File name:

mirror_go_setup_full8050.exe

Full analysis: https://app.any.run/tasks/7c5ceac2-59f9-4fd7-b1c7-ff0cc1f4122d
Verdict: Malicious activity
Analysis date: January 18, 2024, 19:51:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

67908CA5D434F495012FD58DB2D0FED2

SHA1:

20CAEBD7F3F99CF5B27F55C1F1AC082117046A2C

SHA256:

3E14C743DA4F94BA2A358AB45BD519C18D54931F5B840B0AEEEB3824BA2FEE69

SSDEEP:

49152:mTWMwt0bSZjgVuOai5L/1qJBB+rUBpm4oDHCxCxef:mTw0WZkVuOj/cxmq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • mirror_go_setup_full8050.exe (PID: 2020)
      • mirror_go_full8050.exe (PID: 2632)
      • mirror_go_full8050.tmp (PID: 2668)
  • SUSPICIOUS

    • Reads the Internet Settings

      • mirror_go_setup_full8050.exe (PID: 2020)
      • mirror_go_full8050.tmp (PID: 2668)
    • Reads Microsoft Outlook installation path

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Executable content was dropped or overwritten

      • mirror_go_setup_full8050.exe (PID: 2020)
      • mirror_go_full8050.tmp (PID: 2668)
      • mirror_go_full8050.exe (PID: 2632)
    • Likely accesses (executes) a file from the Public directory

      • NFWCHK.exe (PID: 1216)
      • mirror_go_full8050.tmp (PID: 2668)
      • mirror_go_full8050.exe (PID: 2632)
    • Reads Internet Explorer settings

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Checks Windows Trust Settings

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Reads security settings of Internet Explorer

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Reads settings of System Certificates

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Process requests binary or script from the Internet

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Reads the Windows owner or organization settings

      • mirror_go_full8050.tmp (PID: 2668)
    • The process drops C-runtime libraries

      • mirror_go_full8050.tmp (PID: 2668)
    • Process drops legitimate windows executable

      • mirror_go_full8050.tmp (PID: 2668)
  • INFO

    • Checks supported languages

      • mirror_go_setup_full8050.exe (PID: 2020)
      • NFWCHK.exe (PID: 1216)
      • wmpnscfg.exe (PID: 2424)
      • mirror_go_full8050.exe (PID: 2632)
      • mirror_go_full8050.tmp (PID: 2668)
      • ProcessKiller.exe (PID: 2692)
    • Reads the computer name

      • mirror_go_setup_full8050.exe (PID: 2020)
      • NFWCHK.exe (PID: 1216)
      • mirror_go_full8050.tmp (PID: 2668)
      • wmpnscfg.exe (PID: 2424)
      • ProcessKiller.exe (PID: 2692)
    • Create files in a temporary directory

      • mirror_go_setup_full8050.exe (PID: 2020)
      • mirror_go_full8050.exe (PID: 2632)
      • mirror_go_full8050.tmp (PID: 2668)
    • Reads the machine GUID from the registry

      • mirror_go_setup_full8050.exe (PID: 2020)
      • NFWCHK.exe (PID: 1216)
      • ProcessKiller.exe (PID: 2692)
    • Checks proxy server information

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Creates files or folders in the user directory

      • mirror_go_setup_full8050.exe (PID: 2020)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2424)
    • Creates files in the program directory

      • mirror_go_full8050.tmp (PID: 2668)
    • Dropped object may contain TOR URL's

      • mirror_go_full8050.tmp (PID: 2668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:09:24 09:37:08+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 665088
InitializedDataSize: 466432
UninitializedDataSize: -
EntryPoint: 0x815e6
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 3.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: wondershare-mirrorgo_setup_full8050.exe
FileVersion: 3.0.0.0
LegalCopyright: Copyright©2017 Wondershare. All rights reserved.
ProductName: Wondershare MirrorGo
ProductVersion: 1.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mirror_go_setup_full8050.exe nfwchk.exe no specs wmpnscfg.exe no specs mirror_go_full8050.exe mirror_go_full8050.tmp processkiller.exe mirror_go_setup_full8050.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1216C:\Users\Public\Documents\Wondershare\NFWCHK.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exemirror_go_setup_full8050.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
.NET Framework Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\public\documents\wondershare\nfwchk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1776"C:\Users\admin\AppData\Local\Temp\mirror_go_setup_full8050.exe" C:\Users\admin\AppData\Local\Temp\mirror_go_setup_full8050.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
wondershare-mirrorgo_setup_full8050.exe
Exit code:
3221226540
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\mirror_go_setup_full8050.exe
c:\windows\system32\ntdll.dll
2020"C:\Users\admin\AppData\Local\Temp\mirror_go_setup_full8050.exe" C:\Users\admin\AppData\Local\Temp\mirror_go_setup_full8050.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
wondershare-mirrorgo_setup_full8050.exe
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\mirror_go_setup_full8050.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2424"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2632"C:\Users\Public\Documents\Wondershare\mirror_go_full8050.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare MirrorGo.log" /installpath: "C:\Program Files\Wondershare\Wondershare MirrorGo\" /DIR="C:\Program Files\Wondershare\Wondershare MirrorGo\" /WAEWIN=30152C:\Users\Public\Documents\Wondershare\mirror_go_full8050.exe
mirror_go_setup_full8050.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
MirrorGo
Exit code:
0
Version:
2.0.11.346
Modules
Images
c:\users\public\documents\wondershare\mirror_go_full8050.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2668"C:\Users\admin\AppData\Local\Temp\is-7ULCH.tmp\mirror_go_full8050.tmp" /SL5="$301A8,101985913,486912,C:\Users\Public\Documents\Wondershare\mirror_go_full8050.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare MirrorGo.log" /installpath: "C:\Program Files\Wondershare\Wondershare MirrorGo\" /DIR="C:\Program Files\Wondershare\Wondershare MirrorGo\" /WAEWIN=30152C:\Users\admin\AppData\Local\Temp\is-7ULCH.tmp\mirror_go_full8050.tmp
mirror_go_full8050.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7ulch.tmp\mirror_go_full8050.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2692"C:\Users\admin\AppData\Local\Temp\is-ISVO9.tmp\ProcessKiller.exe"C:\Users\admin\AppData\Local\Temp\is-ISVO9.tmp\ProcessKiller.exe
mirror_go_full8050.tmp
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
ProcessKiller
Exit code:
0
Version:
1.0.0.2
Modules
Images
c:\users\admin\appdata\local\temp\is-isvo9.tmp\processkiller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
5 856
Read events
5 811
Write events
45
Delete events
0

Modification events

(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(2020) mirror_go_setup_full8050.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
AA5195B5474ADA01
Executable files
129
Suspicious files
17
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
2020mirror_go_setup_full8050.exeC:\Users\Public\Documents\Wondershare\mirror_go_full8050.exe.~P2S
MD5:
SHA256:
2020mirror_go_setup_full8050.exeC:\Users\Public\Documents\Wondershare\mirror_go_full8050.exe
MD5:
SHA256:
2020mirror_go_setup_full8050.exeC:\Users\admin\AppData\Local\Temp\wsduilib.logtext
MD5:B053EBF5E0F23A2C8117F7252F441904
SHA256:83839794748E936EC34BF7B8A3E4A45671162D4B28E3E02B3651223B98B25FDA
2020mirror_go_setup_full8050.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:F1766F9D7DD4589BAAC142D457E8C601
SHA256:4E14C5A0DC7499647D940FCCD5C713D8FAC4DA94E93145C556C9FD567074526E
2020mirror_go_setup_full8050.exeC:\Users\Public\Documents\Wondershare\WAE_DOWNTASK_8050.xmlxml
MD5:57CBB8A8BBCC6911B23D1279DB53CC22
SHA256:F0A47C92D5E920C39BCF278F844EA5F351DF66A2F0E7725B2758576BFB04836E
2020mirror_go_setup_full8050.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe.configxml
MD5:AD0967A0AB95AA7D71B3DC92B71B8F7A
SHA256:9C1212BC648A2533B53A2D0AFCEC518846D97630AFB013742A9622F0DF7B04FC
2020mirror_go_setup_full8050.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57binary
MD5:9165DFEB5CA84C2D25818377998F8E77
SHA256:E5BF91BB9F00B20954FABCEBF1346ABD0833423EBB6E1A1089046A26A10FF686
2020mirror_go_setup_full8050.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57binary
MD5:2AF85801E81882221E37DBAF8B49BC2C
SHA256:C6837B7347DDC30911FCAE510AAB9148B083EB01B369E2D5314990516B08A50C
2020mirror_go_setup_full8050.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2020mirror_go_setup_full8050.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exeexecutable
MD5:27CFB3990872CAA5930FA69D57AEFE7B
SHA256:43881549228975C7506B050BCE4D9B671412D3CDC08C7516C9DBBB7F50C25146
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
29
DNS requests
5
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2020
mirror_go_setup_full8050.exe
HEAD
200
184.25.51.40:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
unknown
2020
mirror_go_setup_full8050.exe
GET
200
8.209.73.211:80
http://platform.wondershare.com/rest/v2/downloader/runtime/?client_sign={C4BA3647-0000-0QM0-0001-12A9866C77DE}&product_id=8050&wae=3.0.0
unknown
xml
1.64 Kb
unknown
2020
mirror_go_setup_full8050.exe
HEAD
200
184.25.51.49:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
unknown
2020
mirror_go_setup_full8050.exe
GET
184.25.51.40:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
unknown
2020
mirror_go_setup_full8050.exe
GET
200
23.32.238.48:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?bbdfe4b13a85bec4
unknown
compressed
4.66 Kb
unknown
2020
mirror_go_setup_full8050.exe
GET
206
184.25.51.40:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
executable
16.3 Mb
unknown
2020
mirror_go_setup_full8050.exe
GET
206
184.25.51.49:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
binary
16.3 Mb
unknown
2020
mirror_go_setup_full8050.exe
GET
184.25.51.49:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
unknown
2020
mirror_go_setup_full8050.exe
GET
206
184.25.51.40:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
binary
16.3 Mb
unknown
2020
mirror_go_setup_full8050.exe
GET
206
184.25.51.40:80
http://download.wondershare.com/cbs_down/mirror_go_full8050.exe
unknown
binary
16.3 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2020
mirror_go_setup_full8050.exe
8.209.73.211:80
platform.wondershare.com
Alibaba US Technology Co., Ltd.
DE
unknown
2020
mirror_go_setup_full8050.exe
184.25.51.40:80
download.wondershare.com
Akamai International B.V.
DE
unknown
2020
mirror_go_setup_full8050.exe
184.25.51.49:80
download.wondershare.com
Akamai International B.V.
DE
unknown
2020
mirror_go_setup_full8050.exe
163.181.92.237:443
wae.wondershare.cc
Zhejiang Taobao Network Co.,Ltd
DE
unknown
2020
mirror_go_setup_full8050.exe
23.32.238.48:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2020
mirror_go_setup_full8050.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
platform.wondershare.com
  • 8.209.73.211
unknown
download.wondershare.com
  • 184.25.51.40
  • 184.25.51.49
whitelisted
wae.wondershare.cc
  • 163.181.92.237
  • 163.181.92.236
  • 163.181.92.234
  • 163.181.92.238
  • 163.181.92.233
  • 163.181.92.232
  • 163.181.92.231
  • 163.181.92.235
unknown
ctldl.windowsupdate.com
  • 23.32.238.48
  • 2.19.198.83
  • 23.32.238.59
  • 23.32.238.81
  • 2.19.198.80
  • 2.19.198.81
  • 23.32.238.58
  • 23.32.238.64
  • 23.32.238.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2020
mirror_go_setup_full8050.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
ProcessKiller.exe
Plan B