File name:

wps_office_inst.exe

Full analysis: https://app.any.run/tasks/bebb7f82-c694-40f2-aa1b-5abc91054c20
Verdict: Malicious activity
Analysis date: April 01, 2026, 02:11:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
wps
anti-evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

D98B03FA9DAED52B646F407C9E0CB09A

SHA1:

B9611D0FE1EC573AE3657D3B17E1FB563006A1F8

SHA256:

8B10AE0503B1A182034BD2784D545D8A5535CA8369303DBE7A392415F545BF5F

SSDEEP:

98304:zXs0U4TRJjNRV52w1cj+5gCm4mvh2gZJMGTE+pqyw8dAtL6wvP6xIwRwl7Gq0gLE:nnZlsyNC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • WPS mutex has been found

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • The process checks if it is being run in the virtual environment

      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
  • INFO

    • Checks supported languages

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • Reads the computer name

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • Reads security settings of Internet Explorer

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • Create files in a temporary directory

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • Reads the machine GUID from the registry

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • Creates files or folders in the user directory

      • wps_office_inst.exe (PID: 6884)
      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
    • There is functionality for taking screenshot (YARA)

      • 96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe (PID: 5672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:02:06 04:20:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4223488
InitializedDataSize: 1539072
UninitializedDataSize: -
EntryPoint: 0x2b8f37
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 12.2.0.21574
ProductVersionNumber: 12.2.0.21574
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Zhuhai Kingsoft Office Software Co.,Ltd
FileDescription: WPS Office Setup
FileVersion: 12,2,0,21574
InternalName: konlinesetup_xa
LegalCopyright: Copyright©2025 Kingsoft Corporation. All rights reserved.
OriginalFileName: konlinesetup_xa.exe
ProductName: WPS Office
ProductVersion: 12,2,0,21574
MIMEType: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wps_office_inst.exe 96aa40b0f55bd6748cdc4993345e7fba-16_setup_xa_mui_free.exe.601.1133.exe

Process information

PID
CMD
Path
Indicators
Parent process
5672"C:\ProgramData\WPS\Installers\96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe" -installCallByOnlineSetup -defaultOpen -defaultOpenPdf -asso_pic_setup -createIcons -pinTaskbar -curlangofinstalledproduct=en_US -notElevateAndDirectlyInstall -D="C:\Users\admin\AppData\Local\Kingsoft\WPS Office" -notautostartwps -enableSetupMuiPkg -appdata="C:\Users\admin\AppData\Roaming"C:\ProgramData\WPS\Installers\96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
wps_office_inst.exe
User:
admin
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
MEDIUM
Description:
WPS Install Application
Version:
12,2,0,23196
Modules
Images
c:\programdata\wps\installers\96aa40b0f55bd6748cdc4993345e7fba-16_setup_xa_mui_free.exe.601.1133.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msi.dll
6884"C:\Users\admin\AppData\Local\Temp\wps_office_inst.exe" C:\Users\admin\AppData\Local\Temp\wps_office_inst.exe
explorer.exe
User:
admin
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
MEDIUM
Description:
WPS Office Setup
Version:
12,2,0,21574
Modules
Images
c:\users\admin\appdata\local\temp\wps_office_inst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
14 902
Read events
14 876
Write events
23
Delete events
3

Modification events

(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\kwpsonlinesetup
Operation:writeName:infoHdid
Value:
35d04b2c52073a0b21a6e8d3459bd09f
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\kwpsonlinesetup
Operation:writeName:global_progress
Value:
download_start
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\kwpsonlinesetup
Operation:writeName:infoGuid
Value:
3E578AE8FE7F4934AE587BBACF658FCF
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\kwpsonlinesetup
Operation:writeName:startup_time
Value:
2026-04-01 02
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\kwpsonlinesetup
Operation:writeName:global_progress
Value:
startup
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\Office\6.0\Common
Operation:writeName:newGuideShow
Value:
1
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:countrycode
Value:
FR
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:lastupdatecountrycode
Value:
1775009489786
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:lastUpdateDeviceInfoDate
Value:
2026/3/31
(PID) Process:(6884) wps_office_inst.exeKey:HKEY_CURRENT_USER\SOFTWARE\kingsoft\Office\6.0\Common
Operation:writeName:Version
Value:
12.2.0.23196
Executable files
0
Suspicious files
0
Text files
0
Unknown types
1 028

Dropped files

PID
Process
Filename
Type
6884wps_office_inst.exeC:\ProgramData\WPS\Installers\96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_et.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_pdf.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_prometheus.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_prome_init.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_qing.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_wpp.txt
MD5:
SHA256:
567296aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exeC:\Users\admin\AppData\Local\Temp\wps\~e66a5\CONTROL\prereadimages_wps.txt
MD5:
SHA256:
6884wps_office_inst.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:D276C792780FBEDD4AD17AEE5379796B
SHA256:6D6958ACD89C3A17E1868AEBD1786AE3D0D2832843FC249F1FDFDA78AF020860
6884wps_office_inst.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:36D0EBE9E9ED8090063AD06322ED6465
SHA256:1C140DD3512250C5BC3458593DEA25FD65BA5C9FCECC2D15DE9AD3BEF4E155BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
61
TCP/UDP connections
33
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
6884
wps_office_inst.exe
POST
204
142.251.20.139:443
https://www.google-analytics.com/mp/collect?firebase_app_id=1:463244832315:android:fe82dee1e0f73e232db61e&api_secret=UViz3S6KTv6YlgsE1g4FAQ
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5392
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
6884
wps_office_inst.exe
142.251.20.139:443
www.google-analytics.com
GOOGLE
US
whitelisted
6884
wps_office_inst.exe
90.84.175.86:443
params.wps.com
OCBHONEY OCB public cloud network
FR
whitelisted
6884
wps_office_inst.exe
185.229.190.27:443
wdl1.pcfg.cache.wpscdn.com
CDN77 _
GB
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 23.52.181.212
  • 88.221.169.152
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.13.138
  • 142.251.13.101
  • 142.251.13.139
  • 142.251.13.100
  • 142.251.13.102
  • 142.251.13.113
whitelisted
www.google-analytics.com
  • 142.251.20.139
  • 142.251.20.113
  • 142.251.20.101
  • 142.251.20.100
  • 142.251.20.102
  • 142.251.20.138
whitelisted
params.wps.com
  • 90.84.175.86
unknown
wdl1.pcfg.cache.wpscdn.com
  • 185.229.190.27
unknown
api.wps.com
  • 90.84.175.86
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted

Threats

No threats detected
Process
Message
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
[kscreen] isElide:0 switchRec:0 switchRecElide:1
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_BrandAreaWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout
96aa40b0f55bd6748cdc4993345e7fba-16_setup_XA_mui_Free.exe.601.1133.exe
QLayout: Attempting to add QLayout "" to QWidget "m_customizeSettingsWidget", which already has a layout