File name:

logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe

Full analysis: https://app.any.run/tasks/ddacd109-d009-477b-9db0-8cff5d8d8581
Verdict: Malicious activity
Analysis date: April 07, 2025, 15:13:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

3D9D2A24671C63F167E1E42B1A86E6E3

SHA1:

79DDC5A4302B371ECD6518EE59B72AED923D71C8

SHA256:

706E26CD388F76001ED0C33C5748BB6D42699EF1CC8FE0D7D42CBA8DD7907C12

SSDEEP:

98304:qQAbuTH9zSQgZ5LdRdwaQe/HZjsTAc+LeCvce/Unba+O+CB3jD9hl8X:iU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • Setup.exe (PID: 744)
      • MSetup.exe (PID: 2108)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • Setup.exe (PID: 744)
      • MSetup.exe (PID: 2108)
    • Executable content was dropped or overwritten

      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
    • Reads Internet Explorer settings

      • MSetup.exe (PID: 2108)
    • Reads Microsoft Outlook installation path

      • MSetup.exe (PID: 2108)
  • INFO

    • Checks supported languages

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • Setup.exe (PID: 744)
      • MSetup.exe (PID: 2108)
    • Reads the computer name

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • Setup.exe (PID: 744)
      • MSetup.exe (PID: 2108)
    • The sample compiled with english language support

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
    • Reads the machine GUID from the registry

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
    • Reads the software policy settings

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • slui.exe (PID: 7408)
    • Checks proxy server information

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • slui.exe (PID: 7408)
      • MSetup.exe (PID: 2108)
    • Process checks computer location settings

      • logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe (PID: 7604)
      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • Setup.exe (PID: 744)
    • Create files in a temporary directory

      • logitech-webcam-software-2.80.853.0-installer.exe (PID: 5756)
      • MSetup.exe (PID: 2108)
    • Reads CPU info

      • MSetup.exe (PID: 2108)
    • Creates files or folders in the user directory

      • MSetup.exe (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:23 14:47:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 2093056
InitializedDataSize: 2296832
UninitializedDataSize: -
EntryPoint: 0x1b75bc
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.9.0
ProductVersionNumber: 0.0.9.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Softonic
FileDescription: Softonic
FileVersion: 0.0.9.0
LegalCopyright: (c) Softonic. All rights reserved.
ProductName: Softonic
ProductVersion: 0.0.9.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start logitech-webcam-software-2.80.853.0-installer_x8g8-r2.exe sppextcomobj.exe no specs slui.exe no specs logitech-webcam-software-2.80.853.0-installer.exe slui.exe setup.exe no specs msetup.exe no specs logitech-webcam-software-2.80.853.0-installer_x8g8-r2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
744"C:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\setup.exe" /smartcheck C:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\Setup.exelogitech-webcam-software-2.80.853.0-installer.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
HIGH
Description:
Logitech Installer
Version:
2.19.0.11
Modules
Images
c:\users\admin\appdata\local\temp\logitech_webcam_2.80.853.0\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2108"C:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\MSetup.exe" /smartcheck C:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\MSetup.exeSetup.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
HIGH
Description:
Logitech Installer
Version:
2.19.0.11
Modules
Images
c:\users\admin\appdata\local\temp\logitech_webcam_2.80.853.0\msetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
5756"C:\Users\admin\Downloads\logitech-webcam-software-2.80.853.0-installer.exe" C:\Users\admin\Downloads\logitech-webcam-software-2.80.853.0-installer.exe
logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
HIGH
Description:
Logitech Webcam Software 2.80.853.0 (ENU)
Exit code:
0
Version:
2.80.853.0.0
Modules
Images
c:\users\admin\downloads\logitech-webcam-software-2.80.853.0-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7408C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7508"C:\Users\admin\AppData\Local\Temp\logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe" C:\Users\admin\AppData\Local\Temp\logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exeexplorer.exe
User:
admin
Company:
Softonic
Integrity Level:
MEDIUM
Description:
Softonic
Exit code:
3221226540
Version:
0.0.9.0
Modules
Images
c:\users\admin\appdata\local\temp\logitech-webcam-software-2.80.853.0-installer_x8g8-r2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7604"C:\Users\admin\AppData\Local\Temp\logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe" C:\Users\admin\AppData\Local\Temp\logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe
explorer.exe
User:
admin
Company:
Softonic
Integrity Level:
HIGH
Description:
Softonic
Exit code:
0
Version:
0.0.9.0
Modules
Images
c:\users\admin\appdata\local\temp\logitech-webcam-software-2.80.853.0-installer_x8g8-r2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7616C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7664"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 390
Read events
3 378
Write events
11
Delete events
1

Modification events

(PID) Process:(5756) logitech-webcam-software-2.80.853.0-installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Logitech\QuickCam10
Operation:writeName:WebUnzipPath
Value:
C:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0
(PID) Process:(2108) MSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:{D40EB009-0499-459c-A8AF-C9C110766215}
Value:
(PID) Process:(2108) MSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2108) MSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2108) MSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2108) MSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
MSetup.exe
(PID) Process:(2108) MSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:ID
Value:
(PID) Process:(2108) MSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(2108) MSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(2108) MSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\logishrd\LWS2
Operation:writeName:languageIDTemp
Value:
1033
Executable files
29
Suspicious files
9
Text files
933
Unknown types
0

Dropped files

PID
Process
Filename
Type
7604logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exeC:\Users\admin\Downloads\logitech-webcam-software-2.80.853.0-installer.exe
MD5:
SHA256:
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\Config\lPRO564s.cfgbinary
MD5:88FAC57E89B6ADB76F19E1BBD8B268AE
SHA256:727291EA73BBA012FE9354F4FA90E9CFDD6EE98C8FBC6FC675BAC28038DFDA8F
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\LogiKey.pubbinary
MD5:859565BECF5B01298F8E8A6CBD09098C
SHA256:9FD6E50B70496ABEFD36F00E19C4ED48F2484E7045E4094010BFC204891B8150
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\MSetup.exeexecutable
MD5:F8E58AEB2ED931D4D471E761AF761292
SHA256:D8E02CDAAC34A16EE6201BF5191B21FCD49E04C952C005D2775050D2545A0C9B
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\LU\lu_logicool.exeexecutable
MD5:7A142497DECBA72B28B478E107668711
SHA256:CEF7AA6738EBC582EFCE3F9852733FC8E052809F593F33DCCC530549439B6D76
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\LWS\LauncherMain_Release_x86.msi
MD5:
SHA256:
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\Setup.exeexecutable
MD5:3FCE83869508101E94EF23BB8D028BFD
SHA256:A01AB81AF1B0D7590B5F80CE57ADCED9F159FA0ADBEEE95A19E6026A2E901D1A
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\Config\lvPRO5s.cfgbinary
MD5:80CD2ECB1EE571A52D3ABDC1F20866EB
SHA256:98EC11EE1669E19141572796A439296769A20ADB81C001824D75BF961327F8E6
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\LWS\MotionDetection_Release_x86.msi
MD5:
SHA256:
5756logitech-webcam-software-2.80.853.0-installer.exeC:\Users\admin\AppData\Local\Temp\Logitech_Webcam_2.80.853.0\LWS\PicVid_Release_x86.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
25
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1760
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1760
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5216
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7604
logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe
18.245.78.193:443
d2b97w1nkg3oze.cloudfront.net
US
whitelisted
7604
logitech-webcam-software-2.80.853.0-installer_X8g8-r2.exe
146.75.121.91:443
images.sftcdn.net
FASTLY
US
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.34
  • 2.16.164.24
  • 2.16.164.49
  • 2.16.164.120
  • 2.16.164.106
  • 2.16.164.72
whitelisted
google.com
  • 142.250.185.174
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.76
  • 20.190.160.14
  • 20.190.160.67
  • 20.190.160.17
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
d2b97w1nkg3oze.cloudfront.net
  • 18.245.78.193
  • 18.245.78.36
  • 18.245.78.84
  • 18.245.78.144
whitelisted
images.sftcdn.net
  • 146.75.121.91
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 69.192.161.161
whitelisted

Threats

No threats detected
No debug info