File name:

wootechy-imovego_setup.exe

Full analysis: https://app.any.run/tasks/db19af83-d732-4899-85cd-334744c7b59f
Verdict: Malicious activity
Analysis date: February 07, 2024, 12:34:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F9C829BCAFC838B8A26513CD3EA66C65

SHA1:

135E4474B8ACBB72958700C0C7FC9150C4274EA2

SHA256:

0EA145513F8D96405413B90E5E73BC169A88D6FA258734057C3EAA0F38D80726

SSDEEP:

98304:Mko1IGINXg7TWQeVN5s1DfpjvMAMfF+gXMf7MmlWDGCg0O/rrCTItcMfWD/E8UPF:W7yFLiNF71

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wootechy-imovego_setup.exe (PID: 2628)
  • SUSPICIOUS

    • Reads the Internet Settings

      • wootechy-imovego_setup.exe (PID: 2628)
    • Reads settings of System Certificates

      • wootechy-imovego_setup.exe (PID: 2628)
  • INFO

    • Reads Environment values

      • wootechy-imovego_setup.exe (PID: 2628)
    • Creates files in the program directory

      • wootechy-imovego_setup.exe (PID: 2628)
    • Checks proxy server information

      • wootechy-imovego_setup.exe (PID: 2628)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2796)
      • wootechy-imovego_setup.exe (PID: 2628)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2796)
      • wootechy-imovego_setup.exe (PID: 2628)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2796)
    • Reads product name

      • wootechy-imovego_setup.exe (PID: 2628)
    • Reads the machine GUID from the registry

      • wootechy-imovego_setup.exe (PID: 2628)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:08 08:51:23+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 755712
InitializedDataSize: 3571200
UninitializedDataSize: -
EntryPoint: 0x7f85f
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.9.1
ProductVersionNumber: 4.0.9.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: wootechy-imovego_setup.exe
FileVersion: 4.0.9.1
LegalCopyright: Copyright (C) 2023 WooTechy. All rights reserved.
ProductName: WooTechy iMoveGo
ProductVersion: 4.0.9.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wootechy-imovego_setup.exe wmpnscfg.exe no specs wootechy-imovego_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\AppData\Local\Temp\wootechy-imovego_setup.exe" C:\Users\admin\AppData\Local\Temp\wootechy-imovego_setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
wootechy-imovego_setup.exe
Exit code:
3221226540
Version:
4.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\wootechy-imovego_setup.exe
c:\windows\system32\ntdll.dll
2628"C:\Users\admin\AppData\Local\Temp\wootechy-imovego_setup.exe" C:\Users\admin\AppData\Local\Temp\wootechy-imovego_setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
wootechy-imovego_setup.exe
Exit code:
0
Version:
4.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\wootechy-imovego_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2796"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
3 018
Read events
2 999
Write events
19
Delete events
0

Modification events

(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2628) wootechy-imovego_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
Executable files
0
Suspicious files
0
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Arabic\pr_1.pngimage
MD5:D521836B44DAE6047E51358B28E88C33
SHA256:83B5CFD9AC885B0904CE356CB23E14002BB14377619445FFC2FF76B24672BC23
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Arabic\pr_2.pngimage
MD5:7B07F5398F254F36E6E047BA0C328BFD
SHA256:690FEE8E32C36170263AE1B9EC968FEC09910F8D56FEAC4446D201B892031C02
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Arabic\text.initext
MD5:6D4B954917B8555ACA6E1F581F6F7FDA
SHA256:368275E355DC8FCFDD1A23E8126FB67A2C88FEF86C8F924C3778FB9783F7E4D5
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Chinese\pr_2.pngimage
MD5:7B07F5398F254F36E6E047BA0C328BFD
SHA256:690FEE8E32C36170263AE1B9EC968FEC09910F8D56FEAC4446D201B892031C02
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Arabic\pr_3.pngimage
MD5:7BF745E9F0709E715F12791E450349EC
SHA256:B9D498F9C81733108229E7267B307709BD69529885A4C7786629C22CF5138AC8
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Chinese\pr_1.pngimage
MD5:D521836B44DAE6047E51358B28E88C33
SHA256:83B5CFD9AC885B0904CE356CB23E14002BB14377619445FFC2FF76B24672BC23
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Arabic\UrlInfo.initext
MD5:687A9BE16B0060B6D04CB0D210CD24CC
SHA256:A6821EF2111849B7BCE2BCD5F294DE9C03EE40F3021A4FBDCF889733B3CC16C5
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Chinese\pr_4.pngimage
MD5:0E2AE39E851B46496797BCB664D4B9AF
SHA256:9D280C44872BFF29EFD67BD1C5F260F1B25E5ACC8219941A24835B83B644F63F
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Chinese\text.initext
MD5:6D4B954917B8555ACA6E1F581F6F7FDA
SHA256:368275E355DC8FCFDD1A23E8126FB67A2C88FEF86C8F924C3778FB9783F7E4D5
2628wootechy-imovego_setup.exeC:\Program Files\imyfone_down\wootechy-imovego_setup\language\Chinese\pr_3.pngimage
MD5:7BF745E9F0709E715F12791E450349EC
SHA256:B9D498F9C81733108229E7267B307709BD69529885A4C7786629C22CF5138AC8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
24
DNS requests
2
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2628
wootechy-imovego_setup.exe
HEAD
200
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
2628
wootechy-imovego_setup.exe
HEAD
200
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
GET
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
2628
wootechy-imovego_setup.exe
GET
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
2628
wootechy-imovego_setup.exe
GET
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
2628
wootechy-imovego_setup.exe
GET
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
2628
wootechy-imovego_setup.exe
GET
18.239.69.15:80
http://download.wootechy.com/imovego/wootechy-imovego.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2628
wootechy-imovego_setup.exe
142.250.185.78:443
www.google-analytics.com
GOOGLE
US
whitelisted
2628
wootechy-imovego_setup.exe
18.239.69.15:443
download.wootechy.com
US
unknown
2628
wootechy-imovego_setup.exe
18.239.69.15:80
download.wootechy.com
US
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.185.78
whitelisted
download.wootechy.com
  • 18.239.69.15
  • 18.239.69.83
  • 18.239.69.105
  • 18.239.69.11
unknown

Threats

PID
Process
Class
Message
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2628
wootechy-imovego_setup.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2628
wootechy-imovego_setup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
wootechy-imovego_setup.exe
[0] 0 ~ 49719687,length = 49719688
wootechy-imovego_setup.exe
[1] 49719688 ~ 99439375,length = 49719688
wootechy-imovego_setup.exe
[2] 99439376 ~ 149159063,length = 49719688
wootechy-imovego_setup.exe
[3] 149159064 ~ 198878751,length = 49719688
wootechy-imovego_setup.exe
[4] 198878752 ~ 248598439,length = 49719688