File name:

windowsupdateagent-7.6-x86.exe

Full analysis: https://app.any.run/tasks/900fb431-41bc-4538-ba8a-565d984db71a
Verdict: Malicious activity
Analysis date: July 17, 2019, 16:49:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
MD5:

8C8C7AFEC7C17837BEE660DCBD035BD0

SHA1:

E901A9994F10CF31F557E84AD27688FD368C7611

SHA256:

9FC6856827123D0391A2C7451CCB1CBF93261442252DD87819AD5B8DB72B0EC0

SSDEEP:

196608:kbou8KGmme8zM8RrWozfdwDpLzzpz6zU6WXcay16lVyzOQAUzjTU9AUnHLaQo:k0RzmmDzvRHYLpz6ABXfnfqOQNznQ2l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MergedWuSetup.exe (PID: 3064)
      • WUA-Win7SP1.exe (PID: 3440)
      • wusetup.exe (PID: 2236)
    • Changes settings of System certificates

      • wusetup.exe (PID: 2236)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • windowsupdateagent-7.6-x86.exe (PID: 3884)
      • WUA-Win7SP1.exe (PID: 3440)
    • Executed as Windows Service

      • vssvc.exe (PID: 2828)
    • Executed via COM

      • DllHost.exe (PID: 2108)
      • DrvInst.exe (PID: 3196)
    • Searches for installed software

      • DllHost.exe (PID: 2108)
      • wusetup.exe (PID: 2236)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:03:07 08:49:28+01:00
PEType: PE32
LinkerVersion: 11
CodeSize: 23040
InitializedDataSize: 13824
UninitializedDataSize: -
EntryPoint: 0x49d5
OSVersion: 6.3
ImageVersion: 6.3
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 6.3.21.0
ProductVersionNumber: 6.3.21.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Windows Update Merged Standalone Setup
FileVersion: 6.3.0021.0 (winblue_gdr_dev.140306-1815)
InternalName: mergedwusetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: mergedwusetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.3.0021.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 07-Mar-2014 07:49:28
Detected languages:
  • English - United States
Debug artifacts:
  • sfxcab.pdb
CompanyName: Microsoft Corporation
FileDescription: Windows Update Merged Standalone Setup
FileVersion: 6.3.0021.0 (winblue_gdr_dev.140306-1815)
InternalName: mergedwusetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mergedwusetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.3.0021.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 07-Mar-2014 07:49:28
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_NET_RUN_FROM_SWAP
  • IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0000582C
0x00005A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.38269
.data
0x00007000
0x00011344
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.434903
.idata
0x00019000
0x00000F22
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.33965
.magic
0x0001A000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.183339
.rsrc
0x0001B000
0x00000E6C
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.65583
.reloc
0x0001C000
0x0000104E
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
3.15938

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.05653
1126
Latin 1 / Western European
English - United States
RT_MANIFEST
100
3.0946
282
Latin 1 / Western European
English - United States
RT_DIALOG
107
2.9591
224
Latin 1 / Western European
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
Cabinet.dll
KERNEL32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
msvcrt.dll
ntdll.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start windowsupdateagent-7.6-x86.exe mergedwusetup.exe no specs wua-win7sp1.exe wusetup.exe no specs vssvc.exe no specs SPPSurrogate no specs drvinst.exe no specs windowsupdateagent-7.6-x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2108C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2236c:\a59cbb03294ae3c8e8774c20fb22\wusetup.exec:\a59cbb03294ae3c8e8774c20fb22\wusetup.exeWUA-Win7SP1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Update Setup
Exit code:
0
Version:
7.6.7600.320 (winmain_wtr_wsus3sp2(oobla).140514-0912)
Modules
Images
c:\a59cbb03294ae3c8e8774c20fb22\wusetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2828C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3064c:\5346efdaea82beb8e7c066a5\MergedWuSetup.exec:\5346efdaea82beb8e7c066a5\MergedWuSetup.exewindowsupdateagent-7.6-x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Update Merged Standalone Setup
Exit code:
0
Version:
7.6.7600.320 (winmain_wtr_wsus3sp2(oobla).140514-0912)
Modules
Images
c:\5346efdaea82beb8e7c066a5\mergedwusetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3196DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot21" "" "" "6f9bf5bcb" "00000000" "000005C8" "000002BC"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3440WUA-Win7SP1.exe c:\5346efdaea82beb8e7c066a5\WUA-Win7SP1.exe
MergedWuSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Update Merged Standalone Setup
Exit code:
0
Version:
6.3.0021.0 (winblue_gdr_dev.140306-1815)
Modules
Images
c:\5346efdaea82beb8e7c066a5\wua-win7sp1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3816"C:\Users\admin\AppData\Local\Temp\windowsupdateagent-7.6-x86.exe" C:\Users\admin\AppData\Local\Temp\windowsupdateagent-7.6-x86.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Update Merged Standalone Setup
Exit code:
3221226540
Version:
6.3.0021.0 (winblue_gdr_dev.140306-1815)
Modules
Images
c:\users\admin\appdata\local\temp\windowsupdateagent-7.6-x86.exe
c:\systemroot\system32\ntdll.dll
3884"C:\Users\admin\AppData\Local\Temp\windowsupdateagent-7.6-x86.exe" C:\Users\admin\AppData\Local\Temp\windowsupdateagent-7.6-x86.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Update Merged Standalone Setup
Exit code:
0
Version:
6.3.0021.0 (winblue_gdr_dev.140306-1815)
Modules
Images
c:\users\admin\appdata\local\temp\windowsupdateagent-7.6-x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
320
Read events
151
Write events
169
Delete events
0

Modification events

(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
Operation:writeName:Blob
Value:
1900000001000000100000003C70FAEA25600CE3B2CC5F0B222ED629140000000100000014000000D5F656CB8FE8A25C6268D13D94905BD7CE9A18C40300000001000000140000003B1EFD3A66EA28B16697394703A72CA340A05BD50B00000001000000540000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020003200300031003000000069000000010000000E000000300C060A2B0601040182373C03020F000000010000002000000008FBA831C08544208F5208686B991CA1B2CFC510E7301784DDF1EB5BF0393239040000000100000010000000A266BB7DCC38A562631361BBF61DD11B5C0000000100000004000000001000002000000001000000F1050000308205ED308203D5A003020102021028CC3A25BFBA44AC449A9B586B4339AA300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3130303632333231353732345A170D3335303632333232303430315A308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479203230313030820222300D06092A864886F70D01010105000382020F003082020A0282020100B9089E28E4E4EC064E5068B341C57BEBAEB68EAF81BA22441F6534694CBE704017F2167BE279FD86ED0D39F41BA8AD92901ECB3D768F5AD9B591102E3C058D8A6D2454E71FED56AD83B4509C15A51774885920FC08C58476D368D46F2878CE5CB8F3509044FFE3635FBEA19A2C961504D607FE1E8421E0423111C4283694CF50A4629EC9D6AB7100B25B0CE696D40A2496F5FFC6D5B71BD7CBB72162AF12DCA15D37E31AFB1A4698C09BC0E7631F2A0893027E1E6A8EF29F1889E42285A2B1845740FFF50ED86F9CEDE2453101CD17E97FB08145E3AA214026A172AAA74F3C01057EEE8358B15E06639962917882B70D930C246AB41BDB27EC5F95043F934A30F59718B3A7F919A793331D01C8DB22525CD725C946F9A2FB875943BE9B62B18D2D86441A46AC78617E3009FAAE89C4412A2266039139459CC78B0CA8CA0D2FFB52EA0CF76333239DFEB01FAD67D6A75003C6047063B52CB1865A43B7FBAEF96E296E21214126068CC9C3EEB0C28593A1B985D9E6326C4B4C3FD65DA3E5B59D77C39CC055B77400E3B838AB839750E19A42241DC6C0A330D11A5AC85234F773F1C7181F33AD7AECCB4160F3239420C24845AC5C51C62E80C2E27715BD8587ED369D9691EE00B5A370EC9FE38D80688376BAAF5D70522216E266FBBAB3C5C2F73E2F77A6CADEC1A6C6484CC3375123D327D7B84E7096F0A14476AF78CF9AE166130203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414D5F656CB8FE8A25C6268D13D94905BD7CE9A18C4301006092B06010401823715010403020100300D06092A864886F70D01010B05000382020100ACA5968CBFBBAEA6F6D7718743315688FD1C32715B35B7D4F091F2AF37E214F1F30226053E16147F14BAB84FFB89B2B2E7D409CC6DB95B3B64657066B7F2B15ADF1A02F3F551B8676D79F3BF567BE484B92B1E9B409C2634F947189869D81CD7B6D1BF8F61C267C4B5EF60438E101B3649E420CAADA7C1B1276509F8CDF55B2AD08433F3EF1FF2F59C0B589337A075A0DE72DE6C752A6622F58C0630569F40B930AA40771582D78BECC0D3B2BD83C5770C1EAEAF1953A04D79719F0FAF30CE67F9D62CCC22417A07F2974218CE59791055DE6F10E4B8DA836640160968235B972E269A02BB578CC5B8BA69623280899EA1FDC0927C7B2B3319842A63C5006862FA9F478D997A453AA7E9EDEE6942B5F3819B4756107BFC7036841873EAEFF9974D9E3323DD260BBA2AB73F44DC8327FFBD61592B11B7CA4FDBC58B0C1C31AE32F8F8B942F77FDC619A76B15A04E1113D6645B71871BEC92485D6F3D4BA41345D122D25B98DA613486D4BB0077D99930961817457268AAB69E3E4D9C788CC24D8EC52245C1EBC9114E296DEEB0ADA9EDD5FB35BDBD482ECC620508725403AFBC7EECDFE33E56EC3840955032539C0E9355D6531A8F6BFA009CD29C7B336322EDC95F383C15ACF8B8DF6EAB321F8A4ED1E310EB64C11AB600BA412232217A3366482910412E0AB6F1ECB500561B440FF598671D1D533697CA9738A38D7640CF169
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE
Operation:writeName:Blob
Value:
040000000100000010000000CE0490D5E56C34A5AE0BE98BE581185D140000000100000014000000722D3A02319043B914054EE1EAA7C731D12389340300000001000000140000008F43288AD272F3103B6FB1428485EA3014C0BCFE69000000010000000E000000300C060A2B0601040182373C03020B00000001000000540000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F0072006900740079002000320030003100310000000F0000000100000020000000279CD652C4E252BFBE5217AC722205D7729BA409148CFA9E6D9E5B1CB94EAFF1190000000100000010000000BB048F1838395F6FC3A1F3D2B7E976545C0000000100000004000000001000002000000001000000F1050000308205ED308203D5A00302010202103F8BC8B5FC9FB29643B569D66C42E144300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303131301E170D3131303332323232303532385A170D3336303332323232313330345A308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479203230313130820222300D06092A864886F70D01010105000382020F003082020A0282020100B28041AA35384D13723268224DB8B2F1FFD552BC6CC7F5D24A8C36EED1C25C7E8C8AAEAF13286FC073E33ACED025A85A3A6DEFA8B859AB132368CD0C2987D16F805C8F447F5D90015258AC51C55F2A87DCDCD80A1DC103B97BB056E8A3DE6461C29EF8F37CB9EC0DB554FE4CB6654F88F09C48990C420B097C315917790678288D893A4C0325BE716A5C0BE78460A49922E3D2AF84A4A7FBD198ED0CA9DE9489E10EA0DCC0CE993DEA0852BB5679E41F84BA1EB8B4C4495C4F314B87DDDD0567269980E07111A3B8A541E2A453B9F73229830C13BF365E04B34B43472F6BE2911ED3984FDD4207C8E81D12FC99A96B3E927EC8D6693AFC64BDB6099DCAFD0C0BA29B77604B0394A4306912D6422DC1414CCADCAAFD8F5B83469AD9FCB1D1E3B3C97F487ACD24F0418F5C74D0ACB010200649B7C72D21C857E3D086F30368FBD0CE71C189994A64016CFDEC3091CF413C92C7E5BA861D6184C75F833962AEB4922F47F30BF855EBA01F59D0BB749B1ED076E6F2E906D710E8FA64DE69C635968802F046B83F27996FCB71892935F7481602358FD5797C4D02CF5FEB8A834F457188F9A90D4E72E9C29C07CF491B4E040E63518C5ED800C1552CB6C6E0C2654EC93439F59CB3C47EE8616E135F15C45FD97EED1DCEEE44ECCB2E86B1EC38F670EDAB5C13C1D90F0DC780B255ED34F7AC9BE4C3DAE7473CA6B58F31DFC54BAFEBF10203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414722D3A02319043B914054EE1EAA7C731D1238934301006092B06010401823715010403020100300D06092A864886F70D01010B050003820201007F72CF0FB7C515DB9BC049CA265BFE9E13E6D3F0D2DB975FF24B3F4DB3AE19AEEDD797A0ACEFA93AA3C241B0E5B8919E13812403E609FD3F574039212456D1102F4B40A936864BB453579AFBF17E898F11FE186C51AAE8ED0995B5E571C9A1E98775A6157FC97E37545E7493C5C367CC0D4F6BA8170C6D08927E8BDD81AA2D7021C33D0614BBBF245EA784D73F0F2122BD4B0006DB971CD85ED4C50B5C876E50A4E8C338A4FBCB2CC592669B855ECB7A6C937C8029585B57B54069BA0879A66462159D879645B5662320038B1C73A0D3A27933E0505986DB2FE50225EA732A9F0014C836C7923BE94E00ECD85609B9334912D2540B01ABAC47B691297D4CB475805201E8CA82F69FCCAC9C8F17EA2F26B0AB72AC0BFE9E511EC74355674F51B357D6B6ECEE52B73AE94EE1D78188BC4F8E75BB4BA8F035AA26D4676749B2704C3B93DC1DDF78908672B238A4D1DC924DC958EB2B125CD43BAE8C6BB083E5013FF80932F693353422AFDD370D7709802BCD4800F18C9919470501E9D1BFD14ED0E628433799A40A4A08D99A7173D2AACD31136376A1376F92381E7D123C6632E7CB6DE1FC5289DDCAD666059A9661BEA228C71CA3A736503C3AA4DF4A6EE6873BCEEBF0E081379D133C528EBDB91D34C61DD50A6A3D9829708C892AD1AB8210481FDCF4EFA5C5BB551A3863844EB76CAD9554EC6522104917B8C01EC70FAC5447
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000406E6BB3BF3CD501BC080000D40A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000406E6BB3BF3CD501BC080000D40A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
23
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
400000000000000080B9B7B3BF3CD501BC080000D40A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
4000000000000000DA1BBAB3BF3CD501BC080000FC070000E8030000010000000000000000000000BA3DAB7CE13ECF4A97BB7E100BEB9DDC0000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Leave)
Value:
400000000000000012B8D6B3BF3CD501BC080000FC070000E8030000000000000000000000000000BA3DAB7CE13ECF4A97BB7E100BEB9DDC0000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000C67CDBB3BF3CD501BC080000D40A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2236) wusetup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000C67CDBB3BF3CD501BC080000D40A0000D007000001000000000000000A010081BA3DAB7CE13ECF4A97BB7E100BEB9DDC0000000000000000
Executable files
28
Suspicious files
7
Text files
112
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\el\eula.rtftext
MD5:EC45B6E1F6BBF0F77B616C685C56A059
SHA256:93AB618230EEB9D2BD5B2FD17E5652EBAD6B2E8CDDA78F6E8984625AEBE49E86
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\el\wusetup.exe.muiexecutable
MD5:050255E481A9CE33A310C7EE6ACEABBB
SHA256:4913D6A6395F4D339673A0E7300BCF383787ABB7CFFEC4AA8A850A9B15D7E8FA
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\en\wusetup.exe.muiexecutable
MD5:8EA3CC86B2802E13DEDACC1C368B2A8F
SHA256:B3DC22667B1F03775A0F02CCFE2E2C01ACDD099AF6A16BECFDB12EA6D258C5E3
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\wusetup.exeexecutable
MD5:8797B25C25DB37CB2715DAF56D8A27AF
SHA256:5CE0926BAAEAF59F554C53505F84856E070DCB0309D01C6F76F2711D4809D548
3884windowsupdateagent-7.6-x86.exeC:\5346efdaea82beb8e7c066a5\MergedWuSetup.exeexecutable
MD5:ECA875136BBDEBC71F141F841C0D633E
SHA256:E294BDE1B22A8C950761E78B997AF2E6CB68A22F10E9148DC5F1EE1B3D8FF15A
3884windowsupdateagent-7.6-x86.exeC:\5346efdaea82beb8e7c066a5\WUA-Win7SP1.exeexecutable
MD5:5EFAF8662DC85C3581BD3BFDFAEDF4C3
SHA256:354CC326C787E4444F53674B8DFFEA9AEE55D02A4AE393D68AF96145AD2A9B76
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\cs\eula.rtftext
MD5:6940F05F9C0FA1C65C789CF3D17CC3E9
SHA256:91ADE4761C4A29A761334AB27145EDCA214B09FDACBEEC37012993427C5826E4
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\WUClient-SelfUpdate-ActiveX.cabcompressed
MD5:5F71A284F57AECD4A8588C9602F9DB26
SHA256:8BCE99A8D466B729DC554F23E01F5375903B733DD82838B22DCDF7FAA165C081
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\wusetup.infini
MD5:41DF52E45AA7B87631BFFB39A20AF32D
SHA256:5A661E9DFEEE5661E13F7E0BA6984C129619E7A9FA771285D825D0817595EB88
3440WUA-Win7SP1.exeC:\a59cbb03294ae3c8e8774c20fb22\WUClient-SelfUpdate-Aux-TopLevel.cabcompressed
MD5:D50A43AC883D8F1DA9BC428FA7C2DBF0
SHA256:805BFFBFEDB47604D1E1AE6E74A62077E7B5CF6D09413EDD26145E5BFC3F67B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info