| File name: | wicreset.exe |
| Full analysis: | https://app.any.run/tasks/108cd4b9-fd50-42a7-b0b5-1824e658a6fa |
| Verdict: | Malicious activity |
| Analysis date: | November 07, 2023, 04:22:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F3AAC20E36FB29FFEEF2EF8BD3763666 |
| SHA1: | C16D0BD877CF6312734E965BFA4A0E862BBA4854 |
| SHA256: | 8E23F6F4C10255D128627A60048117C663930453A6596A2658DAECECD77E8E3E |
| SSDEEP: | 49152:hRlKFK8ayk4NGSP9EghX2jieQKMIrc/SfZELwQSJYsWo+qU24o2Ah4gIXRATd7p7:xKFdtk4pP3hX2j2KMIYwHJVCAx6AB7p7 |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 15:27:46+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.80.0.0 |
| ProductVersionNumber: | 5.80.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | WWW.WIC.SUPPORT |
| FileDescription: | WicReset Setup |
| FileVersion: | 5.80.0.0 |
| LegalCopyright: | |
| ProductName: | WicReset |
| ProductVersion: | 5.80.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3216 | "C:\Users\admin\AppData\Local\Temp\wicreset.exe" | C:\Users\admin\AppData\Local\Temp\wicreset.exe | — | explorer.exe | |||||||||||
User: admin Company: WWW.WIC.SUPPORT Integrity Level: MEDIUM Description: WicReset Setup Exit code: 0 Version: 5.80.0.0 Modules
| |||||||||||||||
| 3372 | "C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmp" /SL5="$70134,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" | C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmp | — | wicreset.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3408 | "C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 | C:\Users\admin\AppData\Local\Temp\wicreset.exe | wicreset.tmp | ||||||||||||
User: admin Company: WWW.WIC.SUPPORT Integrity Level: HIGH Description: WicReset Setup Exit code: 0 Version: 5.80.0.0 Modules
| |||||||||||||||
| 3444 | "C:\Program Files\WicReset\wicreset.exe" | C:\Program Files\WicReset\wicreset.exe | wicreset.tmp | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3576 | "C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmp" /SL5="$601EA,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 | C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmp | — | wicreset.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 5D42303D4FA360F31DD9DCEE56C1B0CEB6BDBD24B097DBF0431D5D4DDB709117 | |||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\WicReset\wicreset.exe | |||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 7920C051C9CDC03E40EC62463364F47D7318C6FA7E630F8C5F744A938DDB67B4 | |||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: F80D00002A5B871A3211DA01 | |||
| (PID) Process: | (3576) wicreset.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3408 | wicreset.exe | C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 3576 | wicreset.tmp | C:\Program Files\WicReset\wicreset.exe | executable | |
MD5:496D0BD5AA103097CCA8528DB0D47FE6 | SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B | |||
| 3216 | wicreset.exe | C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 3576 | wicreset.tmp | C:\Program Files\WicReset\is-SMVN4.tmp | executable | |
MD5:58E7080D8B85EF01176F748BEAC723DA | SHA256:95EB04331863353260F569AB50E86E5CBEFE72022914FF1A15E9747AF5552C06 | |||
| 3444 | wicreset.exe | C:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-18x-standard.bin | binary | |
MD5:BEEF59F6DE2F2F388BE3A40778EF8518 | SHA256:3F32092E0F4CE56148EB06FD6E0F7B897C66DDF95923D123BC436A809D9CF79C | |||
| 3576 | wicreset.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WicReset\WicReset.lnk | binary | |
MD5:E933DC269BF79882012C089B769E5835 | SHA256:8D1F094835C3B9E62B5E622F8509D69100FEDF31A06EB8B58F699191A212A027 | |||
| 3576 | wicreset.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WicReset\Uninstall WicReset.lnk | binary | |
MD5:61BF0A818E0887A3CDE62CBAB4BC8135 | SHA256:8DB50248F137F9EEBC78700DB25119EF43B5982C9383F9E6E6219FFC94A4CB5D | |||
| 3444 | wicreset.exe | C:\Users\admin\AppData\Roaming\wicreset\devices.srs | binary | |
MD5:8823E570EFA668912F4A96A700271184 | SHA256:5DCA33672C379567B997A6DAF0253EA1F5DA27CFF2F4DD942B12B53FC51B7F87 | |||
| 3444 | wicreset.exe | C:\Users\admin\AppData\Roaming\wicreset\patterns\colour-b-xxx-standard.bin | binary | |
MD5:0467ED95C6427C627E3CBC967CF8D638 | SHA256:82A7425F7E47C4D2D8D8E6124493084CCE5BE153C86FDBF768E9881A3EA17E21 | |||
| 3576 | wicreset.tmp | C:\Program Files\WicReset\is-STMSO.tmp | executable | |
MD5:496D0BD5AA103097CCA8528DB0D47FE6 | SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.printhelp.info/data/redist/upgrades.xml | unknown | xml | 628 b | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.2manuals.com/WIC/support_message.php | unknown | text | 7 b | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.printhelp.info/data/redist/upgrades.zip | unknown | compressed | 169 Kb | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.2manuals.com/WIC/banners/content.xml | unknown | xml | 1.48 Kb | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.2manuals.com/WIC/banners/u-csfwr.png | unknown | image | 9.24 Kb | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.2manuals.com/WIC/wicfaq.rss | unknown | xml | 5.85 Kb | unknown |
3444 | wicreset.exe | GET | 200 | 176.9.157.164:80 | http://www.2manuals.com/WIC/wicreset.rss | unknown | xml | 58.9 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3444 | wicreset.exe | 176.9.157.164:80 | wasteinkcounter.com | Hetzner Online GmbH | DE | unknown |
3444 | wicreset.exe | 192.168.100.255:3289 | — | — | — | whitelisted |
3444 | wicreset.exe | 176.9.157.164:23457 | wasteinkcounter.com | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
wasteinkcounter.com |
| unknown |
www.printhelp.info |
| malicious |
www.2manuals.com |
| malicious |
Process | Message |
|---|---|
wicreset.exe | d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).
|
wicreset.exe | d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).
|