File name:

WinThumbsPreloader-1.0.3-setup.exe

Full analysis: https://app.any.run/tasks/c65e0a1a-884f-49aa-95be-60a3e8eaaa15
Verdict: Malicious activity
Analysis date: January 23, 2024, 16:44:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BE55BC1D72B4729C17DA9F2832E436F8

SHA1:

C49135673D7F0114B2A5FD3EF14684BD0FACB565

SHA256:

A5B4A8E694656606A5E96A4C72924EDB3C8DB9C9083233F75C1A953AC66BDD3D

SSDEEP:

49152:x7HeQqhlQ6NY3fkHG9F84iw4EnX91iRBoi8Xq3vI5VDq3mOvfS0RbhR9u291x5h1:5+QqZ8fkHG9FBeEnX3iRBJ8k2RqWUPtN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2568)
      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2484)
      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2568)
      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2484)
      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
    • Reads the Windows owner or organization settings

      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
    • Reads the Internet Settings

      • WinThumbsPreloader.exe (PID: 2320)
    • Reads settings of System Certificates

      • WinThumbsPreloader.exe (PID: 2320)
    • Likely accesses (executes) a file from the Public directory

      • WinThumbsPreloader.exe (PID: 2824)
  • INFO

    • Reads the computer name

      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2404)
      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
      • WinThumbsPreloader.exe (PID: 2320)
      • WinThumbsPreloader.exe (PID: 2824)
      • WinThumbsPreloader.exe (PID: 3320)
      • WinThumbsPreloader.exe (PID: 3088)
      • WinThumbsPreloader.exe (PID: 3612)
      • WinThumbsPreloader.exe (PID: 3756)
      • WinThumbsPreloader.exe (PID: 2612)
      • WinThumbsPreloader.exe (PID: 3624)
      • WinThumbsPreloader.exe (PID: 3092)
    • Create files in a temporary directory

      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2568)
      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2484)
    • Checks supported languages

      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2568)
      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2404)
      • WinThumbsPreloader-1.0.3-setup.exe (PID: 2484)
      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
      • WinThumbsPreloader.exe (PID: 2320)
      • WinThumbsPreloader.exe (PID: 2824)
      • WinThumbsPreloader.exe (PID: 3088)
      • WinThumbsPreloader.exe (PID: 3320)
      • WinThumbsPreloader.exe (PID: 3612)
      • WinThumbsPreloader.exe (PID: 3624)
      • WinThumbsPreloader.exe (PID: 2612)
      • WinThumbsPreloader.exe (PID: 3756)
      • WinThumbsPreloader.exe (PID: 3092)
    • Creates files in the program directory

      • WinThumbsPreloader-1.0.3-setup.tmp (PID: 2780)
    • Reads Environment values

      • WinThumbsPreloader.exe (PID: 2320)
    • Reads the machine GUID from the registry

      • WinThumbsPreloader.exe (PID: 2320)
      • WinThumbsPreloader.exe (PID: 2824)
      • WinThumbsPreloader.exe (PID: 3088)
      • WinThumbsPreloader.exe (PID: 3320)
      • WinThumbsPreloader.exe (PID: 3624)
      • WinThumbsPreloader.exe (PID: 3612)
      • WinThumbsPreloader.exe (PID: 2612)
      • WinThumbsPreloader.exe (PID: 3756)
      • WinThumbsPreloader.exe (PID: 3092)
    • Manual execution by a user

      • explorer.exe (PID: 1808)
      • WinThumbsPreloader.exe (PID: 2824)
      • WinThumbsPreloader.exe (PID: 3320)
      • WinThumbsPreloader.exe (PID: 3624)
      • WinThumbsPreloader.exe (PID: 2612)
      • WinThumbsPreloader.exe (PID: 3088)
      • WinThumbsPreloader.exe (PID: 3756)
      • WinThumbsPreloader.exe (PID: 3612)
      • WinThumbsPreloader.exe (PID: 3092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 10:09:11+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 89088
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.3.0
ProductVersionNumber: 1.0.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Original work: Dmitry Bruhov, MT fork https://github.com/art
FileDescription: WinThumbsPreloader Setup
FileVersion: 1.0.3
LegalCopyright: Copyright (c) 2022 Original work: Dmitry Bruhov, MT fork https://github.com/arturdd/WinThumbsPreload
OriginalFileName:
ProductName: WinThumbsPreloader
ProductVersion: 1.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
14
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winthumbspreloader-1.0.3-setup.exe winthumbspreloader-1.0.3-setup.tmp no specs winthumbspreloader-1.0.3-setup.exe winthumbspreloader-1.0.3-setup.tmp winthumbspreloader.exe explorer.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs winthumbspreloader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1808"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2320"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe
WinThumbsPreloader-1.0.3-setup.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader
Exit code:
0
Version:
1.0.3
Modules
Images
c:\program files\winthumbspreloader\winthumbspreloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2404"C:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmp" /SL5="$8010A,859858,831488,C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" C:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmpWinThumbsPreloader-1.0.3-setup.exe
User:
admin
Company:
Original work: Dmitry Bruhov, MT fork https://github.com/art
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8l70v.tmp\winthumbspreloader-1.0.3-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2484"C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe
WinThumbsPreloader-1.0.3-setup.tmp
User:
admin
Company:
Original work: Dmitry Bruhov, MT fork https://github.com/art
Integrity Level:
HIGH
Description:
WinThumbsPreloader Setup
Exit code:
0
Version:
1.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winthumbspreloader-1.0.3-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2568"C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe
explorer.exe
User:
admin
Company:
Original work: Dmitry Bruhov, MT fork https://github.com/art
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader Setup
Exit code:
0
Version:
1.0.3
Modules
Images
c:\users\admin\appdata\local\temp\winthumbspreloader-1.0.3-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2612"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\MSOCache"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader
Exit code:
0
Version:
1.0.3
Modules
Images
c:\program files\winthumbspreloader\winthumbspreloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2780"C:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmp" /SL5="$F0176,859858,831488,C:\Users\admin\AppData\Local\Temp\WinThumbsPreloader-1.0.3-setup.exe" /SPAWNWND=$1800E6 /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmp
WinThumbsPreloader-1.0.3-setup.exe
User:
admin
Company:
Original work: Dmitry Bruhov, MT fork https://github.com/art
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hguij.tmp\winthumbspreloader-1.0.3-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2824"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Users\Public\Pictures\Sample Pictures"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader
Exit code:
0
Version:
1.0.3
Modules
Images
c:\program files\winthumbspreloader\winthumbspreloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3088"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Program Files"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader
Exit code:
0
Version:
1.0.3
Modules
Images
c:\program files\winthumbspreloader\winthumbspreloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3092"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe" -m "C:\Windows"C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WinThumbsPreloader
Exit code:
0
Version:
1.0.3
Modules
Images
c:\program files\winthumbspreloader\winthumbspreloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
5 563
Read events
5 543
Write events
14
Delete events
6

Modification events

(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
7B92F0A3D9A1A6F43CA55B8C93858CC9201B14BD499105E9F59CAA5CC77F7E18
(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe
(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
37FE034A9AFD6710C9FB33A1FDF5CA98836CC0214A39BB658DF6FB88F060E042
(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
DC0A0000A2D9A3771B4EDA01
(PID) Process:(2780) WinThumbsPreloader-1.0.3-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(2320) WinThumbsPreloader.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
8
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\unins000.exeexecutable
MD5:A57AEAE5C64BF8603EAD9F90CD78709E
SHA256:E8D9075EFB8288CFF316FE2612E46DE1012ABA2C87D4273308C151B21C0B420A
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\is-HNH3F.tmpexecutable
MD5:A57AEAE5C64BF8603EAD9F90CD78709E
SHA256:E8D9075EFB8288CFF316FE2612E46DE1012ABA2C87D4273308C151B21C0B420A
2484WinThumbsPreloader-1.0.3-setup.exeC:\Users\admin\AppData\Local\Temp\is-HGUIJ.tmp\WinThumbsPreloader-1.0.3-setup.tmpexecutable
MD5:917279BBA0D60A2D2F45D81A6B8EEC99
SHA256:1C23F50003D713E876842AB6C8C56776D9D16B5ABA1EB6A922554AB39B6000D0
2568WinThumbsPreloader-1.0.3-setup.exeC:\Users\admin\AppData\Local\Temp\is-8L70V.tmp\WinThumbsPreloader-1.0.3-setup.tmpexecutable
MD5:917279BBA0D60A2D2F45D81A6B8EEC99
SHA256:1C23F50003D713E876842AB6C8C56776D9D16B5ABA1EB6A922554AB39B6000D0
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\is-VEUO1.tmpexecutable
MD5:D9449B951285DBD798A74B4E95E62D41
SHA256:26A7024D8C494990FB90915E2F68FEA8B10C3E74CBE80786957DCE9CD5BE4479
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exe.configxml
MD5:84F5BCB71BA0966887FF5C5CCB4E954E
SHA256:74ABFDA6CA833AA0FE3B2DC800F787AB6D723D213368556CAE99D8B06F7F7587
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\is-S8422.tmpxml
MD5:84F5BCB71BA0966887FF5C5CCB4E954E
SHA256:74ABFDA6CA833AA0FE3B2DC800F787AB6D723D213368556CAE99D8B06F7F7587
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\WinThumbsPreloader.exeexecutable
MD5:D9449B951285DBD798A74B4E95E62D41
SHA256:26A7024D8C494990FB90915E2F68FEA8B10C3E74CBE80786957DCE9CD5BE4479
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\is-T5C4G.tmptext
MD5:F8091CBE567C3F4F6F429652555B5952
SHA256:D8B4F93F399B6B7DEC434DEC3F8DB0B6AE7EDB8285290C424F39D61D51D22824
2780WinThumbsPreloader-1.0.3-setup.tmpC:\Program Files\WinThumbsPreloader\LICENSE.txttext
MD5:F8091CBE567C3F4F6F429652555B5952
SHA256:D8B4F93F399B6B7DEC434DEC3F8DB0B6AE7EDB8285290C424F39D61D51D22824
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2320
WinThumbsPreloader.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted

Threats

No threats detected
No debug info