URL:

https://www.nch.com.au/components/wpsetup.exe

Full analysis: https://app.any.run/tasks/0a0947ce-c539-4917-9a23-33254869e7e8
Verdict: Malicious activity
Analysis date: October 21, 2023, 21:23:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
SHA1:

1D93F1CB9FBB023131FCAD444B7C4A2933E32492

SHA256:

C66C4399567DF0FF1F3EE77FEDE3B77294A64A5A5B1A5F5E2A647635F3B6928E

SSDEEP:

3:N8DSLyZGTlIXLALmWaA:2OLyZKGXL0aA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • wpsetup.exe (PID: 3848)
      • wpsetup.exe (PID: 3428)
      • nchsetup.exe (PID: 1768)
      • wavepad.exe (PID: 3928)
      • wavepad.exe (PID: 1616)
    • Drops the executable file immediately after the start

      • wpsetup.exe (PID: 3428)
      • nchsetup.exe (PID: 1768)
      • mp3el3.exe (PID: 3168)
  • SUSPICIOUS

    • Reads the Internet Settings

      • wpsetup.exe (PID: 3428)
      • nchsetup.exe (PID: 1768)
    • Searches for installed software

      • nchsetup.exe (PID: 1768)
    • Starts itself from another location

      • nchsetup.exe (PID: 1768)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3852)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3852)
      • nchsetup.exe (PID: 1768)
    • Checks supported languages

      • wpsetup.exe (PID: 3428)
      • nchsetup.exe (PID: 1768)
      • mp3el3.exe (PID: 3168)
      • wavepad.exe (PID: 3928)
      • wavepad.exe (PID: 1616)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2512)
      • iexplore.exe (PID: 3852)
    • Create files in a temporary directory

      • wpsetup.exe (PID: 3428)
      • mp3el3.exe (PID: 3168)
      • wavepad.exe (PID: 3928)
    • Reads the computer name

      • wpsetup.exe (PID: 3428)
      • nchsetup.exe (PID: 1768)
      • wavepad.exe (PID: 1616)
      • wavepad.exe (PID: 3928)
    • Creates files in the program directory

      • nchsetup.exe (PID: 1768)
      • mp3el3.exe (PID: 3168)
    • Reads the machine GUID from the registry

      • wavepad.exe (PID: 3928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start iexplore.exe no specs iexplore.exe wpsetup.exe no specs wpsetup.exe nchsetup.exe mp3el3.exe no specs wavepad.exe no specs wavepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1616"C:\Program Files\NCH Software\WavePad\wavepad.exe" -installschedC:\Program Files\NCH Software\WavePad\wavepad.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
WavePad Sound Editor
Exit code:
0
Version:
17.86+
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\nch software\wavepad\wavepad.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1768"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
wpsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
WavePad Sound Editor
Exit code:
0
Version:
17.86+
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\sechost.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\lpk.dll
2512"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3852 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rpcrt4.dll
3168"C:\Program Files\NCH Software\WavePad\mp3el3.exe" -LQUIET -instby fiWavePad -instsvar WAVEPADRelatedprogramspaidoffLLIBInstquickonC:\Program Files\NCH Software\WavePad\mp3el3.exenchsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\nch software\wavepad\mp3el3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
3428"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exe
iexplore.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
WavePad Sound Editor
Exit code:
0
Version:
17.86+
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\wpsetup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
3848"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exeiexplore.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
WavePad Sound Editor
Exit code:
3221226540
Version:
17.86+
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\wpsetup.exe
c:\windows\system32\ntdll.dll
3852"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.nch.com.au/components/wpsetup.exe"C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3928"C:\Program Files\NCH Software\WavePad\wavepad.exe"C:\Program Files\NCH Software\WavePad\wavepad.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
WavePad Sound Editor
Exit code:
0
Version:
17.86+
Modules
Images
c:\program files\nch software\wavepad\wavepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
14 178
Read events
13 851
Write events
323
Delete events
4

Modification events

(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000056010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3852) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
10
Suspicious files
149
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2512iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\96DD3FB36E520A44B4555F9239BEA849_1E30AB43F05877570F9CEC14C54F43AAbinary
MD5:58BC6C9EE1A4526535F4C6E43008D913
SHA256:6629F766CCFF484C0C9E596548F0CF46ACAF2C12CB5C2B306A73E7A9D9F43E34
3428wpsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.cabcompressed
MD5:1BD3FEA24602132A1669B29A372AA9A5
SHA256:8B47BC17F939F1556609F60A34B7CEED86A9BFE4C2BFD2E4B0095FBB75BDA59A
3852iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFDBB76E7BB062BEED.TMPbinary
MD5:E7A14E7244C1DC9BC5CFBE24B2AEE60B
SHA256:5FA9706C4A79F1166565E524C51204369F6802312E4F775D924691643409DDAD
3852iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exe.78tcy2u.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3852iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\wpsetup.exeexecutable
MD5:918D348B56B5C2A96D1A168B388E6247
SHA256:71DC01D55CC995F36ED9F97129804FBF902875179662182CE9033D9298153ECB
2512iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\wpsetup[1].exeexecutable
MD5:E9AB9E9B82DA6A762DD7D2814C47ECD9
SHA256:78B248D2CD9C248F57A6DF5572C679A46CA972225F6330C508FA65CE052740A2
2512iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_9F6005AF34C7906F717D420F892FD6D0binary
MD5:BE71582A0C2B9013EC066C5083F34618
SHA256:168B66F70A533D99E6D4A9D9997CE92FCB1E5AD74AAB70E2EF188D2EAD965147
2512iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3428wpsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cabcompressed
MD5:18B38AC2E659419E1570B05940B2AD7F
SHA256:DF3B2EC03E9C29B29E45ECF63BB0F1E7BB425C507A92EE56DC637DD853D5F821
2512iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\96DD3FB36E520A44B4555F9239BEA849_1E30AB43F05877570F9CEC14C54F43AAbinary
MD5:A1D42ABC33E08E2C3B05D2D9C6EBAF9B
SHA256:A5F68304ABCA2EE15E6932AB17C17C44A263620F5C0C4F386B95C491F260E91A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2512
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?060020e49c501eb3
unknown
compressed
4.66 Kb
unknown
2512
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSY%2BQAyqcBl6zxPqFEOTI24pxAWAwQUpbTW6zbE52um38RkCwEqIAS4ZiMCEA4DlyuKT0e2xUD3fS94%2FWQ%3D
unknown
binary
727 b
unknown
2512
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b40315f06fd1d4d8
unknown
compressed
4.66 Kb
unknown
2512
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEA9iL28hwv9dUh9yOh1H1i0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2512
iexplore.exe
66.39.105.214:443
PAIR-NETWORKS
US
unknown
2512
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2512
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1768
nchsetup.exe
173.247.253.164:443
secure.nch.com.au
INMOTION
US
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
secure.nch.com.au
  • 173.247.253.164
unknown

Threats

No threats detected
No debug info