File name:

BingWallpaper.exe

Full analysis: https://app.any.run/tasks/7621e78e-aef8-49af-b15d-fdfc97f657d5
Verdict: Malicious activity
Analysis date: September 27, 2024, 19:17:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

37629A0AF0DA32481F515580AD65BD4D

SHA1:

6CD46F5A55974C14E9B4110384C91C8F8A21A857

SHA256:

76D14FA043D8AF232C2AE4712FF89D39D0318A1CD2A9E973926EF720CC135B7B

SSDEEP:

98304:tn2Uzb3T46DdybtlxTxEh5LNRv0Tb5QOl6TH//rjAFzkN0IrPAzANhgEKfLazl7a:YLQC/rYOUzeCN6OFFyLu1a/b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • BingWallpaper.exe (PID: 2144)
      • BWInstaller.exe (PID: 2796)
    • Process drops legitimate windows executable

      • BingWallpaper.exe (PID: 2144)
      • msiexec.exe (PID: 5184)
      • rundll32.exe (PID: 6852)
      • rundll32.exe (PID: 2180)
      • rundll32.exe (PID: 2580)
    • Executable content was dropped or overwritten

      • BingWallpaper.exe (PID: 2144)
      • rundll32.exe (PID: 6852)
      • rundll32.exe (PID: 2180)
      • rundll32.exe (PID: 2580)
      • BingWallpaperApp.exe (PID: 6632)
  • INFO

    • Create files in a temporary directory

      • BingWallpaper.exe (PID: 2144)
    • Checks supported languages

      • BingWallpaper.exe (PID: 2144)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:11:24 11:50:57+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.2
CodeSize: 25600
InitializedDataSize: 15115776
UninitializedDataSize: -
EntryPoint: 0x6a00
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.9
ProductVersionNumber: 2.0.0.9
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: BingWallpaper
FileVersion: 2.0.0.9
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: WEXTRACT.EXE .MUI
ProductName: BingWallpaper
ProductVersion: 2.0.0.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
10
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bingwallpaper.exe startupinstaller.exe no specs bwinstaller.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe bingwallpaperapp.exe rundll32.exe rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
2144"C:\Users\admin\AppData\Local\Temp\BingWallpaper.exe" C:\Users\admin\AppData\Local\Temp\BingWallpaper.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BingWallpaper
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\temp\bingwallpaper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2180rundll32.exe "C:\WINDOWS\Installer\MSI9682.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4167343 8 CustomActions!CustomActions.CustomActions.InstallPingC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2580rundll32.exe "C:\WINDOWS\Installer\MSI98B6.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4167921 14 CustomActions!CustomActions.CustomActions.VSRegisterCheckC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2796"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe
StartupInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BWInstaller
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\bwinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4004C:\Windows\syswow64\MsiExec.exe -Embedding 3FCE1507508C0855068E322B86EFC445C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4792"C:\Windows\System32\msiexec.exe" /q /i BWCInstaller.msi /norestartC:\Windows\SysWOW64\msiexec.exeBWInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5072C:\Users\admin\AppData\Local\Temp\IXP000.TMP\StartupInstaller.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\StartupInstaller.exeBingWallpaper.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\startupinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5184C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6632"C:\Users\admin\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe" C:\Users\admin\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Bing Wallpaper
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\microsoft\bingwallpaperapp\bingwallpaperapp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
6852rundll32.exe "C:\WINDOWS\Installer\MSI93D2.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4166765 2 CustomActions!CustomActions.CustomActions.StartAppC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
15 035
Read events
14 893
Write events
133
Delete events
9

Modification events

(PID) Process:(2796) BWInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Dispatcher
Operation:writeName:MachineID
Value:
56ED68D94E1D4990B42ED4331814B358
(PID) Process:(2796) BWInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\BingWallpaperApp
Operation:writeName:PartnerCode
Value:
W015
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
401400002EEFA2E61111DB01
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
1B12854DBAA00B3BB708A3DA3F2A7DF3128FC288D90DCA84DA5AC46E08399407
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3f8d2c.rbs
Value:
31133969
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3f8d2c.rbsLow
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Users\admin\AppData\Roaming\Microsoft\Installer\
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\E75EB4F5223116D48A5EDF60E49565E9
Operation:writeName:DE93B092CDFB69348933CFCBCB9A1843
Value:
01:\Software\Microsoft\BingWallpaperApp\isMSIInstalled
Executable files
25
Suspicious files
24
Text files
18
Unknown types
1

Dropped files

PID
Process
Filename
Type
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWCInstaller.msi
MD5:
SHA256:
5184msiexec.exeC:\Windows\Installer\3f8d2a.msi
MD5:
SHA256:
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWCProgressBar.dllexecutable
MD5:6FF6CCE68A2C9B39B9DA73293DFC7E6A
SHA256:BF7CDB8F2DADEC9E0EA8F4B9C716C65C74EA47A51A37BFB10422AB318DF3E233
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe.configxml
MD5:9C0A668B0AE7B65B99EA9025259919D3
SHA256:FFEC523E8536A9D9DC961806333D07953E478562420398BBFCEC42A56F87E182
2796BWInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:FB64A9EBEDF48D3895381D5B7D80743D
SHA256:EA21D495930AD76F267A33A0F593DBF0C7EA75E457FCAE49A29DAAD8BD920F42
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BrowserDefMgr.dllexecutable
MD5:AC82867B3105BBE0526067B94F4177A4
SHA256:21F2404E615394F5A310BCE48E75F61B4962866AB53CE39CD3D42F75AB7DDE5A
2796BWInstaller.exeC:\Users\admin\AppData\Local\Temp\ZMG7491.tmptext
MD5:AB34F21547A4B5D1EA2F8CC4E8D35B68
SHA256:D50325912972A9DE3BA14802187A5F311EF773B0830E44B603C59F4256DE7437
2796BWInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C0018BB1B5834735BFA60CD063B31956der
MD5:732CFEB76B91C4D13978A00B8C666ED7
SHA256:9FAB9FC0A1DA813E6DDB93904C1FCFA6546CFBE70747FF8468DDD14D2552DBD2
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\LocalizedTitles.jsonbinary
MD5:888C9CB6099CFFD5CEE9280A56E6B5BC
SHA256:3CC476E0F5A79FD61D1AF091C8F9665B00E4A7D748EA3122CD852B88C242D674
5184msiexec.exeC:\Windows\Installer\3f8d2d.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
51
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2796
BWInstaller.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2180
rundll32.exe
GET
200
20.41.62.11:80
http://g.ceipmsn.com/8SE/44?MI=56ED68D94E1D4990B42ED4331814B358&LV=10.0.19041.3636&OS=10.0.19045.1&TE=40&TV=isW015%7cpkBingWallpaper%7ctmen-us%7cvr2.0.0.9%7cat1%7crt1%7cpt2
unknown
unknown
1020
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6796
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2628
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6632
BingWallpaperApp.exe
GET
200
20.41.62.11:80
http://g.ceipmsn.com/8SE/44?MI=56ED68D94E1D4990B42ED4331814B358&LV=2.0.0.9&OS=10.0.19045.1MI=56ED68D94E1D4990B42ED4331814B358&LV=2.0.0.9&OS=10.0.19045.0&TE=40&TV=isW015%7cpkBingWallpaper%7ctmen-us%7cmo%3dMCwxMjgweDcyMA%253D%253D%7cvr2.0.0.9%7cpt6
unknown
unknown
6796
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6564
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4324
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2796
BWInstaller.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2628
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.68
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
g.ceipmsn.com
  • 20.41.62.11
unknown
browser.pipe.aria.microsoft.com
  • 20.42.72.131
whitelisted
bingwallpaper.microsoft.com
  • 52.173.134.115
whitelisted

Threats

No threats detected
No debug info