| File name: | pw-free-online.exe |
| Full analysis: | https://app.any.run/tasks/03dff6de-673e-4dfe-a4f6-e739d22b997d |
| Verdict: | Malicious activity |
| Analysis date: | December 15, 2023, 10:53:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B00F4EF87125599AE72DEF4555E48175 |
| SHA1: | 8B1073B0CEC1D85A6CA39842E43C8A9F49526953 |
| SHA256: | BC917C4424C078290C3CBBB13E5F2F9C2939222D058D70056688718AE33E13A9 |
| SSDEEP: | 98304:UkL2991YngbfnLTccGEE7kc7EF2DKlVcu/xI9Gu1:j2991OgDtQIc7E4Wcu/xI911 |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:04:14 18:10:23+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 406016 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.8.0.0 |
| ProductVersionNumber: | 12.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | MiniTool Software Limited |
| FileDescription: | MiniTool Partition Wizard Setup |
| FileVersion: | 12.8 |
| LegalCopyright: | Copyright © 2023 MiniTool Software Limited, all rights reserved. |
| OriginalFileName: | |
| ProductName: | MiniTool Partition Wizard |
| ProductVersion: | 12.8 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Users\admin\AppData\Local\Temp\is-G18JM.tmp\pw-free-online.tmp" /SL5="$1B0142,2294223,1148928,C:\Users\admin\Desktop\pw-free-online.exe" | C:\Users\admin\AppData\Local\Temp\is-G18JM.tmp\pw-free-online.tmp | — | pw-free-online.exe | |||||||||||
User: admin Company: MiniTool Software Limited Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1073807364 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1436 | C:\Windows\System32\vds.exe | C:\Windows\System32\vds.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Virtual Disk Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1996 | "C:\Users\admin\Desktop\pw-free-online.exe" | C:\Users\admin\Desktop\pw-free-online.exe | — | explorer.exe | |||||||||||
User: admin Company: MiniTool Software Limited Integrity Level: MEDIUM Description: MiniTool Partition Wizard Setup Exit code: 1073807364 Version: 12.8 Modules
| |||||||||||||||
| 2108 | "C:\Users\admin\AppData\Local\Temp\is-HDBJ2.tmp\pw-free-online.tmp" /SL5="$110156,2294223,1148928,C:\Users\admin\Desktop\pw-free-online.exe" /SPAWNWND=$1A0194 /NOTIFYWND=$1B0142 | C:\Users\admin\AppData\Local\Temp\is-HDBJ2.tmp\pw-free-online.tmp | — | pw-free-online.exe | |||||||||||
User: admin Company: MiniTool Software Limited Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1073807364 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2364 | "C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\SmDownloader.exe" /HWND:1114488 /PATH:"C:\Program Files\MiniTool Partition Wizard 12\..\MiniTool ShadowMaker" /URL:https://www.partitionwizard.com/download/online-setup-config/pwfree-v12-bundle-sm.ini /VERYSILENT /USERMSG:1439 /LANG:english | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\SmDownloader.exe | pw-free-online.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1073807364 Modules
| |||||||||||||||
| 2368 | C:\Windows\System32\vdsldr.exe -Embedding | C:\Windows\System32\vdsldr.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Virtual Disk Service Loader Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2424 | "C:\Users\admin\Desktop\pw-free-online.exe" /SPAWNWND=$1A0194 /NOTIFYWND=$1B0142 | C:\Users\admin\Desktop\pw-free-online.exe | pw-free-online.tmp | ||||||||||||
User: admin Company: MiniTool Software Limited Integrity Level: HIGH Description: MiniTool Partition Wizard Setup Exit code: 1073807364 Version: 12.8 Modules
| |||||||||||||||
| 2456 | "C:\Program Files\MiniTool Partition Wizard 12\partitionwizard.exe" | C:\Program Files\MiniTool Partition Wizard 12\partitionwizard.exe | — | explorer.exe | |||||||||||
User: admin Company: MiniTool Software Limited Integrity Level: MEDIUM Description: MiniTool Partition Wizard Exit code: 3221226540 Version: 12.8.0.0 Modules
| |||||||||||||||
| 2668 | "taskkill.exe" /f /im "updatechecker.exe" | C:\Windows\System32\taskkill.exe | — | pw-free-online.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2968 | "C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe" /createtask | C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe | — | pwfree-32bit-online.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2108) pw-free-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2108) pw-free-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2108) pw-free-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2108) pw-free-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 6299E559F8C9C1F419E4E415861CE81DF739739294F5F49A1283FB9699AB7F53 | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\MiniTool Partition Wizard 12\7-zip.dll | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete value | Name: | SessionHash |
Value: F3A1F1F0B986C4C4817D410701153F8F6656DEF9DE21E36FBA12903669A34E10 | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete value | Name: | Owner |
Value: EC0C0000C43ECBFF442FDA01 | |||
| (PID) Process: | (3308) pwfree-32bit-online.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2424 | pw-free-online.exe | C:\Users\admin\AppData\Local\Temp\is-HDBJ2.tmp\pw-free-online.tmp | executable | |
MD5:38088568F4393EDC27739E4E3B3B157A | SHA256:398B1FE38A434790F6D5E82D72BBAEF3B3DFBA13740BDE388FB7749312C1B917 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\pwpro.bmp | image | |
MD5:91B84953535C8E68D9B8180AE60FF0CE | SHA256:10C9CF3C6885E339A7C9C4808716A7FDE113B4C4EE93FB2D5393240DF2D206B6 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\pwbmp.bmp | image | |
MD5:C4C50E455CB11D349A5200508F2F7D4F | SHA256:BA68E855CE14DAF9B319E3BA91199FE504804EC58080B722686AAA2CCDE9EF38 | |||
| 1996 | pw-free-online.exe | C:\Users\admin\AppData\Local\Temp\is-G18JM.tmp\pw-free-online.tmp | executable | |
MD5:38088568F4393EDC27739E4E3B3B157A | SHA256:398B1FE38A434790F6D5E82D72BBAEF3B3DFBA13740BDE388FB7749312C1B917 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\unsupport.bmp | image | |
MD5:4AC29DE505CFB25BBB88D190AD379D82 | SHA256:93A93EC1F9AF7118B2FB05A1ABC420781130E5663B92536A23EC6A4B172A0843 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\SmDownloader.exe | executable | |
MD5:0BB1BE1CEE6BC878ACBB41B1AF7CFC88 | SHA256:166960F92A85A33207DAD124FEA1938740A82809C05DD449FD19F39C2C029038 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\line.bmp | image | |
MD5:9DC5BF6E4B2CAD053D12AD24260D9327 | SHA256:EFB22F0B990C4ED4A8D36868C7D9D3793B61F0728343306CAEAE0AE5F0751447 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\libcurl.dll | executable | |
MD5:56F4C7D613927081E8311BC46EE0EC92 | SHA256:F959786D18020A9DED99DC668E1F576CAC8DD364E22D773D40E4FC693264555C | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\support.bmp | image | |
MD5:12CA16A9C8707B7F0A257E6CABBBEA3A | SHA256:624677996B347CD36593D4A1107B265C903268086F2F548B50C0F329FD649A33 | |||
| 2108 | pw-free-online.tmp | C:\Users\admin\AppData\Local\Temp\is-GBHA0.tmp\libeay32.dll | executable | |
MD5:D805C955E95F9B1A753733EA80439C45 | SHA256:963B663BAB4B063403D01AF996AB80252718D12FE4AF39F334532B0B26C9DAD3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3704 | partitionwizard.exe | GET | — | 104.18.20.161:80 | http://www.partitionwizard.com/checking-update/verconfig-v11-free.txt | unknown | — | — | unknown |
3704 | partitionwizard.exe | GET | 301 | 104.18.20.178:80 | http://tracking.minitool.com/pw/launch.php?120800-from-free-v12 | unknown | html | 272 b | unknown |
3704 | partitionwizard.exe | GET | 200 | 104.18.20.178:80 | http://tracking.minitool.com/pw/launch.html?120800-from-free-v12 | unknown | html | 521 b | unknown |
3704 | partitionwizard.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8be229b1a76ba8a7 | unknown | compressed | 4.66 Kb | unknown |
3704 | partitionwizard.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b9de9e9115f7e844 | unknown | compressed | 4.66 Kb | unknown |
3704 | partitionwizard.exe | GET | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
3704 | partitionwizard.exe | GET | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
3704 | partitionwizard.exe | GET | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCZXmpIP%2Bo%2BHhJmodADfw%2Fc | unknown | binary | 472 b | unknown |
3704 | partitionwizard.exe | GET | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEFWAEhXnhCXkEikk9ZU5A80%3D | unknown | binary | 471 b | unknown |
3704 | partitionwizard.exe | GET | 200 | 142.250.74.195:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEGupzMnM%2BqGaCjIQPyd58u0%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3388 | SmDownloader.exe | 104.18.20.161:443 | www.partitionwizard.com | CLOUDFLARENET | — | unknown |
2364 | SmDownloader.exe | 104.18.20.161:443 | www.partitionwizard.com | CLOUDFLARENET | — | unknown |
2364 | SmDownloader.exe | 104.18.20.178:443 | cdn2.minitool.com | CLOUDFLARENET | — | unknown |
3388 | SmDownloader.exe | 104.18.20.178:443 | cdn2.minitool.com | CLOUDFLARENET | — | unknown |
3704 | partitionwizard.exe | 104.18.20.161:80 | www.partitionwizard.com | CLOUDFLARENET | — | unknown |
3704 | partitionwizard.exe | 104.18.20.178:80 | cdn2.minitool.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
www.partitionwizard.com |
| unknown |
cdn2.minitool.com |
| unknown |
tracking.minitool.com |
| unknown |
www.googletagmanager.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
www.google-analytics.com |
| whitelisted |
region1.analytics.google.com |
| whitelisted |
stats.g.doubleclick.net |
| whitelisted |
www.google.sk |
| whitelisted |
Process | Message |
|---|---|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_caption_menu_button_clicked()
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_append_partition_management_tab()
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_actionPartitionRecovery_triggered()
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_action_change_lanuage()
|
partitionwizard.exe | Unknown property flat-widget-border-color
|
partitionwizard.exe | Unknown property flat-widget-border-color
|
partitionwizard.exe | libpng warning: iCCP: known incorrect sRGB profile
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_exit_triggered()
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_signal_device_changed()
|
partitionwizard.exe | QMetaObject::connectSlotsByName: No matching signal for on_checking_license_exited(int)
|