File name:

updf-9010100000-win-installer.exe

Full analysis: https://app.any.run/tasks/ef8ed111-a195-4c81-a274-cf0d80a31a10
Verdict: Malicious activity
Analysis date: October 01, 2024, 20:25:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C984808047FA888308E57BB897756F41

SHA1:

CF1E01C29C60835F51BF5398F0BE5C3F7FC21090

SHA256:

317DC881EC104B1B94E28907F6E7D43F7C85836B551C0B41E80A3243FF432417

SSDEEP:

98304:4+cD4dnptWw7X6k72ABz43MgSM0bR1KjKuWTbbkZ9zfjtHiFW6opNtIOXzmNMCNj:HzCrssBZaQzQ6WVwoGWpk5WEXAZAWPFX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • updf-9010100000-win-installer.exe (PID: 6924)
      • updf-9010100000-win-installer.tmp (PID: 6200)
      • 7z.exe (PID: 2368)
      • UPDF.exe (PID: 6996)
    • Reads the Windows owner or organization settings

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Reads security settings of Internet Explorer

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Get information on the list of running processes

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • cmd.exe (PID: 4524)
      • UPDF.exe (PID: 6996)
      • WebView.exe (PID: 6568)
      • UPDFSetup.exe (PID: 4368)
    • Starts CMD.EXE for commands execution

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • UPDFSetup.exe (PID: 4368)
    • Drops 7-zip archiver for unpacking

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • 7z.exe (PID: 2368)
    • Process drops legitimate windows executable

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • 7z.exe (PID: 2368)
      • UPDF.exe (PID: 6996)
    • The process drops C-runtime libraries

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • UPDF.exe (PID: 6996)
      • 7z.exe (PID: 2368)
    • Executing commands from a ".bat" file

      • UPDFSetup.exe (PID: 4368)
  • INFO

    • Create files in a temporary directory

      • updf-9010100000-win-installer.exe (PID: 6924)
      • updf-9010100000-win-installer.tmp (PID: 6200)
      • UPDFSetup.exe (PID: 4368)
    • Checks supported languages

      • updf-9010100000-win-installer.exe (PID: 6924)
      • updf-9010100000-win-installer.tmp (PID: 6200)
      • crashpad_handler.exe (PID: 6852)
      • UPDFSetup.exe (PID: 4368)
    • Reads the computer name

      • updf-9010100000-win-installer.tmp (PID: 6200)
      • UPDFSetup.exe (PID: 4368)
    • The process uses the downloaded file

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Process checks computer location settings

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Creates files in the program directory

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Creates files or folders in the user directory

      • crashpad_handler.exe (PID: 6852)
      • UPDFSetup.exe (PID: 4368)
    • Reads the machine GUID from the registry

      • UPDFSetup.exe (PID: 4368)
    • Checks proxy server information

      • UPDFSetup.exe (PID: 4368)
    • Creates a software uninstall entry

      • updf-9010100000-win-installer.tmp (PID: 6200)
    • Sends debugging messages

      • UPDFSetup.exe (PID: 4368)
    • Application launched itself

      • msedge.exe (PID: 5664)
    • Manual execution by a user

      • powershell_ise.exe (PID: 7584)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 476160
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.7.0
ProductVersionNumber: 1.0.7.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Superace Software Technology Co., Ltd.
FileDescription: UPDF_Win Setup
FileVersion: 1.0.7.0
LegalCopyright: Copyright © 2023 Superace Software Technology Co., Ltd.
OriginalFileName:
ProductName: UPDF_Win
ProductVersion: 1.0.7.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
222
Monitored processes
85
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start updf-9010100000-win-installer.exe updf-9010100000-win-installer.tmp cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs updfsetup.exe crashpad_handler.exe no specs tasklist.exe no specs conhost.exe no specs tasklist.exe no specs conhost.exe no specs tasklist.exe no specs conhost.exe no specs 7z.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs updf.exe tasklist.exe no specs conhost.exe no specs 7z.exe no specs conhost.exe no specs tasklist.exe no specs conhost.exe no specs webview.exe no specs tasklist.exe no specs conhost.exe no specs qcefwing.exe no specs qcefwing.exe no specs qcefwing.exe no specs tasklist.exe no specs conhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shellexperiencehost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs powershell_ise.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs updf-9010100000-win-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetasklist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
240"C:\Program Files (x86)\UPDF\QCefWing.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1676,11048595970096811595,9601828900299139902,131072 --enable-features=CastMediaRouteProvider --disable-features=NetworkService --lang=en-US --service-sandbox-type=utility --no-sandbox --use-gl=swiftshader-webgl --locales-dir-path="C:\Program Files (x86)\UPDF\resources\locales" --log-file="C:\Program Files (x86)\UPDF\debug.log" --log-severity=disable --resources-dir-path="C:\Program Files (x86)\UPDF\resources" --user-agent="UPDF 1.0.3.0 START/1.0 (Windows; en-us)" --lang=en-US --bridge-obj-name=QCefClient --log-file="C:\Program Files (x86)\UPDF\debug.log" --mojo-platform-channel-handle=2416 /prefetch:8C:\Program Files (x86)\UPDF\QCefWing.exeWebView.exe
User:
admin
Integrity Level:
MEDIUM
Description:
QCefView Widget Auxiliary Process
Version:
1.0.0.1
Modules
Images
c:\program files (x86)\updf\qcefwing.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files (x86)\updf\libcef.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\program files (x86)\updf\vcruntime140.dll
884\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7z.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
12327z.exe x "C:\Program Files (x86)\UPDF\assets.7z" -aoa -y -oC:\Users\admin\AppData\Local\UPDFC:\Program Files (x86)\UPDF\7z.exeUPDF.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Console
Exit code:
0
Version:
22.01
Modules
Images
c:\program files (x86)\updf\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1328"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4124 --field-trial-handle=2264,i,2627252427239696268,2407416838637998326,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1328"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5204 --field-trial-handle=2264,i,2627252427239696268,2407416838637998326,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1436find /c /i "UPDFSetup.exe" C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1680"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2388 --field-trial-handle=2264,i,2627252427239696268,2407416838637998326,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1696"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7fffd3d95fd8,0x7fffd3d95fe4,0x7fffd3d95ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1940"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5620 --field-trial-handle=2264,i,2627252427239696268,2407416838637998326,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
19 763
Read events
19 698
Write events
64
Delete events
1

Modification events

(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\UPDF_Win
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\UPDF_Win\
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
UPDF_Win
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:DisplayName
Value:
UPDF_Win version 1.0.7.0
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\UPDF_Win\unins000.exe"
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files (x86)\UPDF_Win\unins000.exe" /SILENT
(PID) Process:(6200) updf-9010100000-win-installer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64F0F31B-1791-46EC-96ED-44120E105F77}_is1
Operation:writeName:DisplayVersion
Value:
1.0.7.0
Executable files
464
Suspicious files
642
Text files
333
Unknown types
6

Dropped files

PID
Process
Filename
Type
6924updf-9010100000-win-installer.exeC:\Users\admin\AppData\Local\Temp\is-N8SMC.tmp\updf-9010100000-win-installer.tmpexecutable
MD5:1D20CD05BAD951EB76A4399FF44141D6
SHA256:27415BCD062F4A74428DD6D9C0485EC7E55CE03E7940C5B8695785B3E963D4C5
1436find.exeC:\Users\admin\AppData\Local\Temp\findSoftRes.txttext
MD5:21438EF4B9AD4FC266B6129A2F60DE29
SHA256:13BF7B3039C63BF5A50491FA3CFD8EB4E699D1BA1436315AEF9CBE5711530354
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\is-F432R.tmpexecutable
MD5:56C1CA85D1E016BA6511AB5610377510
SHA256:1CC832DBD17514E3E3AD5A43D4AAE35D085358B03F04C7EE7427FE28A5E29AD5
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:C26D7D913FD245AFC0F0D658595447DC
SHA256:73E4264DD66696163FBBF868729841F2E9B86F5A59912E64FB9718A8C889A7AA
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\is-5IG7S.tmpexecutable
MD5:801750157960C928AF876C3EC8DD4651
SHA256:BE330DE7AA8F2F33BCDABF0CEC2551399B4EA0F22335A0277EA9C3A7AA405BDD
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\is-PEJQE.tmpexecutable
MD5:6F1AAD861A3D1C2A72B1EA5C20CC4B06
SHA256:F0618F31ACCEA8D45BF87D893F3BA91016C75DC5671E3D258832621C131D8162
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\is-1ODNJ.tmpexecutable
MD5:FCD5963E1B8889F47AEBC770BFB5F27F
SHA256:C089091DCCE7E14FB6B1ACE74E7805FAF09CD1B05A27FC7E452D532ACC0EB7CE
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\7z.exeexecutable
MD5:56C1CA85D1E016BA6511AB5610377510
SHA256:1CC832DBD17514E3E3AD5A43D4AAE35D085358B03F04C7EE7427FE28A5E29AD5
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\is-6IBG3.tmpexecutable
MD5:B951011BA021C374455E8D1E18AF84D2
SHA256:1C057286BDF0CB90F7DD1FECF5E8AFBCFF1E27F2A94612967C0634AE639CA43D
6200updf-9010100000-win-installer.tmpC:\Program Files (x86)\UPDF_Win\unins000.exeexecutable
MD5:0BB8AC3BCD6574EA1D38897762B5D900
SHA256:E07BFA624D997C9FE395566133258DF3D8A2024DA49BFEA1990D1867401F64CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
158
DNS requests
151
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4744
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5160
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
892
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
892
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8004
svchost.exe
HEAD
200
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a1310cb6-94be-46c6-b8dc-986450234260?P1=1728085208&P2=404&P3=2&P4=SBpmMx5PumJ94j0NhjSU2XvCDxtvy04lcRLn9CWirpR%2bFrosBBKW6sJMsR8kaBJgW0fylWStDFr%2fXSN8Lx%2b7SQ%3d%3d
unknown
whitelisted
8004
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a1310cb6-94be-46c6-b8dc-986450234260?P1=1728085208&P2=404&P3=2&P4=SBpmMx5PumJ94j0NhjSU2XvCDxtvy04lcRLn9CWirpR%2bFrosBBKW6sJMsR8kaBJgW0fylWStDFr%2fXSN8Lx%2b7SQ%3d%3d
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
8004
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a1310cb6-94be-46c6-b8dc-986450234260?P1=1728085208&P2=404&P3=2&P4=SBpmMx5PumJ94j0NhjSU2XvCDxtvy04lcRLn9CWirpR%2bFrosBBKW6sJMsR8kaBJgW0fylWStDFr%2fXSN8Lx%2b7SQ%3d%3d
unknown
whitelisted
8004
svchost.exe
GET
206
2.19.126.155:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a1310cb6-94be-46c6-b8dc-986450234260?P1=1728085208&P2=404&P3=2&P4=SBpmMx5PumJ94j0NhjSU2XvCDxtvy04lcRLn9CWirpR%2bFrosBBKW6sJMsR8kaBJgW0fylWStDFr%2fXSN8Lx%2b7SQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
8
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4744
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4368
UPDFSetup.exe
216.239.32.178:443
www.google-analytics.com
GOOGLE
US
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4744
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
google.com
  • 142.250.185.78
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.136
whitelisted
www.google-analytics.com
  • 216.239.32.178
  • 216.239.34.178
  • 216.239.38.178
  • 216.239.36.178
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
api.updf.com
  • 47.253.146.137
  • 47.253.145.106
unknown
go.microsoft.com
  • 184.28.89.167
whitelisted
download.updf.com
  • 104.22.10.211
  • 104.22.11.211
  • 172.67.13.136
unknown

Threats

PID
Process
Class
Message
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
Device Retrieving External IP Address Detected
ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io)
Process
Message
UPDFSetup.exe
current sid is S-1-5-21-1693682860-607145093-2874071422-1001
UPDFSetup.exe
emailStr== ""
UPDFSetup.exe
GATask::addTask event: start_open "{\"client_id\":\"08f5a310-68d7-4e98-abc7-78fb472ecc0b\",\"events\":[{\"name\":\"start_open\",\"params\":{\"action\":\"start_open_num\",\"sub_id\":\"9010100000\",\"sub_id_channel\":\"9010100000\"}}]}"
UPDFSetup.exe
"2024-10-01 20:26:02:385" QUrl("https://www.google-analytics.com/mp/collect?api_secret=17FRpEYQTyW0SytHIVmkxw&measurement_id=G-VZ450WPD94")
UPDFSetup.exe
"2024-10-01 20:26:02:547" QUrl("https://www.google-analytics.com/mp/collect?api_secret=17FRpEYQTyW0SytHIVmkxw&measurement_id=G-VZ450WPD94") mSeconds: 160
UPDF.exe
_isRunning = false;
UPDF.exe
current sid is S-1-5-21-1693682860-607145093-2874071422-1001
UPDF.exe
emailStr== ""
UPDF.exe
set out dir old path: "" new outdir: "C:/Users/admin/Documents/UPDF/"
UPDF.exe
set out dir old path end: "C:/Users/admin/Documents/UPDF/"