File name:

Uptdate.exe

Full analysis: https://app.any.run/tasks/1ee0065d-4390-4795-8fb7-1539094ec98d
Verdict: Malicious activity
Analysis date: May 28, 2025, 17:36:05
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

74D8041591E0106A8222A05301813831

SHA1:

988C03975208057AD0572C1B31DD53E3760FC8A3

SHA256:

665CFE731E8370C6A6E09CD4F33FFEF6BBDB04408831EBE8AFFA5696370DDB59

SSDEEP:

196608:w+NGB1v7JdncWB4CFlhasBRvYdZ1L5VQdy+v9gA:w+NGDv74sldnw5Vn+v9x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Uptdate.exe (PID: 7416)
      • nudwee.exe (PID: 6964)
    • Changes the autorun value in the registry

      • HeimdallGuard.exe (PID: 7748)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7492)
      • Uptdate.exe (PID: 7416)
    • Application launched itself

      • HeimdallGuard.exe (PID: 7748)
    • Executable content was dropped or overwritten

      • Uptdate.exe (PID: 7416)
    • Starts itself from another location

      • Uptdate.exe (PID: 7416)
  • INFO

    • The sample compiled with english language support

      • Uptdate.exe (PID: 7416)
    • Checks supported languages

      • Uptdate.exe (PID: 7416)
      • HeimdallGuard.exe (PID: 7748)
      • HeimdallGuard.exe (PID: 7948)
      • nudwee.exe (PID: 6964)
    • Reads the computer name

      • HeimdallGuard.exe (PID: 7748)
      • HeimdallGuard.exe (PID: 7948)
      • Uptdate.exe (PID: 7416)
    • Manual execution by a user

      • WinRAR.exe (PID: 7492)
    • Reads the machine GUID from the registry

      • HeimdallGuard.exe (PID: 7748)
      • HeimdallGuard.exe (PID: 7948)
    • Create files in a temporary directory

      • HeimdallGuard.exe (PID: 7748)
      • Uptdate.exe (PID: 7416)
    • Compiled with Borland Delphi (YARA)

      • Uptdate.exe (PID: 7416)
    • Disables trace logs

      • HeimdallGuard.exe (PID: 7748)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7492)
    • Reads the software policy settings

      • HeimdallGuard.exe (PID: 7748)
    • Checks proxy server information

      • HeimdallGuard.exe (PID: 7748)
    • Detects InnoSetup installer (YARA)

      • Uptdate.exe (PID: 7416)
    • Launch of the file from Registry key

      • HeimdallGuard.exe (PID: 7748)
    • Process checks computer location settings

      • Uptdate.exe (PID: 7416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (53.4)
.exe | Win64 Executable (generic) (35.5)
.exe | Win32 Executable (generic) (5.8)
.exe | Generic Win/DOS Executable (2.5)
.exe | DOS Executable Generic (2.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:08 09:03:48+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.42
CodeSize: 76288
InitializedDataSize: 3749376
UninitializedDataSize: -
EntryPoint: 0x9c60
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ASUSTeK COMPUTER INC.
FileDescription: -
FileVersion: 30.100.2148.1
InternalName: GPIO_DCH_Intel_Z_V30.100.2148.1_26466.exe
LegalCopyright: © ASUSTeK COMPUTER INC. All rights reserved.
OriginalFileName: GPIO_DCH_Intel_Z_V30.100.2148.1_26466.exe
ProductName: Intel GPIO Driver
ProductVersion: 30.100.2148.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
7
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start uptdate.exe winrar.exe heimdallguard.exe conhost.exe no specs heimdallguard.exe no specs conhost.exe no specs nudwee.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6964"C:\Users\admin\AppData\Local\Temp\6106733c42\nudwee.exe" C:\Users\admin\AppData\Local\Temp\6106733c42\nudwee.exeUptdate.exe
User:
admin
Company:
ASUSTeK COMPUTER INC.
Integrity Level:
MEDIUM
Exit code:
1
Version:
30.100.2148.1
Modules
Images
c:\users\admin\appdata\local\temp\6106733c42\nudwee.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7416"C:\Users\admin\AppData\Local\Temp\Uptdate.exe" C:\Users\admin\AppData\Local\Temp\Uptdate.exe
explorer.exe
User:
admin
Company:
ASUSTeK COMPUTER INC.
Integrity Level:
MEDIUM
Exit code:
0
Version:
30.100.2148.1
Modules
Images
c:\users\admin\appdata\local\temp\uptdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7492"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\HGuard.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7748"C:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\HeimdallGuard.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\HeimdallGuard.exe
WinRAR.exe
User:
admin
Company:
HeimdallGuard Sikkerhet AS
Integrity Level:
MEDIUM
Description:
HeimdallGuard Endpoint Agent
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7492.9083\heimdallguard.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7756\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeHeimdallGuard.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7948"C:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\HeimdallGuard.exe" --watchdogC:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\HeimdallGuard.exeHeimdallGuard.exe
User:
admin
Company:
HeimdallGuard Sikkerhet AS
Integrity Level:
MEDIUM
Description:
HeimdallGuard Endpoint Agent
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7492.9083\heimdallguard.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
7956\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeHeimdallGuard.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 141
Read events
6 118
Write events
23
Delete events
0

Modification events

(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\HGuard.zip
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7492) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7748) HeimdallGuard.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7748) HeimdallGuard.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
3
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7748HeimdallGuard.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\debug.logtext
MD5:7AE1BEED9FA1AD40E511AD72DC8D3E32
SHA256:E13292D95EDC79001B0C61ED617FE369761C98FD961F04FFA3F132EC8497D2AA
7492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
7416Uptdate.exeC:\Windows\Tasks\nudwee.jobbinary
MD5:4F33FFDC9AE9D2ED2A9A8A10B825F9FC
SHA256:5A67F470F2C71FC0C3BA2057D5CC94B26EA980A414A2C014A5F5D2D11BB0B6AD
7492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7492.9083\HeimdallGuard.exeexecutable
MD5:6566F6528082C63B40080DBDE3D9BAB9
SHA256:89795017A9C9143834A50BEDEE4AD39A21D76B1F9AC06DC761BDD893F9CD779F
7416Uptdate.exeC:\Users\admin\AppData\Local\Temp\6106733c42\nudwee.exeexecutable
MD5:74D8041591E0106A8222A05301813831
SHA256:665CFE731E8370C6A6E09CD4F33FFEF6BBDB04408831EBE8AFFA5696370DDB59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
50
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7292
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7292
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1020
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.2
  • 40.126.32.133
  • 40.126.32.68
  • 20.190.160.130
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
countervector.pro
  • 188.114.96.3
  • 188.114.97.3
unknown
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info