| File name: | WindowsXP-KB4012598-x86-Custom-ESN.exe |
| Full analysis: | https://app.any.run/tasks/ff56a07b-88e6-4ea1-a6a3-34e2f96f51a4 |
| Verdict: | Malicious activity |
| Analysis date: | December 17, 2024, 09:54:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | BEE60A32968454F39B29916AA6F32798 |
| SHA1: | 1FBE054158B612F4D37558975F925469239FA4C3 |
| SHA256: | BF6DE36E727E712608177A5D220BFD1D0419B63EEE6C626118C91302D5EF7B84 |
| SSDEEP: | 24576:gIkKmqxdNMWwlTOEzqgpySi87SCZTmXHLAgz3zegW9cgmjOrS+Sy:1kKxxdNMWwlTOEegpySi87SCZTmXHLZI |
| .exe | | | MS generic-sfx Cabinet File Unpacker (32/64bit MSCFU) (82.5) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (7.3) |
| .exe | | | Win64 Executable (generic) (6.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.5) |
| .exe | | | Win32 Executable (generic) (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:03:13 06:51:25+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap, Net run from swap |
| PEType: | PE32 |
| LinkerVersion: | 7.1 |
| CodeSize: | 35840 |
| InitializedDataSize: | 7680 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6b23 |
| OSVersion: | 5.2 |
| ImageVersion: | 5.2 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 6.3.18.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Spanish (Modern) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Security Update |
| FileVersion: | 1 |
| InternalName: | SFXCAB.EXE |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | SFXCAB.EXE |
| ProductName: | Windows XP Family |
| ProductVersion: | 6.3.0018.0 |
| BuildDate: | 2017/02/11 |
| Appliesto: | Windows XP Service Pack 3 |
| InstallationType: | Full |
| InstallerVersion: | 6.3.13.0 |
| InstallerEngine: | update.exe |
| KBArticleNumber: | 4012598 |
| SupportLink: | http://support.microsoft.com?kbid=4012598 |
| PackageType: | Security Update |
| ProcArchitecture: | x86 |
| Self-ExtractorVersion: | SFXCAB v6.3.18.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2796 | "C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe" | C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Security Update Exit code: 3221226540 Version: 1 Modules
| |||||||||||||||
| 3952 | c:\2e76939fe7a285192eeea87bb1640a\update\update.exe | C:\2e76939fe7a285192eeea87bb1640a\update\update.exe | — | WindowsXP-KB4012598-x86-Custom-ESN.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Programa de instalación de Windows Service Pack Version: 6.3.0013.0 built by: dnsrv Modules
| |||||||||||||||
| 5536 | "C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe" | C:\Users\admin\AppData\Local\Temp\WindowsXP-KB4012598-x86-Custom-ESN.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Security Update Version: 1 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0009._p | binary | |
MD5:18FAC39E34347CE765F64667CC4CB1D6 | SHA256:FB47EDE63F5631607C70E2232202FC9C7BEEAFD236E7AA0A4495A49F17E678E9 | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_.dll | executable | |
MD5:EE207E35AEA4D5DF41D90221E1B66EFA | SHA256:CF64C95E9A2D02967EFC22B00EFB3736156B913A95231EB63C1DF45D43475E64 | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0002._p | binary | |
MD5:580F5DB16D1D55DF006A7AB25D0A5418 | SHA256:D0F715B477CE59B7CC236F80AFAEC32414BFA40FCB57AD2205F7D1422AB752FC | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0005._p | binary | |
MD5:3B8ED7A53CB9E69D7FB67AD9AC22A50A | SHA256:A0D0B8AE09107B2EDB0C9EE4F86FAB693BB271E4F1B870220F422F1F8FBBD76A | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0003._p | binary | |
MD5:4083F5CC488AE66FDE0E334BBA9999F5 | SHA256:3C8D2C403773C382AF78F05654CEE8EA7AEC0384D93C77F1A0083631AE0B677D | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0006._p | binary | |
MD5:D1AD0343E1134FD7F40F979CDA3ABC20 | SHA256:FB8787F9DE24276F79DFA1798BAB9730CBEF753F05904DEFE606CCED41B87357 | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0001._p | binary | |
MD5:DDD832F5CB41C3435345299C1F8CE18C | SHA256:CE6129764B3481E057D218F8C7A01E6175FBE6C4906110BE46AA8EDCE8F3DA0F | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0007._p | binary | |
MD5:A6CEF57522F6102CF0FFC844E5653998 | SHA256:F52BF9B7CDE9B477EEF49768A8198B3BDB102F02815BA730E4BB68FE3B3E98A3 | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\_sfx_0000._p | binary | |
MD5:5E700C6B198EE8C9CBE4E2250A851F20 | SHA256:3236C8BA13F72023F7E287EE68DF4ED78A4F21516697C9DAD97265FBB69941B9 | |||
| 5536 | WindowsXP-KB4012598-x86-Custom-ESN.exe | C:\2e76939fe7a285192eeea87bb1640a\SP3QFE\sprv0c0a.dll | executable | |
MD5:0BAA140CD02E529CD039773A5AEFEA1E | SHA256:BD3326BBB8294794C676BFF5BD371BD72F5F419E247B3EE21BED7290154B0EDD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3984 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
3984 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1684 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3040 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 104.126.37.123:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1176 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1076 | svchost.exe | 23.213.166.81:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |