windows10upgrade20517.exe

Windows 10 Upgrade Assistant

Microsoft Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from download.microsoft.com and multiple other hosts.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Windows 10 Upgrade Assistant

Version:
1.4.9200.17329

MD5:
4675e25b59f46bb49c82fd400ac6e644

SHA-1:
e1618742e0a6c5e907c65a30e5624bbc51c3566b

SHA-256:
ce9f6f7c07c513df2f2622c194ced83a234c08476bb1ce90d6413a26b4e04d39

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/28/2024 3:51:01 PM UTC  (today)

File size:
5.5 MB (5,783,056 bytes)

Product version:
1.4.9200.17329

Copyright:
Copyright © Microsoft Corporation. All rights reserved.

Original file name:
Windows10Upgrader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\2glhaomk\windows10upgrade20517.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
6/5/2015 12:42:45 AM

Valid to:
9/5/2016 12:42:45 AM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
330000010A2C79AED7797BA6AC00010000010A

File PE Metadata
Compilation timestamp:
6/16/2016 9:20:13 AM

OS version:
6.2

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
98304:kBs/zPJaAPyCmDUXS++KUDGkrXRszrzQ+X1ikuneHjKZE5zTQ8vH3CKSyvORwh:1bPJaSyCO++FGkrXRsbPune/5Y8/y4vR

Entry address:
0x4C4B5

Entry point:
E8, 37, 0A, 00, 00, E9, 0D, FE, FF, FF, CC, CC, CC, CC, CC, 3B, 0D, 20, 80, 46, 00, 75, 03, C2, 00, 00, E9, 05, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 81, EC, 24, 03, 00, 00, A3, 00, 8B, 46, 00, 89, 0D, FC, 8A, 46, 00, 89, 15, F8, 8A, 46, 00, 89, 1D, F4, 8A, 46, 00, 89, 35, F0, 8A, 46, 00, 89, 3D, EC, 8A, 46, 00, 66, 8C, 15, 18, 8B, 46, 00, 66, 8C, 0D, 0C, 8B, 46, 00, 66, 8C, 1D, E8, 8A, 46, 00, 66, 8C, 05, E4, 8A, 46, 00, 66, 8C, 25, E0, 8A, 46, 00, 66, 8C, 2D, DC, 8A, 46, 00, 9C, 8F, 05, 10...
 
[+]

Entropy:
7.9469  (probably packed)

Code size:
411.5 KB (421,376 bytes)

The file windows10upgrade20517.exe has been seen being distributed by the following 19 URLs.

http://download.microsoft.com/download/0/4/7/047889D0-578C-4A44-A38F-7F30A6CB3809/.../Windows10Upgrade20662.exe

http://download.microsoft.com/download/0/4/7/047889D0-578C-4A44-A38F-7F30A6CB3809/.../Windows10Upgrade20660.exe

http://download.microsoft.com/download/0/4/7/047889D0-578C-4A44-A38F-7F30A6CB3809/.../Windows10Upgrade24490.exe

C:\Users\User\Downloads\Windows10Upgrade9194.exe

http://download.microsoft.com/download/0/4/7/047889D0-578C-4A44-A38F-7F30A6CB3809/.../Windows10Upgrade20522.exe

http://222.165.175.166/data/db4f50306bd5421f/download.microsoft.com/download/0/4/7/047889D0-578C-4A44-A38F-7F30A6CB3809/.../Windows10Upgrade20528.exe