File name:

WirelessSetupChecker.exe

Full analysis: https://app.any.run/tasks/a90b5d2d-0f47-401f-bbb0-9c46a021ee96
Verdict: Malicious activity
Analysis date: February 15, 2024, 22:11:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

556988EF3BBA4382F93AB0FFBAD23CD1

SHA1:

9B34801C2927C3DD70FC759E92AEA8DF81B8C65D

SHA256:

4714F9880D1F33E6FD215DDEE6E37B06A23FE5330A7D99EA911243C3941E11BA

SSDEEP:

49152:StPBdgrk2jdrfnts88tn2YXcvVtbr0471P/UV3OBKwI8WoPxjT+NDLW0GA8:0BdgrLjdn8tn2qcvVtbg4FUV3OBKwI8x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WirelessSetupChecker.exe (PID: 2036)
    • Starts NET.EXE for service management

      • WirelessSetupChecker.exe (PID: 2036)
      • net.exe (PID: 2964)
  • SUSPICIOUS

    • Application launched itself

      • WirelessSetupChecker.exe (PID: 2036)
    • Executes as Windows Service

      • WirelessSetupChecker.exe (PID: 3464)
  • INFO

    • Checks supported languages

      • WirelessSetupChecker.exe (PID: 2036)
      • WirelessSetupChecker.exe (PID: 2844)
      • WirelessSetupChecker.exe (PID: 3464)
      • WirelessSetupChecker.exe (PID: 3500)
    • Reads the computer name

      • WirelessSetupChecker.exe (PID: 2844)
      • WirelessSetupChecker.exe (PID: 3464)
      • WirelessSetupChecker.exe (PID: 2036)
      • WirelessSetupChecker.exe (PID: 3500)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:08:18 08:49:53+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 1195008
InitializedDataSize: 376832
UninitializedDataSize: -
EntryPoint: 0x100cce
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Brother Industries, Ltd.
FileDescription: WirelessSetupChecker
FileVersion: 1, 0, 0, 1
InternalName: WirelessSetupChecker.exe
LegalCopyright: Copyright (C) 2011-2016 Brother Industries, Ltd.
OriginalFileName: WirelessSetupChecker.exe
ProductName: WirelessSetupChecker
ProductVersion: 1, 0, 0, 1
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wirelesssetupchecker.exe wirelesssetupchecker.exe no specs net.exe no specs net1.exe no specs wirelesssetupchecker.exe no specs wirelesssetupchecker.exe no specs wirelesssetupchecker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Users\admin\Desktop\WirelessSetupChecker.exe" C:\Users\admin\Desktop\WirelessSetupChecker.exe
explorer.exe
User:
admin
Company:
Brother Industries, Ltd.
Integrity Level:
HIGH
Description:
WirelessSetupChecker
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\wirelesssetupchecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2472"C:\Users\admin\Desktop\WirelessSetupChecker.exe" C:\Users\admin\Desktop\WirelessSetupChecker.exeexplorer.exe
User:
admin
Company:
Brother Industries, Ltd.
Integrity Level:
MEDIUM
Description:
WirelessSetupChecker
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\wirelesssetupchecker.exe
c:\windows\system32\ntdll.dll
2844WirelessSetupChecker -installC:\Users\admin\Desktop\WirelessSetupChecker.exeWirelessSetupChecker.exe
User:
admin
Company:
Brother Industries, Ltd.
Integrity Level:
HIGH
Description:
WirelessSetupChecker
Exit code:
1
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\wirelesssetupchecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2964net start "Brother Wireless Setup Helper"C:\Windows\System32\net.exeWirelessSetupChecker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3464C:\Users\admin\Desktop\WirelessSetupChecker.exe -sC:\Users\admin\Desktop\WirelessSetupChecker.exeservices.exe
User:
SYSTEM
Company:
Brother Industries, Ltd.
Integrity Level:
SYSTEM
Description:
WirelessSetupChecker
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\wirelesssetupchecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3500WirelessSetupChecker -removeC:\Users\admin\Desktop\WirelessSetupChecker.exeWirelessSetupChecker.exe
User:
admin
Company:
Brother Industries, Ltd.
Integrity Level:
HIGH
Description:
WirelessSetupChecker
Exit code:
1
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\wirelesssetupchecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3948C:\Windows\system32\net1 start "Brother Wireless Setup Helper"C:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
Total events
176
Read events
176
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info