File name:

Setup_WinThruster_2024.exe

Full analysis: https://app.any.run/tasks/6090a25a-06a2-4ccf-8b8f-43c71c6e285e
Verdict: Malicious activity
Analysis date: December 19, 2023, 15:00:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

013CA19ACB836AB6258483DB10250B28

SHA1:

5A8651BEF56E8603665D4EC5E1EC7CFC9AAC50D7

SHA256:

89EF4EA4A236566CD4FE2187436434EEF0488FEE1B8C85EEC994755B740FDB9F

SSDEEP:

98304:U+QqZ8fH0FGb9oy5OkwZt1pdKKrd94ou61bw01zWC7aIPiqXBis6/wTGCTUoDmBD:1W0ByPt8jUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • WTNotifications.exe (PID: 1588)
    • Drops the executable file immediately after the start

      • Setup_WinThruster_2024.tmp (PID: 532)
      • Setup_WinThruster_2024.exe (PID: 548)
    • Actions looks like stealing of personal data

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Uses Task Scheduler to autorun other applications

      • WinThruster.exe (PID: 1216)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Setup_WinThruster_2024.tmp (PID: 532)
    • Process drops SQLite DLL files

      • Setup_WinThruster_2024.tmp (PID: 532)
    • Searches for installed software

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Reads the Internet Settings

      • WinThruster.exe (PID: 1216)
    • Reads browser cookies

      • WinThruster.exe (PID: 1216)
    • Reads Mozilla Firefox installation path

      • WinThruster.exe (PID: 1216)
    • Checks for Java to be installed

      • WinThruster.exe (PID: 1216)
  • INFO

    • Reads the computer name

      • Setup_WinThruster_2024.tmp (PID: 1432)
      • Setup_WinThruster_2024.tmp (PID: 532)
      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Checks supported languages

      • Setup_WinThruster_2024.exe (PID: 124)
      • Setup_WinThruster_2024.tmp (PID: 532)
      • Setup_WinThruster_2024.exe (PID: 548)
      • Setup_WinThruster_2024.tmp (PID: 1432)
      • WinThruster.exe (PID: 1216)
      • WTNotifications.exe (PID: 1588)
    • Create files in a temporary directory

      • Setup_WinThruster_2024.exe (PID: 548)
      • Setup_WinThruster_2024.exe (PID: 124)
      • Setup_WinThruster_2024.tmp (PID: 532)
      • WinThruster.exe (PID: 1216)
    • Creates files in the program directory

      • Setup_WinThruster_2024.tmp (PID: 532)
      • WinThruster.exe (PID: 1216)
    • Process checks computer location settings

      • WTNotifications.exe (PID: 1588)
    • Creates files or folders in the user directory

      • WTNotifications.exe (PID: 1588)
      • WinThruster.exe (PID: 1216)
    • Checks proxy server information

      • WinThruster.exe (PID: 1216)
    • Reads CPU info

      • WinThruster.exe (PID: 1216)
    • Reads the machine GUID from the registry

      • WinThruster.exe (PID: 1216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 10:09:11+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 135680
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.0.3
ProductVersionNumber: 8.0.0.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Solvusoft
FileDescription: WinThruster
FileVersion: 8.0.0.3
LegalCopyright: Solvusoft
OriginalFileName:
ProductName: WinThruster
ProductVersion: 8.0.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start setup_winthruster_2024.exe no specs setup_winthruster_2024.tmp no specs setup_winthruster_2024.exe setup_winthruster_2024.tmp no specs wtnotifications.exe winthruster.exe schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exeexplorer.exe
User:
admin
Company:
Solvusoft
Integrity Level:
MEDIUM
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\setup_winthruster_2024.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
532"C:\Users\admin\AppData\Local\Temp\is-5C2FP.tmp\Setup_WinThruster_2024.tmp" /SL5="$501AC,6735781,878080,C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-5C2FP.tmp\Setup_WinThruster_2024.tmpSetup_WinThruster_2024.exe
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5c2fp.tmp\setup_winthruster_2024.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
548"C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" /SPAWNWND=$401B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\setup_winthruster_2024.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1216"C:\Program Files\WinThruster\WinThruster.exe" /STARTC:\Program Files\WinThruster\WinThruster.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\program files\winthruster\winthruster.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1432"C:\Users\admin\AppData\Local\Temp\is-T2O80.tmp\Setup_WinThruster_2024.tmp" /SL5="$301AA,6735781,878080,C:\Users\admin\AppData\Local\Temp\Setup_WinThruster_2024.exe" C:\Users\admin\AppData\Local\Temp\is-T2O80.tmp\Setup_WinThruster_2024.tmpSetup_WinThruster_2024.exe
User:
admin
Company:
Solvusoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t2o80.tmp\setup_winthruster_2024.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1588"C:\Program Files\WinThruster\WTNotifications.exe"C:\Program Files\WinThruster\WTNotifications.exe
Setup_WinThruster_2024.tmp
User:
admin
Company:
Solvusoft
Integrity Level:
HIGH
Description:
WinThruster automatic scan and notifications
Exit code:
0
Version:
8.0.0.3
Modules
Images
c:\program files\winthruster\wtnotifications.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2480"C:\Windows\System32\schtasks.exe" /Create /TN "WinThruster automatic scan and notifications" /TR "\"C:\Program Files\WinThruster\WTNotifications.exe\"" /SC ONLOGON /RL HIGHEST /FC:\Windows\System32\schtasks.exeWinThruster.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
13 403
Read events
13 384
Write events
13
Delete events
6

Modification events

(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F60773385BCEBAA298702C3CF98E278D4150A572003800F069131F53E1F9F00D
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\WinThruster\WinThruster.exe
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
BC4C8E23BEFF1EEB6E852B6220F5EF0538DB6A60740C4F6DD4C0E23554C712F3
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
1402000052F547268C32DA01
(PID) Process:(532) Setup_WinThruster_2024.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\WinThruster
Operation:writeName:TrayAllowed
Value:
1
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\WinThruster
Operation:writeName:s_SmartEnabled
Value:
1
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1216) WinThruster.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
10
Suspicious files
25
Text files
57
Unknown types
0

Dropped files

PID
Process
Filename
Type
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-DBE7O.tmpexecutable
MD5:79042F1299CD2846202F2755C3E2F901
SHA256:023FEBE862C1393092178EEC61E44807C586099B9783E517F6572AD912FD6291
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\sqlite3.dllexecutable
MD5:FDF0245A035F89DE1AF8A2091258C9AC
SHA256:6120E410FF9E5CAD41B47CD5FCB23CC3F8BD8F505A86E158C578E15869489367
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\Brazilian.initext
MD5:E5DDBBF0D69458DC5048F5EF8F3CF2BF
SHA256:7300E77C8EF317CF9C43EFA0ED5591017AF87FC2E805F04D738058F80877ABE2
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\Danish.initext
MD5:12486F6930181BE47A2256AAB641AA93
SHA256:422D7189328D1FBEF58AB37ED492F7958FF9010C042C1BE1146E0BBEE9E455DD
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-A0FN4.tmptext
MD5:05D92A969983B83314A0EA2FCEF74203
SHA256:7D07617E39F7DFECCAF894C89B6F85D35D41082B8BED893513BB1B7CAD4AC823
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-APABJ.tmptext
MD5:1951AB55333B713ADBF771CC7AD20D54
SHA256:BAEDB24B675F9ECEAD1E84580BF6358D14510297952DC292E8F80CEB6FBF49F2
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\English.initext
MD5:05D92A969983B83314A0EA2FCEF74203
SHA256:7D07617E39F7DFECCAF894C89B6F85D35D41082B8BED893513BB1B7CAD4AC823
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-UQSOG.tmptext
MD5:6DDF4ABC7BC7958555495A1BBEE1C3A6
SHA256:3EE2ADB95184FBFA3D13E86D9EF698503BDE4E22C8964D31F20E5E4F3127FB4C
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\is-RLKOG.tmpexecutable
MD5:FDF0245A035F89DE1AF8A2091258C9AC
SHA256:6120E410FF9E5CAD41B47CD5FCB23CC3F8BD8F505A86E158C578E15869489367
532Setup_WinThruster_2024.tmpC:\Program Files\WinThruster\unins000.exeexecutable
MD5:5A2B6C5E837AA26F74CAB929F83979C3
SHA256:14DE6E0342A20F301EED2E091E4D04F8C83B6B94257860CCBDCCE41FA348839E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1216
WinThruster.exe
116.203.251.147:443
subscriptions.avqtools.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
subscriptions.avqtools.com
  • 116.203.251.147
unknown

Threats

No threats detected
No debug info