File name:

winaerotweaker.zip

Full analysis: https://app.any.run/tasks/1d54a6d9-6a18-4fd6-8e83-2306186d42c9
Verdict: Malicious activity
Analysis date: November 01, 2023, 14:36:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
tweaker
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BF982C18BF19FDEA302D12D99CC14483

SHA1:

79F9C93636E024A86508E82CDBEBBA4EC129C139

SHA256:

370095778B69F763AF03E553F5A83B192C7183D098CB0D87350F66FB525573B8

SSDEEP:

98304:PpA9q6ssUcCvuoKU+TyRTtyopLcxO7fiKiQMtA+Oh+EX4PLfKMxLKkqY9UlH6E4U:qB61oBA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1032)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 960)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 3116)
    • Creates or modifies Windows services

      • WinaeroTweaker.exe (PID: 3116)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
    • Reads the Internet Settings

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 2216)
      • WinaeroTweaker.exe (PID: 3116)
    • Starts CMD.EXE for commands execution

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 3116)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2224)
      • cmd.exe (PID: 2084)
    • Application launched itself

      • WinaeroTweaker.exe (PID: 2216)
    • Reads settings of System Certificates

      • WinaeroTweaker.exe (PID: 3116)
    • Adds/modifies Windows certificates

      • WinaeroTweaker.exe (PID: 2216)
    • Reads Internet Explorer settings

      • WinaeroTweaker.exe (PID: 3116)
    • Process drops legitimate windows executable

      • WinaeroTweaker.exe (PID: 3116)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 3076)
  • INFO

    • Reads the computer name

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 1248)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 2216)
      • WinaeroTweaker.exe (PID: 3116)
    • Checks supported languages

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 1248)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1032)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 960)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 2216)
      • WinaeroTweaker.exe (PID: 3116)
      • WinaeroTweakerHelper.exe (PID: 3064)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3372)
    • Create files in a temporary directory

      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1032)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 960)
      • WinaeroTweaker.exe (PID: 3116)
    • Manual execution by a user

      • cmd.exe (PID: 2296)
      • WinaeroTweaker.exe (PID: 2216)
    • Creates files in the program directory

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3812)
      • WinaeroTweaker.exe (PID: 3116)
    • Reads the machine GUID from the registry

      • WinaeroTweaker.exe (PID: 2216)
      • WinaeroTweaker.exe (PID: 3116)
    • Reads Environment values

      • WinaeroTweaker.exe (PID: 3116)
    • Reads CPU info

      • WinaeroTweaker.exe (PID: 3116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: Deflated
ZipModifyDate: 2023:06:16 12:29:34
ZipCRC: 0x68b2f9ca
ZipCompressedSize: 226
ZipUncompressedSize: 471
ZipFileName: SilentSetup.cmd
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
15
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs cmd.exe no specs winaerotweaker-1.55.0.0-setup.exe no specs winaerotweaker-1.55.0.0-setup.tmp no specs winaerotweaker-1.55.0.0-setup.exe winaerotweaker-1.55.0.0-setup.tmp no specs cmd.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs winaerotweaker.exe no specs winaerotweaker.exe winaerotweakerhelper.exe no specs cmd.exe no specs sc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
960"C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SPAWNWND=$13012E /NOTIFYWND=$3045C /SP- /VERYSILENTC:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe
WinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Winaero
Integrity Level:
HIGH
Description:
Winaero Tweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\users\admin\desktop\winaerotweaker-1.55.0.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1032WinaeroTweaker-1.55.0.0-setup.exe /SP- /VERYSILENTC:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.execmd.exe
User:
admin
Company:
Winaero
Integrity Level:
MEDIUM
Description:
Winaero Tweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\users\admin\desktop\winaerotweaker-1.55.0.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1248"C:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmp" /SL5="$3045C,3507132,832000,C:\Users\admin\Desktop\WinaeroTweaker-1.55.0.0-setup.exe" /SP- /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmpWinaeroTweaker-1.55.0.0-setup.exe
User:
admin
Company:
Winaero
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-tbd0l.tmp\winaerotweaker-1.55.0.0-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1440sc.exe config wuauserv start= demandC:\Windows\System32\sc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2084"C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweakerhelper.exe /fC:\Windows\System32\cmd.exeWinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2216"C:\Program Files\Winaero Tweaker\WinaeroTweaker.exe" C:\Program Files\Winaero Tweaker\WinaeroTweaker.exeexplorer.exe
User:
admin
Company:
https://winaero.com
Integrity Level:
MEDIUM
Description:
WinaeroTweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\program files\winaero tweaker\winaerotweaker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2224"C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweaker.exe /fC:\Windows\System32\cmd.exeWinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2296C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\SilentSetup.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3064"C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exe" -C:\Program Files\Winaero Tweaker\WinaeroTweakerHelper.exeWinaeroTweaker.exe
User:
admin
Company:
http://winaero.com
Integrity Level:
HIGH
Description:
Winaero Tweaker 32bit support process
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\program files\winaero tweaker\winaerotweakerhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\gdi32.dll
3076"C:\Windows\System32\cmd.exe" /c sc.exe config wuauserv start= demandC:\Windows\System32\cmd.exeWinaeroTweaker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
6 358
Read events
6 282
Write events
69
Delete events
7

Modification events

(PID) Process:(3372) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
21
Suspicious files
12
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\Elevator.exeexecutable
MD5:DF2708F6C7B1D60CFCF071142519A834
SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\no_tab_explorer.exeexecutable
MD5:FB6E5BD898E6D6369F29A3FE0EDA0198
SHA256:100AC04E146983684553D9FEDC8442E7B0C619A832A1CF414F2482334ED472C9
3372WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3372.39193\SilentSetup.cmdtext
MD5:197BEF36215F7D3A3863D1331BB5A18C
SHA256:85AE2F1E32A5F46A1F6E3DD4B9C3F5641B6748560D1F5C62EC1024B324E3E1E9
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\unins000.exeexecutable
MD5:052A74D2B5F148905F95967688F799C5
SHA256:D3F40D26CC6DE2E992466DA8EEE55417787E0451B852690BDFA9623B3BB4C36F
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\is-MSE6V.tmpexecutable
MD5:052A74D2B5F148905F95967688F799C5
SHA256:D3F40D26CC6DE2E992466DA8EEE55417787E0451B852690BDFA9623B3BB4C36F
1032WinaeroTweaker-1.55.0.0-setup.exeC:\Users\admin\AppData\Local\Temp\is-TBD0L.tmp\WinaeroTweaker-1.55.0.0-setup.tmpexecutable
MD5:86703BD9DE2D284E858A60A09E5B9ADC
SHA256:74B32D4954EE2AA19E9D6C71F9797889F4BA6D838A5D50C5C8AE298BD89D702C
960WinaeroTweaker-1.55.0.0-setup.exeC:\Users\admin\AppData\Local\Temp\is-QNT3V.tmp\WinaeroTweaker-1.55.0.0-setup.tmpexecutable
MD5:86703BD9DE2D284E858A60A09E5B9ADC
SHA256:74B32D4954EE2AA19E9D6C71F9797889F4BA6D838A5D50C5C8AE298BD89D702C
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\AppData\Local\Temp\is-7OU3A.tmp\_isetup\_iscrypt.dllexecutable
MD5:A69559718AB506675E907FE49DEB71E9
SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\is-KDBD7.tmpexecutable
MD5:23C3E2111BE79604C718B474500213B8
SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D
3812WinaeroTweaker-1.55.0.0-setup.tmpC:\Program Files\Winaero Tweaker\WinaeroTweaker.exeexecutable
MD5:23C3E2111BE79604C718B474500213B8
SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3116
WinaeroTweaker.exe
GET
200
67.27.235.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ece396c6e641254f
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted
3116
WinaeroTweaker.exe
68.183.112.81:443
winaero.com
DIGITALOCEAN-ASN
US
unknown
3116
WinaeroTweaker.exe
67.27.235.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
winaero.com
  • 68.183.112.81
whitelisted
ctldl.windowsupdate.com
  • 67.27.235.254
  • 8.238.189.126
  • 8.241.123.254
  • 8.241.122.126
  • 8.253.95.121
whitelisted

Threats

No threats detected
No debug info