File name:

simplewall-3.8.2-setup.exe

Full analysis: https://app.any.run/tasks/90471fa1-7e91-4ac0-8d43-972a302f9bb1
Verdict: Malicious activity
Analysis date: July 07, 2024, 23:46:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
github
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

977149D5F11ED72CAFBAE43D94D264EE

SHA1:

1549510A741AB7BAA169BB8A70DAFB0848094141

SHA256:

0768E0966B5D0723065A40B272A8F3E6763B918EEB274C4FFA08B54911DD96F8

SSDEEP:

24576:cG0xta5Mip3maf7rdS+SERkgV4PoZ5YJqFhh9l/9icl4ptwPh:N03a5Mip3maTrdS+SERkgVooZ5YJqFh9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates or modifies Windows services

      • simplewall.exe (PID: 2992)
    • Drops the executable file immediately after the start

      • simplewall-3.8.2-setup.exe (PID: 5940)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Executable content was dropped or overwritten

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Creates a software uninstall entry

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Creates or modifies Windows services

      • simplewall.exe (PID: 2992)
    • Reads security settings of Internet Explorer

      • simplewall.exe (PID: 2992)
    • Checks Windows Trust Settings

      • simplewall.exe (PID: 2992)
  • INFO

    • Checks supported languages

      • simplewall-3.8.2-setup.exe (PID: 5940)
      • simplewall.exe (PID: 2992)
    • Creates files or folders in the user directory

      • simplewall.exe (PID: 2992)
      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Checks proxy server information

      • simplewall.exe (PID: 2992)
    • Process checks computer location settings

      • simplewall.exe (PID: 2992)
    • Create files in a temporary directory

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Reads the computer name

      • simplewall-3.8.2-setup.exe (PID: 5940)
      • simplewall.exe (PID: 2992)
    • Creates files in the program directory

      • simplewall-3.8.2-setup.exe (PID: 5940)
    • Reads the software policy settings

      • simplewall.exe (PID: 2992)
    • Reads the machine GUID from the registry

      • simplewall.exe (PID: 2992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:19+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.8.2.0
ProductVersionNumber: 3.8.2.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: https://github.com/henrypp
CompanyName: Henry++
FileDescription: simplewall
FileVersion: 3.8.2
InternalName: simplewall
LegalCopyright: (c) Henry++. All rights reversed.
OriginalFileName: simplewall-3.8.2-setup.exe
ProductName: simplewall
ProductVersion: 3.8.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start simplewall-3.8.2-setup.exe simplewall.exe sppextcomobj.exe no specs slui.exe no specs simplewall-3.8.2-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2992"C:\Program Files\simplewall\simplewall.exe"C:\Program Files\simplewall\simplewall.exe
simplewall-3.8.2-setup.exe
User:
admin
Company:
Henry++
Integrity Level:
HIGH
Description:
simplewall
Version:
3.8.2
Modules
Images
c:\program files\simplewall\simplewall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5396"C:\Users\admin\Desktop\simplewall-3.8.2-setup.exe" C:\Users\admin\Desktop\simplewall-3.8.2-setup.exeexplorer.exe
User:
admin
Company:
Henry++
Integrity Level:
MEDIUM
Description:
simplewall
Exit code:
3221226540
Version:
3.8.2
Modules
Images
c:\users\admin\desktop\simplewall-3.8.2-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5940"C:\Users\admin\Desktop\simplewall-3.8.2-setup.exe" C:\Users\admin\Desktop\simplewall-3.8.2-setup.exe
explorer.exe
User:
admin
Company:
Henry++
Integrity Level:
HIGH
Description:
simplewall
Exit code:
0
Version:
3.8.2
Modules
Images
c:\users\admin\desktop\simplewall-3.8.2-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7112C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7144"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
65 301
Read events
65 235
Write events
48
Delete events
18

Modification events

(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:InstallLocation
Value:
"C:\Program Files\simplewall"
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:UninstallString
Value:
"C:\Program Files\simplewall\uninstall.exe"
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:DisplayName
Value:
simplewall
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\simplewall\simplewall.exe"
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:DisplayVersion
Value:
3.8.2
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:Publisher
Value:
Henry++
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:URLInfoAbout
Value:
https://github.com/henrypp
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:NoModify
Value:
1
(PID) Process:(5940) simplewall-3.8.2-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\simplewall
Operation:writeName:NoRepair
Value:
1
(PID) Process:(2992) simplewall.exeKey:HKEY_CLASSES_ROOT\Local Settings\MrtCache\C:%5CWINDOWS%5CSystemApps%5CMicrosoft.Windows.FilePicker_cw5n1h2txyewy%5Cresources.pri\1da5902d9584b49\a01460c8
Operation:writeName:@{1527c705-839a-4832-9118-54d4Bd6a0c89_10.0.19041.3636_neutral_neutral_cw5n1h2txyewy?ms-resource://FilePicker/Resources/AppxManifest_DisplayName}
Value:
Executable files
4
Suspicious files
11
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Local\Temp\nsqEC7C.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Local\Temp\nsqEC7C.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
5940simplewall-3.8.2-setup.exeC:\Program Files\simplewall\Readme.txttext
MD5:8AB55928E810C004BAA0D03BBAF805B3
SHA256:DC41B4868354789A15A2206F4D0C43132C18C9815808678131AFA971D46E3A25
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Local\Temp\nsqEC7C.tmp\modern-header.bmpimage
MD5:940C56737BF9BB69CE7A31C623D4E87A
SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC
5940simplewall-3.8.2-setup.exeC:\Program Files\simplewall\License.txttext
MD5:3C34AFDC3ADF82D2448F12715A255122
SHA256:0B383D5A63DA644F628D99C33976EA6487ED89AAA59F0B3257992DEAC1171E6B
5940simplewall-3.8.2-setup.exeC:\Program Files\simplewall\History.txttext
MD5:A7011E630FC1E14994803C5231596E4D
SHA256:363D81B601B47FE93A514BA766A9963840C18B783DCBB42A20873D3042E6D7B5
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\simplewall\License.lnklnk
MD5:216CCFE7D8EC0E82E97DB7DA1EE57650
SHA256:CE8AD5AD330CB62EAEFCC6D540458ADFD02257CC70BA8DE11A14AC3E82F343AD
5940simplewall-3.8.2-setup.exeC:\Program Files\simplewall\simplewall.exe.sigbinary
MD5:50338EAECF5DF494A273440F3D530CF9
SHA256:317FBBC17CC96EF0909574AF818F2300A29D57B7C9F67B452A53C8350AD66059
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\simplewall\History.lnklnk
MD5:831D2965A98F1FAABCA7E4586CAD1EE1
SHA256:3DC7117626DAE1BC5084EA6DA0B982D0CFF1B4F1FE390F967E255FF45C5ED680
5940simplewall-3.8.2-setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\simplewall\simplewall.lnklnk
MD5:2CCDE30833844B581C52BB86AC46DE49
SHA256:F2242AB83D732893A95D9F7B892BDAAF58FB378D552F3781169F0D62EC665E1C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
40
DNS requests
17
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1776
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1776
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3760
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
2056
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1776
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2824
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1776
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1776
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
2992
simplewall.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
unknown
4656
SearchApp.exe
104.126.37.139:443
www.bing.com
Akamai International B.V.
DE
unknown
2056
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.108.133
  • 185.199.111.133
  • 185.199.109.133
shared
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.17
  • 40.126.32.68
  • 20.190.160.14
  • 40.126.32.72
  • 40.126.32.74
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
www.bing.com
  • 104.126.37.139
  • 104.126.37.131
whitelisted

Threats

PID
Process
Class
Message
2168
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Process
Message
simplewall.exe
[Error],_r_fs_openfile,0xC000000F,C:\Program Files\KernelLogger\host.exe