| File name: | WinThumbsPreloader-1.0.3-setup.exe |
| Full analysis: | https://app.any.run/tasks/c65e0a1a-884f-49aa-95be-60a3e8eaaa15 |
| Verdict: | Malicious activity |
| Analysis date: | January 23, 2024, 16:44:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BE55BC1D72B4729C17DA9F2832E436F8 |
| SHA1: | C49135673D7F0114B2A5FD3EF14684BD0FACB565 |
| SHA256: | A5B4A8E694656606A5E96A4C72924EDB3C8DB9C9083233F75C1A953AC66BDD3D |
| SSDEEP: | 49152:x7HeQqhlQ6NY3fkHG9F84iw4EnX91iRBoi8Xq3vI5VDq3mOvfS0RbhR9u291x5h1:5+QqZ8fkHG9FBeEnX3iRBJ8k2RqWUPtN |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:03 10:09:11+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 89088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.3.0 |
| ProductVersionNumber: | 1.0.3.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Original work: Dmitry Bruhov, MT fork https://github.com/art |
| FileDescription: | WinThumbsPreloader Setup |
| FileVersion: | 1.0.3 |
| LegalCopyright: | Copyright (c) 2022 Original work: Dmitry Bruhov, MT fork https://github.com/arturdd/WinThumbsPreload |
| OriginalFileName: | |
| ProductName: | WinThumbsPreloader |
| ProductVersion: | 1.0.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1808 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2320 | "C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | WinThumbsPreloader-1.0.3-setup.tmp | ||||||||||||
User: admin Integrity Level: MEDIUM Description: WinThumbsPreloader Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 2404 | "C:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmp" /SL5="$8010A,859858,831488,C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmp | — | WinThumbsPreloader-1.0.3-setup.exe | |||||||||||
User: admin Company: Original work: Dmitry Bruhov, MT fork https://github.com/art Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2484 | "C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A | C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe | WinThumbsPreloader-1.0.3-setup.tmp | ||||||||||||
User: admin Company: Original work: Dmitry Bruhov, MT fork https://github.com/art Integrity Level: HIGH Description: WinThumbsPreloader Setup Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 2568 | "C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" | C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe | explorer.exe | ||||||||||||
User: admin Company: Original work: Dmitry Bruhov, MT fork https://github.com/art Integrity Level: MEDIUM Description: WinThumbsPreloader Setup Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 2612 | "C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\MSOCache" | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: WinThumbsPreloader Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 2780 | "C:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmp" /SL5="$F0176,859858,831488,C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A | C:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmp | WinThumbsPreloader-1.0.3-setup.exe | ||||||||||||
User: admin Company: Original work: Dmitry Bruhov, MT fork https://github.com/art Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2824 | "C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Users\Public\Pictures\Sample Pictures" | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: WinThumbsPreloader Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 3088 | "C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Program Files" | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: WinThumbsPreloader Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| 3092 | "C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Windows" | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: WinThumbsPreloader Exit code: 0 Version: 1.0.3 Modules
| |||||||||||||||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 7B92F0A3D9A1A6F43CA55B8C93858CC9201B14BD499105E9F59CAA5CC77F7E18 | |||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | |||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 37FE034A9AFD6710C9FB33A1FDF5CA98836CC0214A39BB658DF6FB88F060E042 | |||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: DC0A0000A2D9A3771B4EDA01 | |||
| (PID) Process: | (2780) WinThumbsPreloader-1.0.3-setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2320) WinThumbsPreloader.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\unins000.exe | executable | |
MD5:A57AEAE5C64BF8603EAD9F90CD78709E | SHA256:E8D9075EFB8288CFF316FE2612E46DE1012ABA2C87D4273308C151B21C0B420A | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\is-HNH3F.tmp | executable | |
MD5:A57AEAE5C64BF8603EAD9F90CD78709E | SHA256:E8D9075EFB8288CFF316FE2612E46DE1012ABA2C87D4273308C151B21C0B420A | |||
| 2484 | WinThumbsPreloader-1.0.3-setup.exe | C:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmp | executable | |
MD5:917279BBA0D60A2D2F45D81A6B8EEC99 | SHA256:1C23F50003D713E876842AB6C8C56776D9D16B5ABA1EB6A922554AB39B6000D0 | |||
| 2568 | WinThumbsPreloader-1.0.3-setup.exe | C:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmp | executable | |
MD5:917279BBA0D60A2D2F45D81A6B8EEC99 | SHA256:1C23F50003D713E876842AB6C8C56776D9D16B5ABA1EB6A922554AB39B6000D0 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\is-VEUO1.tmp | executable | |
MD5:D9449B951285DBD798A74B4E95E62D41 | SHA256:26A7024D8C494990FB90915E2F68FEA8B10C3E74CBE80786957DCE9CD5BE4479 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe.config | xml | |
MD5:84F5BCB71BA0966887FF5C5CCB4E954E | SHA256:74ABFDA6CA833AA0FE3B2DC800F787AB6D723D213368556CAE99D8B06F7F7587 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\is-S8422.tmp | xml | |
MD5:84F5BCB71BA0966887FF5C5CCB4E954E | SHA256:74ABFDA6CA833AA0FE3B2DC800F787AB6D723D213368556CAE99D8B06F7F7587 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe | executable | |
MD5:D9449B951285DBD798A74B4E95E62D41 | SHA256:26A7024D8C494990FB90915E2F68FEA8B10C3E74CBE80786957DCE9CD5BE4479 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\is-T5C4G.tmp | text | |
MD5:F8091CBE567C3F4F6F429652555B5952 | SHA256:D8B4F93F399B6B7DEC434DEC3F8DB0B6AE7EDB8285290C424F39D61D51D22824 | |||
| 2780 | WinThumbsPreloader-1.0.3-setup.tmp | C:\Program Files\WinThumbsPreloader\LICENSE.txt | text | |
MD5:F8091CBE567C3F4F6F429652555B5952 | SHA256:D8B4F93F399B6B7DEC434DEC3F8DB0B6AE7EDB8285290C424F39D61D51D22824 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2320 | WinThumbsPreloader.exe | 140.82.121.5:443 | api.github.com | GITHUB | US | unknown |
Domain | IP | Reputation |
|---|---|---|
api.github.com |
| whitelisted |