| File name: | WorkshopDL.2.0.4_installer.exe |
| Full analysis: | https://app.any.run/tasks/6024f3f5-4e33-43ca-a18e-c12523ef7a86 |
| Verdict: | Malicious activity |
| Analysis date: | June 15, 2025, 21:58:33 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | 53659871F7D05FC4D266F86C2F645E06 |
| SHA1: | 87DFA73CF2A158BCE3C2315DD18F3424D91DD06B |
| SHA256: | 8B179746A7FF085A7882D191C37E770AA373CD02E17EEC7244885AAADDDDFC2A |
| SSDEEP: | 98304:FXRiGUHOSZOsK1ooVE3l/LBtMF2R+bxv78LS8ntmi2jiJGwr2hVFxT4ZUSWKHQtj:wJ+JD1 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:10:20 13:41:28+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 98304 |
| InitializedDataSize: | 53248 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1288a |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.29 |
| ProductVersionNumber: | 2.0.0.29 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | - |
| FileVersion: | 2, 0, 0, 29 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| PrivateBuild: | - |
| ProductName: | WorkshopDL Install Program |
| ProductVersion: | 2, 0, 0, 29 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 640 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://steamcommunity.com/workshop/ | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | WorkshopDL.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 984 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2320,i,15678630694482255597,5886481555476479772,262144 --variations-seed-version --mojo-platform-channel-handle=2396 /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1496 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6076,i,15678630694482255597,5886481555476479772,262144 --variations-seed-version --mojo-platform-channel-handle=4296 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1704 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=1548,i,15678630694482255597,5886481555476479772,262144 --variations-seed-version --mojo-platform-channel-handle=6260 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1816 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x290,0x294,0x298,0x288,0x2a0,0x7ffc4565f208,0x7ffc4565f214,0x7ffc4565f220 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1828 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3656,i,15678630694482255597,5886481555476479772,262144 --variations-seed-version --mojo-platform-channel-handle=3000 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 2216 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://steamcommunity.com/workshop/ | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6188 | "C:\WorkshopDL\WorkshopDL.exe" | C:\WorkshopDL\WorkshopDL.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6200 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2764,i,15678630694482255597,5886481555476479772,262144 --variations-seed-version --mojo-platform-channel-handle=2780 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 6224 | "C:\Users\admin\Desktop\WorkshopDL.2.0.4_installer.exe" | C:\Users\admin\Desktop\WorkshopDL.2.0.4_installer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 2, 0, 0, 29 Modules
| |||||||||||||||
| (PID) Process: | (6224) WorkshopDL.2.0.4_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WorkshopDL |
| Operation: | write | Name: | DisplayName |
Value: WorkshopDL | |||
| (PID) Process: | (6224) WorkshopDL.2.0.4_installer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WorkshopDL |
| Operation: | write | Name: | UninstallString |
Value: C:\WorkshopDL\Uninstall.exe | |||
| (PID) Process: | (6188) WorkshopDL.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6188) WorkshopDL.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6188) WorkshopDL.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6188) WorkshopDL.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (640) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (640) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2216) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 1 | |||
| (PID) Process: | (2216) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\AdvTray.mfx | executable | |
MD5:D9FB3B5FC60D04F33FADD47837075F6B | SHA256:EAB82AB6DAE40B99D5170A003D7B406C3E362CA1372FC3567A716C1F2C0807A5 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\WorkshopDL.exe | executable | |
MD5:E42DB9EAC82BC070A001395815C690E8 | SHA256:138C07A2C5AB8F21D45DD7EB982D82544B984A05E813962847738E14F2BF5062 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\Download.mfx | executable | |
MD5:DF328D462F07AE2581B1EF41D48CC00C | SHA256:935E69577BD7312B44338538DF5AC0B35F0A55B23A660BBB54A2E45F49371AB0 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Uninstall.$A | executable | |
MD5:9086CCADF45CB48DD30C3E32A75242A8 | SHA256:22B3AFD0A8E745ECFE9508C983A3FF31AA24613F827F3E0D9EC38F90DBB8C8A4 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\Archive.mfx | executable | |
MD5:0D1416E079CC907971A7EEBE49189EB1 | SHA256:C75918D99DD8983FFF3DC51EA3F28AD7A9DA8C84F273E5A20736F227626FB50B | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\Archive.$A | executable | |
MD5:0D1416E079CC907971A7EEBE49189EB1 | SHA256:C75918D99DD8983FFF3DC51EA3F28AD7A9DA8C84F273E5A20736F227626FB50B | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\KcBoxA.mfx | executable | |
MD5:08AC00F4D05E68D8B5AB6870BF1F076E | SHA256:1CAE93696EC030BE6317A338C3C8BC4274A53632C03CA60AAB0BEE59D361A380 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\KcBoxB.mfx | executable | |
MD5:86D2B0DF60742AD2678A9B6F8683EA7B | SHA256:7F129F2A2305FBD396661EF2910AB48346D589F20EBC7EB85249ECCE80D307AF | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Uninstall.exe | executable | |
MD5:9086CCADF45CB48DD30C3E32A75242A8 | SHA256:22B3AFD0A8E745ECFE9508C983A3FF31AA24613F827F3E0D9EC38F90DBB8C8A4 | |||
| 6224 | WorkshopDL.2.0.4_installer.exe | C:\WorkshopDL\Modules\Get.$A | executable | |
MD5:C61FD0D847DF328FD6F0A98E4F030F41 | SHA256:791E717345991C4BF183C6450667498A89B59C4E8A5ABB52E2751FDE63D3AD43 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6188 | WorkshopDL.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
6188 | WorkshopDL.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
6188 | WorkshopDL.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D | unknown | — | — | whitelisted |
6428 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:5pN6J3Fw1BDT6OYVq0n3L7XM8pOYAxXi2HR4wA2bL-U&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
6188 | WorkshopDL.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D | unknown | — | — | whitelisted |
3768 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7964 | steamcmd.exe | GET | 200 | 184.24.77.46:80 | http://media.steampowered.com/client/steam_cmd_win32 | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 72.246.169.163:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4380 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 2.16.241.12:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6188 | WorkshopDL.exe | 185.199.108.133:443 | raw.githubusercontent.com | FASTLY | US | whitelisted |
6188 | WorkshopDL.exe | 184.24.77.156:443 | steamcdn-a.akamaihd.net | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
raw.githubusercontent.com |
| whitelisted |
steamcdn-a.akamaihd.net |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
7964 | steamcmd.exe | Potential Corporate Privacy Violation | ET USER_AGENTS Steam HTTP Client User-Agent |
Process | Message |
|---|---|
WorkshopDL.exe | Start app
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|
WorkshopDL.exe | Last Error: 0
|