File name:

Windows10Upgrade9252.exe

Full analysis: https://app.any.run/tasks/d4e77d54-fe45-4989-8c8c-c4a8016b031e
Verdict: Malicious activity
Analysis date: September 27, 2019, 14:33:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BC9CD9E254FCAD2D8D2EF56245842F48

SHA1:

446ABF76D2E9792E735D3210C9BF1B80F825B8FD

SHA256:

EC639A3892DC210711DB11893E06AD884A6E1B5281F3005BCC0110437657BB36

SSDEEP:

98304:sq/jZSyRTB8jNafLVIH2/rvyXt1ZmGToSZ0TBHXOh5vH3Caht5fDC3jKCs9gLnhS:sq7ZSyRTB8QCH2/TMf7srH+b/yUDC3jK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Windows10UpgraderApp.exe (PID: 2096)
    • Loads dropped or rewritten executable

      • Windows10UpgraderApp.exe (PID: 2096)
    • Changes settings of System certificates

      • Windows10UpgraderApp.exe (PID: 2096)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Windows10Upgrade9252.exe (PID: 3512)
    • Creates files in the program directory

      • Windows10Upgrade9252.exe (PID: 3512)
    • Reads internet explorer settings

      • Windows10UpgraderApp.exe (PID: 2096)
    • Creates a software uninstall entry

      • Windows10Upgrade9252.exe (PID: 3512)
    • Adds / modifies Windows certificates

      • Windows10UpgraderApp.exe (PID: 2096)
    • Low-level read access rights to disk partition

      • Windows10UpgraderApp.exe (PID: 2096)
    • Creates files in the Windows directory

      • Windows10UpgraderApp.exe (PID: 2096)
      • Windows10Upgrade9252.exe (PID: 3512)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:08:19 21:24:05+02:00
PEType: PE32
LinkerVersion: 10.1
CodeSize: 436736
InitializedDataSize: 169984
UninitializedDataSize: -
EntryPoint: 0x4ef6e
OSVersion: 6.2
ImageVersion: 6.2
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.9200.22866
ProductVersionNumber: 1.4.9200.22866
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Arabic
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: مساعد تحديث Windows 10
InternalName: Windows10Upgrader.exe
LegalCopyright: Copyright © Microsoft Corporation. All rights reserved.
OriginalFileName: Windows10Upgrader.exe
ProductName: Windows 10 Update Assistant
FileVersion: 1.4.9200.22866
ProductVersion: 1.4.9200.22866

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 19-Aug-2019 19:24:05
Detected languages:
  • Arabic - Saudi Arabia
  • Bulgarian - Bulgaria
  • Chinese - Hong Kong SAR
  • Chinese - PRC
  • Chinese - Taiwan
  • Croatian - Croatia
  • Czech - Czech Republic
  • Danish - Denmark
  • Dutch - Netherlands
  • English - United Kingdom
  • English - United States
  • Estonian - Estonia
  • Finnish - Finland
  • French - France
  • German - Germany
  • Greek - Greece
  • Hebrew - Israel
  • Hungarian - Hungary
  • Italian - Italy
  • Japanese - Japan
  • Korean - Korea
  • Latvian - Latvia
  • Lithuanian - Lithuania
  • Norwegian - Norway (Bokmal)
  • Polish - Poland
  • Portuguese - Brazil
  • Portuguese - Portugal
  • Romanian - Romania
  • Russian - Russia
  • Serbian - Serbia (Latin)
  • Slovak - Slovakia
  • Slovenian - Slovenia
  • Spanish - Spain (International sort)
  • Swedish - Sweden
  • Thai - Thailand
  • Turkish - Turkey
  • Ukrainian - Ukraine
Debug artifacts:
  • upgraderstub.pdb
CompanyName: Microsoft Corporation
FileDescription: Asistente para actualización a Windows 10
InternalName: Windows10Upgrader.exe
LegalCopyright: Copyright © Microsoft Corporation. Todos los derechos reservados.
OriginalFilename: Windows10Upgrader.exe
ProductName: Asistente para actualización a Windows 10
FileVersion: 1.4.9200.22866
ProductVersion: 1.4.9200.22866

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 19-Aug-2019 19:24:05
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0006A8FC
0x0006AA00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.59148
.data
0x0006C000
0x00001EAC
0x00000C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.42686
.idata
0x0006E000
0x00001956
0x00001A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.5769
.boxloadV
0x00070000
0x00000056
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
0.93435
.rsrc
0x00071000
0x00022000
0x00021800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.31411
.reloc
0x00093000
0x00005624
0x00005800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
5.02555

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.9036
1900
Latin 1 / Western European
English - United States
RT_MANIFEST
2
0.903812
36
Latin 1 / Western European
Chinese - Hong Kong SAR
RT_STRING
3
3.13127
1162
Latin 1 / Western European
Spanish - Spain (International sort)
RT_STRING
4
2.30706
80
Latin 1 / Western European
Lithuanian - Lithuania
RT_STRING
5
4.59938
1384
Latin 1 / Western European
English - United States
RT_ICON
6
2.79537
16936
Latin 1 / Western European
English - United States
RT_ICON
7
3.12441
9640
Latin 1 / Western European
English - United States
RT_ICON
8
3.00143
6760
Latin 1 / Western European
English - United States
RT_ICON
9
3.41612
4264
Latin 1 / Western European
English - United States
RT_ICON
10
3.35245
2440
Latin 1 / Western European
English - United States
RT_ICON

Imports

ADVAPI32.dll
Cabinet.dll
KERNEL32.dll
PSAPI.DLL
RPCRT4.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
msvcrt.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start windows10upgrade9252.exe windows10upgraderapp.exe windows10upgrade9252.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2096"C:\Windows10Upgrade\Windows10UpgraderApp.exe" C:\Windows10Upgrade\Windows10UpgraderApp.exe
Windows10Upgrade9252.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
0
Version:
1.4.9200.22866
Modules
Images
c:\windows10upgrade\windows10upgraderapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3036"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows 10 Update Assistant
Exit code:
3221226540
Version:
1.4.9200.22866
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252.exe
c:\systemroot\system32\ntdll.dll
3512"C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe" C:\Users\admin\AppData\Local\Temp\Windows10Upgrade9252.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows 10 Update Assistant
Exit code:
0
Version:
1.4.9200.22866
Modules
Images
c:\users\admin\appdata\local\temp\windows10upgrade9252.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
359
Read events
302
Write events
56
Delete events
1

Modification events

(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:Publisher
Value:
Microsoft Corporation
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayName
Value:
Windows 10 Update Assistant
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayIcon
Value:
"C:\Windows10Upgrade\Windows10UpgraderApp.exe"
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:DisplayVersion
Value:
1.4.9200.22866
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:UninstallString
Value:
"C:\Windows10Upgrade\Windows10UpgraderApp.exe" /Uninstall
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5C69738-B486-402E-85AC-2456D98A64E4}
Operation:writeName:EstimatedSize
Value:
5120
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3512) Windows10Upgrade9252.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2096) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2096) Windows10UpgraderApp.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
54
Suspicious files
0
Text files
161
Unknown types
7

Dropped files

PID
Process
Filename
Type
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\cosquery.dllexecutable
MD5:F6F6913BE848F72FF7D012FE77AB07EE
SHA256:BB186553C6E7E76DE7A45773770C59833DCDF4F74B94F8F47C2514057418450C
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\DevInv.dllexecutable
MD5:261AC59F28E83677D1DF6236E6AF5A9B
SHA256:948FA2A3FC2644912CA041C4F7B61D8F5DA2504817DE0DE03FD4C44780B715B2
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\Windows10UpgraderApp.exeexecutable
MD5:D99C13032F46D987A238CE139F6713AA
SHA256:5A81BC1F44C98132A7A372EC04615AE11CAD0A7C0D61B47C4CEA350EDFEBC379
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\wimgapi.dllexecutable
MD5:5F2711DD78B1B99312783AD964222FA1
SHA256:F15B04C8C17C619CB6F1FBA43DC04E7FDF2D91785ADDCAA39497197BCA3D162F
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\DW20.EXEexecutable
MD5:1F72306A11D4DE3233EA19250469A9EE
SHA256:226210E3DFF8FB5691F17BCDE628A08953D422D0D9CDEB16EFC02F3A4D5AF00D
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\GetCurrentOOBE.dllexecutable
MD5:517C696E458FD3BBD57511C14F833936
SHA256:D90B5FC574B6AAE651234D71A7E9C24D1D796794528154E727CC12F172C62240
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\esdstub.dllexecutable
MD5:0B967EFB2CA72FA81AB44C58DEC0A551
SHA256:67596BE8D7D893B0E97407D59E83795DA9F5927AA6862505FFB86494AA261341
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\GetCurrentRollback.EXEexecutable
MD5:FE109FFAECA87EAE3CF68095F98E0EC2
SHA256:11A8C32CB5B987C26562153C896A3BE7AC15881972295074471805A78084861B
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\windlp.dllexecutable
MD5:E7337572EA254AEB42122959FCD5F58F
SHA256:732A0EC5A855258C636670685E141680765E4263E1649E62501B24127061314D
3512Windows10Upgrade9252.exeC:\Users\admin\AppData\Local\Temp\WXU55FD.tmp\downloader.dllexecutable
MD5:7FFA257DAADF00C874ABFD26BABA7E7B
SHA256:3A708EC95D5112F409C92AC0F20181A6308B9D5FCB680EF896B2B77F7A7B93F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2096
Windows10UpgraderApp.exe
GET
205.185.216.42:80
http://dl.delivery.mp.microsoft.com/filestreamingservice/files/4e9b9e0e-8c5f-4163-97fa-a767d842904a/18362.175.190612-0046.19h1_release_svc_refresh_CLIENTCONSUMER_RET_x86FRE_en-us.esd
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2096
Windows10UpgraderApp.exe
2.19.38.59:443
go.microsoft.com
Akamai International B.V.
whitelisted
2.19.38.59:443
go.microsoft.com
Akamai International B.V.
whitelisted
2096
Windows10UpgraderApp.exe
2.18.233.19:443
download.microsoft.com
Akamai International B.V.
whitelisted
2096
Windows10UpgraderApp.exe
205.185.216.42:80
dl.delivery.mp.microsoft.com
Highwinds Network Group, Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 2.19.38.59
whitelisted
download.microsoft.com
  • 2.18.233.19
whitelisted
dl.delivery.mp.microsoft.com
  • 205.185.216.42
  • 205.185.216.10
whitelisted

Threats

No threats detected
No debug info