File name:

Windows10Upgrade9252.exe

Full analysis: https://app.any.run/tasks/3eb2491e-6807-432d-8d80-52c1262a6bee
Verdict: Malicious activity
Analysis date: December 06, 2024, 01:24:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

C0B25DEF4312FBDDBCC4F01C6C0F5BA6

SHA1:

8D16A183D61233E7D6B6AF7B3CAFC6645AC2ACB1

SHA256:

C0424D0AE06CA1E6E0249B40D33AC40D74075856D543EC0924884664FBA52B79

SSDEEP:

98304:GgjXlctych4cCzJ8k2omX8sUf0ht5f/LyXtcH/B:JjKtych9CzJqXM32jyXE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • Windows10Upgrade9252.exe (PID: 3884)
      • Windows10Upgrade9252.exe (PID: 4504)
    • Process drops legitimate windows executable

      • Windows10Upgrade9252.exe (PID: 3884)
    • Executable content was dropped or overwritten

      • Windows10Upgrade9252.exe (PID: 3884)
    • Creates a software uninstall entry

      • Windows10Upgrade9252.exe (PID: 3884)
    • Reads security settings of Internet Explorer

      • Windows10Upgrade9252.exe (PID: 3884)
      • Windows10UpgraderApp.exe (PID: 3172)
    • Reads Microsoft Outlook installation path

      • Windows10UpgraderApp.exe (PID: 3172)
    • Reads Internet Explorer settings

      • Windows10UpgraderApp.exe (PID: 3172)
    • Checks Windows Trust Settings

      • Windows10UpgraderApp.exe (PID: 3172)
  • INFO

    • Creates files or folders in the user directory

      • Windows10UpgraderApp.exe (PID: 3172)
    • Checks supported languages

      • Windows10Upgrade9252.exe (PID: 3884)
      • Windows10UpgraderApp.exe (PID: 3172)
    • Reads the computer name

      • Windows10Upgrade9252.exe (PID: 3884)
      • Windows10UpgraderApp.exe (PID: 3172)
    • Process checks computer location settings

      • Windows10Upgrade9252.exe (PID: 3884)
    • Creates files in the program directory

      • Windows10UpgraderApp.exe (PID: 3172)
    • Create files in a temporary directory

      • Windows10UpgraderApp.exe (PID: 3172)
    • The process uses the downloaded file

      • Windows10UpgraderApp.exe (PID: 3172)
    • Reads the machine GUID from the registry

      • Windows10UpgraderApp.exe (PID: 3172)
    • Reads the software policy settings

      • Windows10UpgraderApp.exe (PID: 3172)
    • Checks proxy server information

      • Windows10UpgraderApp.exe (PID: 3172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2046:06:23 08:08:25+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.2
CodeSize: 473600
InitializedDataSize: 295424
UninitializedDataSize: -
EntryPoint: 0x71a80
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 1.4.19041.2183
ProductVersionNumber: 1.4.19041.2183
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Bulgarian
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: WindowsInstallationAssistant
InternalName: WindowsInstallationAssistant.exe
LegalCopyright: © Microsoft Corporation. Всички права запазени.
OriginalFileName: WindowsInstallationAssistant.exe
ProductName: Помощник за инсталиране на Windows
FileVersion: 1.4.19041.2183
ProductVersion: 1.4.19041.2183
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start windows10upgrade9252.exe windows10upgraderapp.exe windows10upgrade9252.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3172"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe
Windows10Upgrade9252.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Installation Assistant
Version:
1.4.19041.2183
Modules
Images
c:\program files (x86)\windowsinstallationassistant\windows10upgraderapp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3884"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WindowsInstallationAssistant
Exit code:
0
Version:
1.4.19041.2183
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4504"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WindowsInstallationAssistant
Exit code:
3221226540
Version:
1.4.19041.2183
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 255
Read events
1 237
Write events
18
Delete events
0

Modification events

(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:Publisher
Value:
Microsoft Corporation
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayName
Value:
Windows 10 Update Assistant
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayIcon
Value:
"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe"
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayVersion
Value:
1.4.19041.2183
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" /ForceUninstall
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:EstimatedSize
Value:
5120
(PID) Process:(3884) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantBox\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0200000000000000
(PID) Process:(3172) Windows10UpgraderApp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantApp\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0200000000000000
(PID) Process:(3172) Windows10UpgraderApp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantApp\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0300000000000000
(PID) Process:(3172) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
16
Suspicious files
14
Text files
29
Unknown types
1

Dropped files

PID
Process
Filename
Type
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\Windows10UpgraderApp.exeexecutable
MD5:AB38A78503D8AD3CE7D69F937D71A99C
SHA256:F635CD1996967C2297E3F20C4838D2F45D1535CFEA38971909683E26158FB782
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\WinDlp.dllexecutable
MD5:87BC3D50A51CAE672F2E3ED50691E5B5
SHA256:896994DF8E63229DC8C860F40CFD92C6FCEA6E684EC0D51F111C812EEE7349BA
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\GetCurrentDeploy.dllexecutable
MD5:410FAC98056AB0BE74E4539A4C0EAAFF
SHA256:09EC6DC5CB94160B2C4D9F1F4224A7DC1951F227DD311ACB1BC4335F23DB9B24
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\logo.pngimage
MD5:AFEED45DF4D74D93C260A86E71E09102
SHA256:F5FB1E3A7BCA4E2778903E8299C63AB34894E810A174B0143B79183C0FA5072F
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\default.htmhtml
MD5:B2A06AF2867A2BB3D4B198A22F7936B3
SHA256:40F468006AB37EF4FCC54C5FF25005644F15D696F1269F67B450C9E3CE5E8D23
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\eula.csstext
MD5:B81D1E97C529AC3D7F5A699AFCE27080
SHA256:35C6E30C7954F7E4B806C883576218621E2620166C8940701B33157BDD0BA225
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\pass.pngimage
MD5:5A7499645619886BFE949250E1807415
SHA256:DB27BAD6E59128D58031706C83210AE780A9261E01AF6FDE6323BD30F7A97B12
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\default.csstext
MD5:7F5FCAC447CC2150AC90020F8DC8C98B
SHA256:453D8CA4F52FB8FD40D5B4596596911B9FB0794BB89FBF9B60DC27AF3EAA2850
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\default_sunvalley.htmhtml
MD5:66B63E270CC9186F7186B316606F541F
SHA256:00F8F3E4534146858326D6D2524F3360DFC9E5D149E207D61CABAC17AD7A5F9F
3884Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU615D.tmp\resources\ux\bullet.pngimage
MD5:062F3F1FFF1DEB4E8ABE7A16C8AA6398
SHA256:F67AC334038896E37CA126AC4DBD1FFF51CD0FFE8C99ED1CB709D64864B72392
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
36
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3172
Windows10UpgraderApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7056
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7056
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6532
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
2.23.209.182:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1852
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
3172
Windows10UpgraderApp.exe
23.32.186.57:443
go.microsoft.com
AKAMAI-AS
BR
whitelisted
3172
Windows10UpgraderApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3172
Windows10UpgraderApp.exe
23.212.89.111:443
download.microsoft.com
AKAMAI-AS
MX
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.130
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.181.156
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
download.microsoft.com
  • 23.212.89.111
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.73
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.4
  • 20.190.159.0
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info