File name:

Setup_WinThruster_2024.exe

Full analysis: https://app.any.run/tasks/6090a25a-06a2-4ccf-8b8f-43c71c6e285e
Verdict: Malicious activity
Analysis date: December 19, 2023, 15:00:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

013CA19ACB836AB6258483DB10250B28

SHA1:

5A8651BEF56E8603665D4EC5E1EC7CFC9AAC50D7

SHA256:

89EF4EA4A236566CD4FE2187436434EEF0488FEE1B8C85EEC994755B740FDB9F

SSDEEP:

98304:U+QqZ8fH0FGb9oy5OkwZt1pdKKrd94ou61bw01zWC7aIPiqXBis6/wTGCTUoDmBD:1W0ByPt8jUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • WTNotifications.exe (PID: 1588)
    • Actions looks like stealing of personal data

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Drops the executable file immediately after the start

      • Setup_WinThruster_2024.tmp (PID: 532)
      • Setup_WinThruster_2024.exe (PID: 548)
    • Uses Task Scheduler to autorun other applications

      • WinThruster.exe (PID: 1216)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup_WinThruster_2024.tmp (PID: 532)
    • Searches for installed software

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Process drops SQLite DLL files

      • Setup_WinThruster_2024.tmp (PID: 532)
    • Reads the Internet Settings

      • WinThruster.exe (PID: 1216)
    • Checks for Java to be installed

      • WinThruster.exe (PID: 1216)
    • Reads Mozilla Firefox installation path

      • WinThruster.exe (PID: 1216)
    • Reads browser cookies

      • WinThruster.exe (PID: 1216)
  • INFO

    • Checks supported languages

      • Setup_WinThruster_2024.exe (PID: 124)
      • Setup_WinThruster_2024.tmp (PID: 1432)
      • WTNotifications.exe (PID: 1588)
      • Setup_WinThruster_2024.exe (PID: 548)
      • WinThruster.exe (PID: 1216)
      • Setup_WinThruster_2024.tmp (PID: 532)
    • Create files in a temporary directory

      • Setup_WinThruster_2024.exe (PID: 124)
      • Setup_WinThruster_2024.tmp (PID: 532)
      • WinThruster.exe (PID: 1216)
      • Setup_WinThruster_2024.exe (PID: 548)
    • Creates files in the program directory

      • Setup_WinThruster_2024.tmp (PID: 532)
      • WinThruster.exe (PID: 1216)
    • Reads the computer name

      • Setup_WinThruster_2024.tmp (PID: 1432)
      • WinThruster.exe (PID: 1216)
      • WTNotifications.exe (PID: 1588)
      • Setup_WinThruster_2024.tmp (PID: 532)
    • Creates files or folders in the user directory

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Process checks computer location settings

      • WTNotifications.exe (PID: 1588)
    • Checks proxy server information

      • WinThruster.exe (PID: 1216)
    • Reads CPU info

      • WinThruster.exe (PID: 1216)
    • Reads the machine GUID from the registry

      • WinThruster.exe (PID: 1216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 10:09:11+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 135680
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.0.3
ProductVersionNumber: 8.0.0.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Solvusoft
FileDescription: WinThruster
FileVersion: 8.0.0.3
LegalCopyright: Solvusoft
OriginalFileName:
ProductName: WinThruster
ProductVersion: 8.0.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup_winthruster_2024.exe no specs setup_winthruster_2024.tmp no specs setup_winthruster_2024.exe setup_winthruster_2024.tmp no specs wtnotifications.exe winthruster.exe schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exeexplorer.exe
User:
admin
Company:
Solvusoft
Integrity Level:
MEDIUM
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\setup_winthruster_2024.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
532"C:\Users\admin\AppData\Local\Temp\is-5C2FP.tmp\Setup_WinThruster_2024.tmp" /SL5="$501AC,6735781,878080,C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-5C2FP.tmp\Setup_WinThruster_2024.tmpSetup_WinThruster_2024.exe
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5c2fp.tmp\setup_winthruster_2024.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
548"C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\setup_winthruster_2024.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1216"C:\Program Files\WinThruster\WinThruster.exe" /STARTC:\Program Files\WinThruster\WinThruster.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\program files\winthruster\winthruster.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1432"C:\Users\admin\AppData\Local\Temp\is-T2O80.tmp\Setup_WinThruster_2024.tmp" /SL5="$301AA,6735781,878080,C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" C:\Users\admin\AppData\Local\Temp\is-T2O80.tmp\Setup_WinThruster_2024.tmpSetup_WinThruster_2024.exe
User:
admin
Company:
Solvusoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t2o80.tmp\setup_winthruster_2024.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1588"C:\Program Files\WinThruster\WTNotifications.exe"C:\Program Files\WinThruster\WTNotifications.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster automatic scan and notifications
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\program files\winthruster\wtnotifications.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2480"C:\Windows\System32\schtasks.exe" /Create /TN "WinThruster automatic scan and notifications" /TR "\"C:\Program Files\WinThruster\WTNotifications.exe\"" /SC ONLOGON /RL HIGHEST /FC:\Windows\System32\schtasks.exeWinThruster.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
13 403
Read events
13 384
Write events
13
Delete events
6

Modification events

(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F60773385BCEBAA298702C3CF98E278D4150A572003800F069131F53E1F9F00D
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\WinThruster\WinThruster.exe
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
BC4C8E23BEFF1EEB6E852B6220F5EF0538DB6A60740C4F6DD4C0E23554C712F3
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
1402000052F547268C32DA01
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\WinThruster
Operation:writeName:TrayAllowed
Value:
1
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\WinThruster
Operation:writeName:s_SmartEnabled
Value:
1
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
10
Suspicious files
25
Text files
57
Unknown types
0

Dropped files

PID
Process
Filename
Type
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\WinThruster.exeexecutable
MD5:E8A10026CAD81CD88B0355BCFDA698ED
SHA256:D7E44EC78CE06E6C657F79EA1779F2B0277178584734B78926EF4E0AF06C56A8
548Setup_WinThruster_2024.exeC:\Users\admin\AppData\Local\Temp\is-5C2FP.tmp\Setup_WinThruster_2024.tmpexecutable
MD5:9EBBC17D45F786E52DB6EAF4BAB7E09A
SHA256:6B35A6556A551E3D0802E29A3B2037884445357CBE05A80BDB90F00A0FBF9D9C
124Setup_WinThruster_2024.exeC:\Users\admin\AppData\Local\Temp\is-T2O80.tmp\Setup_WinThruster_2024.tmpexecutable
MD5:9EBBC17D45F786E52DB6EAF4BAB7E09A
SHA256:6B35A6556A551E3D0802E29A3B2037884445357CBE05A80BDB90F00A0FBF9D9C
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-ENC2F.tmpexecutable
MD5:E8A10026CAD81CD88B0355BCFDA698ED
SHA256:D7E44EC78CE06E6C657F79EA1779F2B0277178584734B78926EF4E0AF06C56A8
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-DBE7O.tmpexecutable
MD5:79042F1299CD2846202F2755C3E2F901
SHA256:023FEBE862C1393092178EEC61E44807C586099B9783E517F6572AD912FD6291
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\Brazilian.initext
MD5:E5DDBBF0D69458DC5048F5EF8F3CF2BF
SHA256:7300E77C8EF317CF9C43EFA0ED5591017AF87FC2E805F04D738058F80877ABE2
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-TEBM0.tmptext
MD5:12486F6930181BE47A2256AAB641AA93
SHA256:422D7189328D1FBEF58AB37ED492F7958FF9010C042C1BE1146E0BBEE9E455DD
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-EENUF.tmpexecutable
MD5:5A2B6C5E837AA26F74CAB929F83979C3
SHA256:14DE6E0342A20F301EED2E091E4D04F8C83B6B94257860CCBDCCE41FA348839E
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-RLKOG.tmpexecutable
MD5:FDF0245A035F89DE1AF8A2091258C9AC
SHA256:6120E410FF9E5CAD41B47CD5FCB23CC3F8BD8F505A86E158C578E15869489367
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\Danish.initext
MD5:12486F6930181BE47A2256AAB641AA93
SHA256:422D7189328D1FBEF58AB37ED492F7958FF9010C042C1BE1146E0BBEE9E455DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1216
WinThruster.exe
116.203.251.147:443
subscriptions.avqtools.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
subscriptions.avqtools.com
  • 116.203.251.147
unknown

Threats

No threats detected
No debug info