File name:

kaspersky4win202121.16.6.467ru_45357.exe

Full analysis: https://app.any.run/tasks/eb37de0f-1990-4357-811d-c88571defbf7
Verdict: Malicious activity
Analysis date: May 14, 2024, 11:43:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

63C9A22C500DF9925F2E513AE1091653

SHA1:

BC93F45C412173045C0E39CB1B6A622C52669DE0

SHA256:

47F5CE81CE33612610A6EFC353A0735A4BAF8486A898D7ECEADB8A58D2415DFC

SSDEEP:

98304:g37Sg7FX9xYuq/adLg37g73UStI6phCP9KAOPfmtwlsLPt6Hk7J0SHlQ9Lp7BKUp:HcFYx9g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 1960)
      • startup.exe (PID: 2480)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
    • Executable content was dropped or overwritten

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
      • startup.exe (PID: 1960)
    • Reads security settings of Internet Explorer

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads the Internet Settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads settings of System Certificates

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Checks Windows Trust Settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Application launched itself

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
    • Starts itself from another location

      • startup.exe (PID: 1960)
    • Adds/modifies Windows certificates

      • startup.exe (PID: 2480)
    • The process verifies whether the antivirus software is installed

      • startup.exe (PID: 2480)
  • INFO

    • Checks supported languages

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • wmpnscfg.exe (PID: 1580)
      • startup.exe (PID: 524)
      • startup.exe (PID: 1960)
      • startup.exe (PID: 2480)
      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 2272)
    • Create files in a temporary directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads the machine GUID from the registry

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads the computer name

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 1960)
      • startup.exe (PID: 2480)
      • wmpnscfg.exe (PID: 1580)
    • Checks proxy server information

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Reads the software policy settings

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Creates files or folders in the user directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
    • Creates files in the program directory

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Process checks whether UAC notifications are on

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1580)
    • Checks for the presence of KasperskyLab

      • kaspersky4win202121.16.6.467ru_45357.exe (PID: 3980)
      • startup.exe (PID: 524)
      • startup.exe (PID: 2480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:01:14 07:47:03+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 233472
InitializedDataSize: 4243456
UninitializedDataSize: -
EntryPoint: 0x4200
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.16.6.467
ProductVersionNumber: 21.16.6.467
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Лаборатория Касперского
FileDescription: Kaspersky [21.16.6.467.0.5.0]
FileVersion: 21.16.6.467
LegalCopyright: © 2024 АО "Лаборатория Касперского"
LegalTrademarks: Зарегистрированные товарные знаки и знаки обслуживания являются собственностью их правообладателей
ProductName: Kaspersky
ProductVersion: 21.16.6.467
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start kaspersky4win202121.16.6.467ru_45357.exe wmpnscfg.exe no specs startup.exe kaspersky4win202121.16.6.467ru_45357.exe no specs startup.exe startup.exe

Process information

PID
CMD
Path
Indicators
Parent process
524"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" -auto_update_mode="C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" /-self_remove -l=ru-RU -xpos=270 -ypos=64 -prevsetupver=21.16.6.467.0.5.0C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe
kaspersky4win202121.16.6.467ru_45357.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.17.7.539.0.2.0\au_setup_3b92ccf2-11e7-11ef-9e36-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1580"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1960"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe
startup.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
HIGH
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\programdata\kaspersky lab setup files\kfa21.17.7.539.0.2.0\au_setup_3b92ccf2-11e7-11ef-9e36-12a9866c77de\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2272"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" -cleanup="C:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED;3980"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exekaspersky4win202121.16.6.467ru_45357.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.16.6.467.0.5.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\users\admin\appdata\local\temp\kaspersky4win202121.16.6.467ru_45357.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
2480"C:\Windows\temp\3D4C30547E11FE11E963219A68C677ED\startup.exe" /-elevated=;"C:\ProgramData\Kaspersky Lab Setup Files\KFA21.17.7.539.0.2.0\au_setup_3B92CCF2-11E7-11EF-9E36-12A9866C77DE\startup.exe"C:\Windows\Temp\3D4C30547E11FE11E963219A68C677ED\startup.exe
startup.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
HIGH
Description:
Kaspersky [21.17.7.539.0.2.0]
Version:
21.17.7.539
Modules
Images
c:\windows\temp\3d4c30547e11fe11e963219a68c677ed\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\dcc4c2547e11fe11e963219a68c677ed\setup.dll
c:\windows\system32\user32.dll
3980"C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe" C:\Users\admin\AppData\Local\Temp\kaspersky4win202121.16.6.467ru_45357.exe
explorer.exe
User:
admin
Company:
Лаборатория Касперского
Integrity Level:
MEDIUM
Description:
Kaspersky [21.16.6.467.0.5.0]
Exit code:
0
Version:
21.16.6.467
Modules
Images
c:\users\admin\appdata\local\temp\kaspersky4win202121.16.6.467ru_45357.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 958
Read events
24 546
Write events
379
Delete events
33

Modification events

(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
4
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
230
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
Free
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\KasperskyLabSetup\Setup21.16.6.467.0.5.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3980) kaspersky4win202121.16.6.467ru_45357.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
50
Suspicious files
33
Text files
81
Unknown types
1

Dropped files

PID
Process
Filename
Type
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2024-05-14-12-43-52_KFA.21.16.6.467.log
MD5:
SHA256:
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\3B92CCF0-11E7-11EF-9E36-12A9866C77DE\downloader_neutral.initext
MD5:1224967A336A831FC3D44D58BB3B471E
SHA256:20019DA9AFBEE4E3E2A9A1F9D32AD53DD4E3BC23368FC8E5E5F77758026F812A
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2024-05-14-12-43-52_KAV.21.16.6.467.logtext
MD5:3A1AD6B754288D32FB47BD451BDAAE6B
SHA256:CA407E53B74C5BE42938F87E0376770C1315ABBDFBE0C8B6CFEA3D7F5BD1B01F
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.dllexecutable
MD5:BB9DF6ED16BAD5BBCDE9B106E11DFF6F
SHA256:DC5F2821548E5A660FC920224846994DA0169972F18A15E04FC9943A6A08F734
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.visuals.dllexecutable
MD5:5BCC51F3BB85949E37FFC08CF1501F70
SHA256:FDCBE09D8C6EE7681E88BBF7BBCC6C87F089D034E00DF6A422C3482F4A99A2BD
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.setup.ui.core.dllexecutable
MD5:78FB3F1E9F69BECA863AF1FF7713249C
SHA256:323AA8D8707A030BF245D6031B7FB439C929A3A24C5621A03276114691E45AAC
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\kl.ui.framework.uikit.b2c.dllexecutable
MD5:FB389C9C3C063163F5609608405F66BC
SHA256:7E97138FE069A260A05BAD7BEDDC31FC54D0909F36728AB0EFA761E7580393DF
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\setup.dllexecutable
MD5:986033838280C8D36C4FCC14B03CAA35
SHA256:42ABFB0FD3D1FBA8832F5EB2AA0E0D42A10B60F4A033C1B3838668287A4E88D6
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectorconverterswpf.dllexecutable
MD5:CA5E6167B66C384F62E56FE0E1757AF3
SHA256:A9EDC78BC8DD9E6AB098C96D2F26949BF8CC7C1F1071C5D96154022DAC685979
3980kaspersky4win202121.16.6.467ru_45357.exeC:\Users\admin\AppData\Local\Temp\FECC29B37E11FE11E963219A68C677ED\sharpvectorcss.dllexecutable
MD5:25E40483458B8083EB12D38B6CEAD136
SHA256:1A87D710B34B187F75E9213C95AB5EB129DA63906F122035E7BADF7044C929C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
40
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3980
kaspersky4win202121.16.6.467ru_45357.exe
GET
200
80.231.123.135:80
http://crl.kaspersky.com/aia/KasperskyLabPublicServicesRootCertificationAuthority.crt
unknown
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
GET
200
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2f209f4c903930da
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
80.231.123.135:80
crl.kaspersky.com
AS6453
FR
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
3980
kaspersky4win202121.16.6.467ru_45357.exe
130.117.190.147:443
crl.kaspersky.com
COGENT-174
DE
unknown
524
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown
524
startup.exe
130.117.190.147:443
crl.kaspersky.com
COGENT-174
DE
unknown
2480
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
unknown

DNS requests

Domain
IP
Reputation
ds.kaspersky.com
  • 62.67.238.152
  • 81.19.104.172
  • 82.202.184.184
  • 82.202.185.148
  • 82.202.185.146
  • 82.202.184.193
  • 130.117.190.228
unknown
crl.kaspersky.com
  • 80.231.123.135
  • 130.117.190.147
  • 212.73.221.196
whitelisted
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
dm.s.kaspersky-labs.com
  • 130.117.190.147
  • 212.73.221.196
  • 80.231.123.135
unknown

Threats

No threats detected
Process
Message
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
LocalizationEngine Making localization parameters
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
Core DisplayCulture = ru-RU DisplayCulture.FullLocalization = ru-RU FormatCulture = en-US
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[2232551] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[56151142] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
Interactivity Trigger[26065365] attached to MainWindow
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
kaspersky4win202121.16.6.467ru_45357.exe Information: 0 :
kaspersky4win202121.16.6.467ru_45357.exe
Core OnApplicationStartup