File name:

update.exe

Full analysis: https://app.any.run/tasks/ffcd8583-3fa6-4d45-8834-77d96d48f2e4
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 11, 2024, 06:14:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

AA4D9605CD145167B687CE861342A7DE

SHA1:

04E144C7A4B3C197709E1D2BF950FD8F6C810C68

SHA256:

7BE49F2D295ADF8228723D4DE51753DCB4637CE011196280334FC21F964679BF

SSDEEP:

384:jXGHDI26DHpZPxQt/PaLDiPY/w8mkgHCAQJ99+:jXKDI2I/BWOX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • update.exe (PID: 4444)
      • Digital Unlocker.exe (PID: 7388)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • ShellExperienceHost.exe (PID: 8880)
      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker.exe (PID: 8556)
      • KsDumper11.exe (PID: 7436)
      • Digital Unlocker.exe (PID: 2388)
    • Executable content was dropped or overwritten

      • update.exe (PID: 4444)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8420)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • KsDumper11.exe (PID: 7436)
      • kdu.exe (PID: 6648)
      • kdu.exe (PID: 8884)
      • Digital Unlocker.exe (PID: 9104)
    • Process drops legitimate windows executable

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8420)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • msiexec.exe (PID: 8712)
      • Digital Unlocker.exe (PID: 9104)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
    • Searches for installed software

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
    • Starts itself from another location

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 8712)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 8712)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 8712)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 8712)
    • Starts CMD.EXE for commands execution

      • KsDumper11.exe (PID: 7436)
    • Drops a system driver (possible attempt to evade defenses)

      • kdu.exe (PID: 6648)
      • KsDumper11.exe (PID: 7436)
      • kdu.exe (PID: 8884)
    • Creates or modifies Windows services

      • kdu.exe (PID: 6648)
      • kdu.exe (PID: 8884)
    • Creates files in the driver directory

      • kdu.exe (PID: 6648)
      • kdu.exe (PID: 8884)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 4528)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 2360)
      • cmd.exe (PID: 5916)
    • Potential Corporate Privacy Violation

      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker.exe (PID: 8556)
      • Digital Unlocker.exe (PID: 2388)
    • Executes application which crashes

      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker_dump.exe (PID: 3276)
    • Process requests binary or script from the Internet

      • Digital Unlocker.exe (PID: 2388)
  • INFO

    • Checks supported languages

      • update.exe (PID: 4444)
      • identity_helper.exe (PID: 8368)
      • Digital Unlocker.exe (PID: 7388)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8420)
      • msiexec.exe (PID: 8712)
      • msiexec.exe (PID: 8784)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • msiexec.exe (PID: 1148)
      • msiexec.exe (PID: 6904)
      • KsDumper11.exe (PID: 7436)
      • msiexec.exe (PID: 8472)
      • kdu.exe (PID: 8200)
      • kdu.exe (PID: 6648)
      • kdu.exe (PID: 8884)
      • Digital Unlocker.exe (PID: 9104)
      • ShellExperienceHost.exe (PID: 8880)
      • Digital Unlocker.exe (PID: 8556)
      • Digital Unlocker_dump.exe (PID: 3276)
      • Digital Unlocker.exe (PID: 2388)
    • Disables trace logs

      • update.exe (PID: 4444)
    • Checks proxy server information

      • update.exe (PID: 4444)
      • Digital Unlocker.exe (PID: 9104)
      • WerFault.exe (PID: 9068)
      • Digital Unlocker.exe (PID: 8556)
      • WerFault.exe (PID: 7580)
      • Digital Unlocker.exe (PID: 2388)
    • Reads the machine GUID from the registry

      • update.exe (PID: 4444)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • msiexec.exe (PID: 8712)
      • kdu.exe (PID: 6648)
      • kdu.exe (PID: 8884)
      • KsDumper11.exe (PID: 7436)
    • Reads the computer name

      • update.exe (PID: 4444)
      • Digital Unlocker.exe (PID: 7388)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • identity_helper.exe (PID: 8368)
      • msiexec.exe (PID: 8712)
      • msiexec.exe (PID: 8784)
      • msiexec.exe (PID: 1148)
      • msiexec.exe (PID: 6904)
      • msiexec.exe (PID: 8472)
      • KsDumper11.exe (PID: 7436)
      • Digital Unlocker.exe (PID: 9104)
      • ShellExperienceHost.exe (PID: 8880)
      • Digital Unlocker.exe (PID: 8556)
      • Digital Unlocker.exe (PID: 2388)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
    • Create files in a temporary directory

      • update.exe (PID: 4444)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8420)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker.exe (PID: 8556)
      • Digital Unlocker.exe (PID: 2388)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7812)
      • msiexec.exe (PID: 8712)
      • WinRAR.exe (PID: 9088)
      • msedge.exe (PID: 7044)
    • Manual execution by a user

      • firefox.exe (PID: 1184)
      • msedge.exe (PID: 7812)
      • WinRAR.exe (PID: 9088)
      • KsDumper11.exe (PID: 7600)
      • KsDumper11.exe (PID: 7436)
      • Digital Unlocker.exe (PID: 4544)
      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker.exe (PID: 8556)
      • Digital Unlocker.exe (PID: 8736)
      • Digital Unlocker.exe (PID: 4160)
      • Digital Unlocker_dump.exe (PID: 7044)
      • Digital Unlocker_dump.exe (PID: 3276)
      • Digital Unlocker.exe (PID: 2388)
    • Application launched itself

      • firefox.exe (PID: 1116)
      • firefox.exe (PID: 1184)
      • msedge.exe (PID: 7560)
      • msedge.exe (PID: 7812)
    • The process uses the downloaded file

      • update.exe (PID: 4444)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • msedge.exe (PID: 9196)
      • msedge.exe (PID: 7812)
      • firefox.exe (PID: 1116)
      • WinRAR.exe (PID: 9088)
    • Process checks computer location settings

      • update.exe (PID: 4444)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8504)
      • Digital Unlocker.exe (PID: 2388)
    • Sends debugging messages

      • Digital Unlocker.exe (PID: 7388)
      • KsDumper11.exe (PID: 7436)
      • Digital Unlocker.exe (PID: 9104)
      • Digital Unlocker.exe (PID: 8556)
      • ShellExperienceHost.exe (PID: 8880)
      • Digital Unlocker.exe (PID: 2388)
    • Reads Environment values

      • identity_helper.exe (PID: 8368)
    • Creates files in the program directory

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 8576)
      • Digital Unlocker.exe (PID: 9104)
    • Reads the software policy settings

      • msiexec.exe (PID: 8712)
      • WerFault.exe (PID: 9068)
      • WerFault.exe (PID: 7580)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 8712)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 9068)
      • WerFault.exe (PID: 7580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2050:08:22 15:36:20+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 11264
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x4a0e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Updater_for_DigitalUnlocker
FileVersion: 1.0.0.0
InternalName: update.exe
LegalCopyright: Copyright © 2023
LegalTrademarks: -
OriginalFileName: update.exe
ProductName: Updater_for_DigitalUnlocker
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
262
Monitored processes
116
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start update.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs digital unlocker.exe no specs digital unlocker.exe firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs firefox.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs windowsdesktop-runtime-6.0.33-win-x64.exe windowsdesktop-runtime-6.0.33-win-x64.exe windowsdesktop-runtime-6.0.33-win-x64.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs winrar.exe ksdumper11.exe no specs ksdumper11.exe kdu.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs kdu.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs kdu.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs digital unlocker.exe no specs digital unlocker.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs shellexperiencehost.exe no specs msedge.exe no specs werfault.exe digital unlocker.exe no specs digital unlocker.exe msedge.exe no specs digital unlocker_dump.exe no specs digital unlocker_dump.exe werfault.exe digital unlocker.exe no specs digital unlocker.exe

Process information

PID
CMD
Path
Indicators
Parent process
32"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5816 -childID 5 -isForBrowser -prefsHandle 5924 -prefMapHandle 5468 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e19d5e85-5ab1-440e-a60a-3b82aabc0d55} 1116 "\\.\pipe\gecko-crash-server-pipe.1116" 18fe32934d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
488"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=5636 --field-trial-handle=2332,i,4503227244153261016,15390281048801551390,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
780"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4588 -childID 2 -isForBrowser -prefsHandle 4576 -prefMapHandle 1552 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {aebfebc5-28de-45cc-9200-a8d3ee931aef} 1116 "\\.\pipe\gecko-crash-server-pipe.1116" 18fdf67ebd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
872"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5200 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5220 -prefMapHandle 5208 -prefsLen 36339 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7fe69808-9f3d-4034-83ba-afc1eed135a4} 1116 "\\.\pipe\gecko-crash-server-pipe.1116" 18fe0689710 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1116"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1148C:\Windows\syswow64\MsiExec.exe -Embedding D37BABEEFEDD6A729C3A6F199344E310C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1184"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
1280"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5468 -childID 3 -isForBrowser -prefsHandle 5476 -prefMapHandle 5472 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {6eb2b58a-2e8c-4ca2-88ca-7bc9107914d2} 1116 "\\.\pipe\gecko-crash-server-pipe.1116" 18fde4b0bd0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=7784 --field-trial-handle=2332,i,4503227244153261016,15390281048801551390,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2360"cmd.exe" /c taskkill /IM "kdu.exe"C:\Windows\System32\cmd.exeKsDumper11.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
60 382
Read events
59 305
Write events
1 023
Delete events
54

Modification events

(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4444) update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\update_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
597
Suspicious files
693
Text files
191
Unknown types
7

Dropped files

PID
Process
Filename
Type
1116firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.binbinary
MD5:297E88D7CEB26E549254EC875649F4EB
SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journalbinary
MD5:D817E87AAAD26AE89D2ADE4765C95F2A
SHA256:4F3E2B9A000D5B1107372922E66919DC1B628F51DCF77C32751D9B6D63083E27
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:7A97B8DBC4F98D175F958C00F463A52A
SHA256:92074D2ED1AA1FD621287E35DB9EF1AE3DC04777EFAE5F09E7A3B4534C201548
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:AF26E0AF77A2D6C69F95FDF2C618A949
SHA256:3120375B93BA836BCB17C24A5CA76AEA512C15A334A17DA0A6AF250F4B0D0E1A
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:7A97B8DBC4F98D175F958C00F463A52A
SHA256:92074D2ED1AA1FD621287E35DB9EF1AE3DC04777EFAE5F09E7A3B4534C201548
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
1116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
101
TCP/UDP connections
188
DNS requests
229
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4444
update.exe
GET
200
188.114.97.3:80
http://dev.codingbot.kr/unlocker/latestVersion.txt
unknown
whitelisted
4444
update.exe
GET
200
188.114.97.3:80
http://dev.codingbot.kr/unlocker/240831.zip
unknown
whitelisted
1064
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1116
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
1116
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
1116
firefox.exe
POST
200
184.24.77.79:80
http://r10.o.lencr.org/
unknown
unknown
1116
firefox.exe
POST
200
142.250.186.131:80
http://o.pki.goog/s/wr3/XjA
unknown
unknown
1116
firefox.exe
POST
200
184.24.77.79:80
http://r10.o.lencr.org/
unknown
unknown
1116
firefox.exe
POST
200
184.24.77.79:80
http://r10.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
7056
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5644
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4444
update.exe
188.114.97.3:80
dev.codingbot.kr
CLOUDFLARENET
NL
unknown
1064
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1064
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.110
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.115.3.253
whitelisted
dev.codingbot.kr
  • 188.114.97.3
  • 188.114.96.3
unknown
login.live.com
  • 40.126.31.73
  • 20.190.159.2
  • 20.190.159.73
  • 20.190.159.71
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.67
  • 40.126.31.69
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 93.184.215.14
whitelisted

Threats

PID
Process
Class
Message
9104
Digital Unlocker.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
9104
Digital Unlocker.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
8556
Digital Unlocker.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
8556
Digital Unlocker.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2388
Digital Unlocker.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2388
Digital Unlocker.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
7 ETPRO signatures available at the full report
Process
Message
Digital Unlocker.exe
You must install .NET to run this application. App: C:\Users\admin\AppData\Local\Temp\Digital Unlocker.exe Architecture: x64 App host version: 6.0.30 .NET location: Not found Learn about runtime installation: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win10-x64&apphost_version=6.0.30
KsDumper11.exe
{X=0,Y=0,Width=39,Height=39}
KsDumper11.exe
{X=0,Y=0,Width=39,Height=39}
KsDumper11.exe
{X=0,Y=0,Width=39,Height=39}
Digital Unlocker.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 9104. Message ID: [0x2509].
Digital Unlocker.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 8556. Message ID: [0x2509].
Digital Unlocker.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 2388. Message ID: [0x2509].