File name:

winzip24-downwz.exe

Full analysis: https://app.any.run/tasks/a06cac92-99be-45c5-846c-3760e0ab6634
Verdict: Malicious activity
Analysis date: December 20, 2019, 18:58:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A4C7B661EC6AF289D200C308EF921CB5

SHA1:

BF8B2EA5ACACF6E015E227A90DF904A5771A946F

SHA256:

C7A4BADF4A5E2D72FCFE98BB9309C7EBCB3A839331EED9E23382D05D22E87A1E

SSDEEP:

24576:qZbDbHvHRCG+YF8JmiyeVnnZNXMICDmJ10pu3:+HvHn+YF8JmiyeVnnZNcIdJ+pu3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WzCABCacheSyncHelper32.exe (PID: 3060)
    • Loads dropped or rewritten executable

      • WzCABCacheSyncHelper32.exe (PID: 3060)
      • svchost.exe (PID: 864)
      • winzip32.exe (PID: 3460)
    • Runs injected code in another process

      • FAHWindow32.exe (PID: 1820)
    • Writes to a start menu file

      • msiexec.exe (PID: 1852)
    • Application was injected by another process

      • explorer.exe (PID: 352)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • winzip24-downwz.exe (PID: 3344)
      • msiexec.exe (PID: 1852)
    • Changes the autorun value in the registry

      • msiexec.exe (PID: 1852)
    • Creates COM task schedule object

      • winzip32.exe (PID: 3460)
      • adxregistrator.exe (PID: 2444)
      • adxregistrator.exe (PID: 3300)
    • Changes IE settings (feature browser emulation)

      • msiexec.exe (PID: 1852)
      • MsiExec.exe (PID: 3424)
    • Modifies the open verb of a shell class

      • winzip32.exe (PID: 3460)
      • msiexec.exe (PID: 1852)
    • Creates a software uninstall entry

      • winzip32.exe (PID: 3460)
    • Creates files in the user directory

      • winzip32.exe (PID: 3460)
    • Creates files in the program directory

      • winzip32.exe (PID: 3460)
      • winzip24-downwz.exe (PID: 940)
    • Reads Internet Cache Settings

      • winzip24-downwz.exe (PID: 940)
    • Reads internet explorer settings

      • winzip24-downwz.exe (PID: 940)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 1852)
    • Creates files in the program directory

      • MsiExec.exe (PID: 3424)
      • msiexec.exe (PID: 1852)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 1852)
    • Reads Microsoft Office registry keys

      • adxregistrator.exe (PID: 3300)
      • adxregistrator.exe (PID: 2444)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1852)
    • Application launched itself

      • msiexec.exe (PID: 1852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:08:15 14:48:12+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 519168
InitializedDataSize: 196096
UninitializedDataSize: -
EntryPoint: 0x4ece0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 24.0.13543.0
ProductVersionNumber: 24.0.13543.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: WinZip Computing
FileDescription: WinZipStub Installer
FileVersion: 24.0.13543.0
InternalName: WinZipStubInstaller.exe
LegalCopyright: (c) 2015-2019 Corel Corporation All rights reserved.
ProductName: WinZipStub
ProductVersion: 24.0.13543.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 15-Aug-2019 12:48:12
Detected languages:
  • English - United States
CompanyName: WinZip Computing
FileDescription: WinZipStub Installer
FileVersion: 24.0.13543.0
InternalName: WinZipStubInstaller.exe
LegalCopyright: (c) 2015-2019 Corel Corporation All rights reserved.
ProductName: WinZipStub
ProductVersion: 24.0.13543.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 7
Time date stamp: 15-Aug-2019 12:48:12
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0007EB3C
0x0007EC00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.61195
.rdata
0x00080000
0x0002005A
0x00020200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.97357
.data
0x000A1000
0x00003BCC
0x00002E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.69667
.gfids
0x000A5000
0x000007CC
0x00000800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.97267
.tls
0x000A6000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x000A7000
0x00004E58
0x00005000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.53812
.reloc
0x000AC000
0x000065F4
0x00006600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.62785

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.16947
2013
UNKNOWN
English - United States
RT_MANIFEST
101
1.91924
20
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
KERNEL32.dll
RPCRT4.dll
USER32.dll (delay-loaded)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
17
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start inject winzip24-downwz.exe winzip24-downwz.exe msiexec.exe msiexec.exe no specs closefah.exe no specs msiexec.exe no specs wzpreviewer32.exe no specs wzpreloader.exe no specs winzip32.exe no specs wzcabcachesynchelper32.exe svchost.exe fahconsole.exe no specs fahwindow32.exe no specs adxregistrator.exe no specs adxregistrator.exe no specs explorer.exe winzip24-downwz.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
352C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
504"C:\Users\admin\Desktop\winzip24-downwz.exe" C:\Users\admin\Desktop\winzip24-downwz.exeexplorer.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
MEDIUM
Description:
WinZipStub Installer
Exit code:
3221226540
Version:
24.0.13543.0
Modules
Images
c:\users\admin\desktop\winzip24-downwz.exe
c:\systemroot\system32\ntdll.dll
864C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
940 run=1 shortcut="C:\Users\admin\Desktop\winzip24-downwz.exe"C:\Users\admin\AppData\Local\Temp\38e6e5\winzip24-downwz.exe
winzip24-downwz.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZipStub Installer
Exit code:
0
Version:
24.0.13543.0
Modules
Images
c:\users\admin\appdata\local\temp\38e6e5\winzip24-downwz.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\lpk.dll
1268"C:\Program Files\WinZip\WzPreloader.exe"C:\Program Files\WinZip\WzPreloader.exemsiexec.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZip Preloader
Exit code:
0
Version:
24.0.13573.0
Modules
Images
c:\program files\winzip\wzpreloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1820"C:\Program Files\WinZip\FAHWindow32.exe" registerC:\Program Files\WinZip\FAHWindow32.exeFAHConsole.exe
User:
SYSTEM
Company:
WinZip Computing, S.L.
Integrity Level:
SYSTEM
Description:
File Association Helper
Exit code:
0
Version:
3.0.0.11
Modules
Images
c:\program files\winzip\fahwindow32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\winzip\fahdll32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1852C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1936C:\Windows\system32\MsiExec.exe -Embedding 43D017FC5EB68696DDDF85AD54270057C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2444"C:\Program Files\WinZip\adxregistrator.exe" /install="C:\Program Files\WinZip\WinZipExpressForOffice.dll" /privileges=admin /GenerateLogFile=falseC:\Program Files\WinZip\adxregistrator.exeMsiExec.exe
User:
SYSTEM
Company:
Add-in Express Ltd.
Integrity Level:
SYSTEM
Description:
Add-in Express .NET Registrator
Exit code:
0
Version:
9.2.4635.0
Modules
Images
c:\program files\winzip\adxregistrator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2732"C:\Users\admin\AppData\Local\Temp\CloseFAH.exe" C:\Users\admin\AppData\Local\Temp\CloseFAH.exeMsiExec.exe
User:
admin
Company:
WinZip Computing
Integrity Level:
HIGH
Description:
WinZip CloseFAH
Exit code:
0
Version:
24.0.13650
Modules
Images
c:\users\admin\appdata\local\temp\closefah.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
6 789
Read events
5 197
Write events
1 585
Delete events
7

Modification events

(PID) Process:(940) winzip24-downwz.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:install_language
Value:
English
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:status
Value:
0
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_CURRENT_USER\Software\Corel\stubframework\WNZP\24
Operation:writeName:channel
Value:
nkln24-downwz
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip24-downwz_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip24-downwz_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip24-downwz_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip24-downwz_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(940) winzip24-downwz.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\winzip24-downwz_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
78
Suspicious files
5
Text files
62
Unknown types
13

Dropped files

PID
Process
Filename
Type
864svchost.exeC:\Windows\appcompat\programs\RecentFileCache.bcftxt
MD5:
SHA256:
940winzip24-downwz.exeC:\ProgramData\UniqueId\databinary
MD5:
SHA256:
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\js\common.jstext
MD5:
SHA256:
3344winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e6e5\winzip24-downwz.exeexecutable
MD5:
SHA256:
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\img\progress_background.pngimage
MD5:17D7B3B6595A0D6860AF793BC8916F30
SHA256:74BFC424E331DF2961B4DF57D65FBFFC116594333DC1DDE0CD1277C351FA9C69
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\img\close-hover.pngimage
MD5:CDEDAD55D5AF2695E648D9D84ADFE854
SHA256:39D20DD0DB593B35E7807A68DFE22A566192FB8EF8675F4B9171A377E4391AB7
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\img\button-hover.pngimage
MD5:7D3A382C149EE7588958281A816918BF
SHA256:97E35A7F7DC87983E8D1DDAA120BBA9D81BFE3AE4A6F99301A4749224CFBDD02
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\img\close-normal.pngimage
MD5:4F64DCC3BE1513D9F8A1EE8D954B8CEA
SHA256:D5F0C3F36D1FCAE6ECB04BDF66D8B8E32B6486243DD138C3CDF520485BE464F9
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\img\headerImg.pngimage
MD5:EA07C82C382D670FCCAC91863B5EE0AD
SHA256:19416D915F430E0223E5F342487FC90E978F275104A15DC56238A9FC09381722
940winzip24-downwz.exeC:\Users\admin\AppData\Local\Temp\38e8b9\common\js\external.jstext
MD5:140918FEDED87FE0A5563A4080071258
SHA256:25DF7AB9509D4E8760F1FDC99684E0E72AAC6E885CBDD3396FEBC405EA77E7F6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
4
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
940
winzip24-downwz.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logUserActivity
US
xml
186 b
malicious
940
winzip24-downwz.exe
POST
200
54.68.21.135:80
http://www.installportal.com/v1/token
US
text
196 b
malicious
940
winzip24-downwz.exe
POST
200
54.68.21.135:80
http://www.installportal.com/v1/token
US
text
202 b
malicious
940
winzip24-downwz.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logUserActivity
US
xml
186 b
malicious
940
winzip24-downwz.exe
POST
200
18.236.15.144:80
http://i.installportal.com/v1/logAnalytics
US
xml
204 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
940
winzip24-downwz.exe
18.236.15.144:80
i.installportal.com
US
malicious
940
winzip24-downwz.exe
54.68.21.135:80
i.installportal.com
Amazon.com, Inc.
US
malicious
940
winzip24-downwz.exe
23.210.248.134:443
download.winzip.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
i.installportal.com
  • 18.236.15.144
  • 54.68.21.135
unknown
www.installportal.com
  • 54.68.21.135
  • 18.236.15.144
unknown
download.winzip.com
  • 23.210.248.134
whitelisted

Threats

Found threats are available for the paid subscriptions
3 ETPRO signatures available at the full report
No debug info