| File name: | wpsupdate.exe |
| Full analysis: | https://app.any.run/tasks/0bf3e294-6ec5-4bd7-999f-708f90021022 |
| Verdict: | Suspicious activity |
| Analysis date: | July 10, 2024, 07:06:10 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 110665592F8303336F163952ECA46D1A |
| SHA1: | 3E79F1A7FE6124BB48FAED57C9ED56351D405DE8 |
| SHA256: | 2E07D9B7E4B0B49975AA0779203616AF41CF1BF049CDEBD83A0A54EAD3638AD8 |
| SSDEEP: | 98304:5s01qsRTQMF5GtC24DMyTsXZnfj4Qpnd018JaQA5pDYga6SxtuQqvx/g1sCRxN1Y:SrLg |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:05:13 18:16:04+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.24 |
| CodeSize: | 3307008 |
| InitializedDataSize: | 2949632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x133433 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.1.0.16929 |
| ProductVersionNumber: | 12.1.0.16929 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Zhuhai Kingsoft Office Software Co.,Ltd |
| FileDescription: | WPS Office Expansion tool |
| FileVersion: | 12,1,0,16929 |
| InternalName: | wpsupdate |
| LegalCopyright: | Copyright©2024 Kingsoft Corporation. All rights reserved. |
| OriginalFileName: | wpsupdate.exe |
| ProductName: | WPS Office |
| ProductVersion: | 12,1,0,16929 |
| MIMEType: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1192 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6128 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1296 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3424 --field-trial-handle=2340,i,962390425848334580,10067521152592788068,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 3221226029 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1348 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5792 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1544 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=5316 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1544 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1700 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5980 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2176 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5816 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2412 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3424 --field-trial-handle=2340,i,962390425848334580,10067521152592788068,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\AppData\Local\Temp\wpsupdate.exe" | C:\Users\admin\AppData\Local\Temp\wpsupdate.exe | explorer.exe | ||||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Office Expansion tool Exit code: 0 Version: 12,1,0,16929 Modules
| |||||||||||||||
| 3676 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5488 --field-trial-handle=2452,i,8598058985623514605,11180690496134062008,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\updateinfo\cacheStatusInfo |
| Operation: | write | Name: | RunningPid |
Value: 2472 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\updateinfo |
| Operation: | write | Name: | StartupInfo |
Value: BA675FC | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\updateinfo |
| Operation: | write | Name: | RemoveChangeLogDate |
Value: 20240710 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\updateinfo\cacheStatusInfo |
| Operation: | write | Name: | wpsUpdateStatus |
Value: NewUpdateUINotShow | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common |
| Operation: | write | Name: | InfoHD3t |
Value: 10 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common |
| Operation: | write | Name: | InfoHD3_C |
Value: 685e750062c3dffacda1a9b413916051 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common |
| Operation: | write | Name: | InfoHD3Verify_C |
Value: 32003000320034002D0037002D00310030007C00570044004300200032002E0035002B0051004D003000300030003000310020002000200020002000200020002000200020002000200020007C00310038002D00460037002D00370038002D00360046002D00390036002D00450045000000 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\khdinfo |
| Operation: | write | Name: | InfoLastHardInfo |
Value: | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\khdinfo |
| Operation: | write | Name: | InfoCurHardInfo |
Value: 1cfad3a65ce87cfbdd11606697afa299|5b3ac5d03292edd296fa474447ca5161 | |||
| (PID) Process: | (2472) wpsupdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Kingsoft\Office\6.0\Common\khdinfo |
| Operation: | write | Name: | InfoHDModifiedType |
Value: hdidRecalByOldHdidFromRegIsEmpty|2024-7-10 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF1d2cee.TMP | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1d2cee.TMP | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1d2cee.TMP | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1d2cee.TMP | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1d2cfe.TMP | — | |
MD5:— | SHA256:— | |||
| 6652 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | unknown |
3944 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
3724 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
6876 | msedge.exe | GET | — | 195.138.255.24:80 | http://apps.identrust.com/roots/dstrootcax3.p7c | unknown | — | — | unknown |
6876 | msedge.exe | GET | 304 | 72.246.169.163:80 | http://x1.i.lencr.org/ | unknown | — | — | unknown |
5912 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
5912 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
6876 | msedge.exe | GET | 304 | 2.23.197.184:80 | http://r3.i.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4392 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5872 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4656 | SearchApp.exe | 184.86.251.14:443 | www.bing.com | Akamai International B.V. | DE | unknown |
3944 | svchost.exe | 20.190.159.75:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4656 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3944 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1060 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
updatepro.wps.cn |
| unknown |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
arc.msn.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
ntp.msn.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6876 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
6876 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
Process | Message |
|---|---|
wpsupdate.exe | 2024/07/10 07:06:16 I wpsupdate 000009a8:00000170 kupdate::Execute cmd=[]
|
wpsupdate.exe | 2024/07/10 07:06:16 I wpsupdate 000009a8:000007b4 [WorkerMain]Update work thread begin.
|
wpsupdate.exe | 2024/07/10 07:06:16 I wpsupdate 000009a8:000007b4 [WorkerMain]nomal mode.
|
wpsupdate.exe | 2024/07/10 07:06:16 E wpsupdate 000009a8:000007b4 Failed to _collectSendUpdateRequestResultInfo: invalid params
|
wpsupdate.exe | 2024/07/10 07:06:19 I wpsupdate 000009a8:000007b4 Send Request: <?xml version="1.0" encoding="UTF-8" ?>
<update protocol="1.0">
<office productid="PG01-WPS-9999-0-X-Pro" version="0.0.0.0" openupgradetimecontrol="true" currenttime="2024-07-10 07:06:19" />
</update>
.
|
wpsupdate.exe | 2024/07/10 07:06:19 E wpsupdate 000009a8:000007b4 Failed PostData: 0x80004005.
|
wpsupdate.exe | 2024/07/10 07:06:19 E wpsupdate 000009a8:000007b4 Failed post request to server: 0x80004005.
|
wpsupdate.exe | 2024/07/10 07:06:19 E wpsupdate 000009a8:000007b4 Failed send request: http://updatepro.wps.cn/updateserver/update.
|
wpsupdate.exe | 2024/07/10 07:06:19 E wpsupdate 000009a8:000007b4 Failed to _collectSendUpdateRequestResultInfo: invalid params
|
wpsupdate.exe | 2024/07/10 07:06:19 E wpsupdate 000009a8:000007b4 Can't get update address: 0x80004005.
|