| File name: | wybuild-setup.exe |
| Full analysis: | https://app.any.run/tasks/18bab317-ad25-4740-b6cc-e48a2a5b3d4e |
| Verdict: | Malicious activity |
| Analysis date: | August 16, 2024, 23:10:36 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 2F1D7C660F3A50A5C358F6E0658484E4 |
| SHA1: | C660CEC179D8528BA7E0D15A5775E1CC9A88F045 |
| SHA256: | 24A02A95E2CC81609F8268B33223760748ABF57CC4F8CF9754A69E36197DFAF2 |
| SSDEEP: | 49152:BltrOhg8wwe5d773ggAMb6e0u1QANtvOdtQBbUCX1IqH4j/Z9UoY9IDsyfPSs+d/:7tSm8wFM3Mb698QASdtQNb1kjB9UoYSU |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:12:05 22:50:46+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 119808 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x323c |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.6.18.4 |
| ProductVersionNumber: | 2.6.18.4 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | ASCII |
| CompanyName: | wyDay |
| FileDescription: | wyBuild 2.6.18.4 |
| FileVersion: | 2.6.18.4 |
| LegalCopyright: | Copyright © 2005-2012 wyDay |
| LegalTrademarks: | wyBuild |
| OriginalFileName: | wybuild-setup.exe |
| ProductName: | wyBuild |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3992 | "C:\Program Files (x86)\wyBuild\InstantUpdate.exe" /autoupdate | C:\Program Files (x86)\wyBuild\InstantUpdate.exe | wybuild.exe | ||||||||||||
User: admin Company: wyDay Integrity Level: MEDIUM Description: wyUpdate Exit code: 1 Version: 2.6.18.4 Modules
| |||||||||||||||
| 6548 | "C:\Users\admin\AppData\Local\Temp\wybuild-setup.exe" | C:\Users\admin\AppData\Local\Temp\wybuild-setup.exe | explorer.exe | ||||||||||||
User: admin Company: wyDay Integrity Level: MEDIUM Description: wyBuild 2.6.18.4 Exit code: 0 Version: 2.6.18.4 Modules
| |||||||||||||||
| 6600 | "C:\Program Files (x86)\wyBuild\wybuild.exe" | C:\Program Files (x86)\wyBuild\wybuild.exe | — | wybuild-setup.exe | |||||||||||
User: admin Company: wyDay Integrity Level: MEDIUM Description: wyBuild Version: 2.6.18.4 Modules
| |||||||||||||||
| 6732 | "C:\Users\admin\AppData\Local\Temp\wybuild-setup.exe" /UAC:4029C /NCRC | C:\Users\admin\AppData\Local\Temp\wybuild-setup.exe | wybuild-setup.exe | ||||||||||||
User: admin Company: wyDay Integrity Level: HIGH Description: wyBuild 2.6.18.4 Exit code: 0 Version: 2.6.18.4 Modules
| |||||||||||||||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | DisplayName |
Value: wyBuild | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | DisplayVersion |
Value: 2.6.18.4 | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | HelpLink |
Value: http://wyday.com/ | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | Publisher |
Value: wyDay | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | URLInfoAbout |
Value: http://wyday.com/ | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | URLUpdateInfo |
Value: http://wyday.com/ | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wyUpdate |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files (x86)\wyBuild\uninstall.exe | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\wyUpdate\Setup |
| Operation: | write | Name: | AddToStartMenu |
Value: 1 | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\wyUpdate\Setup |
| Operation: | write | Name: | AddToDesktop |
Value: 1 | |||
| (PID) Process: | (6732) wybuild-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\wyUpdate |
| Operation: | write | Name: | Version |
Value: 2.6.18.4 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\UAC.dll | executable | |
MD5:88AD3FD90FC52AC3EE0441A38400A384 | SHA256:E58884695378CF02715373928BB8ADE270BAF03144369463F505C3B3808CBC42 | |||
| 6548 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsk491C.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\uninstall.ico | image | |
MD5:02D55318B5EE15E632FB928135632B4D | SHA256:72DED4F6F301AC5F783DC6596E95D7C8357662055AF03DD1DE2A8B480CDAF07A | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\EULA.rtf | text | |
MD5:A043A77FB67D5FB47D0761A89FD84F09 | SHA256:3264D591E6F1C553CAA8B89FE222EEDC3D77885D7304368EEF27C334976F8B26 | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\check.ico | image | |
MD5:2EA94A518888462D0ABBA68CA7043205 | SHA256:E8C63C7EA91724AA1A52CEB30233CE350BF61B22C458BA01B351321EFB491F22 | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\repair.ico | image | |
MD5:C65FA199F47A93012A2DC5DC359455FE | SHA256:7E1E8652835E59C9C28B03B418DF91744DB2331F832E28B6D84924E77D041551 | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\modern-header.bmp | image | |
MD5:356960F4B85C65E4095D0843D8E8A56A | SHA256:1A47DEE3B561E017E2AF71D3E68CB17D0390225AC50DF242FE1F2FD2403ED57C | |||
| 6732 | wybuild-setup.exe | C:\Program Files (x86)\wyBuild\AutomaticUpdater\Microsoft .NET 4.0\AutomaticUpdater.dll | executable | |
MD5:2863FE94130E9C2E83198F64D328BB9E | SHA256:80E08B87C32E5D4090FC3B08657D98F5AAAC4C60B275ADCC69B026829CCF3B1B | |||
| 6732 | wybuild-setup.exe | C:\Users\admin\AppData\Local\Temp\nsm4C2A.tmp\nsDialogs.dll | executable | |
MD5:7818B8790715A8625ED37EB6E139B593 | SHA256:D869E2FFB86A5930CD75CDB430F7F229CE5742239FECC99DD31DBE2EAE625205 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1568 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6872 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2%2BiPob4twryIF%2BFfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa%2FLgCEHNXjHFts5VTE33zCXMYq%2F4%3D | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQP7x3EfW%2FiC3nNRDemlxke%2FNPJPgQUICUjFxG%2F0A2g5yu8ntWaQglPKsUCEGbTKIq2kXtVTq82KjYOivs%3D | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQP7x3EfW%2FiC3nNRDemlxke%2FNPJPgQUICUjFxG%2F0A2g5yu8ntWaQglPKsUCEGbTKIq2kXtVTq82KjYOivs%3D | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 200 | 172.64.149.23:80 | http://crl.comodoca.com/COMODOCodeSigningCA.crl | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 301 | 45.33.71.201:80 | http://wyday.com/files/wyupdate/updates/designer.wys | unknown | — | — | unknown |
6824 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3992 | InstantUpdate.exe | GET | 301 | 45.33.71.201:80 | http://wyday.com/files/wyupdate/updates/designer.wys | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3260 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5336 | SearchApp.exe | 104.126.37.129:443 | www.bing.com | Akamai International B.V. | DE | unknown |
1568 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1568 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
th.bing.com |
| whitelisted |
arc.msn.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |