File name:

kaspersky4win202121.16.6.467ru_45357.exe

Full analysis: https://app.any.run/tasks/eb37de0f-1990-4357-811d-c88571defbf7
Verdict: Malicious activity
Analysis date: May 14, 2024, 11:43:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

63C9A22C500DF9925F2E513AE1091653

SHA1:

BC93F45C412173045C0E39CB1B6A622C52669DE0

SHA256:

47F5CE81CE33612610A6EFC353A0735A4BAF8486A898D7ECEADB8A58D2415DFC

SSDEEP:

98304:g37Sg7FX9xYuq/adLg37g73UStI6phCP9KAOPfmtwlsLPt6Hk7J0SHlQ9Lp7BKUp:HcFYx9g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
      • startup.exe (PID: 1960)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
    • Executable content was dropped or overwritten

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 1960)
      • startup.exe (PID: 2480)
    • Reads the Internet Settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads security settings of Internet Explorer

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads settings of System Certificates

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Checks Windows Trust Settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Application launched itself

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
    • Starts itself from another location

      • startup.exe (PID: 1960)
    • Adds/modifies Windows certificates

      • startup.exe (PID: 2480)
    • The process verifies whether the antivirus software is installed

      • startup.exe (PID: 2480)
  • INFO

    • Checks supported languages

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • wmpnscfg.exe (PID: 1580)
      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 2272)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
      • startup.exe (PID: 1960)
    • Reads the computer name

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • wmpnscfg.exe (PID: 1580)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
      • startup.exe (PID: 1960)
    • Reads the machine GUID from the registry

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Create files in a temporary directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Checks proxy server information

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Checks for the presence of KasperskyLab

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads the software policy settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Creates files or folders in the user directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1580)
    • Process checks whether UAC notifications are on

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Creates files in the program directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:01:14 07:47:03+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 233472
InitializedDataSize: 4243456
UninitializedDataSize: -
EntryPoint: 0x4200
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.16.6.467
ProductVersionNumber: 21.16.6.467
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Лаборатория Касперского
FileDescription: Kaspersky [21.16.6.467.0.5.0]
FileVersion: 21.16.6.467
LegalCopyright: © 2024 АО "Лаборатория Касперского"
LegalTrademarks: Зарегистрированные товарные знаки и знаки обслуживания являются собственностью их правообладателей
ProductName: Kaspersky
ProductVersion: 21.16.6.467
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start kaspersky4win202121.16.6.467ru_45357.exe wmpnscfg.exe no specs startup.exe kaspersky4win202121.16.6.467ru_45357.exe no specs startup.exe startup.exe

Process information

PID
CMD
Path
Indicators
Parent process
524"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" -auto_update_mode="C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" /-self_remove -l=ru-RU -xpos=270 -ypos=64 -prevsetupver=21.16.6.467.0.5.0C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe
kaspersky4win202121.16.6.467ru_45357.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.17.7.539.0.2.0\au_setup_3b92ccf2-11e7-11ef-9e36-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1580"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1960"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe
startup.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
HIGH
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.17.7.539.0.2.0\au_setup_3b92ccf2-11e7-11ef-9e36-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2272"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" -cleanup="C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED;3980"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exekaspersky4win202121.16.6.467ru_45357.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.16.6.467.0.5.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\users\admin\appdata\local\temp\kaspersky4win202121.16.6.467ru_45357.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
2480"C:\Windows\temp\3D4C30547E11FE11E963219A68C677ED\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe"C:\Windows\Temp\3D4C30547E11FE11E963219A68C677ED\startup.exe
startup.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
HIGH
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\windows\temp\3d4c30547e11fe11e963219a68c677ed\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\dcc4c2547e11fe11e963219a68c677ed\setup.dll
c:\windows\system32\user32.dll
3980"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe
explorer.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.16.6.467.0.5.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\users\admin\appdata\local\temp\kaspersky4win202121.16.6.467ru_45357.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 958
Read events
24 546
Write events
379
Delete events
33

Modification events

(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
4
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
230
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
Free
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
50
Suspicious files
33
Text files
81
Unknown types
1

Dropped files

PID
Process
Filename
Type
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2024-05-14-12-43-52_KFA.21.16.6.467.log
MD5:
SHA256:
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\3B92CCF0-11E7-11EF-9E36-12A9866C77DE\downloader_neutral.initext
MD5:1224967A336A831FC3D44D58BB3B471E
SHA256:20019DA9AFBEE4E3E2A9A1F9D32AD53DD4E3BC23368FC8E5E5F77758026F812A
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.core.dllexecutable
MD5:78FB3F1E9F69BECA863AF1FF7713249C
SHA256:323AA8D8707A030BF245D6031B7FB439C929A3A24C5621A03276114691E45AAC
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.dllexecutable
MD5:BB9DF6ED16BAD5BBCDE9B106E11DFF6F
SHA256:DC5F2821548E5A660FC920224846994DA0169972F18A15E04FC9943A6A08F734
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.ui.framework.uikit.dllbinary
MD5:7076C5EB43353580A88554A458C393DC
SHA256:294055DB0EDEBAD0B62F5690D65C401FF3C859BB2CE913C7840142EA344F0F24
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.ui.framework.dllexecutable
MD5:AEB7BA2CE5574025A985313BDDE99CFB
SHA256:92D7B5AD2E92E72804223E71CDE8350BA7F0561E5E1B8C0002CE88E3E88F6EF0
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectormodel.dllexecutable
MD5:FF09404438A1AAF5BAFA792A504E7631
SHA256:CCF8359D7862330EBB1DD0A5F50B9E12E43B1763EF64CDE5417960774D1DCF11
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\3B92CCF0-11E7-11EF-9E36-12A9866C77DE\GuiStrings_KFA.loctext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectorcss.dllexecutable
MD5:25E40483458B8083EB12D38B6CEAD136
SHA256:1A87D710B34B187F75E9213C95AB5EB129DA63906F122035E7BADF7044C929C9
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.ui.framework.localization.dllexecutable
MD5:CCF2531B77412B4EB5410888BD3EEB42
SHA256:170A04A3141B1C4F2606C3BA78D687972DB6319D85D7A45F59958CC9F1FD05BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
40
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3980
kaspersky4win202121.16.6.467ru_45357.exe
GET
200
80.231.123.135:80
http://crl.kaspersky.com/aia/KasperskyLabPublicServicesRootCertificationAuthority.crt
unknown
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
GET
200
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2f209f4c903930da
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
80.231.123.135:80
crl.kaspersky.com
AS6453
FR
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
130.117.190.147:443
crl.kaspersky.com
COGENT-174
DE
unknown
524
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown
524
startup.exe
130.117.190.147:443
crl.kaspersky.com
COGENT-174
DE
unknown
2480
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown

DNS requests

Domain
IP
Reputation
ds.kaspersky.com
  • 62.67.238.152
  • 81.19.104.172
  • 82.202.184.184
  • 82.202.185.148
  • 82.202.185.146
  • 82.202.184.193
  • 130.117.190.228
unknown
crl.kaspersky.com
  • 80.231.123.135
  • 130.117.190.147
  • 212.73.221.196
whitelisted
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
dm.s.kaspersky-labs.com
  • 130.117.190.147
  • 212.73.221.196
  • 80.231.123.135
unknown

Threats

No threats detected
Process
Message
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
LocalizationEngine Making localization parameters
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
Core DisplayCulture = ru-RU DisplayCulture.FullLocalization = ru-RU FormatCulture = en-US
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[2232551] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[56151142] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[26065365] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
Core OnApplicationStartup