File name:

UpdatePack7R2+.exe

Full analysis: https://app.any.run/tasks/9034b708-feeb-4eac-8f2b-cf808f929b99
Verdict: Malicious activity
Analysis date: February 10, 2025, 04:44:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

E27A6E1246D2F9E66E48E17C0EAF60E4

SHA1:

004B3A6CA10DBDFEF81AA6F12739B6682DA8771E

SHA256:

A65F270FC67631FAE758BA9691A686A20C3AB09CC2EC852E918C668D05622EB8

SSDEEP:

49152:KEVqU+T4Xzwj+/oldXJ/gGSuXbL6FfA4DHKQOrDKGTp6hBAvdxFHuacidYabGOIl:KVUbXzI+/61Vg746XjKQOrWG0h8cidXy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6396)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • SFXWget.exe (PID: 6396)
    • Executable content was dropped or overwritten

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • SFXWget.exe (PID: 6396)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • SFXWget.exe (PID: 6396)
    • Starts CMD.EXE for commands execution

      • SFXWget.exe (PID: 6396)
    • The executable file from the user directory is run by the CMD process

      • wget.exe (PID: 6536)
    • There is functionality for taking screenshot (YARA)

      • UpdatePack7R2+.exe (PID: 1224)
  • INFO

    • The sample compiled with english language support

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • SFXWget.exe (PID: 6396)
    • Checks supported languages

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • wget.exe (PID: 6272)
      • SFXWget.exe (PID: 6396)
      • wget.exe (PID: 6536)
    • Checks proxy server information

      • SFXWget.exe (PID: 6204)
      • SFXWget.exe (PID: 6396)
    • Create files in a temporary directory

      • UpdatePack7R2+.exe (PID: 1224)
      • SFXWget.exe (PID: 6204)
      • wget.exe (PID: 6272)
      • SFXWget.exe (PID: 6396)
    • Reads the computer name

      • wget.exe (PID: 6272)
      • SFXWget.exe (PID: 6396)
      • wget.exe (PID: 6536)
    • Reads the machine GUID from the registry

      • wget.exe (PID: 6272)
      • wget.exe (PID: 6536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:05:22 04:21:17+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 25600
InitializedDataSize: 438272
UninitializedDataSize: 16384
EntryPoint: 0x3737
OSVersion: 5.1
ImageVersion: 6
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.5.0.0
ProductVersionNumber: 1.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: simplix
FileDescription: UpdatePack7R2 1.5
FileVersion: 1.5.0.0
LegalCopyright: simplix
ProductName: UpdatePack7R2 Downloader 1.5
ProductVersion: 1.5.0.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start updatepack7r2+.exe sfxwget.exe wget.exe conhost.exe no specs sfxwget.exe cmd.exe no specs conhost.exe no specs wget.exe

Process information

PID
CMD
Path
Indicators
Parent process
1224"C:\Users\admin\AppData\Local\Temp\UpdatePack7R2+.exe" C:\Users\admin\AppData\Local\Temp\UpdatePack7R2+.exe
explorer.exe
User:
admin
Company:
simplix
Integrity Level:
MEDIUM
Description:
UpdatePack7R2 1.5
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\updatepack7r2+.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6204"C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\SFXWget.exe" /S /in="https://update7.simplix.info/UpdatePack7R2.txt" /out="C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\Version.txt" /name=VersionC:\Users\admin\AppData\Local\Temp\nsk571D.tmp\SFXWget.exe
UpdatePack7R2+.exe
User:
admin
Company:
simplix
Integrity Level:
MEDIUM
Description:
SFXWget Tool 2.3
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nsk571d.tmp\sfxwget.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6272"C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exe" --tries=1 --progress=dot --no-check-certificate "https://update7.simplix.info/UpdatePack7R2.txt" -O "C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\Version.txt" C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exe
SFXWget.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsk571d.tmp\wget.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6280\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewget.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6396"C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\SFXWget.exe" /in="https://update7.simplix.info/UpdatePack7R2-25.1.15" /out="C:\Users\admin\Desktop\UpdatePack7R2-25.1.15.exe" /name=UpdatePack7R2C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\SFXWget.exe
UpdatePack7R2+.exe
User:
admin
Company:
simplix
Integrity Level:
MEDIUM
Description:
SFXWget Tool 2.3
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nsk571d.tmp\sfxwget.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6472"C:\WINDOWS\system32\cmd.exe" /c ""C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exe" --tries=1 --progress=dot --no-check-certificate "https://update7.simplix.info/UpdatePack7R2-25.1.15.001" -O - > "C:\Users\admin\Desktop\UpdatePack7R2-25.1.15.exe""C:\Windows\System32\cmd.exeSFXWget.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
6480\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6536"C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exe" --tries=1 --progress=dot --no-check-certificate "https://update7.simplix.info/UpdatePack7R2-25.1.15.001" -O - C:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\nsk571d.tmp\wget.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
970
Read events
970
Write events
0
Delete events
0

Modification events

No data
Executable files
7
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1224UpdatePack7R2+.exeC:\Users\admin\AppData\Local\Temp\nsk571D.tmp\System.dllexecutable
MD5:3937AFA657BD9DCB8B36CB65D65D7587
SHA256:930171644D68307184C7B5E46F81FB6B9D693F171DBD9816480259C838EBAE22
1224UpdatePack7R2+.exeC:\Users\admin\AppData\Local\Temp\nsk571D.tmp\wget.exeexecutable
MD5:815E281A3487B0A157029428A70E7E68
SHA256:E803A98F559E17E6BEBB674052E25768B1E5438DF2540AF1272C3FC514E1CA7B
6204SFXWget.exeC:\Users\admin\AppData\Local\Temp\nsw5A69.tmp\System.dllexecutable
MD5:48E84BAFE66B0D102C4774AEA001A97F
SHA256:4861517735D1264E52F54C3D559607E2A2C23C1C7EA447812F2A2E227450FB8E
1224UpdatePack7R2+.exeC:\Users\admin\AppData\Local\Temp\nsk571D.tmp\SFXWget.exeexecutable
MD5:149B705CE7D310722ADED2C9AA2A38C3
SHA256:D586CC59B304FBA01095C37437A90F24FD8D8D966766A4329067D437BEE5D969
6272wget.exeC:\Users\admin\AppData\Local\Temp\nsk571D.tmp\Version.txttext
MD5:D0CA07A6F42F7E6D52A919B673B10EF2
SHA256:9CDB13E500E36D7F1F4C6E7FBB3415B9740DAD5B9B4CD7FA596F5FAE7F17C6CA
6396SFXWget.exeC:\Users\admin\AppData\Local\Temp\nsi5F3B.tmp\System.dllexecutable
MD5:48E84BAFE66B0D102C4774AEA001A97F
SHA256:4861517735D1264E52F54C3D559607E2A2C23C1C7EA447812F2A2E227450FB8E
6396SFXWget.exeC:\Users\admin\AppData\Local\Temp\nsi5F3B.tmp\ExecDos.dllexecutable
MD5:6029A47C90F52E887D7C27CBDC81DE82
SHA256:1A3702F5A77D6253208B7BCFDDC4A78FC2804BFF2BCA6BAA7A6DC667F07FE9A4
6204SFXWget.exeC:\Users\admin\AppData\Local\Temp\nsw5A69.tmp\ExecDos.dllexecutable
MD5:6029A47C90F52E887D7C27CBDC81DE82
SHA256:1A3702F5A77D6253208B7BCFDDC4A78FC2804BFF2BCA6BAA7A6DC667F07FE9A4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
26
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7124
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3688
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7124
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
104.126.37.179:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6272
wget.exe
188.114.97.3:443
update7.simplix.info
CLOUDFLARENET
NL
unknown
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6536
wget.exe
188.114.97.3:443
update7.simplix.info
CLOUDFLARENET
NL
unknown
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
188
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.179
  • 104.126.37.178
  • 104.126.37.170
  • 104.126.37.163
  • 104.126.37.177
  • 104.126.37.185
  • 104.126.37.137
  • 104.126.37.161
  • 104.126.37.131
whitelisted
update7.simplix.info
  • 188.114.97.3
  • 188.114.96.3
unknown
go.microsoft.com
  • 23.35.238.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.129
  • 40.126.31.130
  • 40.126.31.131
  • 40.126.31.3
  • 20.190.159.130
  • 20.190.159.64
  • 40.126.31.0
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info