File name:

HCupdateInstall.exe

Full analysis: https://app.any.run/tasks/25082fec-3da2-4d51-946c-c610b3ff312f
Verdict: Malicious activity
Analysis date: September 30, 2020, 06:51:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

20A01B1EF5D3CACCFAC2930D198CC679

SHA1:

3A6F1220B78AA3C0F2BF1EA00E4C5061205A96FB

SHA256:

D8BD540E92361824FB1F966A3A8680E399363C9E75660785BF358C904139AC36

SSDEEP:

98304:rljrwm1z1m7kmm5SUVhaYLu55rp2aja9wKXgI0uifgup:xnf1mZmNTq5rp2AaiK/Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Engine.exe (PID: 2600)
      • HCupdate.exe (PID: 2896)
      • HCupdate.exe (PID: 2652)
    • Loads dropped or rewritten executable

      • Engine.exe (PID: 2600)
      • HCupdate.exe (PID: 2896)
  • SUSPICIOUS

    • Creates files in the program directory

      • Engine.exe (PID: 2600)
      • HCupdate.exe (PID: 2896)
    • Executable content was dropped or overwritten

      • HCupdateInstall.exe (PID: 3328)
      • Engine.exe (PID: 2600)
    • Creates a software uninstall entry

      • Engine.exe (PID: 2600)
    • Removes files from Windows directory

      • Engine.exe (PID: 2600)
  • INFO

    • Manual execution by user

      • HCupdate.exe (PID: 2652)
      • HCupdate.exe (PID: 2896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
PEType: PE32
LinkerVersion: 2.25
CodeSize: 153088
InitializedDataSize: 33792
UninitializedDataSize: -
EntryPoint: 0x26590
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.1.14.0
ProductVersionNumber: 1.1.14.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Celestron
FileDescription: Celestron Hand Controller Updater
FileVersion: 1.01.0014
InternalName: Celestron HCupdate Setup
LegalCopyright: Copyright © 2004 Celestron
OriginalFileName: HCupdate.exe
ProductName: HCupdate
ProductVersion: 1.01.0014
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
11
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start hcupdateinstall.exe engine.exe cacls.exe no specs cacls.exe no specs cacls.exe no specs cacls.exe no specs cacls.exe no specs cacls.exe no specs hcupdate.exe no specs hcupdate.exe hcupdateinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440C:\Windows\system32\cacls.exe "C:\Program Files\Celestron\HCupdate\UnInstall_HCupdate.exe" /E /C /G Everyone:FC:\Windows\system32\cacls.exeEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1344C:\Windows\system32\cacls.exe "C:\Windows\system32\VSFLEX7.OCX" /E /C /G Everyone:FC:\Windows\system32\cacls.exeEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2384"C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exe" C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exeexplorer.exe
User:
admin
Company:
Celestron
Integrity Level:
MEDIUM
Description:
Celestron Hand Controller Updater
Exit code:
3221226540
Version:
1.01.0014
Modules
Images
c:\systemroot\system32\ntdll.dll
2600C:\Users\admin\AppData\Local\Temp\SETUP_15993\Engine.exe /TH_ID=_3364 /OriginExe="C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exe"C:\Users\admin\AppData\Local\Temp\SETUP_15993\Engine.exe
HCupdateInstall.exe
User:
admin
Company:
Pantaray Research Ltd.
Integrity Level:
HIGH
Description:
Setup/UnInstall Engine
Exit code:
0
Version:
10.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\setup_15993\engine.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cabinet.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2652"C:\Program Files\Celestron\HCupdate\HCupdate.exe" C:\Program Files\Celestron\HCupdate\HCupdate.exeexplorer.exe
User:
admin
Company:
Celestron
Integrity Level:
MEDIUM
Description:
Celestron Hand Controller Updater
Exit code:
3221226540
Version:
1.01.0014
Modules
Images
c:\program files\celestron\hcupdate\hcupdate.exe
c:\systemroot\system32\ntdll.dll
2848C:\Windows\system32\cacls.exe "C:\Windows\system32\MSCOMCT2.OCX" /E /C /G Everyone:FC:\Windows\system32\cacls.exeEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2896"C:\Program Files\Celestron\HCupdate\HCupdate.exe" C:\Program Files\Celestron\HCupdate\HCupdate.exe
explorer.exe
User:
admin
Company:
Celestron
Integrity Level:
HIGH
Description:
Celestron Hand Controller Updater
Exit code:
0
Version:
1.01.0014
Modules
Images
c:\program files\celestron\hcupdate\hcupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3128C:\Windows\system32\cacls.exe "C:\Windows\system32\MSCOMM32.OCX" /E /C /G Everyone:FC:\Windows\system32\cacls.exeEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3164C:\Windows\system32\cacls.exe "C:\Program Files\Celestron\HCupdate" /T /E /C /G Everyone:FC:\Windows\system32\cacls.exeEngine.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3328"C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exe" C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exe
explorer.exe
User:
admin
Company:
Celestron
Integrity Level:
HIGH
Description:
Celestron Hand Controller Updater
Exit code:
0
Version:
1.01.0014
Modules
Images
c:\users\admin\appdata\local\temp\hcupdateinstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
Total events
460
Read events
194
Write events
250
Delete events
16

Modification events

(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:DisplayName
Value:
Celestron HCupdate
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:UnInstallString
Value:
"C:\Program Files\Celestron\HCupdate\UnInstall_HCupdate.exe"
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:QuietUnInstallString
Value:
"C:\Program Files\Celestron\HCupdate\UnInstall_HCupdate.exe" /silent
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:DisplayVersion
Value:
1.1.14
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:Publisher
Value:
Celestron
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:ModifyPath
Value:
"C:\Users\admin\AppData\Local\Temp\HCupdateInstall.exe"
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:URLInfoAbout
Value:
www.Celestron.com
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:NoModify
Value:
0
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:NoRepair
Value:
1
(PID) Process:(2600) Engine.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Celestron HCupdate
Operation:writeName:UserCount
Value:
1
Executable files
17
Suspicious files
57
Text files
78
Unknown types
5

Dropped files

PID
Process
Filename
Type
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00003#___Registering Files -- Please Wait ___
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\Setup.txttext
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\Icon.bmpimage
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00002#License.txttext
MD5:
SHA256:
2600Engine.exeC:\Program Files\Celestron\HCupdate\UnInstall_HCupdate.txt
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00001#HCupdate.exeexecutable
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\Sidebar.bmpimage
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00004#ASYCFILT.DLLexecutable
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00000#HCupdate.chmchm
MD5:
SHA256:
3328HCupdateInstall.exeC:\Users\admin\AppData\Local\Temp\SETUP_15993\00010#OLEAUT32.DLLexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info