe
User:
admin
Company:
Dell, Inc.
Integrity Level:
MEDIUM
Description:
DellDockFW_UPGRADE_UTILITY Setup
Exit code:
0
Version:
1.2
Modules
Images
c:\users\admin\appdata\local\temp\24314_dellfw_upgrade_dock_utility_v1.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3992"C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp" /SL5="$20138,2740915,793600,C:\Users\admin\AppData\Local\Temp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe" C:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmp24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe
User:
admin
Company:
Dell, Inc.
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-bchoe.tmp\24314_dellfw_upgrade_dock_utility_v1.2.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
3 444
Read events
3 407
Write events
31
Delete events
6

Modification events

(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
60030000ACEE60F69A9BDA01
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
50F4204EBD87179067A14B84148230461B3122CF6D19071BA3B9A97645E705FA
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
963E9592648478E28EEE007B3943F28BDD85E7E408727C50B2457FCB919E22EC
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\OpenWithProgids
Operation:writeName:DellDockFW_UPGRADE_UTILITYFile.exe
Value:
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exe\SupportedTypes
Operation:writeName:.myp
Value:
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\DellDockFW_UPGRADE_UTILITY
(PID) Process:(864) 24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{598FF4F3-A5CE-4782-9F8E-B615F4B2880D}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\DellDockFW_UPGRADE_UTILITY\
Executable files
16
Suspicious files
7
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\DellFW_UPGRADE_DOCK_UTILITY_v1.2.exeexecutable
MD5:9C953B8F51C128897ABCE0FB9AC21D93
SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\is-HR4HF.tmpexecutable
MD5:9C953B8F51C128897ABCE0FB9AC21D93
SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\unins000.exeexecutable
MD5:8E793246AF4897C6C84F6CC4C536FC8E
SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\is-P7E02.tmpexecutable
MD5:8E793246AF4897C6C84F6CC4C536FC8E
SHA256:8D42C9F49AD70774CDCD17F6A89A071B21E2E12E13B51AB673E26A07DBE0E107
397624314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exeC:\Users\admin\AppData\Local\Temp\is-BCHOE.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpexecutable
MD5:832E804AB463815164C8D19D9A98A79B
SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB
210824314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.exeC:\Users\admin\AppData\Local\Temp\is-UUCB8.tmp\24314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpexecutable
MD5:832E804AB463815164C8D19D9A98A79B
SHA256:8CCB174BB377879198F28096DABB6CBBA243A4B2777AEF81C038CA559726F3FB
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Users\admin\AppData\Local\Temp\is-7GQ27.tmp\_isetup\_isdecmp.dllexecutable
MD5:077CB4461A2767383B317EB0C50F5F13
SHA256:8287D0E287A66EE78537C8D1D98E426562B95C50F569B92CEA9CE36A9FA57E64
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\ec_89.01.03.05.binbinary
MD5:F0A5EC75809558A243FD8D24E6048FC0
SHA256:BDBAB2971411C8CFF5543E22EBA1A4B9E2BE584A84E279F53FB7B2B1936FA648
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\is-ISNDI.tmpexecutable
MD5:9C953B8F51C128897ABCE0FB9AC21D93
SHA256:DF84BAC2EA2FA06F447299EFB5AC9DDE1B205CBB93457B5B8E09DB96EA7FCD2C
86424314_DellFW_UPGRADE_DOCK_UTILITY_v1.2.tmpC:\Program Files\DellDockFW_UPGRADE_UTILITY\ec_01.01.00.07.binbinary
MD5:DDD2686AE6794A2C9E1A14F4B3C2C18C
SHA256:BC28B6EF4BC18D41CD599A42EE14F8EC125F6C287259B1F45A9FC4C55E98261B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info