File name:

Virus.exe

Full analysis: https://app.any.run/tasks/8cdafaa6-8069-4d7c-9180-cae4b56b91d9
Verdict: Malicious activity
Analysis date: May 12, 2021, 17:13:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E6C6421352A2D75168ACCC64951C019

SHA1:

3B92006057B7B89AF075B1FB9D66B9254D308613

SHA256:

846A61ED050B4348CC0D604441B41EEEC25CF7A7A473BF9BC6AFCFBF3523614E

SSDEEP:

98304:dY8SZ9I+ESlKlFCJzS/fkPieDqqH2oy4jlkPch0vH3C0ht5fDC3jKPsKgLnhUOOO:dxSjI+E2CFCMwie80jlkEq/yuDC3jvJf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Virus.exe (PID: 1860)
    • Application was dropped or rewritten from another process

      • Windows10UpgraderApp.exe (PID: 2380)
      • Windows10UpgraderApp.exe (PID: 4056)
      • Windows10UpgraderApp.exe (PID: 3660)
      • Windows10UpgraderApp.exe (PID: 3568)
      • Windows10UpgraderApp.exe (PID: 3936)
    • Loads dropped or rewritten executable

      • Windows10UpgraderApp.exe (PID: 2380)
      • Windows10UpgraderApp.exe (PID: 3660)
      • Windows10UpgraderApp.exe (PID: 3568)
    • Changes settings of System certificates

      • Windows10UpgraderApp.exe (PID: 2380)
  • SUSPICIOUS

    • Creates files in the program directory

      • Virus.exe (PID: 1860)
    • Creates files in the Windows directory

      • Virus.exe (PID: 1860)
      • Windows10UpgraderApp.exe (PID: 2380)
      • Windows10UpgraderApp.exe (PID: 3660)
    • Creates a software uninstall entry

      • Virus.exe (PID: 1860)
    • Reads internet explorer settings

      • Windows10UpgraderApp.exe (PID: 2380)
      • Windows10UpgraderApp.exe (PID: 3660)
    • Drops a file with too old compile date

      • Virus.exe (PID: 1860)
    • Adds / modifies Windows certificates

      • Windows10UpgraderApp.exe (PID: 2380)
    • Executable content was dropped or overwritten

      • Virus.exe (PID: 1860)
    • Drops a file that was compiled in debug mode

      • Virus.exe (PID: 1860)
    • Low-level read access rights to disk partition

      • Windows10UpgraderApp.exe (PID: 3660)
  • INFO

    • Reads settings of System Certificates

      • Windows10UpgraderApp.exe (PID: 2380)
      • Windows10UpgraderApp.exe (PID: 3660)
    • Manual execution by user

      • taskmgr.exe (PID: 3496)
      • Windows10UpgraderApp.exe (PID: 4056)
      • Windows10UpgraderApp.exe (PID: 3660)
      • Windows10UpgraderApp.exe (PID: 3936)
      • Windows10UpgraderApp.exe (PID: 3568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

ProductVersion: 1.4.9200.23258
FileVersion: 1.4.9200.23258
ProductName: Windows 10 Update Assistant
OriginalFileName: Windows10Upgrader.exe
LegalCopyright: Copyright © Microsoft Corporation. All rights reserved.
InternalName: Windows10Upgrader.exe
FileDescription: مساعد تحديث Windows 10
CompanyName: Microsoft Corporation
CharacterSet: Unicode
LanguageCode: Arabic
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.4.9200.23258
FileVersionNumber: 1.4.9200.23258
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: 6.2
OSVersion: 6.2
EntryPoint: 0x4f794
UninitializedDataSize: -
InitializedDataSize: 169984
CodeSize: 438784
LinkerVersion: 10.1
PEType: PE32
TimeStamp: 2020:12:10 17:29:41+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 10-Dec-2020 16:29:41
Detected languages:
  • Arabic - Saudi Arabia
  • Bulgarian - Bulgaria
  • Chinese - Hong Kong SAR
  • Chinese - PRC
  • Chinese - Taiwan
  • Croatian - Croatia
  • Czech - Czech Republic
  • Danish - Denmark
  • Dutch - Netherlands
  • English - United Kingdom
  • English - United States
  • Estonian - Estonia
  • Finnish - Finland
  • French - France
  • German - Germany
  • Greek - Greece
  • Hebrew - Israel
  • Hungarian - Hungary
  • Italian - Italy
  • Japanese - Japan
  • Korean - Korea
  • Latvian - Latvia
  • Lithuanian - Lithuania
  • Norwegian - Norway (Bokmal)
  • Polish - Poland
  • Portuguese - Brazil
  • Portuguese - Portugal
  • Romanian - Romania
  • Russian - Russia
  • Serbian - Serbia (Latin)
  • Slovak - Slovakia
  • Slovenian - Slovenia
  • Spanish - Spain (International sort)
  • Swedish - Sweden
  • Thai - Thailand
  • Turkish - Turkey
  • Ukrainian - Ukraine
Debug artifacts:
  • upgraderstub.pdb
CompanyName: Microsoft Corporation
FileDescription: Asistente para actualización a Windows 10
InternalName: Windows10Upgrader.exe
LegalCopyright: Copyright © Microsoft Corporation. Todos los derechos reservados.
OriginalFilename: Windows10Upgrader.exe
ProductName: Asistente para actualización a Windows 10
FileVersion: 1.4.9200.23258
ProductVersion: 1.4.9200.23258

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 10-Dec-2020 16:29:41
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0006B1D4
0x0006B200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.5923
.data
0x0006D000
0x00002074
0x00000C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.43218
.idata
0x00070000
0x000019AC
0x00001A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.61615
.boxloadV
0x00072000
0x00000056
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
0.942162
.rsrc
0x00073000
0x00022000
0x00021800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.31594
.reloc
0x00095000
0x00005696
0x00005800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
5.05445

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.9036
1900
Latin 1 / Western European
English - United States
RT_MANIFEST
2
0.903812
36
Latin 1 / Western European
Chinese - Hong Kong SAR
RT_STRING
3
3.13127
1162
Latin 1 / Western European
Spanish - Spain (International sort)
RT_STRING
4
2.30706
80
Latin 1 / Western European
Lithuanian - Lithuania
RT_STRING
5
4.59938
1384
Latin 1 / Western European
English - United States
RT_ICON
6
2.79537
16936
Latin 1 / Western European
English - United States
RT_ICON
7
3.12441
9640
Latin 1 / Western European
English - United States
RT_ICON
8
3.00143
6760
Latin 1 / Western European
English - United States
RT_ICON
9
3.41612
4264
Latin 1 / Western European
English - United States
RT_ICON
10
3.35245
2440
Latin 1 / Western European
English - United States
RT_ICON

Imports

ADVAPI32.dll
Cabinet.dll
KERNEL32.dll
PSAPI.DLL
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
msvcrt.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start virus.exe windows10upgraderapp.exe taskmgr.exe no specs windows10upgraderapp.exe no specs windows10upgraderapp.exe windows10upgraderapp.exe no specs windows10upgraderapp.exe virus.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1860"C:\Users\admin\AppData\Local\Temp\Virus.exe" C:\Users\admin\AppData\Local\Temp\Virus.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
0
Version:
1.4.9200.23258
Modules
Images
c:\users\admin\appdata\local\temp\virus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2380"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exe
Virus.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
1
Version:
1.4.9200.23258
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3496"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3568"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
0
Version:
1.4.9200.23258
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3660"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
1
Version:
1.4.9200.23258
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3700"C:\Users\admin\AppData\Local\Temp\Virus.exe" C:\Users\admin\AppData\Local\Temp\Virus.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows 10 Update Assistant
Exit code:
3221226540
Version:
1.4.9200.23258
Modules
Images
c:\users\admin\appdata\local\temp\virus.exe
c:\systemroot\system32\ntdll.dll
3936"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows 10 Update Assistant
Exit code:
3221226540
Version:
1.4.9200.23258
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
4056"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows 10 Update Assistant
Exit code:
3221226540
Version:
1.4.9200.23258
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
Total events
494
Read events
434
Write events
60
Delete events
0

Modification events

(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:Publisher
Value:
Microsoft Corporation
(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayName
Value:
Windows 10 Update Assistant
(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayIcon
Value:
"C:\Windows10Upgrade\Windows10UpgraderApp.exe"
(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayVersion
Value:
1.4.9200.23258
(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:UninstallString
Value:
"C:\Windows10Upgrade\Windows10UpgraderApp.exe" /Uninstall
(PID) Process:(1860) Virus.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:EstimatedSize
Value:
5120
(PID) Process:(1860) Virus.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1860) Virus.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2380) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2380) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
54
Suspicious files
2
Text files
166
Unknown types
8

Dropped files

PID
Process
Filename
Type
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\appraiserxp.dllexecutable
MD5:
SHA256:
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\GetCurrentDeploy.dllexecutable
MD5:
SHA256:
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\Windows10UpgraderApp.exeexecutable
MD5:
SHA256:
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\ESDHelper.dllexecutable
MD5:
SHA256:
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\DW20.EXEexecutable
MD5:1F72306A11D4DE3233EA19250469A9EE
SHA256:226210E3DFF8FB5691F17BCDE628A08953D422D0D9CDEB16EFC02F3A4D5AF00D
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\DWTRIG20.EXEexecutable
MD5:0AE71EC7B6DD4A4EB8CCD133542C52C3
SHA256:3190181C570F50A2FB0D157985AFF0F6968C0A4C64A58FB80586DD4E138F6B56
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\cosquery.dllexecutable
MD5:F6F6913BE848F72FF7D012FE77AB07EE
SHA256:BB186553C6E7E76DE7A45773770C59833DCDF4F74B94F8F47C2514057418450C
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\GatherOSState.EXEexecutable
MD5:C8F114021CBABFB4BF0E0EA27B6DA833
SHA256:763420C1E090636450180B3ADF76101BDAC131A26D47214D635AB17A472453D8
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\downloader.dllexecutable
MD5:
SHA256:
1860Virus.exeC:\Users\admin\AppData\Local\Temp\WXUCA80.tmp\bootsect.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
9
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2380
Windows10UpgraderApp.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3660
Windows10UpgraderApp.exe
GET
2.16.107.8:80
http://dl.delivery.mp.microsoft.com/filestreamingservice/files/acf797e6-0a4a-485d-b157-c5e268339896/19042.631.201119-0144.20h2_release_svc_refresh_CLIENTCONSUMER_RET_x86FRE_en-us.esd
unknown
whitelisted
2380
Windows10UpgraderApp.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2380
Windows10UpgraderApp.exe
23.79.157.13:443
go.microsoft.com
Akamai International B.V.
US
malicious
2380
Windows10UpgraderApp.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2380
Windows10UpgraderApp.exe
2.18.233.19:443
download.microsoft.com
Akamai International B.V.
whitelisted
3660
Windows10UpgraderApp.exe
23.79.157.13:443
go.microsoft.com
Akamai International B.V.
US
malicious
3660
Windows10UpgraderApp.exe
2.18.233.19:443
download.microsoft.com
Akamai International B.V.
whitelisted
3660
Windows10UpgraderApp.exe
2.16.107.8:80
dl.delivery.mp.microsoft.com
Akamai International B.V.
suspicious
3660
Windows10UpgraderApp.exe
184.24.20.248:443
go.microsoft.com
Akamai Technologies, Inc.
US
suspicious
192.168.100.131:137
malicious

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.79.157.13
  • 184.24.20.248
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
download.microsoft.com
  • 2.18.233.19
whitelisted
dl.delivery.mp.microsoft.com
  • 2.16.107.8
  • 2.16.107.32
whitelisted

Threats

No threats detected
No debug info