File name:

WIAACMGR.EXE

Full analysis: https://app.any.run/tasks/7e32756b-f549-482d-aded-8a8a8c0c4b19
Verdict: Malicious activity
Analysis date: October 05, 2023, 07:21:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

30A92409EFE198545CFA4A86457C6C0B

SHA1:

7AE6F1A405230BC23498B9FF1FD137D5653B0C41

SHA256:

0CA9B9469FBD76432DB4418D63C089762D6C1598FAC4A69D02F200D90D6119BB

SSDEEP:

98304:D4/SNsuDZYVFBmUzrz5OnaltQtRdxvqe/5next45UrcZs1FPT3WEigP+7mhUd9c6:peypWIHlPSddAWprTIR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WIAACMGR.EXE (PID: 976)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WIAACMGR.EXE (PID: 976)
    • The process drops C-runtime libraries

      • WIAACMGR.EXE (PID: 976)
    • Loads Python modules

      • WIAACMGR.EXE (PID: 3008)
    • Application launched itself

      • WIAACMGR.EXE (PID: 976)
  • INFO

    • Create files in a temporary directory

      • WIAACMGR.EXE (PID: 976)
    • Checks supported languages

      • WIAACMGR.EXE (PID: 976)
      • WIAACMGR.EXE (PID: 3008)
    • Reads the computer name

      • WIAACMGR.EXE (PID: 976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:10:04 19:04:38+02:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 166400
InitializedDataSize: 94208
UninitializedDataSize: -
EntryPoint: 0xb340
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 10.0.19041.1151
ProductVersionNumber: 10.0.19041.1151
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Windows Picture Acquisition Wizard
FileVersion: 10.0.19041.1151 (WinBuild.160101.0800)
InternalName: WIAACMGR
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: WIAACMGR.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1151
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
31
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wiaacmgr.exe no specs wiaacmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
976"C:\Users\admin\AppData\Local\Temp\WIAACMGR.EXE" C:\Users\admin\AppData\Local\Temp\WIAACMGR.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Picture Acquisition Wizard
Exit code:
0
Version:
10.0.19041.1151 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\wiaacmgr.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3008"C:\Users\admin\AppData\Local\Temp\WIAACMGR.EXE" C:\Users\admin\AppData\Local\Temp\WIAACMGR.EXEWIAACMGR.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Picture Acquisition Wizard
Exit code:
0
Version:
10.0.19041.1151 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\wiaacmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
13
Read events
13
Write events
0
Delete events
0

Modification events

No data
Executable files
18
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\_bz2.pydexecutable
MD5:2D461B41F6E9A305DDE68E9C59E4110A
SHA256:ABBE3933A34A9653A757244E8E55B0D7D3A108527A3E9E8A7F2013B5F2A9EFF4
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\libffi-8.dllexecutable
MD5:08B000C3D990BC018FCB91A1E175E06E
SHA256:135C772B42BA6353757A4D076CE03DBF792456143B42D25A62066DA46144FECE
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\select.pydexecutable
MD5:90FEA71C9828751E36C00168B9BA4B2B
SHA256:5BBBB4F0B4F9E5329BA1D518D6E8144B1F7D83E2D7EAF6C50EEF6A304D78F37D
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\_sqlite3.pydexecutable
MD5:EB6313B94292C827A5758EEA82D018D9
SHA256:6B41DFD7D6AC12AFE523D74A68F8BD984A75E438DCF2DAA23A1F934CA02E89DA
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\libssl-1_1.dllexecutable
MD5:8E8A145E122A593AF7D6CDE06D2BB89F
SHA256:A6A14C1BECCBD4128763E78C3EC588F747640297FFB3CC5604A9728E8EF246B1
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\libcrypto-1_1.dllexecutable
MD5:DFFCAB08F94E627DE159E5B27326D2FC
SHA256:135B115E77479EEDD908D7A782E004ECE6DD900BB1CA05CC1260D5DD6273EF15
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\sqlite3.dllexecutable
MD5:395332E795CB6ABACA7D0126D6C1F215
SHA256:8E8870DAC8C96217FEFF4FA8AF7C687470FBCCD093D97121BC1EAC533F47316C
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\rar.exeexecutable
MD5:9C223575AE5B9544BC3D69AC6364F75E
SHA256:90341AC8DCC9EC5F9EFE89945A381EB701FE15C3196F594D9D9F0F67B4FC2213
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\blank.aesbinary
MD5:B10151A86217EFCBFACD20114DFE376B
SHA256:7C75B7CBD20693DDD60A68D758B580E38703AE45E2675C0002EF9DF90DC3F5AE
976WIAACMGR.EXEC:\Users\admin\AppData\Local\Temp\_MEI9762\unicodedata.pydexecutable
MD5:C2556DC74AEA61B0BD9BD15E9CD7B0D6
SHA256:987A6D21CE961AFEAAA40BA69859D4DD80D20B77C4CA6D2B928305A873D6796D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info