| URL: | https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe |
| Full analysis: | https://app.any.run/tasks/acc3e902-9dad-4584-80c4-d9a2c44f912d |
| Verdict: | Malicious activity |
| Analysis date: | November 13, 2024, 11:37:19 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MD5: | BE27889697699E5A153485700F962C69 |
| SHA1: | 5C266FF0C0723FA71DE0979374BAF37A240EB657 |
| SHA256: | E89E1A4C58F19523A4265A76D765D36B5E52A9986A10C603B9DCC8A5943AFB87 |
| SSDEEP: | 3:N8UxXYL2SKIfohDNSlTXK2aA:2UxoL2SKMo6XGA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 512 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2832 -childID 1 -isForBrowser -prefsHandle 2824 -prefMapHandle 2820 -prefsLen 26798 -prefMapSize 244343 -jsInitHandle 1316 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {503e4128-b736-4fe4-8c9f-c6aa80a2231b} 6624 "\\.\pipe\gecko-crash-server-pipe.6624" 207a6585150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 848 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | DPMService.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1048 | "C:\WINDOWS\system32\PnPutil.exe" /add-driver "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents\WacHIDRouterISDU.inf" /install | C:\Windows\System32\pnputil.exe | Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1172 | "C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\database" "--metrics-dir=C:\Users\admin\AppData\Roaming\Dell\Dell Peripheral Manager\DPM\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x648,0x678,0x67c,0x674,0x684,0x7ff6edbcb658,0x7ff6edbcb670,0x7ff6edbcb688 | C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe | — | DPM.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1200 | "C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe" "--database=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\database" "--metrics-dir=C:\ProgramData\Dell\Dell Peripheral Manager\DPMService\Log\\crashdumps\metrics" --annotation=VERSION_FULL_SEMVER=1.7.7 --annotation=VERSION_SEMVER=1.7.7 --initial-client-data=0x504,0x52c,0x530,0x528,0x538,0x7ff7a07f1958,0x7ff7a07f1970,0x7ff7a07f1988 | C:\Program Files\Dell\Dell Peripheral Manager\DPMCrashHandler.exe | — | DPMService.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 1576 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://clientperipherals.dell.com/DPeM/updates/v2/x64/FullInstaller/Setup.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2684 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d49fcc1f-1195-5041-b4f4-14bdcbc806ec}\WacHIDRouterISDF.inf" "9" "423699577" "00000000000001EC" "WinSta0\Default" "00000000000001FC" "208" "C:\Program Files\Dell\Dell Peripheral Manager\temp\WacomComponents" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2784 | "C:\Users\admin\Downloads\Setup.exe" | C:\Users\admin\Downloads\Setup.exe | firefox.exe | ||||||||||||
User: admin Company: Dell Integrity Level: HIGH Description: Dell Peripheral Manager Installer Exit code: 0 Version: ${FILE_VERSION} Modules
| |||||||||||||||
| 3024 | "C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe" -regserver | C:\Program Files\Dell\Dell Peripheral Manager\DPMService.exe | — | Setup.exe | |||||||||||
User: admin Company: Dell Inc. Integrity Level: HIGH Description: Dell Peripheral Manager Service Exit code: 0 Version: 1.7.7 Modules
| |||||||||||||||
| 3620 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | pnputil.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6624) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (6624) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (1048) pnputil.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver |
| Operation: | write | Name: | Owners |
Value: oem8.inf | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPMDriver\Parameters\Wdf |
| Operation: | write | Name: | KmdfLibraryVersion |
Value: 1.15 | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemRoot%/System32/drivers/DPMDriver.sys |
| Operation: | write | Name: | Owners |
Value: oem8.inf | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver |
| Operation: | write | Name: | Configuration |
Value: DPMDriver_Device.NT | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver |
| Operation: | write | Name: | Manufacturer |
Value: %manufacturername% | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Descriptors\Root\DPMDriver |
| Operation: | write | Name: | Description |
Value: %dpmdriver.devicedesc% | |||
| (PID) Process: | (8168) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\DriverDatabase\DriverPackages\dpmdriver.inf_amd64_7ad3ee1bc9d7141b\Configurations\DPMDriver_Device.NT |
| Operation: | write | Name: | Service |
Value: DPMDriver | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:C09FF302D57C404B61E6A89B0B9F36E7 | SHA256:6A5B4F82595799346D0E501FE6CC8629E0FD6ED27B74D0E6CB5073DDB2E3C40B | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db | binary | |
MD5:FF680518BF4ABD23AE2D25C24B050864 | SHA256:2A743CABB6714DF481CC77B8B0DDB6B3B87A1D2DD006ACE99410BC256FAC5F50 | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:8BD997F90ECBED0083C0F3B144B2F721 | SHA256:25EC68792A8D0944AEC3A5C97A589369B3CEF2F6F5F2721E09A1570C270E8255 | |||
| 6624 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6624 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
6624 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6624 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
944 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6624 | firefox.exe | POST | 200 | 2.16.202.121:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6624 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6624 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6624 | firefox.exe | POST | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/ | unknown | — | — | whitelisted |
5332 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2660 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5488 | MoUsoCoreWorker.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 2.23.209.173:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6944 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6624 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6624 | firefox.exe | 2.19.126.160:443 | clientperipherals.dell.com | Akamai International B.V. | DE | whitelisted |
6624 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
clientperipherals.dell.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
a664.dscd.akamai.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
Process | Message |
|---|---|
DPM.exe | C:\Users\Public\Desktop\Adobe Acrobat.lnk |
DPM.exe | C:\Users\Public\Desktop\Skype.lnk |
DPM.exe | C:\Users\Public\Desktop\Microsoft Edge.lnk |
DPM.exe | C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe |
DPM.exe | C:\Users\Public\Desktop\VLC media player.lnk |
DPM.exe | real path |
DPM.exe | real path |
DPM.exe | C:\Program Files\Mozilla Firefox\firefox.exe |
DPM.exe | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
DPM.exe | C:\Users\Public\Desktop\CCleaner.lnk |