analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://au.download.windowsupdate.com/d/msdownload/update/software/defu/2018/11/updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8.exe

Full analysis: https://app.any.run/tasks/4f030314-8011-46ab-b2a5-23e1480ba3de
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 14, 2018, 16:29:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

AAD16174C1933A7EA518F0F7474DB951

SHA1:

3D8089F7A39E1E558F0F701292DD52C854A409F4

SHA256:

8D7366969EB32016F708A8220453C1C2518E36B95CEC4AFCEA2523BC81C841FD

SSDEEP:

3:N1KfV4EWd9r4ExKVKSLJkACANHuI3DyKIATG1ZhMFT0kWpkA:CNKd9AVxpuJ2kMp0kWpJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe (PID: 2596)
      • MpSigStub.exe (PID: 3672)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3228)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2940)
      • iexplore.exe (PID: 3228)
      • updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe (PID: 2596)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3228)
      • iexplore.exe (PID: 2940)
    • Application launched itself

      • iexplore.exe (PID: 2940)
    • Changes internet zones settings

      • iexplore.exe (PID: 2940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start iexplore.exe iexplore.exe updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe mpsigstub.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2940"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3228"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2940 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2596"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
AntiMalware Platform Update (x86)
Exit code:
2147944005
Version:
4.18.1812.3
3672C:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpSigStub.exe /stub 1.1.14905.0 /payload 4.18.1812.3 /program "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe"C:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpSigStub.exeupdateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2147944005
Total events
634
Read events
582
Write events
0
Delete events
0

Modification events

No data
Executable files
15
Suspicious files
1
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
2940iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2940iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2940iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF33938F7E8226DAFB.TMP
MD5:
SHA256:
2940iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018121420181215\index.datdat
MD5:A6A97074A6D17435702B96AA00DF4636
SHA256:FE1BB32090CBFB70D8182C73BE6485A36FF61D3C6EAA912E6B0C4F9C25A26974
2940iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exeexecutable
MD5:211CBFA3049AD53FB0F6464971248FEE
SHA256:3B71179F29B1341582F1C3AF15245917F5F9924CCDFBA3AABBBC83B375FB76AF
2596updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exeC:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpOAV.dllexecutable
MD5:A44417A9D252A522C7929EA326A6B4D1
SHA256:4C3F1684074AE0334FA2FE50465E8F07CB39C0FA114CB482D8031EAD050C67EB
2596updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exeC:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpCmdRun.exeexecutable
MD5:37C9575934ABE598FA14C69E990AF33C
SHA256:3187F2A9FF021C30182606FD2F2B5584AF6C6CBB2920EFBB6596FC3C7F2370EF
2596updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exeC:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpUpdate.dllexecutable
MD5:A862C9951BDA54A133737EE866D5A1C0
SHA256:4CDC8B23B10B5292094110F9021453053663DE6480B0B9767A86E0F029731691
2596updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8[1].exeC:\Users\admin\AppData\Local\Temp\{8DE0DC08-12CC-4F45-8217-CD7B66180939}\MpRtp.dllexecutable
MD5:F3D2ADE7B66A0E32FD92AA82FD17A4D9
SHA256:56AE440ACF14360DC1DEC4B6DAE8CD2C006A60C9E6B0B82F902FB3FDAC30F940
2940iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{844D6D72-FFBD-11E8-BAD8-5254004A04AF}.datbinary
MD5:9C7CBBC216E86FB92ABE760D64173BDE
SHA256:720E0DA1B480FD9F761DF6BB199543EC3E9A63AC91D1FAAD31D216A6DBD8DEA2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3228
iexplore.exe
GET
200
2.16.186.33:80
http://au.download.windowsupdate.com/d/msdownload/update/software/defu/2018/11/updateplatform_0b1fde6c65ab53f5747775ad94e6a8ed8102d7a8.exe
unknown
executable
4.57 Mb
whitelisted
2940
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2940
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3228
iexplore.exe
2.16.186.33:80
au.download.windowsupdate.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
au.download.windowsupdate.com
  • 2.16.186.33
  • 2.16.186.25
whitelisted

Threats

No threats detected
No debug info