File name:

RdrServicesUpdater2_x86.exe

Full analysis: https://app.any.run/tasks/2faad447-cc1c-429a-8c3a-abe16f0bae70
Verdict: Malicious activity
Analysis date: January 30, 2026, 09:07:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
neshta
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

E80F70D0AE23C1DA05C2248101ED7C30

SHA1:

A42349984308FC3D1138A1855836DC6E0B6A5E66

SHA256:

97DE75484307AA5D84670800393317CE8B0AA1203D76FE9B314DE933D76B5635

SSDEEP:

24576:95FHTnyAiHLKjBoIj6Cd0xp4Zs4SwLEeqb+ke51/svWSKqq/75ETc17VZi:9THTnyAiHLKjBoIj6Cd0xp4Zs4SwLEeQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • NESHTA mutex has been found

      • RdrServicesUpdater2_x86.exe (PID: 5752)
  • SUSPICIOUS

    • Mutex name with non-standard characters

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • Using the short paths format

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • Executable content was dropped or overwritten

      • RdrServicesUpdater2_x86.exe (PID: 5752)
  • INFO

    • Create files in a temporary directory

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • Reads security settings of Internet Explorer

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • Reads the computer name

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • Checks supported languages

      • RdrServicesUpdater2_x86.exe (PID: 5752)
      • RdrServicesUpdater2_x86.exe (PID: 6472)
    • Process checks computer location settings

      • RdrServicesUpdater2_x86.exe (PID: 5752)
    • There is functionality for taking screenshot (YARA)

      • RdrServicesUpdater2_x86.exe (PID: 5752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Borland Delphi 6 (85.5)
.exe | Win32 Executable Delphi generic (4.6)
.scr | Windows screen saver (4.2)
.dll | Win32 Dynamic Link Library (generic) (2.1)
.exe | Win32 Executable (generic) (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 29696
InitializedDataSize: 10752
UninitializedDataSize: -
EntryPoint: 0x80e4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
5752"C:\Users\admin\AppData\Local\Temp\RdrServicesUpdater2_x86.exe" C:\Users\admin\AppData\Local\Temp\RdrServicesUpdater2_x86.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rdrservicesupdater2_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6472"C:\Users\admin\AppData\Local\Temp\3582-490\RdrServicesUpdater2_x86.exe" C:\Users\admin\AppData\Local\Temp\3582-490\RdrServicesUpdater2_x86.exeRdrServicesUpdater2_x86.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\rdrservicesupdater2_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
8108"C:\Users\admin\AppData\Local\Temp\RdrServicesUpdater2_x86.exe" C:\Users\admin\AppData\Local\Temp\RdrServicesUpdater2_x86.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rdrservicesupdater2_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
8608C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
495
Read events
495
Write events
0
Delete events
0

Modification events

No data
Executable files
41
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5752RdrServicesUpdater2_x86.exeC:\Windows\svchost.comexecutable
MD5:36FD5E09C417C767A952B4609D73A54B
SHA256:980BAC6C9AFE8EFC9C6FE459A5F77213B0D8524EB00DE82437288EB96138B9A2
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exeexecutable
MD5:85A67D34298E33D2D5A9EC789B6AB594
SHA256:1DEE143B4F88F2375B85C6271A58E2E78FED081BEAE4090678CB2DD7A37FB2D4
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exeexecutable
MD5:6D55E9A1D506D4472409FC2E2D553DAD
SHA256:A171E0A4C806B17CC289B96370BD42F3AC088D286BA8B919F2FFAEF45B681A14
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exeexecutable
MD5:B3DF9BF318BAB4EECA2F61C3576FBEF3
SHA256:55DF504E055F2F93E8F59947347594267F33D01EBE169715071085E434A538F1
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exeexecutable
MD5:CBD96BA6ABE7564CB5980502EEC0B5F6
SHA256:405B8BD647FA703E233B8B609A18999ABE465A8458168F1DAF23197BD2EA36AA
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Java\Java Update\jusched.exeexecutable
MD5:BCAC3CBF6DF41FB1562B295AD30DE227
SHA256:0D663EEBF01B4B5DDDBED809B35F85EBF7D04EC9911CA090E136490C531399E8
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_2989500\java.exeexecutable
MD5:EFED71F23F8225FFCD1C7E0A8ABC462D
SHA256:4D876E31ACA623D8A69BA801E737FBE6D482DBEA6B727E8CA95E3482EAA9F3D3
5752RdrServicesUpdater2_x86.exe
MD5:
SHA256:
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_2989500\javaw.exeexecutable
MD5:951F2A132280DF2D9ADAC9D2DBF743ED
SHA256:931F4BF498303A6586FD92C7FB84FFA4EA30E6109A7678C134B4F427CA5BB14E
5752RdrServicesUpdater2_x86.exeC:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exeexecutable
MD5:5E120E7E52EBD3C0B4F099954EF8B71A
SHA256:EEC3F8FC6506DB5B89E93FAC32C81ACACEA22E20BA57FC99A7A5AD85042AE32A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
22
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
4256
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WaaS/FeatureManagement?IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&CurrentBranch=vb_release&AccountFirstChar=&ActivationChannel=Retail&OEMModel=DELL&FlightRing=Retail&AttrDataVer=186&InstallLanguage=en-US&OSUILocale=en-US&WebExperience=1&FlightingBranchName=&ChassisTypeId=1&OSSkuId=48&App=CDM&InstallDate=1661339444&AppVer=&OSArchitecture=AMD64&DefaultUserRegion=244&TelemetryLevel=1&OSVersion=10.0.19045.4046&DeviceFamily=Windows.Desktop
US
whitelisted
6756
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
6756
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6756
SIHClient.exe
GET
200
20.165.94.63:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6756
SIHClient.exe
GET
304
20.165.94.63:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
4256
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
356
svchost.exe
POST
200
40.126.32.136:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4256
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8628
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.204:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
356
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 20.189.173.13
whitelisted
google.com
  • 142.251.141.78
whitelisted
www.bing.com
  • 2.16.241.204
  • 2.16.241.208
  • 2.16.241.207
  • 2.16.241.206
  • 2.16.241.200
  • 2.16.241.223
  • 2.16.241.203
  • 2.16.241.209
  • 2.16.241.205
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.65
  • 20.190.160.64
  • 20.190.160.130
  • 20.190.160.132
  • 40.126.32.72
  • 20.190.160.66
  • 40.126.32.134
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 135.233.95.135
whitelisted

Threats

PID
Process
Class
Message
4256
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info