File name:

unifying252.exe

Full analysis: https://app.any.run/tasks/6fd103c1-a936-4083-8dc2-417d0143dac7
Verdict: Malicious activity
Analysis date: May 16, 2023, 00:51:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

E27D92658CEBB4EABEA7E74125464023

SHA1:

C8CA0643693FBCA5CDA17886F478666FF0D35CEE

SHA256:

BEA2CA4C9D9ABD1FF214166D638792BE974FFAD7907A8A8ED0370ACBA800E815

SSDEEP:

98304:TIFT3aZ0m6b0GL3vdHLu5UMEyz4IL+ox9frfixLdRz:T03aZ030MdecaCqNOx5Rz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • unifying252.exe (PID: 1780)
    • The process creates files with name similar to system file names

      • unifying252.exe (PID: 1780)
    • Reads the Internet Settings

      • LULnchr.exe (PID: 3784)
      • LogitechUpdate.exe (PID: 3924)
      • LULnchr.exe (PID: 1356)
      • LogitechUpdate.exe (PID: 872)
      • LULnchr.exe (PID: 4020)
      • LULnchr.exe (PID: 868)
      • LogitechUpdate.exe (PID: 3984)
      • LULnchr.exe (PID: 2712)
    • Process requests binary or script from the Internet

      • LogitechUpdate.exe (PID: 3924)
      • LogitechUpdate.exe (PID: 872)
      • LogitechUpdate.exe (PID: 3984)
  • INFO

    • The process checks LSA protection

      • unifying252.exe (PID: 1780)
      • DJCUHost.exe (PID: 3328)
      • LogitechUpdate.exe (PID: 3924)
      • LULnchr.exe (PID: 1356)
      • LogitechUpdate.exe (PID: 872)
      • LULnchr.exe (PID: 3784)
      • LULnchr.exe (PID: 4020)
      • LULnchr.exe (PID: 868)
      • LULnchr.exe (PID: 2712)
      • LogitechUpdate.exe (PID: 3984)
    • Reads the computer name

      • unifying252.exe (PID: 1780)
      • DJCUHost.exe (PID: 3328)
      • LULnchr.exe (PID: 3784)
      • LogitechUpdate.exe (PID: 3924)
      • LULnchr.exe (PID: 1356)
      • LogitechUpdate.exe (PID: 872)
      • LogitechUpdate.exe (PID: 656)
      • LULnchr.exe (PID: 4020)
      • LULnchr.exe (PID: 868)
      • LogitechUpdate.exe (PID: 3984)
      • LULnchr.exe (PID: 2712)
      • LogitechUpdate.exe (PID: 3016)
    • Process checks computer location settings

      • unifying252.exe (PID: 1780)
      • DJCUHost.exe (PID: 3328)
    • Checks supported languages

      • unifying252.exe (PID: 1780)
      • RunNE.exe (PID: 944)
      • DJCUHost.exe (PID: 3328)
      • LULnchr.exe (PID: 3784)
      • LogitechUpdate.exe (PID: 3924)
      • LogitechUpdate.exe (PID: 872)
      • LULnchr.exe (PID: 4020)
      • LogitechUpdate.exe (PID: 656)
      • LULnchr.exe (PID: 868)
      • LogitechUpdate.exe (PID: 3984)
      • LULnchr.exe (PID: 1356)
      • LogitechUpdate.exe (PID: 3016)
      • LULnchr.exe (PID: 2712)
    • Manual execution by a user

      • DJCUHost.exe (PID: 3328)
    • Reads the machine GUID from the registry

      • DJCUHost.exe (PID: 3328)
      • LogitechUpdate.exe (PID: 3924)
      • LogitechUpdate.exe (PID: 872)
      • LogitechUpdate.exe (PID: 3984)
    • Create files in a temporary directory

      • DJCUHost.exe (PID: 3328)
      • unifying252.exe (PID: 1780)
      • LogitechUpdate.exe (PID: 3924)
    • Creates files in the program directory

      • DJCUHost.exe (PID: 3328)
      • LULnchr.exe (PID: 3784)
      • LogitechUpdate.exe (PID: 3924)
      • unifying252.exe (PID: 1780)
      • LogitechUpdate.exe (PID: 3984)
    • Checks proxy server information

      • LogitechUpdate.exe (PID: 3924)
      • LogitechUpdate.exe (PID: 872)
      • LogitechUpdate.exe (PID: 3984)
    • Creates files or folders in the user directory

      • LogitechUpdate.exe (PID: 3924)
      • LogitechUpdate.exe (PID: 872)
      • LogitechUpdate.exe (PID: 3984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

ProductName: Unifying Software Setup
LegalTrademarks: Logitechs trademarks are either registered trademarks or trademarks of Logitech in the US and/or other countries.
LegalCopyright: Copyright 2005-2022 Logitech. All Rights Reserved
FileVersion: 2.52.33
FileDescription: Setup
CompanyName: $Co_Name Inc.
Comments: Privacy Policy: http://www.logicool.co.jp/privacy
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x0000
ProductVersionNumber: 2.52.33.0
FileVersionNumber: 2.52.33.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 6
OSVersion: 4
EntryPoint: 0x31a3
UninitializedDataSize: 1024
InitializedDataSize: 162816
CodeSize: 25088
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2016:12:11 21:50:52+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 11-Dec-2016 21:50:52
Detected languages:
  • English - United States
Comments: Privacy Policy: http://www.logicool.co.jp/privacy
CompanyName: $Co_Name Inc.
FileDescription: Setup
FileVersion: 2.52.33
LegalCopyright: Copyright 2005-2022 Logitech. All Rights Reserved
LegalTrademarks: Logitechs trademarks are either registered trademarks or trademarks of Logitech in the US and/or other countries.
ProductName: Unifying Software Setup

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 11-Dec-2016 21:50:52
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006071
0x00006200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.43434
.rdata
0x00008000
0x00001352
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.2373
.data
0x0000A000
0x000254F8
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.03725
.ndata
0x00030000
0x00018000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00048000
0x0000AC18
0x0000AE00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.0213

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.28813
1070
UNKNOWN
English - United States
RT_MANIFEST
2
2.496
9640
UNKNOWN
English - United States
RT_ICON
3
2.68533
4264
UNKNOWN
English - United States
RT_ICON
4
2.84857
2440
UNKNOWN
English - United States
RT_ICON
5
3.12038
1128
UNKNOWN
English - United States
RT_ICON
103
2.79808
76
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.73893
514
UNKNOWN
English - United States
RT_DIALOG
106
2.91148
248
UNKNOWN
English - United States
RT_DIALOG
108
2.74026
244
UNKNOWN
English - United States
RT_DIALOG
111
2.89887
238
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
14
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start unifying252.exe runne.exe no specs djcuhost.exe lulnchr.exe logitechupdate.exe lulnchr.exe logitechupdate.exe lulnchr.exe logitechupdate.exe no specs lulnchr.exe logitechupdate.exe lulnchr.exe logitechupdate.exe no specs unifying252.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
656"C:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exe" /lang:enu /prod:unifysw /version:2.52.33 /check /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exeLULnchr.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\common files\logishrd\unifying\lu\logitechupdate.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
868lulnchr.exe /lang:enu /prod:unifysw /version:2.52.33 /check /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LULnchr.exe
DJCUHost.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\lulnchr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
872"C:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exe" /lang:enu /prod:unifysw /version:2.52.33 /check /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exe
LULnchr.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\logitechupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
944"C:\Program Files\Common Files\LogiShrd\Unifying\RunNE.exe" C:\Program Files\Common Files\LogiShrd\Unifying\DJCUHost.exeC:\Program Files\Common Files\LogiShrd\Unifying\RunNE.exeunifying252.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
HIGH
Description:
Unifying Software (UNICODE)
Exit code:
1
Version:
1.10.2
Modules
Images
c:\program files\common files\logishrd\unifying\runne.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\logishrd\unifying\nonelevateddll.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1356lulnchr.exe /lang:enu /prod:unifysw /version:2.52.33 /check /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LULnchr.exe
DJCUHost.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\lulnchr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1780"C:\Users\admin\AppData\Local\Temp\unifying252.exe" C:\Users\admin\AppData\Local\Temp\unifying252.exe
explorer.exe
User:
admin
Company:
$Co_Name Inc.
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
2.52.33
Modules
Images
c:\users\admin\appdata\local\temp\unifying252.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2712lulnchr.exe /lang:enu /configureC:\Program Files\Common Files\LogiShrd\Unifying\LU\LULnchr.exe
DJCUHost.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\lulnchr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3016"C:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exe" /lang:enu /configure /conffile=C:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdateProduct.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exeLULnchr.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\logitechupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3328"C:\Program Files\Common Files\LogiShrd\Unifying\DJCUHost.exe" C:\Program Files\Common Files\LogiShrd\Unifying\DJCUHost.exe
explorer.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Unifying Software (UNICODE)
Exit code:
0
Version:
2.52.33
Modules
Images
c:\program files\common files\logishrd\unifying\djcuhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\logishrd\unifying\djapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
3784lulnchr.exe /lang:enu /prod:unifysw /version:2.52.33 /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xmlC:\Program Files\Common Files\LogiShrd\Unifying\LU\LULnchr.exe
DJCUHost.exe
User:
admin
Company:
Logitech, Inc.
Integrity Level:
MEDIUM
Description:
Logitech Updater
Exit code:
0
Version:
2.22.6.0
Modules
Images
c:\program files\common files\logishrd\unifying\lu\lulnchr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
15 444
Read events
15 230
Write events
214
Delete events
0

Modification events

(PID) Process:(1780) unifying252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Unifying
Operation:writeName:LanguageId
Value:
1033
(PID) Process:(3784) LULnchr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3784) LULnchr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3784) LULnchr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3784) LULnchr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3924) LogitechUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3924) LogitechUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3924) LogitechUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3924) LogitechUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3924) LogitechUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
24
Suspicious files
2
Text files
230
Unknown types
2

Dropped files

PID
Process
Filename
Type
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\LU\LogitechUpdate.exeexecutable
MD5:235D42833F2F89083FA70B9787899846
SHA256:CF271DBF5698707D4618BFAA50E7B416558BF794B3DC733212E4D0E48BD703DC
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\DJCU.dllexecutable
MD5:D09CD2FED001441173757D8DDE519181
SHA256:B752FE25F954146161B8400F805543264A5A8C5A07D6BA6ABBA1568504492BE9
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\RunNE.exeexecutable
MD5:2B1396E9D64DA60A949B23D65219FE9A
SHA256:D45331EE5F322B4267D3811AC599035802D33E8046F87C0548955A5E39595427
1780unifying252.exeC:\Users\admin\AppData\Local\Temp\nsqD285.tmp\System.dllexecutable
MD5:3F176D1EE13B0D7D6BD92E1C7A0B9BAE
SHA256:FA4AB1D6F79FD677433A31ADA7806373A789D34328DA46CCB0449BBF347BD73E
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\LU\LULnchr.initext
MD5:F4E8B5311E3643A64F2DF993A6C8F68A
SHA256:9552DBA6ACF22D435954115F47D94A981574654964CD054C62E134BD75495CC5
1780unifying252.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Unifying\Logitech Unifying Software.lnklnk
MD5:9EF4F93946BA686E730055177D57D6EC
SHA256:9CC59A35DF3F631C624ABD6006F2A43C2C08D4E989BFECCDD477C29D53CDFEE8
1780unifying252.exeC:\Users\admin\AppData\Local\Temp\nsqD285.tmp\modern-wizard.bmpimage
MD5:D67C2379CA95E296CF8501038832DB45
SHA256:4C149283AA09DB31D852B383E110FF3D4147B0DA511DE936619784463F0B0C2A
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\NonElevatedDll.dllexecutable
MD5:ED4BCD2FDAD6396540EE3C8FAF71676B
SHA256:42299A7D4468CD82D2B9E8E7BCA0AC4BD968AC325E8F3D20A572C7215D997FAE
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\DJAPI.dllexecutable
MD5:8D94C99591DFADBADE072F5CE4CA4EFD
SHA256:1D1668649B5071FB2525C02E445B81489CE52D84BFCC77D00AC60C7D4FFEEFAA
1780unifying252.exeC:\Program Files\Common Files\LogiShrd\Unifying\LU\LogiKey.pubbinary
MD5:859565BECF5B01298F8E8A6CBD09098C
SHA256:9FD6E50B70496ABEFD36F00E19C4ED48F2484E7045E4094010BFC204891B8150
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
13
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3924
LogitechUpdate.exe
GET
404
99.86.1.36:80
http://d23iz4esrwkib6.cloudfront.net/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig%3flu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
shared
872
LogitechUpdate.exe
GET
404
99.86.1.36:80
http://d23iz4esrwkib6.cloudfront.net/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig%3flu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
shared
3924
LogitechUpdate.exe
GET
302
54.214.210.9:80
http://updates.logitech.com/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?lu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
text
9 b
suspicious
3984
LogitechUpdate.exe
GET
302
54.214.210.9:80
http://updates.logitech.com/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?lu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
text
9 b
suspicious
872
LogitechUpdate.exe
GET
302
54.214.210.9:80
http://updates.logitech.com/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?lu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
text
9 b
suspicious
3984
LogitechUpdate.exe
GET
404
99.86.1.36:80
http://d23iz4esrwkib6.cloudfront.net/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig?/logitech/controldevices/unifying/pc/unifysw/2.52.33/_w7/32/unifysw.exe.sig%3flu.hp=dj&lu.hpo=nil&lu.hv=2.52.33&lu.hl=enu&lu.uv=2.22.6&lu.ulv=2.22.1&lu.uos=_w7&lu.ubi=32
US
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3416
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
3924
LogitechUpdate.exe
54.214.210.9:80
updates.logitech.com
AMAZON-02
US
suspicious
872
LogitechUpdate.exe
54.214.210.9:80
updates.logitech.com
AMAZON-02
US
suspicious
3984
LogitechUpdate.exe
54.214.210.9:80
updates.logitech.com
AMAZON-02
US
suspicious
3924
LogitechUpdate.exe
99.86.1.36:80
d23iz4esrwkib6.cloudfront.net
AMAZON-02
US
suspicious
3984
LogitechUpdate.exe
99.86.1.36:80
d23iz4esrwkib6.cloudfront.net
AMAZON-02
US
suspicious
872
LogitechUpdate.exe
99.86.1.36:80
d23iz4esrwkib6.cloudfront.net
AMAZON-02
US
suspicious

DNS requests

Domain
IP
Reputation
updates.logitech.com
  • 54.214.210.9
suspicious
d23iz4esrwkib6.cloudfront.net
  • 99.86.1.36
  • 99.86.1.79
  • 99.86.1.72
  • 99.86.1.125
shared

Threats

No threats detected
Process
Message
DJCUHost.exe
[01:51:52:0029]: <3324>Unifying Loaded DLL: 2.52.33
DJCUHost.exe
DJCUHost.exe
[01:51:52:0029]: <3324>Unifying Loaded DLL: 2.52.33
DJCUHost.exe
LULnchr.exe
-> LULnchr: started with args: '/lang:enu /prod:unifysw /version:2.52.33 /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xml'
LULnchr.exe
-- LULnchr: will launch target: 'LogitechUpdate.exe' '/lang:enu /prod:unifysw /version:2.52.33 /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xml'
LULnchr.exe
LULnchr: NOTE - Failed to open file 'C:\ProgramData\LogiShrd\Updater\UpdateList.txt'
LULnchr.exe
-> LULnchr: started with args: '/lang:enu /prod:unifysw /version:2.52.33 /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xml'
LULnchr.exe
-- LULnchr: will launch target: 'LogitechUpdate.exe' '/lang:enu /prod:unifysw /version:2.52.33 /conffile=c:\program files\common files\logishrd\unifying\lu\product.unifysw.xml'
LULnchr.exe
LULnchr: NOTE - Failed to open file 'C:\ProgramData\LogiShrd\Updater\UpdateList.txt'