download:

setup_wnysxz001.exe

Full analysis: https://app.any.run/tasks/b2cb55a1-ffa8-4d86-ba4a-f0e2e85cbe36
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: July 18, 2019, 07:07:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
pup
pua
softcnapp
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7457A920304FAA494F748A540B00D2EC

SHA1:

CAA2F6D97024D8B2FFFEFE9AFF23871C355C9B0B

SHA256:

38CEB3D10AD9C92F6FE0BBFB538996B05EE47E4FEBC856AFEB61C03834F325BD

SSDEEP:

196608:SIZMZi34TFJNUWov4W+jG1NAMdzbqWDpJV073/CMKhP6uDkm9Hts3y4:jvyHNUTv4zeNAMdzbqWDpP0rCMxmkQi5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WnZipUtility.exe (PID: 2232)
      • WnZipPower32.exe (PID: 1456)
      • WnZipVirtualCD.exe (PID: 1528)
      • WnZipPower32.exe (PID: 2848)
      • WnZipService.exe (PID: 4072)
      • WnZip.exe (PID: 3756)
      • TimeHelp.exe (PID: 3064)
      • WnZipFileManager.exe (PID: 3708)
      • WnZipUtility.exe (PID: 2848)
      • WnZipUtility.exe (PID: 2928)
      • WnZipUtility.exe (PID: 3664)
      • WnZipUtility.exe (PID: 1848)
      • WnZipUtility.exe (PID: 3752)
      • WnZipTool.exe (PID: 1824)
      • WnZipUtility.exe (PID: 3448)
    • Loads dropped or rewritten executable

      • WnZipPower32.exe (PID: 2848)
      • WnZipFileManager.exe (PID: 3708)
    • SOFTCNAPP was detected

      • WnZipUtility.exe (PID: 3752)
      • WnZipUtility.exe (PID: 2928)
      • WnZipTool.exe (PID: 1824)
  • SUSPICIOUS

    • Uses TASKKILL.EXE to kill process

      • setup_wnysxz001.exe (PID: 3000)
    • Executable content was dropped or overwritten

      • setup_wnysxz001.exe (PID: 3000)
      • WnZipVirtualCD.exe (PID: 1528)
    • Creates files in the program directory

      • setup_wnysxz001.exe (PID: 3000)
      • WnZipUtility.exe (PID: 2232)
      • WnZipFileManager.exe (PID: 3708)
    • Creates files in the Windows directory

      • WnZipVirtualCD.exe (PID: 1528)
    • Creates a software uninstall entry

      • WnZipUtility.exe (PID: 2232)
    • Creates files in the driver directory

      • WnZipVirtualCD.exe (PID: 1528)
    • Creates COM task schedule object

      • WnZipPower32.exe (PID: 2848)
    • Executed as Windows Service

      • WnZipService.exe (PID: 4072)
    • Application launched itself

      • WnZipUtility.exe (PID: 2928)
    • Modifies the open verb of a shell class

      • WnZipUtility.exe (PID: 1848)
      • WnZipUtility.exe (PID: 2232)
  • INFO

    • Manual execution by user

      • WnZip.exe (PID: 3756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:06:27 09:28:08+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 1577984
InitializedDataSize: 8332800
UninitializedDataSize: -
EntryPoint: 0x40ebd
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.9.19627
ProductVersionNumber: 1.3.9.19627
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: 万能压缩
FileDescription: 万能压缩
FileVersion: 1.3.9.19627
InternalName: 万能压缩
LegalCopyright: Copyright (C) 2019
OriginalFileName: Install.exe
ProductName: 万能压缩
ProductVersion: 1,3,9,19627

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 27-Jun-2019 07:28:08
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • G:\svn\YaSuo\ChengXu\Tags\wntag_1.3.9.19627\Bundles\WanNengZip\Temp\Release\Install.pdb
CompanyName: 万能压缩
FileDescription: 万能压缩
FileVersion: 1.3.9.19627
InternalName: 万能压缩
LegalCopyright: Copyright (C) 2019
OriginalFilename: Install.exe
ProductName: 万能压缩
ProductVersion: 1,3,9,19627

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000148

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 27-Jun-2019 07:28:08
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00181363
0x00181400
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.64637
.rdata
0x00183000
0x0006944C
0x00069600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.64652
.data
0x001ED000
0x0001245C
0x0000B400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.23462
.gfids
0x00200000
0x000001B4
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.51026
.tls
0x00201000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x00202000
0x00768DE4
0x00768E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.97354
.reloc
0x0096B000
0x000149FC
0x00014A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.58115

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.41141
1260
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.53107
67624
Latin 1 / Western European
Chinese - PRC
RT_ICON
3
5.88889
38056
Latin 1 / Western European
Chinese - PRC
RT_ICON
4
5.67784
16936
Latin 1 / Western European
Chinese - PRC
RT_ICON
5
5.94895
9640
Latin 1 / Western European
Chinese - PRC
RT_ICON
6
5.93778
5512
Latin 1 / Western European
Chinese - PRC
RT_ICON
7
6.16633
2440
Latin 1 / Western European
Chinese - PRC
RT_ICON
8
6.07871
1720
Latin 1 / Western European
Chinese - PRC
RT_ICON
9
6.0888
1128
Latin 1 / Western European
Chinese - PRC
RT_ICON
101
3.09794
132
Latin 1 / Western European
Chinese - PRC
RT_GROUP_ICON

Imports

ADVAPI32.dll
COMCTL32.dll
CRYPT32.dll
GDI32.dll
IMM32.dll
IPHLPAPI.DLL
KERNEL32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
22
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start setup_wnysxz001.exe taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs wnziputility.exe wnzippower32.exe wnzipvirtualcd.exe wnzippower32.exe no specs wnzipservice.exe wnzip.exe timehelp.exe wnziputility.exe #SOFTCNAPP wnziputility.exe wnzipfilemanager.exe wnziputility.exe #SOFTCNAPP wnziputility.exe wnziputility.exe wnziputility.exe #SOFTCNAPP wnziptool.exe setup_wnysxz001.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1456"C:\Program Files\WanNengZip\WnZipPower32.exe" RegCMC:\Program Files\WanNengZip\WnZipPower32.exe
WnZipUtility.exe
User:
admin
Company:
万能压缩
Integrity Level:
HIGH
Description:
万能压缩
Exit code:
1
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnzippower32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
1528"C:\Program Files\WanNengZip\WnZipVirtualCD.exe" /installC:\Program Files\WanNengZip\WnZipVirtualCD.exe
WnZipUtility.exe
User:
admin
Company:
www.wn51.com
Integrity Level:
HIGH
Description:
虚拟光盘
Exit code:
0
Version:
1.0.0.11031
Modules
Images
c:\program files\wannengzip\wnzipvirtualcd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1824"C:\Program Files\WanNengZip\WnZipTool.exe" LongSpriteC:\Program Files\WanNengZip\WnZipTool.exe
WnZipUtility.exe
User:
admin
Company:
万能压缩
Integrity Level:
MEDIUM
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnziptool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1848"C:\Program Files\WanNengZip\WnZipUtility.exe" DoSetDefaultRelC:\Program Files\WanNengZip\WnZipUtility.exe
WnZipFileManager.exe
User:
admin
Company:
万能压缩
Integrity Level:
MEDIUM
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnziputility.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
2164"C:\Users\admin\Downloads\setup_wnysxz001.exe" C:\Users\admin\Downloads\setup_wnysxz001.exeexplorer.exe
User:
admin
Company:
万能压缩
Integrity Level:
MEDIUM
Description:
万能压缩
Exit code:
3221226540
Version:
1.3.9.19627
Modules
Images
c:\systemroot\system32\ntdll.dll
2232"C:\Program Files\WanNengZip\WnZipUtility.exe" InstallSpreadOperate --NewClientID wnysxz001****** --InstallSilent falseC:\Program Files\WanNengZip\WnZipUtility.exe
setup_wnysxz001.exe
User:
admin
Company:
万能压缩
Integrity Level:
HIGH
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnziputility.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2848"C:\Program Files\WanNengZip\WnZipUtility.exe" UpLoadOpenST --name 主程序C:\Program Files\WanNengZip\WnZipUtility.exe
WnZip.exe
User:
admin
Company:
万能压缩
Integrity Level:
MEDIUM
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnzipcontextmenu32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
2848"C:\Program Files\WanNengZip\WnZipPower32.exe" Reg32CMC:\Program Files\WanNengZip\WnZipPower32.exeWnZipPower32.exe
User:
admin
Company:
万能压缩
Integrity Level:
HIGH
Description:
万能压缩
Exit code:
1
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnzippower32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2928"C:\Program Files\WanNengZip\WnZipUtility.exe" StExOp --RunType 1C:\Program Files\WanNengZip\WnZipUtility.exe
WnZip.exe
User:
admin
Company:
万能压缩
Integrity Level:
MEDIUM
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\program files\wannengzip\wnziputility.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3000"C:\Users\admin\Downloads\setup_wnysxz001.exe" C:\Users\admin\Downloads\setup_wnysxz001.exe
explorer.exe
User:
admin
Company:
万能压缩
Integrity Level:
HIGH
Description:
万能压缩
Exit code:
0
Version:
1.3.9.19627
Modules
Images
c:\users\admin\downloads\setup_wnysxz001.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
2 096
Read events
412
Write events
1 527
Delete events
157

Modification events

(PID) Process:(3000) setup_wnysxz001.exeKey:HKEY_CURRENT_USER\Software\WanNengZip\Setting
Operation:writeName:InstallType
Value:
0
(PID) Process:(3000) setup_wnysxz001.exeKey:HKEY_CURRENT_USER\Software\WanNengZip\PreInstall
Operation:writeName:InstallParentName
Value:
Explorer.EXE
(PID) Process:(3000) setup_wnysxz001.exeKey:HKEY_CURRENT_USER\Software\WanNengZip\PreInstall
Operation:writeName:InstallParentSign
Value:
UnKonw
(PID) Process:(3000) setup_wnysxz001.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WanNengZip
Operation:writeName:InstallPath
Value:
C:\Program Files\WanNengZip\
(PID) Process:(3000) setup_wnysxz001.exeKey:HKEY_CURRENT_USER\Software\WanNengZip\Setting
Operation:writeName:SoftMD5
Value:
7457a920304faa494f748a540b00d2ec
(PID) Process:(2232) WnZipUtility.exeKey:HKEY_CURRENT_USER\Software\WanNengZip\AppInfo
Operation:writeName:CfgRootPath
Value:
C:\Users\admin\AppData\LocalLow\WanNengZip\
(PID) Process:(2232) WnZipUtility.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WanNengZip
Operation:writeName:InstallPath
Value:
C:\Program Files\WanNengZip\
(PID) Process:(2232) WnZipUtility.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WanNengZip
Operation:writeName:LastUninstallTime
Value:
0
(PID) Process:(2232) WnZipUtility.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\TXlTb2Z0\U0hTb2Z0\V2FuTmVuZ1ppcA==
Operation:writeName:LastUninstallTime
Value:
0
(PID) Process:(2232) WnZipUtility.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WanNengZip
Operation:writeName:UninstallNum
Value:
0
Executable files
26
Suspicious files
1
Text files
84
Unknown types
5

Dropped files

PID
Process
Filename
Type
3000setup_wnysxz001.exeC:\Users\admin\AppData\Local\Temp\WanNengZip-98075-7zData.7z
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\Lang\zh-cn.txttext
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\Setting\FilterConfig.xmlxml
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\WnZip.exeexecutable
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\WanNengZip.initext
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\WnZipDecrypt.exeexecutable
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\Common Files\WanNengZip\WanNengZip.initext
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\wnzipvirtualcdbus.catcat
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\WnZipFileManager.exeexecutable
MD5:
SHA256:
3000setup_wnysxz001.exeC:\Program Files\WanNengZip\Setting\AlgorithmConfig.xmlxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
11
DNS requests
10
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2232
WnZipUtility.exe
GET
117.50.93.3:80
http://tjtv3.wn51.com/fdot.php?data=Nzg1OTQ3NTQ1ODU3MzA3MTIwMDMyNDcxMjQ2OTYxNjQ2NzE5MTk1MjQyMzMxOTAwMTgzMzE5NzEzNTYxMDMxMTAyNTgzNzA4NjczNDYyNDI2MzUyNDE0NjY1NTMwNDQzMDcxMjcxMDIxMTEyNTUzMTE1NjYyNjQ0MDczNTM3NTI2NTIyNzExMDE1NTgxMjE0MzUwMDY4MjIyNjE0MTE0MDIwNjczNTUxMjA2NzM1MDMyMDE2MjI3MDY3NDczOTYzNDMzNzIwNTk1MTMwNDk3MQ%3D%3D
CN
malicious
2848
WnZipUtility.exe
GET
117.50.93.3:80
http://proup.wn51.com/proup.php?data=MzUyMTc2NTE2NjYzNjcwODY2NDk1MTA4Njg0ODY3MjQ2ODM0NTk0NTY4NjM2MTQyNjgzOTY5MzQ2ODM5NjYzOTY4MzQ2MDQ3NjYzNDY3MTI2ODU3NTExNjY0NTc0MjY5NTAxNjYxMDI1NDM0NTAwMjA0MTIyMjIyMTE1MTQyNDU3MDM5NjgwMjY4NTYyNDI4NTU0NjE1MDIxOTQ2NjYyNDE5Mzk1MTQzNjg1NDU5Mjg2ODU3MTE0NTY0NTEzODQ2MDM0ODI4NDIwNzIwMTU0OTY2NDMzMDQyMDI3MDAwMzAxODY3MDAzODAyMjY0MDI5
CN
malicious
3664
WnZipUtility.exe
GET
117.50.93.3:80
http://proup.wn51.com/proup.php?data=NTMyMzUxMDQwNDYyMjI1NzA0NDEyNDU3MjE1ODIyNTYyMTM3MjMwMDIxNjIwMjI5MjEzNjAzMzcyMTM2MDQzNjIxMzcyMDY0MDQzNzIyNDgyMTQyMjQxNzYwNDIyOTAzMDYxNzAyNjU0NjM3MDY2NTA3NDgzODM4NzEyNDI5MDA0NDM2MjE2NTIxNTk1NjQ5NjM0NzM0NjUzMTQ3MDQ1NjMxMzYyNDI1MjE0NjIzNDkyMTQyNzEwMDYwMjQ2ODQ3MzM1ODQ5MjkzMjA4MzQ0MTA0MjUyODM3Njg2NzcwMjk2NTA5MzIyODY2Mjc0MzI4MjkyMjMyNjgzNzMzMzU1NA%3D%3D
CN
malicious
2928
WnZipUtility.exe
GET
117.50.93.3:80
http://tjtv3.wn51.com/ts.php?data=NGI0NzA0MWI4MmExMGFkMjJmMjNjMmQyNmI1MDA2ODkJV2FuTmVuZ1ppcAkxLjMuMS45CXdueXN4ejAwMTE5MDcxOAlMb25nU3ByaXRlCTEJMA%3D%3D
CN
malicious
3448
WnZipUtility.exe
GET
106.75.114.162:80
http://tjv5.wn51.com/statistics/timestamp
CN
malicious
1824
WnZipTool.exe
GET
117.50.93.3:80
http://tjtv3.wn51.com/ts.php?data=NGI0NzA0MWI4MmExMGFkMjJmMjNjMmQyNmI1MDA2ODkJV2FuTmVuZ1ppcAkxLjMuMS45CXdueXN4ejAwMTE5MDcxOAlDWkpDS1MJMQkw
CN
malicious
3000
setup_wnysxz001.exe
GET
120.132.61.186:80
http://tjv1.wn51.com/statistics/timestamp
CN
malicious
3752
WnZipUtility.exe
GET
200
163.171.140.206:80
http://d.wn51.com/yasuo/yp/yp.dat
US
binary
481 b
malicious
1824
WnZipTool.exe
GET
200
163.171.140.206:80
http://d.wn51.com/yasuo/cld/tt.dat?rand=10253
US
binary
326 b
malicious
3064
TimeHelp.exe
GET
404
163.171.140.206:80
http://d.wn51.com/yasuo/cld/po.dat?rand=7011
US
text
41 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3752
WnZipUtility.exe
163.171.140.206:80
d.wn51.com
US
malicious
2848
WnZipUtility.exe
117.50.93.3:80
tjtv3.wn51.com
IDC, China Telecommunications Corporation
CN
malicious
3664
WnZipUtility.exe
117.50.93.3:80
tjtv3.wn51.com
IDC, China Telecommunications Corporation
CN
malicious
1824
WnZipTool.exe
163.171.140.206:80
d.wn51.com
US
malicious
1824
WnZipTool.exe
117.50.93.3:80
tjtv3.wn51.com
IDC, China Telecommunications Corporation
CN
malicious
3448
WnZipUtility.exe
106.75.114.162:80
tjv5.wn51.com
China Unicom Beijing Province Network
CN
malicious
2928
WnZipUtility.exe
163.171.140.206:80
d.wn51.com
US
malicious
2928
WnZipUtility.exe
117.50.93.3:80
tjtv3.wn51.com
IDC, China Telecommunications Corporation
CN
malicious
3064
TimeHelp.exe
163.171.140.206:80
d.wn51.com
US
malicious
3000
setup_wnysxz001.exe
120.132.61.186:80
tjv1.wn51.com
China Unicom Beijing Province Network
CN
malicious

DNS requests

Domain
IP
Reputation
tjv1.wn51.com
  • 120.132.61.186
malicious
config.wn51.com
suspicious
tjtv3.wn51.com
  • 117.50.93.3
unknown
d.wn51.com
  • 163.171.140.206
malicious
proup.wn51.com
  • 117.50.93.3
malicious
tjv5.wn51.com
  • 106.75.114.162
malicious

Threats

PID
Process
Class
Message
3752
WnZipUtility.exe
Misc activity
ADWARE [PTsecurity] Softcnapp.J PUP
3752
WnZipUtility.exe
Misc activity
ADWARE [PTsecurity] PUA.Softcnapp payload
2928
WnZipUtility.exe
Misc activity
ADWARE [PTsecurity] PUA.Softcnapp payload
1824
WnZipTool.exe
Misc activity
ADWARE [PTsecurity] PUA.Softcnapp payload
Process
Message
setup_wnysxz001.exe
[zip]CreateRunProcess("C:\Program Files\WanNengZip\WnZipUtility.exe" InstallSpreadOperate --NewClientID wnysxz001****** --InstallSilent false)
WnZipUtility.exe
[zip]CreateRunProcess("C:\Program Files\WanNengZip\WnZipPower32.exe" RegCM)
WnZipUtility.exe
[zip]CreateRunProcess("C:\Program Files\WanNengZip\WnZipVirtualCD.exe" /install)
WnZipPower32.exe
[zip]CreateRunProcess("C:\Program Files\WanNengZip\WnZipPower32.exe" Reg32CM)
WnZipUtility.exe
CheckRegSZValue false -
WnZipUtility.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\UserChoice
WnZipUtility.exe
WnZipUtility.exe
CheckRegSZValue false -
WnZipUtility.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zipx\UserChoice
WnZipUtility.exe