File name:

2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe

Full analysis: https://app.any.run/tasks/43246401-d386-47f6-9692-fb092ee03b01
Verdict: Malicious activity
Analysis date: May 15, 2025, 17:15:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

F7E561A8281C305E47BB461232173FAC

SHA1:

6074567B3AFD4B0DCE5E95BAF35B0703B07BBB0F

SHA256:

2E349D637A8CE63A26B6FF2223EB503ABFB25686B0947E32368F346CA1FDCCC5

SSDEEP:

98304:AbU856cbwQGHg5TcZSFPLyU2GcoXJEU7iBvZ0fqL0XLJM0u90I2PmfUNQDE3kRDX:Ckonf3N0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 496)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 976)
      • WiseFolderHider.exe (PID: 6800)
      • WiseFolderHider.exe (PID: 7552)
      • WFHChecker.exe (PID: 7784)
      • WFHChecker.exe (PID: 744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 496)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 976)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
      • WiseFolderHider.exe (PID: 7552)
    • Reads security settings of Internet Explorer

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • WiseFolderHider.exe (PID: 7552)
      • WiseFolderHider.exe (PID: 6800)
    • Reads the Windows owner or organization settings

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
    • Windows service management via SC.EXE

      • sc.exe (PID: 4560)
    • Application launched itself

      • WiseFolderHider.exe (PID: 6800)
    • Drops a system driver (possible attempt to evade defenses)

      • WiseFolderHider.exe (PID: 7552)
    • There is functionality for taking screenshot (YARA)

      • WFHChecker.exe (PID: 744)
  • INFO

    • Checks supported languages

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 496)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 976)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
      • WiseFolderHider.exe (PID: 7552)
      • WFHChecker.exe (PID: 744)
      • WFHChecker.exe (PID: 7784)
      • WiseFolderHider.exe (PID: 6800)
      • identity_helper.exe (PID: 8188)
    • Create files in a temporary directory

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 496)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 976)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
      • WiseFolderHider.exe (PID: 7552)
    • Reads the computer name

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
      • WiseFolderHider.exe (PID: 6800)
      • WiseFolderHider.exe (PID: 7552)
      • identity_helper.exe (PID: 8188)
    • Process checks computer location settings

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • WiseFolderHider.exe (PID: 7552)
      • WiseFolderHider.exe (PID: 6800)
    • Detects InnoSetup installer (YARA)

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 976)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe (PID: 496)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
    • Compiled with Borland Delphi (YARA)

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
      • WFHChecker.exe (PID: 744)
      • WiseFolderHider.exe (PID: 7552)
    • The sample compiled with english language support

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
    • Local mutex for internet shortcut management

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
    • Checks proxy server information

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 2384)
      • WiseFolderHider.exe (PID: 7552)
    • Creates files in the program directory

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
    • Creates a software uninstall entry

      • 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp (PID: 780)
    • Application launched itself

      • msedge.exe (PID: 5800)
    • Reads the software policy settings

      • WiseFolderHider.exe (PID: 7552)
      • slui.exe (PID: 2800)
    • Reads Environment values

      • identity_helper.exe (PID: 8188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:10:12 11:15:57+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 682496
InitializedDataSize: 105984
UninitializedDataSize: -
EntryPoint: 0xa7ed0
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.5.235
ProductVersionNumber: 5.0.5.235
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: WiseCleaner.com
FileDescription: Wise Folder Hider
FileVersion: 5.0.5
LegalCopyright: WiseCleaner.com
OriginalFileName:
ProductName: Wise Folder Hider
ProductVersion: 5.0.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
191
Monitored processes
56
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
start 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp no specs 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp sppextcomobj.exe no specs slui.exe sc.exe no specs conhost.exe no specs msedge.exe wisefolderhider.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs wfhchecker.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wisefolderhider.exe wfhchecker.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\AppData\Local\Temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe" C:\Users\admin\AppData\Local\Temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe
explorer.exe
User:
admin
Company:
WiseCleaner.com
Integrity Level:
MEDIUM
Description:
Wise Folder Hider
Exit code:
0
Version:
5.0.5
Modules
Images
c:\users\admin\appdata\local\temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
644"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x324,0x328,0x32c,0x320,0x314,0x7ffc89ce5fd8,0x7ffc89ce5fe4,0x7ffc89ce5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5824 --field-trial-handle=2384,i,13886572770403877465,11102320290875129136,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
744"C:\Program Files (x86)\Wise\Wise Folder Hider\WFHChecker.exe" -HelperC:\Program Files (x86)\Wise\Wise Folder Hider\WFHChecker.exeWiseFolderHider.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files (x86)\wise\wise folder hider\wfhchecker.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
780"C:\Users\admin\AppData\Local\Temp\is-PK54P.tmp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp" /SL5="$6030C,5967459,789504,C:\Users\admin\AppData\Local\Temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe" /SPAWNWND=$3030E /NOTIFYWND=$B02D2 C:\Users\admin\AppData\Local\Temp\is-PK54P.tmp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp
2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pk54p.tmp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
864C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
976"C:\Users\admin\AppData\Local\Temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe" /SPAWNWND=$3030E /NOTIFYWND=$B02D2 C:\Users\admin\AppData\Local\Temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe
2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmp
User:
admin
Company:
WiseCleaner.com
Integrity Level:
HIGH
Description:
Wise Folder Hider
Exit code:
0
Version:
5.0.5
Modules
Images
c:\users\admin\appdata\local\temp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
976"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5904 --field-trial-handle=2384,i,13886572770403877465,11102320290875129136,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
1348"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6960 --field-trial-handle=2384,i,13886572770403877465,11102320290875129136,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4420 --field-trial-handle=2384,i,13886572770403877465,11102320290875129136,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
12 015
Read events
11 930
Write events
84
Delete events
1

Modification events

(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\WiseCleaner\WFHPRO
Operation:writeName:path
Value:
C:\Program Files (x86)\Wise\Wise Folder Hider
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\WiseCleaner\WFHPRO
Operation:writeName:Product Name
Value:
Wise Folder Hider
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\WFH
Operation:writeName:ICON
Value:
C:\Program Files (x86)\Wise\Wise Folder Hider\WiseFolderHider.exe
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\WFH
Operation:writeName:ICON
Value:
C:\Program Files (x86)\Wise\Wise Folder Hider\WiseFolderHider.exe
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.0.3 (u)
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Wise\Wise Folder Hider
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Wise\Wise Folder Hider\
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Wise Folder Hider
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(780) 2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Folder Hider_is1
Operation:writeName:Inno Setup: Language
Value:
english
Executable files
24
Suspicious files
143
Text files
133
Unknown types
0

Dropped files

PID
Process
Filename
Type
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Program Files (x86)\Wise\Wise Folder Hider\Languages\Abkhazian.initext
MD5:8F88BEA58980166D6B3BC0B765095982
SHA256:EDB46B16FE9486DA6665F01B13643760B7B4763E4C823C7066D748B54AD295BB
9762e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exeC:\Users\admin\AppData\Local\Temp\is-PK54P.tmp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpexecutable
MD5:5BD71F6C3B6FAC7FDAA75633F0AF9F52
SHA256:0FC8B95D74EC17858ECA1A81A053BB02AD0C40CC9163A6B2A839F7703F098308
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Users\admin\AppData\Local\Temp\is-2F4A7.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4962e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.exeC:\Users\admin\AppData\Local\Temp\is-EO3F2.tmp\2e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpexecutable
MD5:5BD71F6C3B6FAC7FDAA75633F0AF9F52
SHA256:0FC8B95D74EC17858ECA1A81A053BB02AD0C40CC9163A6B2A839F7703F098308
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Users\admin\AppData\Local\Temp\is-2F4A7.tmp\license.txttext
MD5:4A0F1A666912E64F1BA811FC24D7135F
SHA256:D6B418C619BA7456B594DFF10C3FACE4AC28609A64F2BF5E635292D7FF4F57E5
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Program Files (x86)\Wise\Wise Folder Hider\is-K31GH.tmpexecutable
MD5:5BD71F6C3B6FAC7FDAA75633F0AF9F52
SHA256:0FC8B95D74EC17858ECA1A81A053BB02AD0C40CC9163A6B2A839F7703F098308
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Program Files (x86)\Wise\Wise Folder Hider\is-PP0QB.tmpexecutable
MD5:060089C9441F0D1C7EBE8133F424265F
SHA256:6AB96789E2233BE5B659494BB479746575357B2863C2F7884551E77DBBEC2292
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Program Files (x86)\Wise\Wise Folder Hider\unins000.exeexecutable
MD5:5BD71F6C3B6FAC7FDAA75633F0AF9F52
SHA256:0FC8B95D74EC17858ECA1A81A053BB02AD0C40CC9163A6B2A839F7703F098308
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Users\admin\AppData\Local\Temp\is-2F4A7.tmp\Icon_128.bmpimage
MD5:FCAF2D7E995620747896987C88270A42
SHA256:A3959B1A40B71908B24DBEA5972DE0F5FFADAEE5B15E1D3CE8F976EFC432B390
7802e349d637a8ce63a26b6ff2223eb503abfb25686b0947e32368f346ca1fdccc5.tmpC:\Program Files (x86)\Wise\Wise Folder Hider\is-DHNE9.tmpexecutable
MD5:7A92DD4144B6F2C2C74E8A82DE5E8B57
SHA256:23A933C5FD595ED93C3C290266199DCC4920B08A8637745698C116A230854DA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
104
DNS requests
113
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.48.23.151:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3176
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1747705080&P2=404&P3=2&P4=gOOnPM%2bg9Rb0nUpnItDPoZNZVoq3uIYLbpPikHDh9hLNnPh%2bFfTRVODBYALWKHeeX6J4FtsaAFfVO9EU1IEd3Q%3d%3d
unknown
whitelisted
7868
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7868
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3176
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1747705080&P2=404&P3=2&P4=gOOnPM%2bg9Rb0nUpnItDPoZNZVoq3uIYLbpPikHDh9hLNnPh%2bFfTRVODBYALWKHeeX6J4FtsaAFfVO9EU1IEd3Q%3d%3d
unknown
whitelisted
7552
WiseFolderHider.exe
GET
200
23.224.143.82:80
http://www.wisecleaner.net/wisecleaner_feedback/index.php?to=fetch-unread-message&guid={F9339FEF-9940-4014-BC62-766E95AE3203}
unknown
whitelisted
3176
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1747705080&P2=404&P3=2&P4=gOOnPM%2bg9Rb0nUpnItDPoZNZVoq3uIYLbpPikHDh9hLNnPh%2bFfTRVODBYALWKHeeX6J4FtsaAFfVO9EU1IEd3Q%3d%3d
unknown
whitelisted
3176
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a575cead-e662-4f4d-b0c3-81f1438d0388?P1=1747705080&P2=404&P3=2&P4=gOOnPM%2bg9Rb0nUpnItDPoZNZVoq3uIYLbpPikHDh9hLNnPh%2bFfTRVODBYALWKHeeX6J4FtsaAFfVO9EU1IEd3Q%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.48.23.151:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.151
  • 23.48.23.156
  • 23.48.23.150
  • 23.48.23.155
  • 23.48.23.157
  • 23.48.23.148
  • 23.48.23.153
  • 23.48.23.146
  • 23.48.23.162
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 216.58.206.46
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.131
  • 40.126.31.71
  • 20.190.159.131
  • 20.190.159.129
  • 20.190.159.64
  • 20.190.159.130
  • 40.126.31.130
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.wisecleaner.com
  • 172.67.68.11
  • 104.26.3.143
  • 104.26.2.143
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted

Threats

PID
Process
Class
Message
5984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5984
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info