File name:

WRCFree_11.1.10.725.exe

Full analysis: https://app.any.run/tasks/94d9f2d7-443e-4b10-9204-e4376e03796c
Verdict: Malicious activity
Analysis date: March 31, 2025, 13:38:13
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
psexec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

C06A65363980BF3F1247BFD63C0A3F7E

SHA1:

1C4F2639D6D750430D8CFD309289332659DAC67F

SHA256:

75482F3542E72F7DA29B3CF869A8D95A1D756EEEBC7B25D2EA7869E2A1050D69

SSDEEP:

98304:xbUk4fERsrl5SwKmezXpj4AgoHfcy4n1DBFGHRWkAsNya2gb/lavtDCC2tMKkbyD:suTDlz4LQ47zKgETj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • WRCFree_11.1.10.725.exe (PID: 3956)
      • WRCFree_11.1.10.725.exe (PID: 4880)
      • WiseRegCleaner.exe (PID: 5400)
      • WiseRegCleaner.exe (PID: 7216)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Executable content was dropped or overwritten

      • WRCFree_11.1.10.725.exe (PID: 3956)
      • WRCFree_11.1.10.725.exe (PID: 4880)
      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Reads security settings of Internet Explorer

      • WRCFree_11.1.10.725.tmp (PID: 3676)
      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Process drops legitimate windows executable

      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Checks for the .NET to be installed

      • regedit.exe (PID: 6032)
    • Reads Microsoft Outlook installation path

      • regedit.exe (PID: 6032)
    • Reads the history of recent RDP connections

      • regedit.exe (PID: 6032)
    • Reads Internet Explorer settings

      • regedit.exe (PID: 6032)
    • The process checks if it is being run in the virtual environment

      • WiseRegCleaner.exe (PID: 7216)
      • regedit.exe (PID: 6032)
    • PSEXEC has been detected

      • regedit.exe (PID: 6032)
    • Checks for Java to be installed

      • WiseRegCleaner.exe (PID: 7216)
    • Executes as Windows Service

      • VSSVC.exe (PID: 4376)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 4288)
    • Searches for installed software

      • regedit.exe (PID: 6032)
      • WiseRegCleaner.exe (PID: 7216)
  • INFO

    • Checks supported languages

      • WRCFree_11.1.10.725.tmp (PID: 3676)
      • WRCFree_11.1.10.725.exe (PID: 4880)
      • WRCFree_11.1.10.725.tmp (PID: 2908)
      • WRCFree_11.1.10.725.exe (PID: 3956)
      • WiseRegCleaner.exe (PID: 7216)
      • CSTask.exe (PID: 4408)
      • identity_helper.exe (PID: 8004)
    • Process checks computer location settings

      • WRCFree_11.1.10.725.tmp (PID: 3676)
      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Create files in a temporary directory

      • WRCFree_11.1.10.725.exe (PID: 4880)
      • WRCFree_11.1.10.725.exe (PID: 3956)
      • WRCFree_11.1.10.725.tmp (PID: 2908)
      • regedit.exe (PID: 6032)
    • Reads the computer name

      • WRCFree_11.1.10.725.tmp (PID: 2908)
      • WRCFree_11.1.10.725.tmp (PID: 3676)
      • WiseRegCleaner.exe (PID: 7216)
      • CSTask.exe (PID: 4408)
      • identity_helper.exe (PID: 8004)
    • Creates files in the program directory

      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • The sample compiled with english language support

      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Creates a software uninstall entry

      • WRCFree_11.1.10.725.tmp (PID: 2908)
    • Detects InnoSetup installer (YARA)

      • WRCFree_11.1.10.725.exe (PID: 4880)
    • Checks proxy server information

      • WRCFree_11.1.10.725.tmp (PID: 3676)
      • WiseRegCleaner.exe (PID: 7216)
    • Local mutex for internet shortcut management

      • WRCFree_11.1.10.725.tmp (PID: 3676)
    • Application launched itself

      • msedge.exe (PID: 5984)
      • msedge.exe (PID: 1324)
    • Reads the software policy settings

      • WiseRegCleaner.exe (PID: 7216)
      • regedit.exe (PID: 6032)
      • slui.exe (PID: 7588)
    • Reads Environment values

      • identity_helper.exe (PID: 8004)
    • Reads the machine GUID from the registry

      • regedit.exe (PID: 6032)
    • Compiled with Borland Delphi (YARA)

      • WiseRegCleaner.exe (PID: 7216)
    • Checks transactions between databases Windows and Oracle

      • regedit.exe (PID: 6032)
    • Reads Microsoft Office registry keys

      • regedit.exe (PID: 6032)
    • Reads the time zone

      • regedit.exe (PID: 6032)
    • Reads Windows Product ID

      • regedit.exe (PID: 6032)
    • Reads mouse settings

      • regedit.exe (PID: 6032)
    • Disables trace logs

      • regedit.exe (PID: 6032)
    • Reads security settings of Internet Explorer

      • regedit.exe (PID: 6032)
    • Creates files or folders in the user directory

      • WiseRegCleaner.exe (PID: 7216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:10:12 11:15:57+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 682496
InitializedDataSize: 105984
UninitializedDataSize: -
EntryPoint: 0xa7ed0
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 11.1.10.725
ProductVersionNumber: 11.1.10.725
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: WiseCleaner.com
FileDescription: Wise Registry Cleaner
FileVersion: 11.1.10
LegalCopyright: WiseCleaner.com
OriginalFileName:
ProductName: Wise Registry Cleaner
ProductVersion: 11.1.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
317
Monitored processes
56
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start wrcfree_11.1.10.725.exe wrcfree_11.1.10.725.tmp no specs wrcfree_11.1.10.725.exe wrcfree_11.1.10.725.tmp sppextcomobj.exe no specs slui.exe cstask.exe no specs conhost.exe no specs msedge.exe wiseregcleaner.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs wiseregcleaner.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs THREAT regedit.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs SPPSurrogate no specs vssvc.exe no specs msedge.exe no specs plugscheduler.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
736"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1228 --field-trial-handle=2280,i,17722459559488658404,15424268798427810111,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1052\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCSTask.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1228C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1240"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x31c,0x320,0x324,0x314,0x360,0x7ffc88a25fd8,0x7ffc88a25fe4,0x7ffc88a25ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1324"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-windowC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1760"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3280 --field-trial-handle=2280,i,17722459559488658404,15424268798427810111,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2064C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2432"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5008 --field-trial-handle=2280,i,17722459559488658404,15424268798427810111,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2908"C:\Users\admin\AppData\Local\Temp\is-US35T.tmp\WRCFree_11.1.10.725.tmp" /SL5="$1B02DC,5146965,789504,C:\Users\admin\AppData\Local\Temp\WRCFree_11.1.10.725.exe" /SPAWNWND=$40288 /NOTIFYWND=$7034A C:\Users\admin\AppData\Local\Temp\is-US35T.tmp\WRCFree_11.1.10.725.tmp
WRCFree_11.1.10.725.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-us35t.tmp\wrcfree_11.1.10.725.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mpr.dll
3176"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2276 --field-trial-handle=2280,i,17722459559488658404,15424268798427810111,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
713 887
Read events
713 679
Write events
199
Delete events
9

Modification events

(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\WiseCleaner\WRC
Operation:writeName:path
Value:
C:\Program Files (x86)\Wise\Wise Registry Cleaner
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\WiseCleaner\WRC
Operation:writeName:Product Name
Value:
Wise Registry Cleaner
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.0.3 (u)
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Wise\Wise Registry Cleaner
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\Wise\Wise Registry Cleaner\
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:Inno Setup: Icon Group
Value:
Wise Registry Cleaner
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:DisplayName
Value:
Wise Registry Cleaner
(PID) Process:(2908) WRCFree_11.1.10.725.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe
Executable files
26
Suspicious files
373
Text files
158
Unknown types
0

Dropped files

PID
Process
Filename
Type
2908WRCFree_11.1.10.725.tmpC:\Program Files (x86)\Wise\Wise Registry Cleaner\unins000.exeexecutable
MD5:F3059883BA12E5C9FCD7E26D6B9A80F6
SHA256:A3A34F6F67AA5AF6E179D40B901E53F87204FF21FDEC8AB060AAA8EE371607A5
2908WRCFree_11.1.10.725.tmpC:\Users\admin\AppData\Local\Temp\is-KKMD0.tmp\is-TDOOO.tmpexecutable
MD5:183F106261F3A193E9F26A8B5EF11417
SHA256:68DEE14B0CA784A9C98FA8B09BF5DC0F9DC31734E953BA04345ADEAECCA9D32A
2908WRCFree_11.1.10.725.tmpC:\Program Files (x86)\Wise\Wise Registry Cleaner\Languages\is-HD57S.tmptext
MD5:A6C4E4B6D249DB56DADA2F0C28621E1A
SHA256:EF2897FB7A6D366DBB72DA1AD2727EB95E853CC5441B195328D2FBE71D3AAAD2
2908WRCFree_11.1.10.725.tmpC:\Program Files (x86)\Wise\Wise Registry Cleaner\is-5BKGU.tmpexecutable
MD5:7C88467822A9648654FA08F6F20EDA1A
SHA256:5494B196EC622D86D857F1B85F2D8A2ED2E315CE5FB8AEA7062A102F28959A58
2908WRCFree_11.1.10.725.tmpC:\Program Files (x86)\Wise\Wise Registry Cleaner\is-8DR4F.tmpexecutable
MD5:F3059883BA12E5C9FCD7E26D6B9A80F6
SHA256:A3A34F6F67AA5AF6E179D40B901E53F87204FF21FDEC8AB060AAA8EE371607A5
2908WRCFree_11.1.10.725.tmpC:\Users\admin\AppData\Local\Temp\is-KKMD0.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
3956WRCFree_11.1.10.725.exeC:\Users\admin\AppData\Local\Temp\is-US35T.tmp\WRCFree_11.1.10.725.tmpexecutable
MD5:F3059883BA12E5C9FCD7E26D6B9A80F6
SHA256:A3A34F6F67AA5AF6E179D40B901E53F87204FF21FDEC8AB060AAA8EE371607A5
2908WRCFree_11.1.10.725.tmpC:\Program Files (x86)\Wise\Wise Registry Cleaner\is-NOJFV.tmpexecutable
MD5:C06BACEB607AF198D5B504671EB7CD2C
SHA256:2CCEEAB93839CD6FD7B8145D60F8283ACFF80AB04C71EA81244EF15517A31C2D
2908WRCFree_11.1.10.725.tmpC:\Users\admin\AppData\Local\Temp\is-KKMD0.tmp\license.txttext
MD5:4A0F1A666912E64F1BA811FC24D7135F
SHA256:D6B418C619BA7456B594DFF10C3FACE4AC28609A64F2BF5E635292D7FF4F57E5
2908WRCFree_11.1.10.725.tmpC:\Users\admin\AppData\Local\Temp\is-KKMD0.tmp\Icon_128.bmpimage
MD5:A7FE0DB0FF9E7454CF2022AAAEF8B830
SHA256:6BA69800040D3316E66F4D9636D908AA1B515277045E4328161AEF748A17CB44
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
75
DNS requests
68
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7420
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7420
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8180
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1743945942&P2=404&P3=2&P4=gYgXKI7UZ7Z3V288OIJXcymMZybKnwbj547WOp0sqbGO0zzf3wB7nNUxt%2fJksEVa8dXkd3U1lHbmgDgQhq5nYw%3d%3d
unknown
whitelisted
8180
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1743945944&P2=404&P3=2&P4=FDE%2frqSeiY6h7XlRirccQ27VIu3tBOvyT%2fGDAAvJOulTwbW00zsqRntQ2dJMn8Noi5Q3XEj%2beIEJv2NZtX3GLQ%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
20.7.1.246:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5984
msedge.exe
239.255.255.250:1900
whitelisted
7184
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7184
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7184
msedge.exe
104.26.3.143:443
www.wisecleaner.com
CLOUDFLARENET
US
whitelisted
7184
msedge.exe
13.107.253.45:443
edge-mobile-static.azureedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7184
msedge.exe
13.107.6.158:443
business.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
client.wns.windows.com
  • 20.7.1.246
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.wisecleaner.com
  • 104.26.3.143
  • 172.67.68.11
  • 104.26.2.143
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.253.45
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
bzib.nelreports.net
  • 23.48.23.26
  • 23.48.23.51
whitelisted
www.bing.com
  • 92.123.104.35
  • 92.123.104.22
  • 92.123.104.34
  • 92.123.104.33
  • 92.123.104.26
  • 92.123.104.29
  • 92.123.104.31
  • 92.123.104.24
  • 92.123.104.32
  • 2.16.241.206
  • 2.16.241.205
  • 2.16.241.211
  • 2.16.241.203
  • 2.16.241.200
  • 2.16.241.212
  • 2.16.241.201
  • 2.16.241.207
  • 2.16.241.204
whitelisted
pdf.wisecleaner.com
  • 104.26.2.143
  • 172.67.68.11
  • 104.26.3.143
whitelisted

Threats

No threats detected
No debug info