File name:

pw11-free1.exe

Full analysis: https://app.any.run/tasks/30eaeb2a-8cb9-4170-9d3b-81904e5b39c5
Verdict: Malicious activity
Analysis date: January 15, 2024, 07:09:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

75697A70F74DFF19D0D39A817DFDE286

SHA1:

CA90376A51905703E059529A75DFDBBC4BA8A768

SHA256:

354CF4FB3171B4F674FB52949E42E3DC531D5AB6068B7D6B9C3D7CE0337D1124

SSDEEP:

98304:H0QxOB96vofDsBdQMo2uGqbqObXkfyBSSTn/hIP49uGLSgho2ExGg8LbF+hRKP62:yvhfaGT5W8NusP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pw11-free1.exe (PID: 2036)
      • pw11-free1.exe (PID: 532)
      • pw11-free1.tmp (PID: 316)
    • Actions looks like stealing of personal data

      • pw11-free1.tmp (PID: 316)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • pw11-free1.exe (PID: 2036)
      • pw11-free1.exe (PID: 532)
      • pw11-free1.tmp (PID: 316)
    • Reads the Windows owner or organization settings

      • pw11-free1.tmp (PID: 316)
    • Reads Microsoft Outlook installation path

      • pw11-free1.tmp (PID: 316)
    • Reads Internet Explorer settings

      • pw11-free1.tmp (PID: 316)
    • The process drops C-runtime libraries

      • pw11-free1.tmp (PID: 316)
    • Process drops legitimate windows executable

      • pw11-free1.tmp (PID: 316)
    • Reads the Internet Settings

      • pw11-free1.tmp (PID: 316)
  • INFO

    • Create files in a temporary directory

      • pw11-free1.exe (PID: 2036)
      • pw11-free1.exe (PID: 532)
      • pw11-free1.tmp (PID: 316)
      • SmDownloader.exe (PID: 2312)
      • SmDownloader.exe (PID: 1544)
    • Checks supported languages

      • pw11-free1.exe (PID: 2036)
      • pw11-free1.tmp (PID: 1404)
      • pw11-free1.exe (PID: 532)
      • pw11-free1.tmp (PID: 316)
      • SmDownloader.exe (PID: 2312)
      • SmDownloader.exe (PID: 1544)
    • Reads the computer name

      • pw11-free1.tmp (PID: 1404)
      • SmDownloader.exe (PID: 1544)
      • SmDownloader.exe (PID: 2312)
      • pw11-free1.tmp (PID: 316)
    • Reads Environment values

      • pw11-free1.tmp (PID: 316)
    • Reads product name

      • pw11-free1.tmp (PID: 316)
    • Creates files in the program directory

      • pw11-free1.tmp (PID: 316)
    • Reads the machine GUID from the registry

      • pw11-free1.tmp (PID: 316)
    • Checks proxy server information

      • pw11-free1.tmp (PID: 316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (57.2)
.exe | Win32 Executable (generic) (18.2)
.exe | Win16/32 Executable Delphi generic (8.3)
.exe | Generic Win/DOS Executable (8)
.exe | DOS Executable Generic (8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 15:27:46+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 421376
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 11.6.0.0
ProductVersionNumber: 11.6.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: MiniTool Software Limited
FileDescription: MiniTool Partition Wizard Free Setup
FileVersion: 11.6
LegalCopyright: Copyright © 2019 MiniTool Software Limited, all rights reserved.
ProductName: MiniTool Partition Wizard Free
ProductVersion: 11.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pw11-free1.exe pw11-free1.tmp no specs pw11-free1.exe pw11-free1.tmp smdownloader.exe smdownloader.exe

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Users\admin\AppData\Local\Temp\is-RBK3F.tmp\pw11-free1.tmp" /SL5="$500E6,5898796,488960,C:\Users\admin\AppData\Local\Temp\pw11-free1.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-RBK3F.tmp\pw11-free1.tmp
pw11-free1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rbk3f.tmp\pw11-free1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
532"C:\Users\admin\AppData\Local\Temp\pw11-free1.exe" /SPAWNWND=$501B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\pw11-free1.exe
pw11-free1.tmp
User:
admin
Company:
MiniTool Software Limited
Integrity Level:
HIGH
Description:
MiniTool Partition Wizard Free Setup
Exit code:
0
Version:
11.6
Modules
Images
c:\users\admin\appdata\local\temp\pw11-free1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1404"C:\Users\admin\AppData\Local\Temp\is-JH4N3.tmp\pw11-free1.tmp" /SL5="$301AA,5898796,488960,C:\Users\admin\AppData\Local\Temp\pw11-free1.exe" C:\Users\admin\AppData\Local\Temp\is-JH4N3.tmp\pw11-free1.tmppw11-free1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jh4n3.tmp\pw11-free1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1544"C:\Users\admin\AppData\Local\Temp\is-B9TTO.tmp\SmDownloader.exe" /HWND:262550 /PATH:"C:\Program Files\MiniTool Partition Wizard 11" /URL:https://www.partitionwizard.com/download/online-setup-config/pwfree-v116.ini /VERYSILENT /USERMSG:1450 /LANG:englishC:\Users\admin\AppData\Local\Temp\is-B9TTO.tmp\SmDownloader.exe
pw11-free1.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-b9tto.tmp\smdownloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-b9tto.tmp\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
2036"C:\Users\admin\AppData\Local\Temp\pw11-free1.exe" C:\Users\admin\AppData\Local\Temp\pw11-free1.exe
explorer.exe
User:
admin
Company:
MiniTool Software Limited
Integrity Level:
MEDIUM
Description:
MiniTool Partition Wizard Free Setup
Exit code:
0
Version:
11.6
Modules
Images
c:\users\admin\appdata\local\temp\pw11-free1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2312"C:\Users\admin\AppData\Local\Temp\is-B9TTO.tmp\SmDownloader.exe" /HWND:262550 /PATH:"C:\Program Files\MiniTool Partition Wizard 11\..\MiniTool ShadowMaker" /URL:https://www.partitionwizard.com/download/online-setup-config/pwfree-v116-bundle-sm.ini /VERYSILENT /USERMSG:1439 /LANG:englishC:\Users\admin\AppData\Local\Temp\is-B9TTO.tmp\SmDownloader.exe
pw11-free1.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-b9tto.tmp\smdownloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-b9tto.tmp\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
Total events
2 579
Read events
2 397
Write events
182
Delete events
0

Modification events

(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(316) pw11-free1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
Operation:writeName:WpadDecisionReason
Value:
1
Executable files
9
Suspicious files
0
Text files
84
Unknown types
0

Dropped files

PID
Process
Filename
Type
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\000E1F5B.logtext
MD5:CA262D0CEC205A1BF76083D2868E27D6
SHA256:EE8767C1325169D64B5CDDEF575751D12F4DB23F97D4EEBDE0C8C9BB565CDD44
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\sdk-ui\images\progress-bg-corner.pngimage
MD5:608F1F20CD6CA9936EAA7E8C14F366BE
SHA256:86B6E6826BCDE2955D64D4600A4E01693522C1FDDF156CE31C4BA45B3653A7BD
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\is-B9TTO.tmp\minitool.dllexecutable
MD5:0013995E68D583ECBA54315761C1B85E
SHA256:B6907E36CAECD6AD074CA75628F1E46E2E32D23ABD9D859E6F349ADB4CCE34F3
2036pw11-free1.exeC:\Users\admin\AppData\Local\Temp\is-JH4N3.tmp\pw11-free1.tmpexecutable
MD5:B375A9BA6F5676044FA04D167C46820A
SHA256:BC2FED48CB8234FB72119716CA6658A18D757F81F741A3B1F90A0155DB378DD6
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\ie6_main.csstext
MD5:74F08D5A243AE79F1DE64DFFDAF846CB
SHA256:15590060BFD227F656E569031113A080E0D45621A5C944DFC352F869EADAFEF2
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\main.csstext
MD5:9B27E2A266FE15A3AABFE635C29E8923
SHA256:166AA42BC5216C5791388847AE114EC0671A0D97B9952D14F29419B8BE3FB23F
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\sdk-ui\browse.csstext
MD5:6009D6E864F60AEA980A9DF94C1F7E1C
SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\csshover3.htchtml
MD5:52FA0DA50BF4B27EE625C80D36C67941
SHA256:E37E99DDFC73AC7BA774E23736B2EF429D9A0CB8C906453C75B14C029BDD5493
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\sdk-ui\button.csstext
MD5:37E1FF96E084EC201F0D95FEEF4D5E94
SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534
316pw11-free1.tmpC:\Users\admin\AppData\Local\Temp\nsd92553132705\css\sdk-ui\progress-bar.csstext
MD5:5335F1C12201B5F7CF5F8B4F5692E3D1
SHA256:974CD89E64BDAA85BF36ED2A50AF266D245D781A8139F5B45D7C55A0B0841DDA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
17
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2312
SmDownloader.exe
104.18.20.161:443
www.partitionwizard.com
CLOUDFLARENET
unknown
1544
SmDownloader.exe
104.18.20.161:443
www.partitionwizard.com
CLOUDFLARENET
unknown
1544
SmDownloader.exe
104.18.21.178:443
cdn2.minitool.com
CLOUDFLARENET
unknown
2312
SmDownloader.exe
104.18.21.178:443
cdn2.minitool.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
vps.sihomuwe-ter.com
unknown
ww1.sihomuwe-ter.com
unknown
ww2.sihomuwe-ter.com
unknown
www.partitionwizard.com
  • 104.18.20.161
  • 104.18.21.161
unknown
cdn2.minitool.com
  • 104.18.21.178
  • 104.18.20.178
unknown

Threats

No threats detected
No debug info