File name:

WMSetup.exe

Full analysis: https://app.any.run/tasks/c1576ddc-6c38-4112-b1b9-e5d6c99be33d
Verdict: Malicious activity
Analysis date: April 24, 2024, 06:59:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

32F7AFAC4BC7AADECF65E0C7F14E1DCC

SHA1:

3710B3713142679C8A23D117B289BD14EFBFBD55

SHA256:

97C0F47C4713562060C16141BA96D1A157C2D4E29BE8E635DDA5EC9092FF98DA

SSDEEP:

49152:oPbcq8efxg8KZzNhpmzPFZ1/Mp01/waF0QEpRWhCcWK5TgVJ3D+zxNCEsZQGfnCr:oPYGJKZJhpmJZpQre0Q6RGfWK1oZ4bF5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WMSetup.exe (PID: 3004)
      • CCleaner.exe (PID: 3852)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 3852)
    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 3852)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • WMSetup.exe (PID: 3004)
    • Reads security settings of Internet Explorer

      • WMSetup.exe (PID: 3004)
      • CCleaner.exe (PID: 3852)
    • Executable content was dropped or overwritten

      • WMSetup.exe (PID: 3004)
      • CCleaner.exe (PID: 3852)
    • Reads the Internet Settings

      • WMSetup.exe (PID: 3004)
      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • Reads Microsoft Outlook installation path

      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • Reads Internet Explorer settings

      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • The process executes via Task Scheduler

      • CCleaner.exe (PID: 3852)
    • Checks Windows Trust Settings

      • CCleaner.exe (PID: 3852)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 3852)
    • Searches for installed software

      • CCleaner.exe (PID: 3852)
    • Reads the date of Windows installation

      • CCleaner.exe (PID: 3852)
  • INFO

    • Creates files in the program directory

      • WMSetup.exe (PID: 3004)
      • WindowManager.exe (PID: 3332)
      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • Checks supported languages

      • WMSetup.exe (PID: 3004)
      • WindowManager.exe (PID: 3332)
      • CCleaner.exe (PID: 1112)
      • CCleaner.exe (PID: 3852)
      • wmpnscfg.exe (PID: 604)
    • Reads the computer name

      • WMSetup.exe (PID: 3004)
      • WindowManager.exe (PID: 3332)
      • CCleaner.exe (PID: 1112)
      • CCleaner.exe (PID: 3852)
      • wmpnscfg.exe (PID: 604)
    • Create files in a temporary directory

      • WMSetup.exe (PID: 3004)
      • hh.exe (PID: 3084)
    • Reads the machine GUID from the registry

      • hh.exe (PID: 3084)
      • WindowManager.exe (PID: 3332)
      • CCleaner.exe (PID: 3852)
    • Creates files or folders in the user directory

      • WindowManager.exe (PID: 3332)
      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • Reads security settings of Internet Explorer

      • hh.exe (PID: 3084)
    • Checks proxy server information

      • hh.exe (PID: 3084)
      • CCleaner.exe (PID: 3852)
    • Manual execution by a user

      • CCleaner.exe (PID: 1112)
      • wmpnscfg.exe (PID: 604)
    • Reads Environment values

      • CCleaner.exe (PID: 1112)
      • CCleaner.exe (PID: 3852)
    • Reads product name

      • CCleaner.exe (PID: 3852)
    • Reads CPU info

      • CCleaner.exe (PID: 3852)
    • Reads the software policy settings

      • CCleaner.exe (PID: 3852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:03:30 15:05:45+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.35
CodeSize: 150016
InitializedDataSize: 1105408
UninitializedDataSize: -
EntryPoint: 0xe02c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wmsetup.exe windowmanager.exe hh.exe no specs ccleaner.exe no specs ccleaner.exe wmpnscfg.exe no specs wmsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
604"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
668"C:\Users\admin\AppData\Local\Temp\WMSetup.exe" C:\Users\admin\AppData\Local\Temp\WMSetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\wmsetup.exe
c:\windows\system32\ntdll.dll
1112"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
3004"C:\Users\admin\AppData\Local\Temp\WMSetup.exe" C:\Users\admin\AppData\Local\Temp\WMSetup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\wmsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3084"C:\Windows\hh.exe" C:\Program Files\WindowManager\WindowManager.chmC:\Windows\hh.exeWMSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® HTML Help Executable
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
3332"C:\Program Files\WindowManager\WindowManager.exe" C:\Program Files\WindowManager\WindowManager.exe
WMSetup.exe
User:
admin
Company:
DeskSoft
Integrity Level:
HIGH
Description:
WindowManager Application
Version:
10.17.2
Modules
Images
c:\program files\windowmanager\windowmanager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3852"C:\Program Files\CCleaner\CCleaner.exe" /uacC:\Program Files\CCleaner\CCleaner.exe
taskeng.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
Total events
20 838
Read events
20 550
Write events
206
Delete events
82

Modification events

(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MHDSYS32
Operation:writeName:99622DA110
Value:
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\DeskSoft
Operation:writeName:WindowManager
Value:
0100ECF1725AA12D62990A001100010000000000433A5C50726F6772616D2046696C65735C57696E646F774D616E616765720000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4465736B536F66745C57696E646F774D616E61676572000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F57696E646F774D616E616765725F50757263686173652E68746D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F5041442F574D5F5645522E545854000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000687474703A2F2F7777772E6465736B736F66742E636F6D2F57696E646F774D616E616765725F446F776E6C6F61642E68746D0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
116
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:DisplayName
Value:
WindowManager
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:DisplayIcon
Value:
C:\Program Files\WindowManager\WindowManager.exe,0
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:DisplayVersion
Value:
10.17.2
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:Publisher
Value:
DeskSoft
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:HelpLink
Value:
http://www.desksoft.com
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:URLInfoAbout
Value:
http://www.desksoft.com
(PID) Process:(3004) WMSetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowManager
Operation:writeName:URLUpdateInfo
Value:
http://www.desksoft.com
Executable files
5
Suspicious files
30
Text files
15
Unknown types
10

Dropped files

PID
Process
Filename
Type
3004WMSetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\WindowManager\WindowManager.lnk
MD5:
SHA256:
3004WMSetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\WindowManager\Uninstall.lnk
MD5:
SHA256:
3332WindowManager.exeC:\Users\admin\AppData\Roaming\DeskSoft\WindowManager\PinList.dcf_tmp
MD5:
SHA256:
3332WindowManager.exeC:\Users\admin\AppData\Roaming\DeskSoft\WindowManager\PinList.dcf
MD5:
SHA256:
3332WindowManager.exeC:\Users\admin\AppData\Roaming\DeskSoft\WindowManager\MinList.dcf_tmp
MD5:
SHA256:
3332WindowManager.exeC:\Users\admin\AppData\Roaming\DeskSoft\WindowManager\MinList.dcf
MD5:
SHA256:
3004WMSetup.exeC:\Program Files\WindowManager\WindowManager.exeexecutable
MD5:E051C040135AA4863781829C65FB8FD7
SHA256:0DF787E38CFE53358A4989514B0C13B08D1E8F29BCFA159BA4B380D1F7979AB4
3004WMSetup.exeC:\Program Files\WindowManager\WindowManager.chmchm
MD5:EA79B0E6750A9310CF995CE0CFD8ABE4
SHA256:4144A894FC45DFF6E7C32717AB6B752032C3A620CE14871F275DAD963721BE37
3084hh.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\helpman_topicinit[1].jstext
MD5:B2009A52003DC593903BDBBDDD7070AE
SHA256:C713702E446258809891C3085029B509A0FE8FC004590DB8B39E082624560BF2
3332WindowManager.exeC:\Users\admin\AppData\Roaming\DeskSoft\WindowManager\(DFC)Cmd.dcf_tmpbinary
MD5:93B885ADFE0DA089CDF634904FD59F71
SHA256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
22
DNS requests
14
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3332
WindowManager.exe
GET
301
188.68.47.244:80
http://www.desksoft.com/PAD/WM_VER.TXT
unknown
unknown
3852
CCleaner.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?93d5b63600fd6aa9
unknown
unknown
3852
CCleaner.exe
GET
200
2.16.100.179:80
http://ncc.avast.com/ncc.txt
unknown
unknown
3852
CCleaner.exe
GET
304
2.19.126.137:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbdfcac22e51d5bb
unknown
unknown
3852
CCleaner.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fe71f53c2037c306
unknown
unknown
3852
CCleaner.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?83d6684310e48aa8
unknown
unknown
3852
CCleaner.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
unknown
3852
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
unknown
3852
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
unknown
3852
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/s/gts1d4/xgScUbS9jLA/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCPbWWd2504TQndefR6%2FxGh
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3332
WindowManager.exe
188.68.47.244:80
www.desksoft.com
netcup GmbH
DE
unknown
3332
WindowManager.exe
188.68.47.244:443
www.desksoft.com
netcup GmbH
DE
unknown
3852
CCleaner.exe
2.16.100.179:80
ncc.avast.com
Akamai International B.V.
DE
whitelisted
3852
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3852
CCleaner.exe
34.111.24.1:443
ipm-provider.ff.avast.com
GOOGLE
US
unknown
3852
CCleaner.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.desksoft.com
  • 188.68.47.244
unknown
ncc.avast.com
  • 2.16.100.179
  • 2.16.100.160
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
www.ccleaner.com
  • 2.16.97.131
whitelisted
ipm-provider.ff.avast.com
  • 34.111.24.1
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
ctldl.windowsupdate.com
  • 2.19.126.163
  • 2.19.126.137
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
3852
CCleaner.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
CCleaner.exe
[2024-04-24 07:00:19.368] [error ] [settings ] [ 3852: 2728] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2024-04-24 07:00:20.071] [error ] [settings ] [ 3852: 3300] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2024-04-24 07:00:20.087] [error ] [Burger ] [ 3852: 3300] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2024-04-24 07:00:20.087] [error ] [Burger ] [ 3852: 3300] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
OnLanguage - en
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en