File name:

MIWIFIRepairTool.x86.zip

Full analysis: https://app.any.run/tasks/2b21e92e-b59a-4ec3-8395-38309e7dbad6
Verdict: Malicious activity
Analysis date: October 24, 2022, 08:06:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

2FE36EA173EAA37FB915C956CE30EC50

SHA1:

BDC7F127D318A27CEC7AB992430CBC22DE6CEE32

SHA256:

436E57A5E2DAF1C5B4ECE8851A7B7517C1FBC9E69ACBA8FAC3806AA160F251B5

SSDEEP:

24576:rdp/HgYq+SvVIOiyOW8p45sxaIPgUB4Lbj13REQcBuXgHVWd:rfHgY7SvVFy4ybTBOlREQ0Cgod

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MIWIFIRepairTool.x86.exe (PID: 1664)
      • MIWIFIRepairTool.x86.exe (PID: 2244)
    • Loads dropped or rewritten executable

      • MIWIFIRepairTool.x86.exe (PID: 1664)
  • SUSPICIOUS

    • Reads Internet Settings

      • MIWIFIRepairTool.x86.exe (PID: 1664)
    • Uses NETSH.EXE for network configuration

      • MIWIFIRepairTool.x86.exe (PID: 1664)
  • INFO

    • Process checks LSA protection

      • MIWIFIRepairTool.x86.exe (PID: 1664)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1420)
    • Checks supported languages

      • MIWIFIRepairTool.x86.exe (PID: 1664)
    • Reads the computer name

      • MIWIFIRepairTool.x86.exe (PID: 1664)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1420)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1420)
    • Creates a file in a temporary directory

      • MIWIFIRepairTool.x86.exe (PID: 1664)
    • Changes default file association

      • rundll32.exe (PID: 3364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe miwifirepairtool.x86.exe no specs miwifirepairtool.x86.exe netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs notepad.exe no specs rundll32.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1420"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MIWIFIRepairTool.x86.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1664"C:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\MIWIFIRepairTool.x86.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\MIWIFIRepairTool.x86.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
MIWIFIRepairTool
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1420.47275\miwifirepairtool.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1788"C:\Windows\System32\netsh.exe" interface ip set address name=11 source=static addr=192.168.31.100 mask=255.255.255.0C:\Windows\System32\netsh.exeMIWIFIRepairTool.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2244"C:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\MIWIFIRepairTool.x86.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\MIWIFIRepairTool.x86.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MIWIFIRepairTool
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1420.47275\miwifirepairtool.x86.exe
c:\windows\system32\ntdll.dll
3132"C:\Windows\System32\netsh.exe" interface ip set address name=11 source=dhcpC:\Windows\System32\netsh.exeMIWIFIRepairTool.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\credui.dll
3148"C:\Windows\System32\netsh.exe" interface ip set dns name=11 source=static addr=192.168.31.1 register=PRIMARYC:\Windows\System32\netsh.exeMIWIFIRepairTool.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\netsh.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3156"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1420.3173\tftp.logC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\notepad.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3268"C:\Windows\System32\netsh.exe" interface ip set dns name=11 source=dhcpC:\Windows\System32\netsh.exeMIWIFIRepairTool.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\credui.dll
3364"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa1420.5062\miwifi_r4_firmware_f1bbb_2.26.145.binC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3444"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1420.5062\miwifi_r4_firmware_f1bbb_2.26.145.binC:\Windows\system32\NOTEPAD.EXErundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
5 607
Read events
5 141
Write events
466
Delete events
0

Modification events

(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1420) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MIWIFIRepairTool.x86.zip
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1420) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1664MIWIFIRepairTool.x86.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\miwifi_r4_firmware_f1bbb_2.26.145.bin
MD5:
SHA256:
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1420.5062\miwifi_r4_firmware_f1bbb_2.26.145.bin
MD5:
SHA256:
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\MIWIFIRepairTool.x86.zipcompressed
MD5:
SHA256:
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\__rzi_1420.1867compressed
MD5:
SHA256:
1664MIWIFIRepairTool.x86.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\tftp.logtext
MD5:
SHA256:
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1420.3173\tftp.logtext
MD5:
SHA256:
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\MIWIFIRepairTool.x86.exeexecutable
MD5:D1EA5D47A9EE28656D5E742712DA733F
SHA256:86F257F7A37EBEFCD51E76A9C8EB188E8834A1F6CACF0D7D61EBFA1FAD3045BD
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\libcurl.dllexecutable
MD5:8CEC74959F8525CDDC1B26CEB97C00E7
SHA256:E74E8F50886A32638E735A884B4AC70D34D6C063FC1FB118050F2822D57A19D8
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\vcruntime140.dllexecutable
MD5:7587BF9CB4147022CD5681B015183046
SHA256:C40BB03199A2054DABFC7A8E01D6098E91DE7193619EFFBD0F142A7BF031C14D
1420WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1420.47275\vcruntime140d.dllexecutable
MD5:9FAA318E1AA934DBB06EC42A70643DBC
SHA256:9A67DAF983B21B54AF0039872003348BEBED9ECF72CA779D5475EFEEA0B628DE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1664
MIWIFIRepairTool.x86.exe
GET
200
20.47.97.231:80
http://api.miwifi.com/data/tffp_rom_link_info
US
text
330 b
whitelisted
1664
MIWIFIRepairTool.x86.exe
GET
200
193.108.153.5:80
http://bigota.miwifi.com/xiaoqiang/rom/r4/miwifi_r4_firmware_f1bbb_2.26.145.bin
unknown
binary
15.6 Mb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1664
MIWIFIRepairTool.x86.exe
20.47.97.231:80
api.miwifi.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1664
MIWIFIRepairTool.x86.exe
193.108.153.5:80
bigota.miwifi.com
Akamai International B.V.
DE
suspicious

DNS requests

Domain
IP
Reputation
api.miwifi.com
  • 20.47.97.231
unknown
bigota.miwifi.com
  • 193.108.153.5
  • 193.108.153.26
suspicious

Threats

No threats detected
Process
Message
MIWIFIRepairTool.x86.exe
Th 2972 :opening comm socket
MIWIFIRepairTool.x86.exe
Th 2972 :Console disconnected
MIWIFIRepairTool.x86.exe
Th 2976 :Port 17152 may be reused
MIWIFIRepairTool.x86.exe
Th 2780 :connected to console
MIWIFIRepairTool.x86.exe
Th 2972 :Verify Console/GUI parameters
MIWIFIRepairTool.x86.exe
Th 2972 :Version check OK
MIWIFIRepairTool.x86.exe
Th 2780 :GUI Version check OK
MIWIFIRepairTool.x86.exe
Th 2972 :Console connected
MIWIFIRepairTool.x86.exe
Th 3028 :Scheduler signal received
MIWIFIRepairTool.x86.exe
Th 2780 :GUI: new service 4 status 4