File name:

Windows10Upgrade9252 (1).exe

Full analysis: https://app.any.run/tasks/7670f893-c7dd-4bc7-9376-737ce04472b9
Verdict: Malicious activity
Analysis date: June 01, 2025, 18:13:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

C0B25DEF4312FBDDBCC4F01C6C0F5BA6

SHA1:

8D16A183D61233E7D6B6AF7B3CAFC6645AC2ACB1

SHA256:

C0424D0AE06CA1E6E0249B40D33AC40D74075856D543EC0924884664FBA52B79

SSDEEP:

98304:GgjXlctych4cCzJ8k2omX8sUf0ht5f/LyXtcH/B:JjKtych9CzJqXM32jyXE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • Windows10Upgrade9252 (1).exe (PID: 6816)
      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Process drops legitimate windows executable

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Executable content was dropped or overwritten

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Creates a software uninstall entry

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Reads security settings of Internet Explorer

      • Windows10Upgrade9252 (1).exe (PID: 6476)
      • Windows10UpgraderApp.exe (PID: 6028)
    • Reads Microsoft Outlook installation path

      • Windows10UpgraderApp.exe (PID: 6028)
    • Reads Internet Explorer settings

      • Windows10UpgraderApp.exe (PID: 6028)
  • INFO

    • The sample compiled with bulgarian language support

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • The sample compiled with arabic language support

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • The sample compiled with english language support

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Create files in a temporary directory

      • Windows10Upgrade9252 (1).exe (PID: 6476)
      • Windows10UpgraderApp.exe (PID: 6028)
    • Reads the computer name

      • Windows10Upgrade9252 (1).exe (PID: 6476)
      • Windows10UpgraderApp.exe (PID: 6028)
    • Checks supported languages

      • Windows10Upgrade9252 (1).exe (PID: 6476)
      • Windows10UpgraderApp.exe (PID: 6028)
    • Creates files in the program directory

      • Windows10Upgrade9252 (1).exe (PID: 6476)
      • Windows10UpgraderApp.exe (PID: 6028)
    • Process checks computer location settings

      • Windows10Upgrade9252 (1).exe (PID: 6476)
    • Checks proxy server information

      • Windows10UpgraderApp.exe (PID: 6028)
    • Reads the software policy settings

      • Windows10UpgraderApp.exe (PID: 6028)
    • Creates files or folders in the user directory

      • Windows10UpgraderApp.exe (PID: 6028)
    • Reads the machine GUID from the registry

      • Windows10UpgraderApp.exe (PID: 6028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2046:06:23 08:08:25+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.2
CodeSize: 473600
InitializedDataSize: 295424
UninitializedDataSize: -
EntryPoint: 0x71a80
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 10
Subsystem: Windows GUI
FileVersionNumber: 1.4.19041.2183
ProductVersionNumber: 1.4.19041.2183
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Bulgarian
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: WindowsInstallationAssistant
InternalName: WindowsInstallationAssistant.exe
LegalCopyright: © Microsoft Corporation. Всички права запазени.
OriginalFileName: WindowsInstallationAssistant.exe
ProductName: Помощник за инсталиране на Windows
FileVersion: 1.4.19041.2183
ProductVersion: 1.4.19041.2183
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows10upgrade9252 (1).exe windows10upgraderapp.exe slui.exe no specs windows10upgrade9252 (1).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6028"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe
Windows10Upgrade9252 (1).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Installation Assistant
Exit code:
0
Version:
1.4.19041.2183
Modules
Images
c:\program files (x86)\windowsinstallationassistant\windows10upgraderapp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6060C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6476"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252 (1).exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252 (1).exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WindowsInstallationAssistant
Exit code:
0
Version:
1.4.19041.2183
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6816"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252 (1).exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252 (1).exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WindowsInstallationAssistant
Exit code:
3221226540
Version:
1.4.19041.2183
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 415
Read events
1 389
Write events
24
Delete events
2

Modification events

(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:Publisher
Value:
Microsoft Corporation
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayName
Value:
Windows 10 Update Assistant
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayIcon
Value:
"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe"
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayVersion
Value:
1.4.19041.2183
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\WindowsInstallationAssistant\Windows10UpgraderApp.exe" /ForceUninstall
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:EstimatedSize
Value:
5120
(PID) Process:(6476) Windows10Upgrade9252 (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantBox\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0200000000000000
(PID) Process:(6028) Windows10UpgraderApp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantApp\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0200000000000000
(PID) Process:(6028) Windows10UpgraderApp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\UpdateAssistantApp\LocalState\TelemetryUpdateAssistant
Operation:writeName:GlobalEventCounter
Value:
0300000000000000
(PID) Process:(6028) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
16
Suspicious files
20
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\appraiserxp.dllexecutable
MD5:CBB270591C9A1BFB1B10559AB672F705
SHA256:770A9A15E1EB8E2729F23A3D262B55BEF16E4BB7822A2D16EEAC3DB35A116D7F
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\GetCurrentRollback.EXEexecutable
MD5:D705A34A869AC46E3F07C9BE3EA1693A
SHA256:0436DEDA2DBBD46D74E4A83B5897BA26A3EC35A9AB77D4B46E7477D9CDD213B8
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\Windows10UpgraderApp.exeexecutable
MD5:AB38A78503D8AD3CE7D69F937D71A99C
SHA256:F635CD1996967C2297E3F20C4838D2F45D1535CFEA38971909683E26158FB782
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\downloader.dllexecutable
MD5:5B62AD6AE42F32806062AD1BCB3E2DE5
SHA256:96F7B268820511ABEEB6BBFAD0918CF9161366BC2F558EF7F011331E7DE1D6F3
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\resources\ux\default.csstext
MD5:7F5FCAC447CC2150AC90020F8DC8C98B
SHA256:453D8CA4F52FB8FD40D5B4596596911B9FB0794BB89FBF9B60DC27AF3EAA2850
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\resources\ux\default_sunvalley.htmhtml
MD5:66B63E270CC9186F7186B316606F541F
SHA256:00F8F3E4534146858326D6D2524F3360DFC9E5D149E207D61CABAC17AD7A5F9F
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\ESDHelper.dllexecutable
MD5:C61DCF4DB82482A4498FCCA646A6C640
SHA256:C98289454CDCB2266E82204AF73A799B09458A899CDD8366E24FBB613273C0FF
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\GetCurrentDeploy.dllexecutable
MD5:410FAC98056AB0BE74E4539A4C0EAAFF
SHA256:09EC6DC5CB94160B2C4D9F1F4224A7DC1951F227DD311ACB1BC4335F23DB9B24
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\resources\ux\logo.pngimage
MD5:AFEED45DF4D74D93C260A86E71E09102
SHA256:F5FB1E3A7BCA4E2778903E8299C63AB34894E810A174B0143B79183C0FA5072F
6476Windows10Upgrade9252 (1).exeC:\Users\admin\AppData\Local\Temp\WXUFB35.tmp\resources\ux\loading.gifimage
MD5:1A276CB116BDECE96ADF8E32C4AF4FEE
SHA256:9D9A156C6CA2929F0F22C310260723E28428CB38995C0F940F2617B25E15B618
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
32
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6028
Windows10UpgraderApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7896
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7896
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6028
Windows10UpgraderApp.exe
95.100.186.9:443
go.microsoft.com
AKAMAI-AS
FR
whitelisted
6028
Windows10UpgraderApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6028
Windows10UpgraderApp.exe
23.58.110.83:443
download.microsoft.com
AKAMAI-AS
IN
whitelisted
6544
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.22
  • 20.190.160.66
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.20
  • 20.190.160.4
  • 40.126.32.140
  • 20.190.160.5
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.110
whitelisted
go.microsoft.com
  • 95.100.186.9
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
download.microsoft.com
  • 23.58.110.83
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info