File name:

BingWallpaper.exe

Full analysis: https://app.any.run/tasks/7621e78e-aef8-49af-b15d-fdfc97f657d5
Verdict: Malicious activity
Analysis date: September 27, 2024, 19:17:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

37629A0AF0DA32481F515580AD65BD4D

SHA1:

6CD46F5A55974C14E9B4110384C91C8F8A21A857

SHA256:

76D14FA043D8AF232C2AE4712FF89D39D0318A1CD2A9E973926EF720CC135B7B

SSDEEP:

98304:tn2Uzb3T46DdybtlxTxEh5LNRv0Tb5QOl6TH//rjAFzkN0IrPAzANhgEKfLazl7a:YLQC/rYOUzeCN6OFFyLu1a/b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • BingWallpaper.exe (PID: 2144)
      • BWInstaller.exe (PID: 2796)
    • Process drops legitimate windows executable

      • BingWallpaper.exe (PID: 2144)
      • rundll32.exe (PID: 6852)
      • msiexec.exe (PID: 5184)
      • rundll32.exe (PID: 2180)
      • rundll32.exe (PID: 2580)
    • Executable content was dropped or overwritten

      • BingWallpaper.exe (PID: 2144)
      • rundll32.exe (PID: 6852)
      • rundll32.exe (PID: 2180)
      • rundll32.exe (PID: 2580)
      • BingWallpaperApp.exe (PID: 6632)
  • INFO

    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5184)
    • Checks supported languages

      • BingWallpaper.exe (PID: 2144)
    • Create files in a temporary directory

      • BingWallpaper.exe (PID: 2144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:11:24 11:50:57+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.2
CodeSize: 25600
InitializedDataSize: 15115776
UninitializedDataSize: -
EntryPoint: 0x6a00
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.9
ProductVersionNumber: 2.0.0.9
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: BingWallpaper
FileVersion: 2.0.0.9
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: WEXTRACT.EXE .MUI
ProductName: BingWallpaper
ProductVersion: 2.0.0.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
10
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bingwallpaper.exe startupinstaller.exe no specs bwinstaller.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs rundll32.exe bingwallpaperapp.exe rundll32.exe rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
2144"C:\Users\admin\AppData\Local\Temp\BingWallpaper.exe" C:\Users\admin\AppData\Local\Temp\BingWallpaper.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BingWallpaper
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\temp\bingwallpaper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2180rundll32.exe "C:\WINDOWS\Installer\MSI9682.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4167343 8 CustomActions!CustomActions.CustomActions.InstallPingC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2580rundll32.exe "C:\WINDOWS\Installer\MSI98B6.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4167921 14 CustomActions!CustomActions.CustomActions.VSRegisterCheckC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2796"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe"C:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe
StartupInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BWInstaller
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\bwinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4004C:\Windows\syswow64\MsiExec.exe -Embedding 3FCE1507508C0855068E322B86EFC445C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4792"C:\Windows\System32\msiexec.exe" /q /i BWCInstaller.msi /norestartC:\Windows\SysWOW64\msiexec.exeBWInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5072C:\Users\admin\AppData\Local\Temp\IXP000.TMP\StartupInstaller.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\StartupInstaller.exeBingWallpaper.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\startupinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5184C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6632"C:\Users\admin\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe" C:\Users\admin\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Bing Wallpaper
Version:
2.0.0.9
Modules
Images
c:\users\admin\appdata\local\microsoft\bingwallpaperapp\bingwallpaperapp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
6852rundll32.exe "C:\WINDOWS\Installer\MSI93D2.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_4166765 2 CustomActions!CustomActions.CustomActions.StartAppC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
15 035
Read events
14 893
Write events
133
Delete events
9

Modification events

(PID) Process:(2796) BWInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Dispatcher
Operation:writeName:MachineID
Value:
56ED68D94E1D4990B42ED4331814B358
(PID) Process:(2796) BWInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\BingWallpaperApp
Operation:writeName:PartnerCode
Value:
W015
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
401400002EEFA2E61111DB01
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
1B12854DBAA00B3BB708A3DA3F2A7DF3128FC288D90DCA84DA5AC46E08399407
(PID) Process:(5184) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Config.Msi\
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3f8d2c.rbs
Value:
31133969
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Operation:writeName:C:\Config.Msi\3f8d2c.rbsLow
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
Operation:writeName:C:\Users\admin\AppData\Roaming\Microsoft\Installer\
Value:
(PID) Process:(5184) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1693682860-607145093-2874071422-1001\Components\E75EB4F5223116D48A5EDF60E49565E9
Operation:writeName:DE93B092CDFB69348933CFCBCB9A1843
Value:
01:\Software\Microsoft\BingWallpaperApp\isMSIInstalled
Executable files
25
Suspicious files
24
Text files
18
Unknown types
1

Dropped files

PID
Process
Filename
Type
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWCInstaller.msi
MD5:
SHA256:
5184msiexec.exeC:\Windows\Installer\3f8d2a.msi
MD5:
SHA256:
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\DispatchQueue.dllexecutable
MD5:588B3B8D0B4660E99529C3769BBDFEDC
SHA256:D05A41ED2AA8AF71E4C24BFFF27032D6805C7883E9C4A88AA0A885E441BEC649
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exeexecutable
MD5:1646ABD06DCF7820D8D159581627B036
SHA256:8401BE9D30F69F690ED22D0AC98EB11C34AEBFC10A1107570D873105C0180A64
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWCProgressBar.dllexecutable
MD5:6FF6CCE68A2C9B39B9DA73293DFC7E6A
SHA256:BF7CDB8F2DADEC9E0EA8F4B9C716C65C74EA47A51A37BFB10422AB318DF3E233
2796BWInstaller.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:FB64A9EBEDF48D3895381D5B7D80743D
SHA256:EA21D495930AD76F267A33A0F593DBF0C7EA75E457FCAE49A29DAAD8BD920F42
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\BWInstaller.exe.configxml
MD5:9C0A668B0AE7B65B99EA9025259919D3
SHA256:FFEC523E8536A9D9DC961806333D07953E478562420398BBFCEC42A56F87E182
2144BingWallpaper.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\LocalizedTitles.jsonbinary
MD5:888C9CB6099CFFD5CEE9280A56E6B5BC
SHA256:3CC476E0F5A79FD61D1AF091C8F9665B00E4A7D748EA3122CD852B88C242D674
5184msiexec.exeC:\Windows\Installer\3f8d2d.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
51
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2796
BWInstaller.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
2180
rundll32.exe
GET
200
20.41.62.11:80
http://g.ceipmsn.com/8SE/44?MI=56ED68D94E1D4990B42ED4331814B358&LV=10.0.19041.3636&OS=10.0.19045.1&TE=40&TV=isW015%7cpkBingWallpaper%7ctmen-us%7cvr2.0.0.9%7cat1%7crt1%7cpt2
unknown
unknown
6632
BingWallpaperApp.exe
GET
200
20.41.62.11:80
http://g.ceipmsn.com/8SE/44?MI=56ED68D94E1D4990B42ED4331814B358&LV=2.0.0.9&OS=10.0.19045.1MI=56ED68D94E1D4990B42ED4331814B358&LV=2.0.0.9&OS=10.0.19045.0&TE=40&TV=isW015%7cpkBingWallpaper%7ctmen-us%7cmo%3dMCwxMjgweDcyMA%253D%253D%7cvr2.0.0.9%7cpt6
unknown
unknown
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
1020
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2628
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6796
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6796
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
6564
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4324
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2796
BWInstaller.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2628
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.67
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.68
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
g.ceipmsn.com
  • 20.41.62.11
unknown
browser.pipe.aria.microsoft.com
  • 20.42.72.131
whitelisted
bingwallpaper.microsoft.com
  • 52.173.134.115
whitelisted

Threats

No threats detected
No debug info