File name:

wixtrim-bin.zip

Full analysis: https://app.any.run/tasks/cddd168f-39fb-4658-bc5e-a0bfcc74be7f
Verdict: Malicious activity
Analysis date: May 16, 2025, 09:05:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

5D673E5BC60F7436529AC16A5993BD74

SHA1:

8B8D50E80C22BC89E66C84A03CD65420305C40CD

SHA256:

066261B31C150C307C0F2AEAE6180735C988E8B52123C3BB9B1356FCF8667E80

SSDEEP:

98304:B6FFQE3Or+xTaAP35KO1hNsB8e0l2VBmceVmzyH9uJupHLyrPMMj7Q8SZFFAqK8h:Itqmus9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2692)
    • Starts Visual C# compiler

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 2692)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2692)
    • Reads the Internet Settings

      • WixTrim.exe (PID: 1120)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
    • Reads Microsoft Outlook installation path

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
    • Uses .NET C# to load dll

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 148)
      • csc.exe (PID: 1776)
    • There is functionality for taking screenshot (YARA)

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
    • Reads Internet Explorer settings

      • WixTrim.exe (PID: 1120)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
    • Starts a Microsoft application from unusual location

      • WixTrim.vshost.exe (PID: 3420)
    • Reads security settings of Internet Explorer

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
      • dfsvc.exe (PID: 3204)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2692)
    • Checks supported languages

      • WixTrim.exe (PID: 1120)
      • csc.exe (PID: 148)
      • cvtres.exe (PID: 2728)
      • WixTrim.vshost.exe (PID: 3420)
      • dw20.exe (PID: 3196)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
      • csc.exe (PID: 1776)
      • cvtres.exe (PID: 3580)
    • Reads the computer name

      • WixTrim.exe (PID: 1120)
      • dw20.exe (PID: 3196)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
    • Reads the machine GUID from the registry

      • WixTrim.exe (PID: 1120)
      • csc.exe (PID: 148)
      • cvtres.exe (PID: 2728)
      • dw20.exe (PID: 3196)
      • WixTrim.exe (PID: 3056)
      • csc.exe (PID: 1776)
      • dfsvc.exe (PID: 3204)
      • cvtres.exe (PID: 3580)
    • Manual execution by a user

      • WixTrim.exe (PID: 1120)
      • WixTrim.vshost.exe (PID: 3420)
      • rundll32.exe (PID: 3264)
      • WixTrim.exe (PID: 3056)
    • Checks proxy server information

      • WixTrim.exe (PID: 1120)
      • WixTrim.exe (PID: 3056)
    • Create files in a temporary directory

      • WixTrim.exe (PID: 1120)
      • csc.exe (PID: 148)
      • cvtres.exe (PID: 2728)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
      • cvtres.exe (PID: 3580)
      • csc.exe (PID: 1776)
    • Creates files or folders in the user directory

      • WixTrim.exe (PID: 1120)
      • dw20.exe (PID: 3196)
      • dfsvc.exe (PID: 3204)
      • WixTrim.exe (PID: 3056)
    • Reads Environment values

      • dfsvc.exe (PID: 3204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2006:10:02 12:08:18
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Funnel/Funnel/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe wixtrim.exe csc.exe cvtres.exe no specs wixtrim.vshost.exe dw20.exe no specs rundll32.exe no specs dfsvc.exe wixtrim.exe csc.exe cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\3srrtn0q.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1120"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Exit code:
0
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1776"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\heklk0eh.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
WixTrim.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2692"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\wixtrim-bin.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2728C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESEABA.tmp" "c:\Users\admin\AppData\Local\Temp\CSCEAB9.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
3056"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WixTrim
Version:
1.0.2466.20969
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3196dw20.exe -x -s 376C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exeWixTrim.vshost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Error Reporting Shim
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3204"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
ClickOnce
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\dfsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3264"rundll32.exe" dfshim.dll,ShOpenVerbApplication C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.applicationC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3420"C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.vshost.exe" C:\Users\admin\Desktop\Funnel\Funnel\bin\Release\WixTrim.vshost.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
vshost.exe
Exit code:
3762507597
Version:
8.0.50727.42
Modules
Images
c:\users\admin\desktop\funnel\funnel\bin\release\wixtrim.vshost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
4 081
Read events
3 963
Write events
90
Delete events
28

Modification events

(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2692) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\wixtrim-bin.zip
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
16
Suspicious files
11
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\SandDock.dllexecutable
MD5:B35E0BA22F9D6E99243526A21F8C5352
SHA256:53A8A91FD51535A73C9E473222EC65DE60B1CBBBC50104A51E9EF86BEA5560E4
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WindowsInstaller.dllexecutable
MD5:859287D1D935C40C981F9B49039E6F5C
SHA256:EE866160B08AF12A18441C310808CCC6DF430C345549DF61D9A210A1C16698E2
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.dllexecutable
MD5:78AAB7651A7D5F31DEE4B6A9960C337B
SHA256:5A8CCC0082048A147ADC9C95796D9DFF3FC3F17AB29609BCD8D06C30FA6ECC25
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\Interop.MsmMergeTypeLib.dllexecutable
MD5:6951F0FFA143B7F5781832AF0F1BE6C1
SHA256:2AD15AC0393C9FF0C57BE34B886FE901A5BD72D88EADA42C9E2D3F104D101D53
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\ExtensibleDialogs.pdbbinary
MD5:B88EF8C821EB5884E2A26E5F379946F4
SHA256:F49E73084F9C1136BA72CD4496ADA2725D156AE663E3BBB7E1EC1AD759A5F74D
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\SandDock.xmlxml
MD5:46C3F8DC7DFF0ED21A1AD919AA6A65A4
SHA256:68A1D6BFCA97EFF28D6AF60E4AF91436CBB3099494B06759901546ED0AA98FB3
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\Window Layout.xmlxml
MD5:45D1040989520AF543B1F8F20D02A5A3
SHA256:221AB7AB77313D0AE189266B1B42A618C830132A3F4D4A6A1A439E9A877B6456
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WindowsInstaller.pdbbinary
MD5:DE1296AFE3266D924706D79C8616E604
SHA256:E0474B375432C1D2D1C0864FC6C66BBBAB26164F60014666AB4B33BCE818DCF2
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixDesigner.pdbbinary
MD5:A4C6E4545A0DE0515DBB18F353B3D198
SHA256:5758A52FD84FDFAE85DE5542CC367261BF31BFC818D8C93A2FE32FF37FF9D9B4
2692WinRAR.exeC:\Users\admin\Desktop\Funnel\Funnel\bin\Debug\WixDesigner.dllexecutable
MD5:4116A785F7BD460A01C8C88458F93C82
SHA256:E2D99C5C43BB0AFE4C14772CC636609A948B6B74B3F78BE40D3D7B6220490FBE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
ny.firetongue.com
unknown

Threats

No threats detected
Process
Message
WixTrim.exe
Wix: Loading project XML (.98 KB)
WixTrim.exe
Wix: Adding component <WixSequence Id="AdminUISequence">
WixTrim.exe
Wix: Adding component <WixSequence Id="AdminExecuteSequence">
WixTrim.exe
Wix: Adding component <WixSequence Id="AdvertiseExecuteSequence">
WixTrim.exe
Wix: Adding component <WixSequence Id="InstallExecuteSequence">
WixTrim.exe
Wix: Adding component <WixSequence Id="InstallUISequence">
WixTrim.exe
Wix: Preprocessing <Feature>
WixTrim.exe
Wix: Preprocessing <Media>
WixTrim.exe
Wix: Preprocessing <Directory>
WixTrim.exe
Wix: Parsing <Directory> from <Product id=????????-????-????-????-????????????> in file ""