File name:

wicreset.exe

Full analysis: https://app.any.run/tasks/108cd4b9-fd50-42a7-b0b5-1824e658a6fa
Verdict: Malicious activity
Analysis date: November 07, 2023, 04:22:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F3AAC20E36FB29FFEEF2EF8BD3763666

SHA1:

C16D0BD877CF6312734E965BFA4A0E862BBA4854

SHA256:

8E23F6F4C10255D128627A60048117C663930453A6596A2658DAECECD77E8E3E

SSDEEP:

49152:hRlKFK8ayk4NGSP9EghX2jieQKMIrc/SfZELwQSJYsWo+qU24o2Ah4gIXRATd7p7:xKFdtk4pP3hX2j2KMIYwHJVCAx6AB7p7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wicreset.exe (PID: 3216)
      • wicreset.exe (PID: 3408)
      • wicreset.tmp (PID: 3576)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • wicreset.tmp (PID: 3576)
    • Connects to unusual port

      • wicreset.exe (PID: 3444)
  • INFO

    • Checks supported languages

      • wicreset.tmp (PID: 3372)
      • wicreset.exe (PID: 3216)
      • wicreset.exe (PID: 3408)
      • wicreset.tmp (PID: 3576)
      • wicreset.exe (PID: 3444)
    • Create files in a temporary directory

      • wicreset.exe (PID: 3408)
      • wicreset.exe (PID: 3216)
    • Reads the computer name

      • wicreset.tmp (PID: 3372)
      • wicreset.tmp (PID: 3576)
      • wicreset.exe (PID: 3444)
    • Creates files in the program directory

      • wicreset.tmp (PID: 3576)
    • Creates files or folders in the user directory

      • wicreset.exe (PID: 3444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 15:27:46+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 5.80.0.0
ProductVersionNumber: 5.80.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: WWW.WIC.SUPPORT
FileDescription: WicReset Setup
FileVersion: 5.80.0.0
LegalCopyright:
ProductName: WicReset
ProductVersion: 5.80.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wicreset.exe no specs wicreset.tmp no specs wicreset.exe wicreset.tmp no specs wicreset.exe

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Users\admin\AppData\Local\Temp\wicreset.exe" C:\Users\admin\AppData\Local\Temp\wicreset.exeexplorer.exe
User:
admin
Company:
WWW.WIC.SUPPORT
Integrity Level:
MEDIUM
Description:
WicReset Setup
Exit code:
0
Version:
5.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3372"C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmp" /SL5="$70134,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmpwicreset.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hdgp5.tmp\wicreset.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3408"C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 C:\Users\admin\AppData\Local\Temp\wicreset.exe
wicreset.tmp
User:
admin
Company:
WWW.WIC.SUPPORT
Integrity Level:
HIGH
Description:
WicReset Setup
Exit code:
0
Version:
5.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3444"C:\Program Files\WicReset\wicreset.exe"C:\Program Files\WicReset\wicreset.exe
wicreset.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\wicreset\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3576"C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmp" /SL5="$601EA,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmpwicreset.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t7nnk.tmp\wicreset.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 848
Read events
2 842
Write events
0
Delete events
6

Modification events

(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
5D42303D4FA360F31DD9DCEE56C1B0CEB6BDBD24B097DBF0431D5D4DDB709117
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\WicReset\wicreset.exe
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
7920C051C9CDC03E40EC62463364F47D7318C6FA7E630F8C5F744A938DDB67B4
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
F80D00002A5B871A3211DA01
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
6
Suspicious files
63
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3408wicreset.exeC:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
3576wicreset.tmpC:\Program Files\WicReset\wicreset.exeexecutable
MD5:496D0BD5AA103097CCA8528DB0D47FE6
SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B
3216wicreset.exeC:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
3576wicreset.tmpC:\Program Files\WicReset\is-SMVN4.tmpexecutable
MD5:58E7080D8B85EF01176F748BEAC723DA
SHA256:95EB04331863353260F569AB50E86E5CBEFE72022914FF1A15E9747AF5552C06
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-18x-standard.binbinary
MD5:BEEF59F6DE2F2F388BE3A40778EF8518
SHA256:3F32092E0F4CE56148EB06FD6E0F7B897C66DDF95923D123BC436A809D9CF79C
3576wicreset.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\WicReset\WicReset.lnkbinary
MD5:E933DC269BF79882012C089B769E5835
SHA256:8D1F094835C3B9E62B5E622F8509D69100FEDF31A06EB8B58F699191A212A027
3576wicreset.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\WicReset\Uninstall WicReset.lnkbinary
MD5:61BF0A818E0887A3CDE62CBAB4BC8135
SHA256:8DB50248F137F9EEBC78700DB25119EF43B5982C9383F9E6E6219FFC94A4CB5D
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\devices.srsbinary
MD5:8823E570EFA668912F4A96A700271184
SHA256:5DCA33672C379567B997A6DAF0253EA1F5DA27CFF2F4DD942B12B53FC51B7F87
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-b-xxx-standard.binbinary
MD5:0467ED95C6427C627E3CBC967CF8D638
SHA256:82A7425F7E47C4D2D8D8E6124493084CCE5BE153C86FDBF768E9881A3EA17E21
3576wicreset.tmpC:\Program Files\WicReset\is-STMSO.tmpexecutable
MD5:496D0BD5AA103097CCA8528DB0D47FE6
SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
15
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.printhelp.info/data/redist/upgrades.xml
unknown
xml
628 b
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/support_message.php
unknown
text
7 b
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.printhelp.info/data/redist/upgrades.zip
unknown
compressed
169 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/banners/content.xml
unknown
xml
1.48 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/banners/u-csfwr.png
unknown
image
9.24 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/wicfaq.rss
unknown
xml
5.85 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/wicreset.rss
unknown
xml
58.9 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3444
wicreset.exe
176.9.157.164:80
wasteinkcounter.com
Hetzner Online GmbH
DE
unknown
3444
wicreset.exe
192.168.100.255:3289
whitelisted
3444
wicreset.exe
176.9.157.164:23457
wasteinkcounter.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
wasteinkcounter.com
  • 176.9.157.164
unknown
www.printhelp.info
  • 176.9.157.164
malicious
www.2manuals.com
  • 176.9.157.164
malicious

Threats

No threats detected
Process
Message
wicreset.exe
d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).
wicreset.exe
d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).