File name:

WeChat.exe

Full analysis: https://app.any.run/tasks/7568ebd2-66d5-4cde-9940-9e28a0dfd08a
Verdict: Malicious activity
Analysis date: January 04, 2024, 13:12:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A0BD608CEAEAF94B99F28D79041382F5

SHA1:

23ED9DF3979F436C693AD4881935AA411B56FD6A

SHA256:

11DE48379DB2A0C14204EB068D20C73573D3E0B243C78B1A104FD92D00D007D0

SSDEEP:

98304:sieGMi9G4vFCS5MmdAr4wldU8bKavwFjy96ZR12yyi6jKn9aBL/pobTrFgaKIGq/:DjkhSD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • WeChat.exe (PID: 2124)
  • INFO

    • Drops the executable file immediately after the start

      • WeChat.exe (PID: 2124)
    • Reads the computer name

      • WeChat.exe (PID: 2124)
    • Reads the machine GUID from the registry

      • WeChat.exe (PID: 2124)
    • Checks supported languages

      • WeChat.exe (PID: 2124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:19 10:31:29+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 950272
InitializedDataSize: 1613824
UninitializedDataSize: -
EntryPoint: 0x4a1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wechat.exe

Process information

PID
CMD
Path
Indicators
Parent process
2124"C:\Users\admin\AppData\Local\Temp\WeChat.exe" C:\Users\admin\AppData\Local\Temp\WeChat.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\wechat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 923
Read events
2 908
Write events
15
Delete events
0

Modification events

(PID) Process:(2124) WeChat.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2124) WeChat.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
10
DNS requests
3
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
WeChat.exe
GET
301
138.113.101.20:80
http://www.ip138.com/
unknown
unknown
2124
WeChat.exe
GET
200
163.171.146.42:80
http://2023.ip138.com/
unknown
html
917 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2124
WeChat.exe
138.113.101.20:80
www.ip138.com
QUANTILNETWORKS
US
unknown
2124
WeChat.exe
138.113.101.20:443
www.ip138.com
QUANTILNETWORKS
US
unknown
2124
WeChat.exe
163.171.146.42:80
2023.ip138.com
QUANTILNETWORKS
US
unknown
2124
WeChat.exe
82.157.254.217:80
Shenzhen Tencent Computer Systems Company Limited
CN
unknown

DNS requests

Domain
IP
Reputation
www.ip138.com
  • 138.113.101.20
malicious
2023.ip138.com
  • 163.171.146.42
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
Process
Message
WeChat.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2010 Oreans Technologies --- ------------------------------------------------