| File name: | upd_2727023.exe |
| Full analysis: | https://app.any.run/tasks/8c97555d-7ff5-45b8-8230-c29561e0b1b9 |
| Verdict: | Malicious activity |
| Analysis date: | October 18, 2024, 19:17:52 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | ABDCC4A6D9EBCDB3F832DE479BEC51E0 |
| SHA1: | AB8E09F1B836A3BC07A4FD72FC17155F304E8C87 |
| SHA256: | 2FA83A1F4B3196A87645D4E71C3A486C7EB433CCB462C85888D5A5DEE2ABE2E2 |
| SSDEEP: | 98304:S/qPyub0pJ5RnpkrbI2fiDipVDrTCYRtRVVVF4PYp38uKU7sr5jW+e:R |
| .exe | | | Win32 Executable MS Visual C++ (generic) (16.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (14.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.4) |
| .exe | | | Win32 Executable (generic) (2.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:05:16 11:08:48+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 1703936 |
| InitializedDataSize: | 979968 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13c060 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2024.5.16.1107 |
| ProductVersionNumber: | 4.3.4074.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | OPSWAT, Inc. |
| FileDescription: | MDES SDK V4 3rd Party Host |
| FileVersion: | 2024.5.16.1107 |
| InternalName: | wa_3rd_party_host_32.exe |
| LegalCopyright: | © OPSWAT, Inc. All rights reserved. |
| OriginalFileName: | wa_3rd_party_host_32.exe |
| ProductName: | MDES SDK V4 |
| ProductVersion: | 4.3.4074.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2620 | wmic ComputerSystem get domain | C:\Windows\SysWOW64\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5744 | "C:\Users\admin\AppData\Local\Temp\upd_2727023.exe" | C:\Users\admin\AppData\Local\Temp\upd_2727023.exe | — | explorer.exe | |||||||||||
User: admin Company: OPSWAT, Inc. Integrity Level: MEDIUM Description: MDES SDK V4 3rd Party Host Exit code: 0 Version: 2024.5.16.1107 Modules
| |||||||||||||||
| 6368 | "c:\windows\system32\cmd.exe" /c wmic ComputerSystem get domain > C:\ProgramData\haehdee\hdfhhad | C:\Windows\SysWOW64\cmd.exe | — | upd_2727023.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6612 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5744 | upd_2727023.exe | C:\Users\admin\AppData\Roaming\AHdAGhh | text | |
MD5:0B4AA4543A0EF37D5C54C03788A822E5 | SHA256:9E882053DA5103FC3D89C4C563B7261212F427EC73825C1DF4ECCEC090D61166 | |||
| 6368 | cmd.exe | C:\ProgramData\haehdee\hdfhhad | text | |
MD5:C8BBAD190EAAA9755C8DFB1573984D81 | SHA256:7F136265128B7175FB67024A6DDD7524586B025725A878C07D76A9D8AD3DC2AC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.200.189.225:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.216.154.177:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.200.189.225:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7156 | SIHClient.exe | GET | 200 | 2.19.61.135:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.216.154.177:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7156 | SIHClient.exe | GET | 200 | 2.19.61.135:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6944 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.216.154.177:80 | crl.microsoft.com | Akamai International B.V. | IE | whitelisted |
— | — | 23.216.154.177:80 | crl.microsoft.com | Akamai International B.V. | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.200.189.225:80 | www.microsoft.com | Moratelindo Internet Exchange Point | ID | whitelisted |
— | — | 23.200.189.225:80 | www.microsoft.com | Moratelindo Internet Exchange Point | ID | whitelisted |
4020 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
816 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |