File name:

wnwb_8.0.5.0.exe.zip

Full analysis: https://app.any.run/tasks/68c9074d-d26d-4b3f-8800-fb92c6f4dbf8
Verdict: Malicious activity
Analysis date: March 19, 2024, 13:41:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

C21AAD13EB4DE61D9320F66AC17DF767

SHA1:

12677F5737309DDAE4D0DB12652BED3F0883AF5D

SHA256:

1449F45D590A88F77A37FA4BC7CF94C9C718D8DE53C6863732C3FB8FAB516AF4

SSDEEP:

393216:XIe97JD5YaiULWVfjjQ7SEAEqe6AAjc9k7:4g7EVy00KEqe6AAj77

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2860)
      • wnwb_8.0.5.0.exe (PID: 1992)
      • WnImeReg32.exe (PID: 2724)
      • WnImeReg32.exe (PID: 2744)
    • Creates a writable file in the system directory

      • WnImeReg32.exe (PID: 2724)
      • WnImeReg32.exe (PID: 2744)
  • SUSPICIOUS

    • Changes the Home page of Internet Explorer

      • wnwb_8.0.5.0.exe (PID: 1992)
    • Changes the title of the Internet Explorer window

      • wnwb_8.0.5.0.exe (PID: 1992)
    • Executable content was dropped or overwritten

      • wnwb_8.0.5.0.exe (PID: 1992)
      • WnImeReg32.exe (PID: 2744)
      • WnImeReg32.exe (PID: 2724)
    • Creates a software uninstall entry

      • wnwb_8.0.5.0.exe (PID: 1992)
    • Reads the Internet Settings

      • wnwb_8.0.5.0.exe (PID: 1992)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 2292)
      • wnwb_8.0.5.0.exe (PID: 2688)
      • wnwb_8.0.5.0.exe (PID: 1992)
      • msedge.exe (PID: 1232)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2292)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2292)
    • Checks supported languages

      • wnwb_8.0.5.0.exe (PID: 1992)
      • baidu_cb.exe (PID: 2904)
      • wnMBManager.exe (PID: 1236)
      • wnMBManager.exe (PID: 3324)
      • WnImeReg32.exe (PID: 2744)
      • WnImeReg32.exe (PID: 2724)
    • Creates files in the program directory

      • wnwb_8.0.5.0.exe (PID: 1992)
      • wnMBManager.exe (PID: 1236)
    • Reads the computer name

      • wnwb_8.0.5.0.exe (PID: 1992)
      • baidu_cb.exe (PID: 2904)
    • Reads Environment values

      • baidu_cb.exe (PID: 2904)
    • Creates files or folders in the user directory

      • wnwb_8.0.5.0.exe (PID: 1992)
    • Application launched itself

      • msedge.exe (PID: 2504)
      • msedge.exe (PID: 1232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:19 12:17:16
ZipCRC: 0xea16b13a
ZipCompressedSize: 16498899
ZipUncompressedSize: 16963152
ZipFileName: wnwb_8.0.5.0.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
76
Monitored processes
35
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe wnwb_8.0.5.0.exe no specs wnwb_8.0.5.0.exe baidu_cb.exe no specs wnmbmanager.exe no specs wnmbmanager.exe no specs wnimereg32.exe wnimereg32.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
908"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3608 --field-trial-handle=1304,i,2338268186614981150,10797321869204716010,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
948"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1644 --field-trial-handle=1304,i,2338268186614981150,10797321869204716010,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1232"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://wn.tt98.com/updatelog.aspx?wnType=wn51&d=DZ55556&wnwgVer=8.0&wnwgMinVer=5.0&wnnzVer=8.0&wnnzMinVer=5.0C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Program Files\shiqiang\wnwg\wnMBManager.exe" InitBuildFileC:\Program Files\shiqiang\wnwg\wnMBManager.exewnwb_8.0.5.0.exe
User:
admin
Company:
深圳世强软件开发部 www.wnwb.com
Integrity Level:
HIGH
Description:
万能五笔外挂词库管理
Exit code:
0
Version:
8, 0, 5, 0
Modules
Images
c:\program files\shiqiang\wnwg\wnmbmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1428"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=2252 --field-trial-handle=1304,i,2338268186614981150,10797321869204716010,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1544"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1520 --field-trial-handle=1204,i,2473454285909152900,11908035808443883142,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1272 --field-trial-handle=1204,i,2473454285909152900,11908035808443883142,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1900"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=4108 --field-trial-handle=1304,i,2338268186614981150,10797321869204716010,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1932"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3616 --field-trial-handle=1304,i,2338268186614981150,10797321869204716010,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1992"C:\Users\admin\Desktop\wnwb_8.0.5.0.exe\wnwb_8.0.5.0.exe" C:\Users\admin\Desktop\wnwb_8.0.5.0.exe\wnwb_8.0.5.0.exe
explorer.exe
User:
admin
Company:
深圳世强软件开发部 www.wnwb.com
Integrity Level:
HIGH
Description:
万能五笔安装程序
Exit code:
0
Version:
8, 0, 5, 0
Modules
Images
c:\users\admin\desktop\wnwb_8.0.5.0.exe\wnwb_8.0.5.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
12 886
Read events
12 727
Write events
146
Delete events
13

Modification events

(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2860) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\wnwb_8.0.5.0.exe.zip
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
53
Suspicious files
70
Text files
157
Unknown types
34

Dropped files

PID
Process
Filename
Type
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\wnwgData.cab
MD5:
SHA256:
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\wnwg\mb\wnwb_mb
MD5:
SHA256:
2292WinRAR.exeC:\Users\admin\Desktop\wnwb_8.0.5.0.exe\wnwb_8.0.5.0.exeexecutable
MD5:4F62BFB8F465F3CAE6B48B44F8C6EA32
SHA256:D95460473022721FACC56BB19060EFE996EBC41A069EDFFDA659B8C6B204A227
2292WinRAR.exeC:\Users\admin\Desktop\wnwb_8.0.5.0.exe\checksums.txttext
MD5:400ED913B6A40B4130A86F979F04BE06
SHA256:0477410DD5FA132E28E05D9FA242638F454AF85408582B5C47FA5583113EC9B2
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\baidu_cb.exeexecutable
MD5:318A24BC7317F3CC4044E3C1EEC5BDC2
SHA256:290502D1941A115EABF0A5D04C0E490E6F3532CD8BD53EF536897436A1A6E41D
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\WnImeReg64.exeexecutable
MD5:0D241ECF01C3069217F8CCAA48952769
SHA256:EED549CA73A449023C327EACA2A03DAD02FD9128317D1D9761EC75861DCCE2C6
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\wnotherData.cabcompressed
MD5:1F0E31869E771D7855BD882F63D716F0
SHA256:177DD770E9BB727832A4BB33C92B992578D30635CD5F43DA758088EEEC473CF3
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\lx.mbbinary
MD5:0C4A579413A56F148CF2097CB2667087
SHA256:8BAF34BABC3AED483ABBDDA85A201B4AE2EB80F95C1DBDE68E6CD98663C56E82
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\mb_dz.sysbinary
MD5:30F0E6C902D184716F34BE3BF14FD139
SHA256:450E439AA59F9412824A3AACC5F889B4AEA9F5B7CCC6D744FB94F295FB4387F9
1992wnwb_8.0.5.0.exeC:\Program Files\shiqiang\uninst.exeexecutable
MD5:0278D6CF6B6ACA4339F2431AB4E4D343
SHA256:D168509E1572001EDE98A81F1569FDD3997FAB66CDA52E1B62123F8CC6D0605D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
33
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2424
msedge.exe
GET
49.13.77.253:80
http://wn.tt98.com/updatelog.aspx
unknown
unknown
2424
msedge.exe
GET
49.13.77.253:80
http://wn.tt98.com/updatelog.aspx?wnType=wn51&d=DZ55556&wnwgVer=8.0&wnwgMinVer=5.0&wnnzVer=8.0&wnnzMinVer=5.0
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1232
msedge.exe
239.255.255.250:1900
unknown
2424
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2424
msedge.exe
49.13.77.253:80
wn.tt98.com
Hetzner Online GmbH
DE
unknown
2424
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2424
msedge.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
unknown
1232
msedge.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
wn.tt98.com
  • 49.13.77.253
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.139
  • 104.126.37.144
  • 104.126.37.146
  • 104.126.37.136
  • 104.126.37.130
  • 104.126.37.123
  • 104.126.37.131
  • 104.126.37.186
  • 92.123.104.32
  • 92.123.104.21
  • 92.123.104.47
  • 92.123.104.18
  • 92.123.104.33
  • 92.123.104.30
  • 92.123.104.23
  • 92.123.104.17
  • 92.123.104.35
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
self.events.data.microsoft.com
  • 52.168.117.170
whitelisted
ntp.msn.com
  • 204.79.197.203
whitelisted

Threats

No threats detected
No debug info