File name: | udc_setup.exe |
Full analysis: | https://app.any.run/tasks/20ba17d4-8b55-4ea8-8237-2f1c0b404f1c |
Verdict: | Malicious activity |
Analysis date: | August 25, 2024, 10:49:43 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 1A4A47ADED4A0753D1E600987130D5BC |
SHA1: | 10905DAAA339027F4DD15D4C286ACB1696C28886 |
SHA256: | 39CEE175F701AA5F9E8BF91F8143A5D5A0E53BA061346356F9AA1594EB9800C4 |
SSDEEP: | 98304:HpNIrvrpxJrARK60ADoWw6Ayn9XClk0NPkx3KLvqmF0y1fSDivC7uY8Q0aldTpqG:6OFqLN4ZfvEo3f2lNC/W4HE |
.exe | | | Inno Setup installer (53.5) |
---|---|---|
.exe | | | InstallShield setup (21) |
.exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
.exe | | | Win32 Executable (generic) (2.1) |
.exe | | | Win16/32 Executable Delphi generic (1) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2022:02:16 00:54:47+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 684032 |
InitializedDataSize: | 91136 |
UninitializedDataSize: | - |
EntryPoint: | 0xa7ed0 |
OSVersion: | 6.1 |
ImageVersion: | 6 |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 24.4.0.27 |
ProductVersionNumber: | 24.4.0.27 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | Lenovo |
FileDescription: | Lenovo Universal Device Client Setup |
FileVersion: | 24.4.0.27 |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | Lenovo Universal Device Client - Package 1.9.9.3 |
ProductVersion: | 24.4.0.27 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
788 | "C:\WINDOWS\system32\drivers\lenovo\UDC\Service\UDCInfinstaller.exe" -removeinstallerservice | C:\Windows\System32\drivers\lenovo\UDC\Service\UDCInfInstaller.exe | — | UDCInfInstaller.exe | |||||||||||
User: SYSTEM Company: Lenovo Group Ltd. Integrity Level: SYSTEM Description: UDC Inf Installer Exit code: 4294967295 Version: 24.4.0.27 Modules
| |||||||||||||||
872 | C:\WINDOWS\System32\drivers\Lenovo\udc\Service\UDCInfInstaller.exe | C:\Windows\System32\drivers\lenovo\UDC\Service\UDCInfInstaller.exe | services.exe | ||||||||||||
User: SYSTEM Company: Lenovo Group Ltd. Integrity Level: SYSTEM Description: UDC Inf Installer Exit code: 0 Version: 24.4.0.27 Modules
| |||||||||||||||
876 | "C:\WINDOWS\system32\icacls.exe" C:\ProgramData\Lenovo\UDC /inheritance:r /q /grant *S-1-5-32-545:(OI)(CI)RX *S-1-5-32-544:(OI)(CI)F *S-1-5-18:(OI)(CI)F | C:\Windows\System32\icacls.exe | — | UDCInfInstaller.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
888 | "C:\WINDOWS\system32\schtasks.exe" /delete /f /tn "\Lenovo\UDC\Lenovo UDC Diagnostic Scan" | C:\Windows\System32\schtasks.exe | — | UDCInfInstaller.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1124 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | UDCInfDeviceHelper.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1164 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1224 | "C:\WINDOWS\system32\sc.exe" config UDCService start=auto | C:\Windows\System32\sc.exe | — | UDCInfInstaller.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1488 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | sc.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1492 | DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:c14ce8840c48fa1f:LnvAppFrmDevice_Install:24.4.0.27:root\udsudcdriver," "4fa9a6757" "0000000000000204" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
2204 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: 9C1B00001AE0F083DCF6DA01 | |||
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: 0EB0EE1C37F53A8201397FC48E22C6BA2A2E12A928C4BB742784960E974CCFCA | |||
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\WINDOWS\TempInst\x64\Service\AppProvisioningAgent.dll | |||
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0001 |
Value: C:\WINDOWS\TempInst\EmbeddedPlugins\7465B7C2-BECF-4079-B110-05862C08067B\Release\x64\Microsoft.Win32.TaskScheduler.dll | |||
(PID) Process: | (7068) udc_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 1D04AA84E39AB6B27535D7540479C5A41F466AC217A5EB3B33F750DCB9B73766 | |||
(PID) Process: | (6828) UDCInfDeviceHelper.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
(PID) Process: | (1492) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WUDFRd |
Operation: | write | Name: | Owners |
Value: oem1.inf | |||
(PID) Process: | (1492) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UDCService |
Operation: | write | Name: | Owners |
Value: oem1.inf | |||
(PID) Process: | (1492) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UDCInstallerService |
Operation: | write | Name: | Owners |
Value: oem1.inf |
PID | Process | Filename | Type | |
---|---|---|---|---|
7068 | udc_setup.tmp | C:\Windows\TempInst\is-H7761.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\is-UOLLP.tmp | binary | |
MD5:38E0FFC515473280920D9EFD55F36DF0 | SHA256:C4CD0D20888D001FAA522EE863AA5095FD146D8F3B4F8B927C8177BC7E95A80B | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\is-PLI3K.tmp | text | |
MD5:C84CE428007A28946A20A808F31118A4 | SHA256:1CEF95CAAFC9802DA1B9BD92536B36D25AD18300B8433A839E884C376FA576E2 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\InnoInstall.cmd | text | |
MD5:C84CE428007A28946A20A808F31118A4 | SHA256:1CEF95CAAFC9802DA1B9BD92536B36D25AD18300B8433A839E884C376FA576E2 | |||
6924 | udc_setup.exe | C:\Users\admin\AppData\Local\Temp\is-EQREA.tmp\udc_setup.tmp | executable | |
MD5:ECBA884A38E62558961335529E483FBD | SHA256:2B020371F1425B3748D8C180A5DCD2984C24360AD7FFC12B48C2E78EF81A3DC2 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\x64\Service\is-JGD5Q.tmp | executable | |
MD5:2DAB60B98A36325E06E40F4876D46C6C | SHA256:C2D8F6E2285AD34E357ECFC78E3C0807A367A54CAB5E340D3B8B5B526FCF7532 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\x64\Service\CertificateValidationWrapper.dll | executable | |
MD5:2DAB60B98A36325E06E40F4876D46C6C | SHA256:C2D8F6E2285AD34E357ECFC78E3C0807A367A54CAB5E340D3B8B5B526FCF7532 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\x64\Service\is-CCUBP.tmp | executable | |
MD5:8C582AB00A040992EE456D45425956EB | SHA256:B8C55775C5E38AE0585026D4C5FDFF2ECD4FF3A98FCE5436C368A43A539F07E6 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\is-DNG7T.tmp | binary | |
MD5:432808F4B740FA211B6C51C23A89C320 | SHA256:6D0D0A4D82EC224B2F0808E12645EF48F2DDEE7F9E28583352C9C84EF6654DB5 | |||
7068 | udc_setup.tmp | C:\Windows\TempInst\x64\Service\is-NT8MM.tmp | executable | |
MD5:FC3663B623110E8289E16381B2CBE5B7 | SHA256:863CE14383904FE2FA645173E2B1FDFD0F6B150DA2D3865457084052B7490709 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
6224 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3568 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
3568 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
752 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6224 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6224 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3568 | SIHClient.exe | 40.127.169.103:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3568 | SIHClient.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
3568 | SIHClient.exe | 20.166.126.56:443 | fe3cr.delivery.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |