File name:

CDKDriveWebStart.exe

Full analysis: https://app.any.run/tasks/fa319725-c1de-49b4-85fb-0fcc734f94a8
Verdict: Malicious activity
Analysis date: July 18, 2024, 18:32:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E8649773B65FA62638494F701123CE12

SHA1:

342194C4E5775C17F82D4BD9832AF9E6822EF6EE

SHA256:

6FA7D6A68CE2BC4A741305AD5D4EB95778022372A7E2719B2C9206312C1F1A41

SSDEEP:

49152:+7HecD4dnbibBla6LajsbmLApne0Fop4R2uXB3iyLT/ex4XrL7P42DpJXWZn80cx:m+cD4dnsLaIkWnXFopLQ3iUrex4vkY7H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CDKDriveWebStart.exe (PID: 7976)
      • CDKDriveWebStart.exe (PID: 4504)
      • CDKDriveWebStart.tmp (PID: 8156)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CDKDriveWebStart.exe (PID: 7976)
      • CDKDriveWebStart.exe (PID: 4504)
      • CDKDriveWebStart.tmp (PID: 8156)
    • Reads security settings of Internet Explorer

      • CDKDriveWebStart.tmp (PID: 7252)
    • Reads the date of Windows installation

      • CDKDriveWebStart.tmp (PID: 7252)
    • Reads the Windows owner or organization settings

      • CDKDriveWebStart.tmp (PID: 8156)
  • INFO

    • Checks supported languages

      • CDKDriveWebStart.tmp (PID: 7252)
      • CDKDriveWebStart.exe (PID: 7976)
      • CDKDriveWebStart.exe (PID: 4504)
      • CDKDriveWebStart.tmp (PID: 8156)
      • CDK Drive WebStart.exe (PID: 480)
    • Reads the computer name

      • CDKDriveWebStart.tmp (PID: 7252)
      • CDKDriveWebStart.tmp (PID: 8156)
      • CDK Drive WebStart.exe (PID: 480)
    • Process checks computer location settings

      • CDKDriveWebStart.tmp (PID: 7252)
    • Create files in a temporary directory

      • CDKDriveWebStart.exe (PID: 7976)
      • CDKDriveWebStart.exe (PID: 4504)
      • CDKDriveWebStart.tmp (PID: 8156)
    • Creates files in the program directory

      • CDKDriveWebStart.tmp (PID: 8156)
    • Creates a software uninstall entry

      • CDKDriveWebStart.tmp (PID: 8156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.0.0
ProductVersionNumber: 1.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: CDK Global, LLC
FileDescription: CDK Drive WebStart
FileVersion: 1.4.0
LegalCopyright: CDK Global, LLC
OriginalFileName:
ProductName: CDK Drive WebStart
ProductVersion: 1.4.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cdkdrivewebstart.exe cdkdrivewebstart.tmp no specs cdkdrivewebstart.exe cdkdrivewebstart.tmp cdk drive webstart.exe no specs conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
480"C:\Program Files (x86)\CDK\CDKDriveWebStart\CDK Drive WebStart.exe"C:\Program Files (x86)\CDK\CDKDriveWebStart\CDK Drive WebStart.exeCDKDriveWebStart.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
CDK Drive WebStart
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\program files (x86)\cdk\cdkdrivewebstart\cdk drive webstart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4504"C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe" /SPAWNWND=$30248 /NOTIFYWND=$903D2 C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe
CDKDriveWebStart.tmp
User:
admin
Company:
CDK Global, LLC
Integrity Level:
HIGH
Description:
CDK Drive WebStart
Exit code:
0
Version:
1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\cdkdrivewebstart.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
5520\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCDK Drive WebStart.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7104C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7252"C:\Users\admin\AppData\Local\Temp\is-5EOA4.tmp\CDKDriveWebStart.tmp" /SL5="$903D2,844372,832512,C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe" C:\Users\admin\AppData\Local\Temp\is-5EOA4.tmp\CDKDriveWebStart.tmpCDKDriveWebStart.exe
User:
admin
Company:
CDK Global, LLC
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5eoa4.tmp\cdkdrivewebstart.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
7976"C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe" C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe
explorer.exe
User:
admin
Company:
CDK Global, LLC
Integrity Level:
MEDIUM
Description:
CDK Drive WebStart
Exit code:
0
Version:
1.4.0
Modules
Images
c:\users\admin\appdata\local\temp\cdkdrivewebstart.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
8156"C:\Users\admin\AppData\Local\Temp\is-APK8N.tmp\CDKDriveWebStart.tmp" /SL5="$40252,844372,832512,C:\Users\admin\AppData\Local\Temp\CDKDriveWebStart.exe" /SPAWNWND=$30248 /NOTIFYWND=$903D2 C:\Users\admin\AppData\Local\Temp\is-APK8N.tmp\CDKDriveWebStart.tmp
CDKDriveWebStart.exe
User:
admin
Company:
CDK Global, LLC
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-apk8n.tmp\cdkdrivewebstart.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
4 057
Read events
4 028
Write events
23
Delete events
6

Modification events

(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
DC1F00001FAC3CD240D9DA01
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
151C547F0A3B07543F88FA92EB83E31B43267E86DC4595EA339F0728B69ADB63
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files (x86)\CDK\CDKDriveWebStart\CDK Drive WebStart.exe
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
DD43D0BDE8411FA03DD8B6BA8CF712BEA07BEA0EB4BA6AB300189C5E5FEE2AFE
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B5302D2C-A1BE-44DD-BA41-60970B2BC054}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B5302D2C-A1BE-44DD-BA41-60970B2BC054}_is1
Operation:writeName:Inno Setup: App Path
Value:
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B5302D2C-A1BE-44DD-BA41-60970B2BC054}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
CDK Drive WebStart
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B5302D2C-A1BE-44DD-BA41-60970B2BC054}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(8156) CDKDriveWebStart.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B5302D2C-A1BE-44DD-BA41-60970B2BC054}_is1
Operation:writeName:Inno Setup: Language
Value:
english
Executable files
7
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7976CDKDriveWebStart.exeC:\Users\admin\AppData\Local\Temp\is-5EOA4.tmp\CDKDriveWebStart.tmpexecutable
MD5:B750F97619F45F21935E02A9679823E6
SHA256:F2EA1F747F127D39259FF1641E5057EBE2F58B6CB28B8822289A47810346CC9D
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\is-NCEE6.tmpexecutable
MD5:B7739D218E705638636CABDF7F6611E1
SHA256:EE0EB69CB3BE92E614A4F0284215626BEC852191565AA900E36F8DEC2700D523
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\is-A4ASA.tmpexecutable
MD5:994EB590211D1415460569927EC305D0
SHA256:A4149709EFF2724C64B1B2C5990E6B2BDC9D3818B49DFF7CF69A55DE66E18327
8156CDKDriveWebStart.tmpC:\Users\admin\AppData\Local\Temp\is-0F73J.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4504CDKDriveWebStart.exeC:\Users\admin\AppData\Local\Temp\is-APK8N.tmp\CDKDriveWebStart.tmpexecutable
MD5:B750F97619F45F21935E02A9679823E6
SHA256:F2EA1F747F127D39259FF1641E5057EBE2F58B6CB28B8822289A47810346CC9D
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\unins000.exeexecutable
MD5:B7739D218E705638636CABDF7F6611E1
SHA256:EE0EB69CB3BE92E614A4F0284215626BEC852191565AA900E36F8DEC2700D523
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\CDK Drive WebStart.exeexecutable
MD5:994EB590211D1415460569927EC305D0
SHA256:A4149709EFF2724C64B1B2C5990E6B2BDC9D3818B49DFF7CF69A55DE66E18327
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\unins000.datbinary
MD5:53FCE09F766D2EA63B0EA6E9C11CBE06
SHA256:BBB7A602BE2E87C63B193236B1AF5EBD34FE70FE51A2E85BF4DA5A36718B96CD
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\is-DPO1A.tmpxml
MD5:DCCD44FB11B8E4EBDFB822E809A54B6F
SHA256:6862B25736259F7BFD344E43EEA10A703885BE381EEE2A745CEB12916B01A158
8156CDKDriveWebStart.tmpC:\Program Files (x86)\CDK\CDKDriveWebStart\CDK Drive WebStart.exe.configxml
MD5:DCCD44FB11B8E4EBDFB822E809A54B6F
SHA256:6862B25736259F7BFD344E43EEA10A703885BE381EEE2A745CEB12916B01A158
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5968
backgroundTaskHost.exe
20.86.201.138:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4716
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7856
svchost.exe
4.208.221.206:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
5968
backgroundTaskHost.exe
20.223.35.26:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2760
svchost.exe
40.115.3.253:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3548
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4716
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
arc.msn.com
  • 20.86.201.138
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.64
  • 40.126.31.71
whitelisted
google.com
  • 142.250.186.46
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.185
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.144
  • 2.23.209.189
  • 2.23.209.141
  • 2.23.209.135
  • 2.23.209.140
whitelisted

Threats

No threats detected
No debug info