| File name: | wnetwatcher_setup.exe |
| Full analysis: | https://app.any.run/tasks/303145d4-b352-4ee5-8aee-5df4b6ec9626 |
| Verdict: | Malicious activity |
| Analysis date: | January 25, 2024, 23:07:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 064ADD879014AB581A4CDCBA9CFCB6A3 |
| SHA1: | 69D0BD8143108282F6B99C8C153A4C21100477C9 |
| SHA256: | 56D8B9F5B0ED859EE99463519619E7201DCF696DAA86858FD5CE7CAEEB377BF0 |
| SSDEEP: | 12288:hT+yVvtWEbTq0ovxuG5Uag8BTSVlSB3y5cVkTVr3uL6HdSfps:ZWOTq0optuajBTSVlSZyCVkTVr3u8dSO |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:05:03 16:08:42+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23040 |
| InitializedDataSize: | 119808 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3225 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1036 | "C:\Users\admin\AppData\Local\Temp\wnetwatcher_setup.exe" | C:\Users\admin\AppData\Local\Temp\wnetwatcher_setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1924 | "C:\Users\admin\AppData\Local\Temp\wnetwatcher_setup.exe" | C:\Users\admin\AppData\Local\Temp\wnetwatcher_setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2804 | "C:\Program Files\NirSoft\Wireless Network Watcher\WNetWatcher.exe" | C:\Program Files\NirSoft\Wireless Network Watcher\WNetWatcher.exe | — | wnetwatcher_setup.exe | |||||||||||
User: admin Company: NirSoft Integrity Level: HIGH Description: Wireless Network Watcher Exit code: 0 Version: 2.12 Modules
| |||||||||||||||
| 3892 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Local\Temp\nsv955B.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Wireless Network Watcher\Wireless Network Watcher.lnk | binary | |
MD5:952EBE1C769CF37F2E9946C1CE0573A6 | SHA256:989E14A0E5FE301863E528DBA951CBE617B9C4AAF4753F0FCB656BB9673D4AEA | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Local\Temp\nsv955A.tmp | binary | |
MD5:F442BD03862C44DB385306FC0BC1CEDE | SHA256:25C162D4B65FDF106BF07A2396077CB5D2F78A9EC64BFE8DCFC9804F8051C588 | |||
| 1924 | wnetwatcher_setup.exe | C:\Program Files\NirSoft\Wireless Network Watcher\uninst.exe | executable | |
MD5:6AB99921D1385DD56FB4B791DA60A030 | SHA256:E086E0DD1DB0ACB3F45B8352EC2CA787DC903AB4927A6153267823B189183456 | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Local\Temp\nsv955B.tmp\StartMenu.dll | executable | |
MD5:8262FBC2A172FF04146E7587649D7091 | SHA256:AC53840D019B746AB5DABAA40D7720C9A4487C861B155926454BF8B10BD0963D | |||
| 1924 | wnetwatcher_setup.exe | C:\Program Files\NirSoft\Wireless Network Watcher\WNetWatcher.chm | binary | |
MD5:248FA1081A209B92469426B1557931E4 | SHA256:0CB705DA5A33924AF314D9F921B4CF34C63C867F9ED2C12870FE1A0E6491C9CB | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Wireless Network Watcher\Uninstall.lnk | binary | |
MD5:2F9DF4439E3437F041557520A6DB1E24 | SHA256:72DE22E917879B29188E67A0FBAA44244EC0375A1B82F1CFF2FD6B08A06CAA61 | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Wireless Network Watcher\Wireless Network Watcher Help.lnk | binary | |
MD5:6273E77378C72BFB62783B82F20C3167 | SHA256:C3CFECFE07F2D4A56A97F7F99A592DB67FAC308558A50F41537D4F8CD5E4DC11 | |||
| 1924 | wnetwatcher_setup.exe | C:\Users\admin\AppData\Local\Temp\nsv955B.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 1924 | wnetwatcher_setup.exe | C:\Program Files\NirSoft\Wireless Network Watcher\WNetWatcher.exe | executable | |
MD5:AA4CBB3546298FA9C67DC8412E71DD19 | SHA256:DBFA6E3C7FA1706C970EAB16A5E399AE7B64F08738A4E3C13038EDD767C3976D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.1:137 | — | — | — | unknown |
4 | System | 192.168.100.2:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
1.100.168.192.in-addr.arpa |
| unknown |
2.100.168.192.in-addr.arpa |
| unknown |
182.100.168.192.in-addr.arpa |
| unknown |