File name:

ndp462-kb3151802-web (1).exe

Full analysis: https://app.any.run/tasks/0091b6a6-cf5b-4dd1-a49d-fbdfc8cd5606
Verdict: Malicious activity
Analysis date: March 10, 2025, 11:11:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

3140D81D76646B3DD789F7D5AD4C91FB

SHA1:

10A8288F4CB9C9D20731C84A17DC780D7FB9CED8

SHA256:

67242C8FE953D454EDB4171023343F33740E3D16E8469A4B0C11BD42EB85F3FA

SSDEEP:

24576:pXWYAlLOlSmtLvUDSRbm4Jah1rVxzY8Jgok5vsbfRHO+G9u8fHxcVbRv/Y:pmYAlL5eTUDBzrVxzY/B5SfZt8fOVbRo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • ndp462-kb3151802-web (1).exe (PID: 6700)
      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Process drops legitimate windows executable

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Executable content was dropped or overwritten

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Creates file in the systems drive root

      • ndp462-kb3151802-web (1).exe (PID: 896)
  • INFO

    • The sample compiled with english language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Reads the computer name

      • ndp462-kb3151802-web (1).exe (PID: 896)
      • Setup.exe (PID: 6700)
    • Reads the machine GUID from the registry

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Create files in a temporary directory

      • ndp462-kb3151802-web (1).exe (PID: 896)
      • Setup.exe (PID: 6700)
    • Checks supported languages

      • ndp462-kb3151802-web (1).exe (PID: 896)
      • Setup.exe (PID: 6700)
    • The sample compiled with korean language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with chinese language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with russian language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with french language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with Italian language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with turkish language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with polish language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with arabic language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with czech language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with spanish language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with portuguese language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with japanese language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with swedish language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • The sample compiled with german language support

      • ndp462-kb3151802-web (1).exe (PID: 896)
    • Reads CPU info

      • Setup.exe (PID: 6700)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:11:30 23:49:43+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 158720
InitializedDataSize: 29696
UninitializedDataSize: -
EntryPoint: 0x18bee
OSVersion: 5.1
ImageVersion: 10
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.6.1590.0
ProductVersionNumber: 4.6.1590.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft .NET Framework 4.6.2 Setup
FileVersion: 4.6.01590.00
InternalName: NDP462-KB3151802-Web.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: NDP462-KB3151802-Web.exe
ProductName: Microsoft .NET Framework 4.6.2
ProductVersion: 4.6.01590.00
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ndp462-kb3151802-web (1).exe setup.exe no specs sppextcomobj.exe no specs slui.exe no specs ndp462-kb3151802-web (1).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
896"C:\Users\admin\AppData\Local\Temp\ndp462-kb3151802-web (1).exe" C:\Users\admin\AppData\Local\Temp\ndp462-kb3151802-web (1).exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.6.2 Setup
Version:
4.6.01590.00
Modules
Images
c:\users\admin\appdata\local\temp\ndp462-kb3151802-web (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1228"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3156C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6700"C:\Users\admin\AppData\Local\Temp\ndp462-kb3151802-web (1).exe" C:\Users\admin\AppData\Local\Temp\ndp462-kb3151802-web (1).exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Framework 4.6.2 Setup
Exit code:
3221226540
Version:
4.6.01590.00
Modules
Images
c:\users\admin\appdata\local\temp\ndp462-kb3151802-web (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6700C:\e36cc996c0da26bcf00f9742\\Setup.exe /x86 /x64 /webC:\e36cc996c0da26bcf00f9742\Setup.exendp462-kb3151802-web (1).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup Installer
Version:
14.6.1590.0 built by: NETFXREL2
Modules
Images
c:\e36cc996c0da26bcf00f9742\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
256
Read events
256
Write events
0
Delete events
0

Modification events

No data
Executable files
29
Suspicious files
0
Text files
77
Unknown types
0

Dropped files

PID
Process
Filename
Type
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Setup.icoimage
MD5:6125F32AA97772AFDFF2649BD403419B
SHA256:A0C7B4B17A69775E1D94123DFCEEC824744901D55B463BA9DCA9301088F12EA5
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate4.icoimage
MD5:267B198FEF022D3B1D44CCA7FE589373
SHA256:303989B692A57FE34B47BB2F926B91AC605F288AE6C9479B33EAF15A14EB33AC
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate3.icoimage
MD5:0ADE6BE0DF29400E5534AA71ABFA03F6
SHA256:C2F6FAA18B16F728AE5536D5992CC76A4B83530A1EA74B9D11BEBDF871CF3B4E
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate2.icoimage
MD5:F824905E5501603E6720B784ADD71BDD
SHA256:D15A6F1EEFEFE4F9CD51B7B22E9C7B07C7ACAD72FD53E5F277E6D4E0976036C3
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Print.icoimage
MD5:D39BAD9DDA7B91613CB29B6BD55F0901
SHA256:D80FFEB020927F047C11FC4D9F34F985E0C7E5DFEA9FB23F2BC134874070E4E6
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate1.icoimage
MD5:9B70C7FA81DCA6D3B992037D0C251D92
SHA256:18226B9D56D2B1C070A2C606428892773CB00B5B4B95397E79D01DE26685CCD4
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\DisplayIcon.icoimage
MD5:F9657D290048E169FFABBBB9C7412BE0
SHA256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\SplashScreen.bmpimage
MD5:BC32088BFAA1C76BA4B56639A2DEC592
SHA256:B05141DBC71669A7872A8E735E5E43A7F9713D4363B7A97543E1E05DCD7470A7
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate9.icoimage
MD5:8853DA1F831CAE28E59D45F5E51885AC
SHA256:0203C7D678464641C016DC3D658ABA0A68F20B9A141D6E3EE1820C5B8B6401DB
896ndp462-kb3151802-web (1).exeC:\e36cc996c0da26bcf00f9742\Graphics\Rotate5.icoimage
MD5:25F0D572761CB610BDAD6DD980C46CC7
SHA256:CE2AFC0AA52B3D459D6D8D7C551F7B8FBF323E2260326908C37A13F21FEE423E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
24
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4620
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7620
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7620
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4620
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4620
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7620
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.2
  • 40.126.31.73
  • 40.126.31.0
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info