File name:

wfc6setup.exe

Full analysis: https://app.any.run/tasks/2ff24437-8aac-4f3c-a3b6-3c0ff06f33c5
Verdict: Malicious activity
Analysis date: December 09, 2023, 21:39:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

8E5C61D2E3B50521FF505F45BD68C564

SHA1:

B1A241DDF22A84DAB61981A8FE34B85AA65F49EB

SHA256:

81813CD194250C8B49D096CCD484C714FFA0FA5A56CEC46B607C36878CAAF613

SSDEEP:

98304:QMo30HMAOcHxvvHp3Ecupc00rFz/hZ7Rk8yfff7ckGBQG2B6HX+Ow9N8PGK1YF7U:Na

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wfc6setup.exe (PID: 2860)
    • Actions looks like stealing of personal data

      • wfcs.exe (PID: 3604)
  • SUSPICIOUS

    • Reads the Internet Settings

      • wfc6setup.exe (PID: 280)
      • wfc6setup.exe (PID: 2860)
      • wfcUI.exe (PID: 3268)
    • Application launched itself

      • wfc6setup.exe (PID: 280)
    • Uses TASKKILL.EXE to kill process

      • wfc6setup.exe (PID: 2860)
    • Starts SC.EXE for service management

      • wfc6setup.exe (PID: 2860)
      • wfcs.exe (PID: 3604)
    • The process verifies whether the antivirus software is installed

      • wfc6setup.exe (PID: 2860)
      • wfcs.exe (PID: 3604)
      • wfcUI.exe (PID: 3268)
    • Process drops legitimate windows executable

      • wfc6setup.exe (PID: 2860)
      • chrome.exe (PID: 3196)
    • Suspicious use of NETSH.EXE

      • wfc6setup.exe (PID: 2860)
    • Executes as Windows Service

      • wfcs.exe (PID: 3604)
    • Checks Windows Trust Settings

      • wfcUI.exe (PID: 3268)
    • Reads the BIOS version

      • wfcUI.exe (PID: 3268)
    • Reads security settings of Internet Explorer

      • wfcUI.exe (PID: 3268)
    • Reads settings of System Certificates

      • wfcUI.exe (PID: 3268)
  • INFO

    • Reads the computer name

      • wfc6setup.exe (PID: 280)
      • wfc6setup.exe (PID: 2860)
      • wfcs.exe (PID: 3604)
      • wfcUI.exe (PID: 3268)
      • wmpnscfg.exe (PID: 2868)
    • Checks supported languages

      • wfc6setup.exe (PID: 280)
      • wfc6setup.exe (PID: 2860)
      • wfcs.exe (PID: 3604)
      • wfcUI.exe (PID: 3268)
      • wmpnscfg.exe (PID: 2868)
    • Reads the machine GUID from the registry

      • wfc6setup.exe (PID: 2860)
      • wfc6setup.exe (PID: 280)
      • wfcs.exe (PID: 3604)
      • wfcUI.exe (PID: 3268)
    • Creates files in the program directory

      • wfc6setup.exe (PID: 2860)
      • netsh.exe (PID: 4016)
      • wfcs.exe (PID: 3604)
      • wfcUI.exe (PID: 3268)
    • Manual execution by a user

      • chrome.exe (PID: 3196)
      • wmpnscfg.exe (PID: 2868)
    • Application launched itself

      • chrome.exe (PID: 3196)
    • Reads product name

      • wfcUI.exe (PID: 3268)
    • Reads Environment values

      • wfcUI.exe (PID: 3268)
    • Drops the executable file immediately after the start

      • chrome.exe (PID: 3196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2055:12:21 11:32:30+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 3743232
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x393d4a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 6.9.9.0
ProductVersionNumber: 6.9.9.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Best tool to manage Windows Firewall with Advanced Security
CompanyName: Malwarebytes
FileDescription: Malwarebytes Windows Firewall Control - Setup
FileVersion: 6.9.9.0
InternalName: wfc6setup.exe
LegalCopyright: © 2023 Malwarebytes. All rights reserved.
LegalTrademarks: -
OriginalFileName: wfc6setup.exe
ProductName: Malwarebytes Windows Firewall Control - Setup
ProductVersion: 6.9.9.0
AssemblyVersion: 6.9.9.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
31
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wfc6setup.exe no specs wfc6setup.exe taskkill.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs netsh.exe no specs auditpol.exe no specs sc.exe no specs wfcs.exe wfcui.exe sc.exe no specs sc.exe no specs auditpol.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs wmpnscfg.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\system32\sc.exe" config Dnscache start= autoC:\Windows\System32\sc.exewfcs.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
280"C:\Users\admin\Desktop\wfc6setup.exe" C:\Users\admin\Desktop\wfc6setup.exeexplorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Windows Firewall Control - Setup
Exit code:
0
Version:
6.9.9.0
Modules
Images
c:\users\admin\desktop\wfc6setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
600"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3644 --field-trial-handle=1184,i,2178981324023567366,12054688421756930775,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1296"C:\Windows\system32\sc.exe" failure wfcs reset= 3600 actions= restart/60000/restart/60000//C:\Windows\System32\sc.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1380"C:\Windows\system32\sc.exe" config MpsSvc start= autoC:\Windows\System32\sc.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1380"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1328 --field-trial-handle=1184,i,2178981324023567366,12054688421756930775,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1460"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2144 --field-trial-handle=1184,i,2178981324023567366,12054688421756930775,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1844"C:\Windows\system32\taskkill.exe" /f /im wfcsC:\Windows\System32\taskkill.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2376"C:\Windows\system32\sc.exe" start DnscacheC:\Windows\System32\sc.exewfcs.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1056
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2496"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2152 --field-trial-handle=1184,i,2178981324023567366,12054688421756930775,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
12 253
Read events
12 097
Write events
147
Delete events
9

Modification events

(PID) Process:(280) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(280) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(280) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(280) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(280) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2860) wfc6setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
wfc6setup.exe
(PID) Process:(4016) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4016) netsh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Firewall\{3013159F-2137-40F9-BF15-AD9EFF2886AD}
Operation:writeName:PolicyVersion
Value:
522
(PID) Process:(4016) netsh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Firewall\{3013159F-2137-40F9-BF15-AD9EFF2886AD}\StandardProfile\Logging
Operation:delete keyName:(default)
Value:
(PID) Process:(4016) netsh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Firewall\{3013159F-2137-40F9-BF15-AD9EFF2886AD}\StandardProfile
Operation:delete keyName:(default)
Value:
Executable files
12
Suspicious files
37
Text files
46
Unknown types
2

Dropped files

PID
Process
Filename
Type
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Google.Protobuf.dllexecutable
MD5:A92694CE70BF88BB188B161C463EAB43
SHA256:007C7DB235D57EDB35535A3F054739C2B4229225D97DE4FBE814F108B79D3034
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Grpc.Core.Api.dllexecutable
MD5:FEDF6222FBCEFE6F6E4834F3506D5E8B
SHA256:273D87EE016A61B27EFD651D451C435011CDCBF388BFFA8E648CAD1EC21076A9
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\lang\wfcCN.lngtext
MD5:57BD58F6F205D660F08F1BD5721D16EA
SHA256:C74D52B50BAC9F1C4FDD77AA48D1BCA9D7757B9BCE7B23DD006E6EFC66C4B124
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\lang\wfcBR.lngtext
MD5:92F39EC6ECE72F33715300B8B1F999DC
SHA256:19FB5D15583BC793616C4431E34EF45C1BA1D9AE27A4D904DC4A60F7B28ACB46
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\mbcut32.dllexecutable
MD5:60DC31F89D6695EA214B06BC94F94A23
SHA256:B7702596400D9F79E49EF39AA904C654B05328E2A15BE789F0DC01B026E1A7E3
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Memory.dllexecutable
MD5:F09441A1EE47FB3E6571A3A448E05BAF
SHA256:BF3FB84664F4097F1A8A9BC71A51DCF8CF1A905D4080A4D290DA1730866E856F
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Buffers.dllexecutable
MD5:ECDFE8EDE869D2CCC6BF99981EA96400
SHA256:ACCCCFBE45D9F08FFEED9916E37B33E98C65BE012CFFF6E7FA7B67210CE1FEFB
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Numerics.Vectors.dllexecutable
MD5:AAA2CBF14E06E9D3586D8A4ED455DB33
SHA256:1D3EF8698281E7CF7371D1554AFEF5872B39F96C26DA772210A33DA041BA1183
2860wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Runtime.CompilerServices.Unsafe.dllexecutable
MD5:DA04A75DDC22118ED24E0B53E474805A
SHA256:66409F670315AFE8610F17A4D3A1EE52D72B6A46C544CEC97544E8385F90AD74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3268
wfcUI.exe
54.188.94.42:443
telemetry.malwarebytes.com
AMAZON-02
US
unknown
3808
chrome.exe
172.217.16.195:443
update.googleapis.com
GOOGLE
US
whitelisted
3808
chrome.exe
64.233.166.84:443
accounts.google.com
GOOGLE
US
unknown
3808
chrome.exe
142.250.185.196:443
www.google.com
GOOGLE
US
whitelisted
3196
chrome.exe
224.0.0.251:5353
unknown

DNS requests

Domain
IP
Reputation
telemetry.malwarebytes.com
  • 54.188.94.42
  • 35.163.205.81
  • 52.88.253.142
  • 44.242.12.201
  • 54.200.35.46
  • 52.27.99.226
whitelisted
clientservices.googleapis.com
  • 142.250.185.67
whitelisted
www.google.com
  • 142.250.185.196
whitelisted
accounts.google.com
  • 64.233.166.84
shared
update.googleapis.com
  • 172.217.16.195
whitelisted

Threats

No threats detected
No debug info