File name:

wicreset.exe

Full analysis: https://app.any.run/tasks/108cd4b9-fd50-42a7-b0b5-1824e658a6fa
Verdict: Malicious activity
Analysis date: November 07, 2023, 04:22:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F3AAC20E36FB29FFEEF2EF8BD3763666

SHA1:

C16D0BD877CF6312734E965BFA4A0E862BBA4854

SHA256:

8E23F6F4C10255D128627A60048117C663930453A6596A2658DAECECD77E8E3E

SSDEEP:

49152:hRlKFK8ayk4NGSP9EghX2jieQKMIrc/SfZELwQSJYsWo+qU24o2Ah4gIXRATd7p7:xKFdtk4pP3hX2j2KMIYwHJVCAx6AB7p7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wicreset.exe (PID: 3216)
      • wicreset.exe (PID: 3408)
      • wicreset.tmp (PID: 3576)
  • SUSPICIOUS

    • Connects to unusual port

      • wicreset.exe (PID: 3444)
    • Reads the Windows owner or organization settings

      • wicreset.tmp (PID: 3576)
  • INFO

    • Create files in a temporary directory

      • wicreset.exe (PID: 3216)
      • wicreset.exe (PID: 3408)
    • Checks supported languages

      • wicreset.exe (PID: 3408)
      • wicreset.tmp (PID: 3372)
      • wicreset.exe (PID: 3216)
      • wicreset.tmp (PID: 3576)
      • wicreset.exe (PID: 3444)
    • Reads the computer name

      • wicreset.tmp (PID: 3372)
      • wicreset.exe (PID: 3444)
      • wicreset.tmp (PID: 3576)
    • Creates files or folders in the user directory

      • wicreset.exe (PID: 3444)
    • Creates files in the program directory

      • wicreset.tmp (PID: 3576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:06:14 15:27:46+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 66560
InitializedDataSize: 53760
UninitializedDataSize: -
EntryPoint: 0x1181c
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 5.80.0.0
ProductVersionNumber: 5.80.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: WWW.WIC.SUPPORT
FileDescription: WicReset Setup
FileVersion: 5.80.0.0
LegalCopyright:
ProductName: WicReset
ProductVersion: 5.80.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wicreset.exe no specs wicreset.tmp no specs wicreset.exe wicreset.tmp no specs wicreset.exe

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Users\admin\AppData\Local\Temp\wicreset.exe" C:\Users\admin\AppData\Local\Temp\wicreset.exeexplorer.exe
User:
admin
Company:
WWW.WIC.SUPPORT
Integrity Level:
MEDIUM
Description:
WicReset Setup
Exit code:
0
Version:
5.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3372"C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmp" /SL5="$70134,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" C:\Users\admin\AppData\Local\Temp\is-HDGP5.tmp\wicreset.tmpwicreset.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hdgp5.tmp\wicreset.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3408"C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 C:\Users\admin\AppData\Local\Temp\wicreset.exe
wicreset.tmp
User:
admin
Company:
WWW.WIC.SUPPORT
Integrity Level:
HIGH
Description:
WicReset Setup
Exit code:
0
Version:
5.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3444"C:\Program Files\WicReset\wicreset.exe"C:\Program Files\WicReset\wicreset.exe
wicreset.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\wicreset\wicreset.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3576"C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmp" /SL5="$601EA,2615238,121344,C:\Users\admin\AppData\Local\Temp\wicreset.exe" /SPAWNWND=$501F6 /NOTIFYWND=$70134 C:\Users\admin\AppData\Local\Temp\is-T7NNK.tmp\wicreset.tmpwicreset.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t7nnk.tmp\wicreset.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 848
Read events
2 842
Write events
0
Delete events
6

Modification events

(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
5D42303D4FA360F31DD9DCEE56C1B0CEB6BDBD24B097DBF0431D5D4DDB709117
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\WicReset\wicreset.exe
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
7920C051C9CDC03E40EC62463364F47D7318C6FA7E630F8C5F744A938DDB67B4
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
F80D00002A5B871A3211DA01
(PID) Process:(3576) wicreset.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
6
Suspicious files
63
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-b-xxx-standard.binbinary
MD5:0467ED95C6427C627E3CBC967CF8D638
SHA256:82A7425F7E47C4D2D8D8E6124493084CCE5BE153C86FDBF768E9881A3EA17E21
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\devices.srsbinary
MD5:8823E570EFA668912F4A96A700271184
SHA256:5DCA33672C379567B997A6DAF0253EA1F5DA27CFF2F4DD942B12B53FC51B7F87
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-18x-standard.binbinary
MD5:BEEF59F6DE2F2F388BE3A40778EF8518
SHA256:3F32092E0F4CE56148EB06FD6E0F7B897C66DDF95923D123BC436A809D9CF79C
3576wicreset.tmpC:\Program Files\WicReset\wicreset.exeexecutable
MD5:496D0BD5AA103097CCA8528DB0D47FE6
SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-600-standard.binbinary
MD5:147A64EA1D4E7E19CE919D3217F040F2
SHA256:06D15F237A910988C377F73D78E081980EC292F59EDBAB095FD8AF30AC62D231
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-k-xxx-standard.binbinary
MD5:630FA91CCFC3A7E862426117CB7DD46D
SHA256:CCFB2E1B18718DB3634327688038345B28A6D077BD2442DA272CCDBB1D534D0A
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-xxx-standard.binbinary
MD5:74714DC7052DFCDBD19E8C39EAB4E074
SHA256:BC1CBB90C8AF62854139124A87CD9A836FE5E450012436A96674164378B93DDE
3444wicreset.exeC:\Users\admin\AppData\Roaming\wicreset\patterns\colour-l-800-standard.binbinary
MD5:E2BE218354175BC1EC3F79D2443C261D
SHA256:C05C27F712C7D16FB223AD9B65BCC142551DAB2692549CFC08DBD9AC5071A876
3576wicreset.tmpC:\Program Files\WicReset\is-SMVN4.tmpexecutable
MD5:58E7080D8B85EF01176F748BEAC723DA
SHA256:95EB04331863353260F569AB50E86E5CBEFE72022914FF1A15E9747AF5552C06
3576wicreset.tmpC:\Program Files\WicReset\is-STMSO.tmpexecutable
MD5:496D0BD5AA103097CCA8528DB0D47FE6
SHA256:987F3B4229BE7F7FE1A4013D80A0AE729F2D1A5772D47B52046D2FD67777304B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
15
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.printhelp.info/data/redist/upgrades.xml
unknown
xml
628 b
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/support_message.php
unknown
text
7 b
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/wicfaq.rss
unknown
xml
5.85 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.printhelp.info/data/redist/upgrades.zip
unknown
compressed
169 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/banners/content.xml
unknown
xml
1.48 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/banners/u-csfwr.png
unknown
image
9.24 Kb
unknown
3444
wicreset.exe
GET
200
176.9.157.164:80
http://www.2manuals.com/WIC/wicreset.rss
unknown
xml
58.9 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3444
wicreset.exe
176.9.157.164:80
wasteinkcounter.com
Hetzner Online GmbH
DE
unknown
3444
wicreset.exe
192.168.100.255:3289
whitelisted
3444
wicreset.exe
176.9.157.164:23457
wasteinkcounter.com
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
wasteinkcounter.com
  • 176.9.157.164
unknown
www.printhelp.info
  • 176.9.157.164
malicious
www.2manuals.com
  • 176.9.157.164
malicious

Threats

No threats detected
Process
Message
wicreset.exe
d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).
wicreset.exe
d:\development\libraries\wx\src\msw\window.cpp(581): 'SetFocus' failed with error 0x00000057 (the parameter is incorrect.).