File name:

WindowsXP-KB4012598-x86-Custom-ESN.exe

Full analysis: https://app.any.run/tasks/ff56a07b-88e6-4ea1-a6a3-34e2f96f51a4
Verdict: Malicious activity
Analysis date: December 17, 2024, 09:54:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

BEE60A32968454F39B29916AA6F32798

SHA1:

1FBE054158B612F4D37558975F925469239FA4C3

SHA256:

BF6DE36E727E712608177A5D220BFD1D0419B63EEE6C626118C91302D5EF7B84

SSDEEP:

24576:gIkKmqxdNMWwlTOEzqgpySi87SCZTmXHLAgz3zegW9cgmjOrS+Sy:1kKxxdNMWwlTOEegpySi87SCZTmXHLZI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 2796)
    • Drops a system driver (possible attempt to evade defenses)

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
    • Process drops legitimate windows executable

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
    • Executable content was dropped or overwritten

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
  • INFO

    • Reads the computer name

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
      • update.exe (PID: 3952)
    • Checks supported languages

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
      • update.exe (PID: 3952)
    • Reads the machine GUID from the registry

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
      • update.exe (PID: 3952)
    • The sample compiled with spanish language support

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
    • The sample compiled with english language support

      • WindowsXP-KB4012598-x86-Custom-ESN.exe (PID: 5536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | MS generic-sfx Cabinet File Unpacker (32/64bit MSCFU) (82.5)
.exe | Win32 Executable MS Visual C++ (generic) (7.3)
.exe | Win64 Executable (generic) (6.5)
.dll | Win32 Dynamic Link Library (generic) (1.5)
.exe | Win32 Executable (generic) (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:03:13 06:51:25+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 7.1
CodeSize: 35840
InitializedDataSize: 7680
UninitializedDataSize: -
EntryPoint: 0x6b23
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 6.3.18.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Spanish (Modern)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Security Update
FileVersion: 1
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: SFXCAB.EXE
ProductName: Windows XP Family
ProductVersion: 6.3.0018.0
BuildDate: 2017/02/11
Appliesto: Windows XP Service Pack 3
InstallationType: Full
InstallerVersion: 6.3.13.0
InstallerEngine: update.exe
KBArticleNumber: 4012598
SupportLink: http://support.microsoft.com?kbid=4012598
PackageType: Security Update
ProcArchitecture: x86
Self-ExtractorVersion: SFXCAB v6.3.18.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windowsxp-kb4012598-x86-custom-esn.exe update.exe no specs windowsxp-kb4012598-x86-custom-esn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2796"C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe" C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Security Update
Exit code:
3221226540
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\windowsxp-kb4012598-x86-custom-esn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3952c:\2e76939fe7a285192eeea87bb1640a\update\update.exeC:\2e76939fe7a285192eeea87bb1640a\update\update.exeWindowsXP-KB4012598-x86-Custom-ESN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Programa de instalación de Windows Service Pack
Version:
6.3.0013.0 built by: dnsrv
Modules
Images
c:\2e76939fe7a285192eeea87bb1640a\update\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5536"C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe" C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Security Update
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\windowsxp-kb4012598-x86-custom-esn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
72
Read events
72
Write events
0
Delete events
0

Modification events

No data
Executable files
9
Suspicious files
14
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0009._pbinary
MD5:18FAC39E34347CE765F64667CC4CB1D6
SHA256:FB47EDE63F5631607C70E2232202FC9C7BEEAFD236E7AA0A4495A49F17E678E9
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_.dllexecutable
MD5:EE207E35AEA4D5DF41D90221E1B66EFA
SHA256:CF64C95E9A2D02967EFC22B00EFB3736156B913A95231EB63C1DF45D43475E64
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0002._pbinary
MD5:580F5DB16D1D55DF006A7AB25D0A5418
SHA256:D0F715B477CE59B7CC236F80AFAEC32414BFA40FCB57AD2205F7D1422AB752FC
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0005._pbinary
MD5:3B8ED7A53CB9E69D7FB67AD9AC22A50A
SHA256:A0D0B8AE09107B2EDB0C9EE4F86FAB693BB271E4F1B870220F422F1F8FBBD76A
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0003._pbinary
MD5:4083F5CC488AE66FDE0E334BBA9999F5
SHA256:3C8D2C403773C382AF78F05654CEE8EA7AEC0384D93C77F1A0083631AE0B677D
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0006._pbinary
MD5:D1AD0343E1134FD7F40F979CDA3ABC20
SHA256:FB8787F9DE24276F79DFA1798BAB9730CBEF753F05904DEFE606CCED41B87357
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0001._pbinary
MD5:DDD832F5CB41C3435345299C1F8CE18C
SHA256:CE6129764B3481E057D218F8C7A01E6175FBE6C4906110BE46AA8EDCE8F3DA0F
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0007._pbinary
MD5:A6CEF57522F6102CF0FFC844E5653998
SHA256:F52BF9B7CDE9B477EEF49768A8198B3BDB102F02815BA730E4BB68FE3B3E98A3
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\_sfx_0000._pbinary
MD5:5E700C6B198EE8C9CBE4E2250A851F20
SHA256:3236C8BA13F72023F7E287EE68DF4ED78A4F21516697C9DAD97265FBB69941B9
5536WindowsXP-KB4012598-x86-Custom-ESN.exeC:\2e76939fe7a285192eeea87bb1640a\SP3QFE\sprv0c0a.dllexecutable
MD5:0BAA140CD02E529CD039773A5AEFEA1E
SHA256:BD3326BBB8294794C676BFF5BD371BD72F5F419E247B3EE21BED7290154B0EDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
27
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3984
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3984
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1684
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3040
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.123:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
www.bing.com
  • 104.126.37.123
  • 104.126.37.137
  • 104.126.37.186
  • 104.126.37.128
  • 104.126.37.177
  • 104.126.37.131
  • 104.126.37.179
  • 104.126.37.130
  • 104.126.37.185
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.73
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.68
  • 20.190.159.71
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info