| File name: | HPPSdr.exe |
| Full analysis: | https://app.any.run/tasks/4f623063-345d-4b36-9cfc-e67cb019b6e6 |
| Verdict: | Malicious activity |
| Analysis date: | November 03, 2023, 14:21:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | FE236937872C20107145A8F8A0869EBD |
| SHA1: | C4818093839C24A3EBC583B49EF8789C5CEEA130 |
| SHA256: | 5F4467BA1D28CCD2367ACF1D4B6DB15A0D973C5CEC1FF59B25AC8074520B9BA4 |
| SSDEEP: | 98304:Z9MnRNTsjNNJusPSo1vomxCHv4AmOwruCVFKomWdyCc/stSvFwg8kJhpA7w26QGQ:EyUOaQtGLYmPU3dTszFTBo7r |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:02:24 06:14:02+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 183808 |
| InitializedDataSize: | 122880 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x250b7 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 19.0.0.0 |
| ProductVersionNumber: | 19.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Hewlett-Packard Company |
| FileDescription: | HP Webpack |
| FileVersion: | 19.0.0.0 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Hewlett-Packard Company |
| OriginalFileName: | 7zS.sfx |
| ProductName: | HP Webpack |
| ProductVersion: | 19.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3372 | "C:\Users\admin\AppData\Local\Temp\HPPSdr.exe" | C:\Users\admin\AppData\Local\Temp\HPPSdr.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3416 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3496 | "C:\HP\Diagnostics\PSDR\FileExtractor.exe" | C:\HP\Diagnostics\PSDR\FileExtractor.exe | — | HPPSdr.exe | |||||||||||
User: admin Company: HPDC LP Integrity Level: MEDIUM Description: HP Print and Scan Doctor 5.7.4 Exit code: 3221226540 Version: 1.0.0.2 Modules
| |||||||||||||||
| 3624 | "C:\HP\Diagnostics\PSDR\FileExtractor.exe" | C:\HP\Diagnostics\PSDR\FileExtractor.exe | HPPSdr.exe | ||||||||||||
User: admin Company: HPDC LP Integrity Level: HIGH Description: HP Print and Scan Doctor 5.7.4 Exit code: 0 Version: 1.0.0.2 Modules
| |||||||||||||||
| 3688 | "C:\HP\Diagnostics\PSDR\NDP46-KB3045560-Web.exe" | C:\HP\Diagnostics\PSDR\NDP46-KB3045560-Web.exe | — | FileExtractor.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.6 Setup Exit code: 1602 Version: 4.6.00081.00 Modules
| |||||||||||||||
| 3748 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3844 | C:\54123ad1e0459d779813aa0587\\Setup.exe /x86 /x64 /web | C:\54123ad1e0459d779813aa0587\Setup.exe | NDP46-KB3045560-Web.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup Installer Exit code: 1602 Version: 14.0.0081.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 3924 | SetupUtility.exe /aupause | C:\54123ad1e0459d779813aa0587\SetupUtility.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.5 Setup Exit code: 0 Version: 14.0.0081.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 3980 | TMPB620.tmp.exe /Q /X:C:\54123ad1e0459d779813aa0587\TMPB620.tmp.exe.tmp | C:\54123ad1e0459d779813aa0587\TMPB620.tmp.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.6 Setup Exit code: 0 Version: 4.6.00081.00 Modules
| |||||||||||||||
| 4008 | SetupUtility.exe /screboot | C:\54123ad1e0459d779813aa0587\SetupUtility.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.5 Setup Exit code: 0 Version: 14.0.0081.0 built by: NETFXREL2 Modules
| |||||||||||||||
| (PID) Process: | (3416) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A8E678A2-6901-4282-B4F7-A3E5A6C83760}\{E484809C-2353-4669-A8A0-CAEDBE311F21} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3416) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A8E678A2-6901-4282-B4F7-A3E5A6C83760} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3416) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D80F53DD-09C3-4F44-AF6F-3C7102B6D22B}\{E484809C-2353-4669-A8A0-CAEDBE311F21} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3416) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D80F53DD-09C3-4F44-AF6F-3C7102B6D22B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3416) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{ADA2D2C1-5D74-47C7-8C9D-49273AAF4C05} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3372) HPPSdr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3372) HPPSdr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3372) HPPSdr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3372) HPPSdr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3624) FileExtractor.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1033\ndu_firewall.chm | binary | |
MD5:0B98650C63C1D07AA22EA9E24627418F | SHA256:452F45E5937A80DF4A81DC58E7D2DD7F5A47D1F39E4D6047DB44B61EC95E34D1 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1025\ndu_firewall.chm | binary | |
MD5:5DB4574DC67604873C3A5BDAE114BB78 | SHA256:4FB1B4CC7892625E1AE1842B47A1C873F9AB1BBFEC68FF6D66557684C82EC836 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1032\ndu_firewall.chm | binary | |
MD5:2EF3B036FA90ADE4021E7AA64B1B3E17 | SHA256:31FC0B144D73F12F2EF4CD0F8F9B3EBF6EA908CA446BE1DC79947B73A018FA89 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1029\ndu_firewall.chm | binary | |
MD5:561548CCEE59C3B2ED984D9F4368FC2A | SHA256:2429BEA8F4F2D42F8F53D1474A51FF0532F2324A854533FDE9DB4DA0AA54766D | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1036\ndu_firewall.chm | binary | |
MD5:92202197C5115ACBDB5B4E438CAFADF5 | SHA256:E84F5C3614CA4C2A7E6EA0F3A746081209EF0AF686CBDC4B0CD4BE786171AD41 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1030\ndu_firewall.chm | binary | |
MD5:73D8024987151A49BC8D821609A9BC07 | SHA256:15FE05930F8E06955C9A405F8B26C012441B292D7A141D7949B5ABF6F837931E | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1031\ndu_firewall.chm | binary | |
MD5:A99322D2DE831785C6090FC556B760C0 | SHA256:A9B4CAA83B51DB11BB9DE7B627EE7725F8EA79D08ABF40F4A9D491069E9B36C6 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1044\ndu_firewall.chm | binary | |
MD5:6AA6F8368AB323CAF5AA970AFE9EBB79 | SHA256:065C49111DEDE2B78FC258B5F3F66CE5DB9B0A20E9DB8D428C97F1BF29F17074 | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1037\ndu_firewall.chm | binary | |
MD5:7BBB78DF372C20327061AE7E5B2BB596 | SHA256:818D69F45ADE71B22251C048919B375B0286F1AAE79E20C594F8C1397CDE548E | |||
| 3372 | HPPSdr.exe | C:\HP\Diagnostics\PSDR\help\1038\ndu_firewall.chm | binary | |
MD5:0EC7850CE9B076BBB74A80F6C52E45EF | SHA256:ED8320720F9BA690D073794FAEB049822411227FF994A8C0181D4D1CEBE3CDCA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
868 | svchost.exe | HEAD | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=249117&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | GET | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=249117&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528231&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | GET | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528231&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | GET | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
3844 | Setup.exe | GET | 302 | 2.19.246.123:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
3844 | Setup.exe | GET | 302 | 2.19.246.123:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | GET | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink/?LinkId=528226&clcid=0x409 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3844 | Setup.exe | 46.228.146.128:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
3844 | Setup.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
868 | svchost.exe | 23.218.210.69:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
868 | svchost.exe | 184.30.24.206:443 | download.microsoft.com | AKAMAI-AS | DE | unknown |
868 | svchost.exe | 68.232.34.200:443 | download.visualstudio.microsoft.com | EDGECAST | US | whitelisted |
3844 | Setup.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
download.microsoft.com |
| whitelisted |
download.visualstudio.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
Setup.exe | User cancelled installation.
|