| File name: | Microsoft Helpdesk.Client.exe |
| Full analysis: | https://app.any.run/tasks/cc7cec84-e170-47db-85c5-dfb1d41c0b30 |
| Verdict: | Malicious activity |
| Analysis date: | April 05, 2024, 14:23:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 715B39CC70D56AF82235305503B5FAF1 |
| SHA1: | 1F924246A9C41DA69F9DE8AA5926D1C2308AD726 |
| SHA256: | 64F5CD4D8E48DA2CD9F2CE2FABED3B813F8A7BAB7C8A0FAEC1C892DB9AB02BAC |
| SSDEEP: | 3072:zdyfcQ73rZy2kBjfNTMpjfJVOxz8lzqETWi2:kce3rEBxItlqi2 |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:05:18 16:07:24+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 44032 |
| InitializedDataSize: | 33280 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16e7 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1692 | "C:\Users\admin\AppData\Local\Temp\Microsoft Helpdesk.Client.exe" | C:\Users\admin\AppData\Local\Temp\Microsoft Helpdesk.Client.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2572 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe | Microsoft Helpdesk.Client.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: ClickOnce Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates |
| Operation: | delete value | Name: | 03A5B14663EB12023091B84A6D6A68BC871DE66B |
Value: | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\03A5B14663EB12023091B84A6D6A68BC871DE66B |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000003A5B14663EB12023091B84A6D6A68BC871DE66B20000000010000009D0400003082049930820381A003020102020F1688F039255E638E69143907E6330B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3135313233313030303030305A170D3139303730393138343033365A308184310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312A302806035504031321434F4D4F444F205348412D312054696D65205374616D70696E67205369676E657230820122300D06092A864886F70D01010105000382010F003082010A0282010100E9E93DDFD73708C91E38B25253426D22F1B1C406046B9EFD827450437DC6A0BB1F4EF9027126B1EF43D8838C48FCE70F977A9AEB9CDEA6A30E3B1C4418758E78A51769FE4918A4E2BB5C4EFE8E2A547A50F0D5F6CC91E79979D7DE7994D79633FE0E83BE22BF63162CA3DD281BAF3DABEA97D2F1BF0410E73D4845FD1F6865C17F599969C022310C626EA75C650121B063C4221827EEE6FCD2003D472EA8B886565D04DC1317256E1CDF440F15CDB7DBA55776426F00688299D2E3C1DEF08B94574CEC08902221CE222B980C42E64293949893EFFD06D93FBC5B9B543C20B1EE6AD6477AC5AB80E9309ADEF1A43F554D0A09348A7529D269AD970F50BFF8CA090203010001A381F43081F1301F0603551D23041830168014DAED6474149C143CABDD99A9BD5B284D8B3CC9D8301D0603551D0E041604148E6B2D336BF433A793B3139AA5E00AF712356A88300E0603551D0F0101FF0404030206C0300C0603551D130101FF0402300030160603551D250101FF040C300A06082B0601050507030830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010505000382010100BA332440408C7CDB589FB36098B2F5C031FEEB1F6E50F60AE0E4E681AD2687A2DFFDB3DAF473F300FB291B891B153EDB6B52932BC4AC3981D73C67579A3936E028089AE3394F9B89097F7BC5617F598932250A6AAE1A3EF0A227A8B6C3B887F7160448413D5CD8EC9F4D203104D965A1EDCD690753163DDD36020A88EB40E506300BB8164BDCEFBC5509FFC63E122E76B3DCCE42EFF97657E1B70A054098589A5D711693718C6581EA6FF389F7FB73ADB4E7BFD98E6FAA0B4F25F3B8E1D5DD75986881F8AAC0D180C2C4C43989C1F6C99E6CD774F9D997F84FC29A0ACD5E8FF819E9E0A59FC4F09221E62D7925C922F9C3F03A8457AD3A16F46394101D5DD0C6 | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates |
| Operation: | delete value | Name: | A41A37D0270D8433C3CD0220248AD84A5A6A1A26 |
Value: | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A41A37D0270D8433C3CD0220248AD84A5A6A1A26 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000A41A37D0270D8433C3CD0220248AD84A5A6A1A26200000000100000078050000308205743082045CA003020102021004A03DBCE32C5A34420A419FB740AA1A300D06092A864886F70D01010B0500307D310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312330210603550403131A434F4D4F444F2052534120436F6465205369676E696E67204341301E170D3136303230323030303030305A170D3139303230313233353935395A3081B7310B3009060355040613025553310E300C06035504110C0533333633343110300E06035504080C07466C6F72696461310E300C06035504070C0554616D70613124302206035504090C1B343131302047656F72676520526F61642C20537569746520323030310E300C06035504120C053333363334311F301D060355040A0C1653637265656E436F6E6E65637420536F667477617265311F301D06035504030C1653637265656E436F6E6E65637420536F66747761726530820122300D06092A864886F70D01010105000382010F003082010A0282010100EF53C03E3946AAD66D87A2A761DD3F45401CAF1FFA02DF7F15D94DC61B6A7873D2671714D6C382D635025045FFB484BC2A50EBEE0053C614226009D186CBDFB1F4AC68FF6648734C6DEEB8DD82842BA107519322FD8D2A2767D1E370053CE48EA776B6BC137CC903A30DAFFF6E63C58CDC7FE40C832D16474F96631CB88141223A4CB6541E33675296FA57637F295553FB34409A00408613052E54935B092CBB303B1BEC674753D044C9D2E260F6A1CD4EB4E176E0CB09FC271B79A0872DF10746C8522969D8E30ED3A4BDA84876713FAA1534F00CAEE19B514CA24B5835742A636A281F82D8D2BF307BFB325AC1C087751DEA457BEFEC4F60847871122067CF0203010001A38201B3308201AF301F0603551D23041830168014299160FF8A4DFAEBF9A66AB8CFF9E64BBD49CE12301D0603551D0E04160414DBAB147ED014C81E0B99B50DEC9ABFC46911E7EB300E0603551D0F0101FF040403020780300C0603551D130101FF0402300030130603551D25040C300A06082B06010505070303301106096086480186F842010104040302041030460603551D20043F303D303B060C2B06010401B2310102010302302B302906082B06010505070201161D68747470733A2F2F7365637572652E636F6D6F646F2E6E65742F43505330430603551D1F043C303A3038A036A0348632687474703A2F2F63726C2E636F6D6F646F63612E636F6D2F434F4D4F444F525341436F64655369676E696E6743412E63726C307406082B0601050507010104683066303E06082B060105050730028632687474703A2F2F6372742E636F6D6F646F63612E636F6D2F434F4D4F444F525341436F64655369676E696E6743412E637274302406082B060105050730018618687474703A2F2F6F6373702E636F6D6F646F63612E636F6D30240603551D11041D301B81196A6D6F7267616E4073637265656E636F6E6E6563742E636F6D300D06092A864886F70D01010B05000382010100501D24454FC8F1494E7D2858F99BF3D1532953CDD01C2868CFD790BF19100F9AD202EF66EE3DBB8DB48912F6B127F549B1CCA2E125897352F83CD72D4AD95566CC911A1BECFC64B0199760970F06C28FC99352206E21E9A7BFE58A9C5CE29FE51BFED0E9B8262CA6BCAC3CF0151B5CD5400391169A22A95FC747587C48FB70D7DF0410C27D68DBCE05BC9A0C6AF54361F7A5879A4D11BF8D8826E58BDD9526706EC1044745A53A2D3AF4ABA2082964213659D372A28DD13CD37D5BA766410F33D04333257FF70DB9FB4514859B335B5C4E9B932C2DF3F7894B961F5C01CBC94E531290BD572E56B749FDA0B4A78E4A22611E9942F4E776389E1A1FA76638CFB6 | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates |
| Operation: | delete value | Name: | F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0 |
Value: | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0200000000100000078050000308205743082045CA00302010202102766EE56EB49F38EABD770A2FC84DE22300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308185310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312B302906035504031322434F4D4F444F205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010091E85492D20A56B1AC0D24DDC5CF446774992B37A37D23700071BC53DFC4FA2A128F4B7F1056BD9F7072B7617FC94B0F17A73DE3B00461EEFF1197C7F4863E0AFA3E5CF993E6347AD9146BE79CB385A0827A76AF7190D7ECFD0DFA9C6CFADFB082F4147EF9BEC4A62F4F7F997FB5FC674372BD0C00D689EB6B2CD3ED8F981C14AB7EE5E36EFCD8A8E49224DA436B62B855FDEAC1BC6CB68BF30E8D9AE49B6C6999F878483045D5ADE10D3C4560FC32965127BC67C3CA2EB66BEA46C7C720A0B11F65DE4808BAA44EA9F283463784EBE8CC814843674E722A9B5CBD4C1B288A5C227BB4AB98D9EEE05183C309464E6D3E99FA9517DA7C3357413C8D51ED0BB65CAF2C631ADF57C83FBCE95DC49BAF4599E2A35A24B4BAA9563DCF6FAAFF4958BEF0A8FFF4B8ADE937FBBAB8F40B3AF9E843421E89D884CB13F1D9BBE18960B88C2856AC141D9C0AE771EBCF0EDD3DA996A148BD3CF7AFB50D224CC01181EC563BF6D3A2E25BB7B204225295809369E88E4C65F191032D707402EA8B671529695202BBD7DF506A5546BFA0A328617F70D0C3A2AA2C21AA47CE289C064576BF821827B4D5AEB4CB50E66BF44C867130E9A6DF1686E0D8FF40DDFBD042887FA3333A2E5C1E41118163CE18716B2BECA68AB7315C3A6A47E0C37959D6201AAFF26A98AA72BC574AD24B9DBB10FCB04C41E5ED1D3D5E289D9CCCBFB351DAA747E584530203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414BBAF7E023DFAA6F13C848EADEE3898ECD93232D4300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C0500038201010064BF83F15F9A85D0CDB8A129570DE85AF7D1E93EF276046EF15270BB1E3CFF4D0D746ACC818225D3C3A02A5D4CF5BA8BA16DC4540975C7E3270E5D847937401377F5B4AC1CD03BAB1712D6EF34187E2BE979D3AB57450CAF28FAD0DBE5509588BBDF8557697D92D852CA7381BF1CF3E6B86E661105B31E942D7F91959259F14CCEA391714C7C470C3B0B19F6A1B16C863E5CAAC42E82CBF90796BA484D90F294C8A973A2EB067B239DDEA2F34D559F7A6145981868C75E406B23F5797AEF8CB56B8BB76F46F47BF13D4B04D89380595AE041241DB28F15605847DBEF6E46FD15F5D95F9AB3DBD8B8E440B3CD9739AE85BB1D8EBCDC879BD1A6EFF13B6F10386F | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates |
| Operation: | delete value | Name: | B69E752BBE88B4458200A7C0F4F5B3CCE6F35B47 |
Value: | |||
| (PID) Process: | (1692) Microsoft Helpdesk.Client.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\B69E752BBE88B4458200A7C0F4F5B3CCE6F35B47 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000B69E752BBE88B4458200A7C0F4F5B3CCE6F35B472000000001000000E4050000308205E0308203C8A00302010202102E7C87CC0E934A52FE94FD1CB7CD34AF300D06092A864886F70D01010C0500308185310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312B302906035504031322434F4D4F444F205253412043657274696669636174696F6E20417574686F72697479301E170D3133303530393030303030305A170D3238303530383233353935395A307D310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312330210603550403131A434F4D4F444F2052534120436F6465205369676E696E6720434130820122300D06092A864886F70D01010105000382010F003082010A0282010100A69890637791347F8AD1DDE9673111EBCC1EFD311DB3B962573F93BC5BE39F1E243211276BBC5191A7CF9E9E25B35F81A8180F1D1E20300EFB617B8609B3E3FDA2689D1C2C9DBF72E3E475A0E535238EC98AEE1A0C64C7D842A17BB552034B3AB08E234B4B63E02294377BD579900A1418512CE6FEC112F01C3F61610A8CA2DCF6C330AACD28187548C1795A08CDBB8C558CF7D476903A33465073985CF4854A6B0F80DD5ED6BDFDA92FC025F5F978D78D5F10C244553C903C3146CB70AE07A90AE3AFC1016F901A23E25F38DBC6085D47B38341F02E003714B912AA799252CD870F7BD86229A47E30BD1BB58C72B448F2E3E821F95E4C62798B02069F7FD50B0203010001A38201513082014D301F0603551D23041830168014BBAF7E023DFAA6F13C848EADEE3898ECD93232D4301D0603551D0E04160414299160FF8A4DFAEBF9A66AB8CFF9E64BBD49CE12300E0603551D0F0101FF04040302018630120603551D130101FF040830060101FF02010030130603551D25040C300A06082B0601050507030330110603551D20040A300830060604551D2000304C0603551D1F044530433041A03FA03D863B687474703A2F2F63726C2E636F6D6F646F63612E636F6D2F434F4D4F444F52534143657274696669636174696F6E417574686F726974792E63726C307106082B0601050507010104653063303B06082B06010505073002862F687474703A2F2F6372742E636F6D6F646F63612E636F6D2F434F4D4F444F525341416464547275737443412E637274302406082B060105050730018618687474703A2F2F6F6373702E636F6D6F646F63612E636F6D300D06092A864886F70D01010C05000382020100023F0239C3EEF8CA3B89DE0C6D4DB1F14E924FAFC2382C04CCC56311AB0963AFABA2D7023FCC6F19C33DD61A0894FF25D8A988A72B101AE09BB107221A511C3AD4E1E909BFE62474AF1E7B16316E23EF54512D5202E27508054CF1B751E15100C687F66CEE104476576AF1DF586B21AA49D47C374EBDFFB67554401836576711CD4F02E4FEF3DAFC7517DBECB7F7650923491F435783EA7E207761C84DF2BB654DA8F7854507AF7A6927659029408BDF7B3A51398CA81F7079AD6D4220A2CF0C6C038C4CCD730794E75A8E3A04BAA2A17C1FCB633A15A7D4151BA7524732A9F4BF6447D1AA1F534E323073C26FB778829D5CFF46BB6B221D880BF81BAA34A6FC8CF5DD7F658C8C315731D036EC47A1CFCB8BA8EF1C1858C50677CA4B9B51AF4C084A7A8FE2A352E28E8ECC26E4B2D8E538C2A8EDC6819C356BA958614A0A97B44B42B6559DBE99E7706D59F86D2A0C7F19605F0C9A886C30AC520990161BFF2B9DDBD020CA89EA287E328E19DF7B48331ED765F8AEC9F8831493767D64D08ECEBE357DFF72314D9F9EBD1E6C2FA88F0C0650FB8C27B376C9F4E6D7C334E28C87218661FEBF5574E12177030A686CBBE4C9A9E6CF5925EB7CEC450E796668E822CDB8EF98854D96113C098AD07FBC282813FB6ACA548D925CCDC26598069ECE485BD4B5379346417C07DDCFFA43EFBA6761FF7D49E0BB307D5C80E3E616394BA7 | |||
| (PID) Process: | (2572) dfsvc.exe | Key: | HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\StateManager |
| Operation: | write | Name: | StateStore_RandomString |
Value: 65GBJK1PGZBOGJ1V185DO8AK | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2572 | dfsvc.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\4HPL13QO.log | text | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2572 | dfsvc.exe | 92.205.232.78:8040 | www.prohelp.tech | — | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.prohelp.tech |
| unknown |