File name:

iconmaker.exe

Full analysis: https://app.any.run/tasks/07aa3ac2-7a65-41f2-be8f-4b095cfd0128
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:02:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

8D56AC13C3541471529C062CA8E5628B

SHA1:

1ABDF80756D9718A8AE3596159775909EDBD85EC

SHA256:

5CF70EA2B15773FFCC7BFEDF8BCF8D7C4C4A882FD0C61B6504A8103E4670CCF6

SSDEEP:

49152:Eeo7Cy/bxuuRhTnwBH7UeohTFp9mm7HgfPQ5W/V2wxsrD8tYZM/ISedD5wahApD/:Eeo7CybxHys9FfE36W/V2wxsj0I/JzwZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • iconmaker.exe (PID: 6112)
    • Executable content was dropped or overwritten

      • iconmaker.exe (PID: 2320)
    • Creates a software uninstall entry

      • iconmaker.exe (PID: 2320)
    • Searches for installed software

      • iconmaker.exe (PID: 2320)
  • INFO

    • Creates files in the program directory

      • iconmaker.exe (PID: 2320)
    • Creates files or folders in the user directory

      • iconmaker.exe (PID: 2320)
      • WerFault.exe (PID: 5204)
    • The sample compiled with chinese language support

      • iconmaker.exe (PID: 2320)
    • The sample compiled with english language support

      • iconmaker.exe (PID: 2320)
    • Manual execution by a user

      • iconmaker.exe (PID: 6112)
    • Create files in a temporary directory

      • iconmaker.exe (PID: 2320)
    • Checks supported languages

      • iconmaker.exe (PID: 6112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (91.7)
.exe | Win64 Executable (generic) (5.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:10:25 19:47:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.4455.0.0
ProductVersionNumber: 0.4455.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: icon-maker.com
FileDescription: Make your own icon with Easy Icon Maker
FileVersion: Easy Icon Maker
LegalCopyright: icon-maker.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iconmaker.exe sppextcomobj.exe no specs iconmaker.exe werfault.exe no specs iconmaker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2320"C:\Users\admin\AppData\Local\Temp\iconmaker.exe" C:\Users\admin\AppData\Local\Temp\iconmaker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\syswow64\riched32.dll
c:\windows\syswow64\riched20.dll
c:\windows\syswow64\usp10.dll
c:\windows\syswow64\msls31.dll
c:\windows\syswow64\cabinet.dll
c:\users\admin\appdata\local\temp\glfc25c.tmp
c:\windows\syswow64\windows.storage.dll
c:\windows\syswow64\wldp.dll
c:\windows\syswow64\clbcatq.dll
c:\windows\syswow64\propsys.dll
4528"C:\Users\admin\AppData\Local\Temp\iconmaker.exe" C:\Users\admin\AppData\Local\Temp\iconmaker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\iconmaker.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5204C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6112 -s 968C:\Windows\SysWOW64\WerFault.exeiconmaker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
5864C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
6112"C:\Program Files (x86)\Easy Icon Maker\iconmaker.exe" C:\Program Files (x86)\Easy Icon Maker\iconmaker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EasyIconMaker MFC Application
Exit code:
3221225477
Version:
5, 0, 0, 6
Modules
Images
c:\program files (x86)\easy icon maker\iconmaker.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
1 871
Read events
1 862
Write events
9
Delete events
0

Modification events

(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:DisplayName
Value:
Easy Icon Maker
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:UninstallString
Value:
C:\PROGRA~2\EASYIC~1\UNWISE.EXE C:\PROGRA~2\EASYIC~1\INSTALL.LOG
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:DisplayVersion
Value:
5.0
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:HelpLink
Value:
iconmaker.chm
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:Publisher
Value:
icon-maker.com
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:URLInfoAbout
Value:
http://www.icon-maker.com
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:Contact
Value:
support@icon-maker.com
(PID) Process:(2320) iconmaker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Easy Icon Maker
Operation:writeName:Comments
Value:
Easy Icon Maker
(PID) Process:(6112) iconmaker.exeKey:HKEY_CURRENT_USER\SOFTWARE\ASProtect\SpecData
Operation:writeName:14693A8914693A89
Value:
4B5999F8413833EC473A249A44F87D77DB716383233EEBDFF8FF0855CDCF
Executable files
22
Suspicious files
13
Text files
12
Unknown types
1

Dropped files

PID
Process
Filename
Type
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\temp.000executable
MD5:438D25215477B70AE66F6C7DF024373E
SHA256:29398D874EC16BF3EF6E5ECE4B5EB501EE9E3BD87D90F700C8617667DBD6C4C3
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\ChangeIcon.exeexecutable
MD5:438D25215477B70AE66F6C7DF024373E
SHA256:29398D874EC16BF3EF6E5ECE4B5EB501EE9E3BD87D90F700C8617667DBD6C4C3
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\~GLH0002.TMPexecutable
MD5:438D25215477B70AE66F6C7DF024373E
SHA256:29398D874EC16BF3EF6E5ECE4B5EB501EE9E3BD87D90F700C8617667DBD6C4C3
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\~GLH0003.TMPexecutable
MD5:438D25215477B70AE66F6C7DF024373E
SHA256:29398D874EC16BF3EF6E5ECE4B5EB501EE9E3BD87D90F700C8617667DBD6C4C3
2320iconmaker.exeC:\Users\admin\AppData\Local\Temp\GLKB672.tmpexecutable
MD5:517419CAE37F6C78C80F9B7D0FBB8661
SHA256:BFE7E013CFB85E78B994D3AD34ECA08286494A835CB85F1D7BCED3DF6FE93A11
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\~GLH0001.TMPexecutable
MD5:79979253DF215587F29028D8E70F3132
SHA256:4801A2134163DB74C0CF88812D6A434FF0426F07733FBF691A6084CCFCE82287
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\iconmaker.chmchm
MD5:D289E6E90A423C20C806663291BB83FA
SHA256:C6361879B65CB4BA4CFAA39DE15735C66081E63576335D2A9B2A5AFC5B3F403B
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\UNWISE.EXEexecutable
MD5:79979253DF215587F29028D8E70F3132
SHA256:4801A2134163DB74C0CF88812D6A434FF0426F07733FBF691A6084CCFCE82287
2320iconmaker.exeC:\Program Files (x86)\Easy Icon Maker\IconExplorer.exeexecutable
MD5:6EA86EED66AD366A46368C70AB175A72
SHA256:E3DDD91567ACCF1B0AB5FB1DE5B63AA95EE15C2F6E38C5C7B14C5EE3B32B208C
2320iconmaker.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:3B2E23D259394C701050486E642D14FA
SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.89:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4628
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4628
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2.16.164.89:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.89
  • 2.16.164.74
  • 2.16.164.90
  • 2.16.164.106
  • 2.16.164.73
  • 2.16.164.51
  • 2.16.164.72
  • 2.16.164.82
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.68
  • 40.126.31.130
  • 40.126.31.3
  • 20.190.159.23
  • 20.190.159.128
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info