| File name: | WOMicClientSetup5_2.exe |
| Full analysis: | https://app.any.run/tasks/647a757f-6278-4b4c-b079-30ec9c103ea6 |
| Verdict: | Malicious activity |
| Analysis date: | January 18, 2024, 11:21:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | D8C68825B8A2CD1F00736B617240684C |
| SHA1: | 7B68A0832785021E8883CEC41606E60FA4A887E6 |
| SHA256: | C7C7227A636B4C612CDF3F3D803BE3EF1CF8F9AEDAD1C5D6620E0B9F6E0931A8 |
| SSDEEP: | 24576:Y12rpcEd5xQyaYXnCTZh5GYP7INP4w6ZtwZdsIAljoXHNAi7JYYDd+7PJms:QkzSy/nClDzBaZfuo3HYnPJd |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:03 22:19:02+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25600 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x32a0 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 632 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{5cfc84ad-f2d9-7b3d-70ec-a455e5d01b34}\womic.inf" "0" "66d2d8b0f" "000003DC" "WinSta0\Default" "00000550" "208" "c:\program files\womic\driver" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 764 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="WOMic" profile=any dir=in action=allow program="C:\Program Files\WOMic\womicclient.exe" enable=yes protocol=TCP | C:\Windows\System32\netsh.exe | — | WOMicClientSetup5_2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1000 | DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\Windows\INF\oem2.inf" "womic.inf:StdMfg.ntx86:WOVAD_MicArray:1.5.0.0:*womic" "66d2d8b0f" "000003DC" "000005E0" "000005E8" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\AppData\Local\Temp\nsgFEA5.tmp\nsB48.tmp" devcon.exe hwids *WOMic | C:\Users\admin\AppData\Local\Temp\nsgFEA5.tmp\nsB48.tmp | — | WOMicClientSetup5_2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225501 Modules
| |||||||||||||||
| 1652 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="WOMic" profile=any dir=in action=allow program="C:\Program Files\WOMic\womicclient.exe" enable=yes protocol=UDP | C:\Windows\System32\netsh.exe | — | WOMicClientSetup5_2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1924 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2036 | "C:\Users\admin\AppData\Local\Temp\WOMicClientSetup5_2.exe" | C:\Users\admin\AppData\Local\Temp\WOMicClientSetup5_2.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2128 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="WOMic" profile=any dir=out action=allow program="C:\Program Files\WOMic\womicclient.exe" enable=yes protocol=UDP | C:\Windows\System32\netsh.exe | — | WOMicClientSetup5_2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2172 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="WOMic" profile=any dir=out action=allow program="C:\Program Files\WOMic\womicclient.exe" enable=yes protocol=TCP | C:\Windows\System32\netsh.exe | — | WOMicClientSetup5_2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{6e096c00-ed77-7f01-e649-a36dc6ef8c11} Global\{277f914e-640b-48a5-c6ef-8c11c151084f} C:\Windows\System32\DriverStore\Temp\{50db485e-6bb2-31a0-4ccd-410942755312}\womic.inf C:\Windows\System32\DriverStore\Temp\{50db485e-6bb2-31a0-4ccd-410942755312}\womic.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2420) WOMicClientSetup5_2.exe | Key: | HKEY_CURRENT_USER\Software\Wolicheng\WOMic |
| Operation: | write | Name: | language |
Value: 1033 | |||
| (PID) Process: | (1652) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (764) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2128) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2172) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2480) devcon.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (632) drvinst.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2328) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (632) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (632) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\WOMicClient.exe | executable | |
MD5:26BA164873F020120E2267AC1CF16D43 | SHA256:9E07DBCE584991A821EA7030BC8228271D1D2AA8CE3D4BF8F1D2309796D7EBCF | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\Resource_ru.dll | executable | |
MD5:E26ED7B860D4D5FC63E822F82A25D4A0 | SHA256:82099AA1A1334A60624B0EB59AF38BDE790142A23E8727634E10B46BD161CF1D | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\adb.exe | executable | |
MD5:884242FB6CBBEC1F7711B946EF669E0E | SHA256:65210CB4139672B53ACAA2222B1005D036B0B02C437AA47E0E7B616FAB0E2F6F | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\Resource_cn.dll | executable | |
MD5:A987FE5A3328DCBC41F243592AF05200 | SHA256:96C06F8235314D08C76B5962F056663D13398E893E6B1D0C0B1221BE7DC3049B | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\AdbWinApi.dll | executable | |
MD5:ED5A809DC0024D83CBAB4FB9933D598D | SHA256:D60103A5E99BC9888F786EE916F5D6E45493C3247972CB053833803DE7E95CF9 | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WO Mic Client\WO Mic Client.lnk | binary | |
MD5:55842BB659323D59AEEC670DBB783A94 | SHA256:5C00BBB555582C992C1E7D44178FC6E509967668ECDE44F2840595299B76D27F | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WO Mic Client\Uninstall.lnk | binary | |
MD5:D4A24A212784A185B802F5CA0FA56FE9 | SHA256:EC69862DB42E831AA82339418895195B719B44AB8549CA2AB8F261B689014F2C | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\driver\womic.sys | executable | |
MD5:509E86A92D2F96B950106B1FB6499599 | SHA256:91A6E2993D08A720F9D1B83ECC253EAF75B44D8F7BD3C8273F10517D5EB18F14 | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\AdbWinUsbApi.dll | executable | |
MD5:0E24119DAF1909E398FA1850B6112077 | SHA256:25207C506D29C4E8DCEB61B4BD50E8669BA26012988A43FBF26A890B1E60FC97 | |||
| 2420 | WOMicClientSetup5_2.exe | C:\Program Files\WOMic\driver\womic.inf | text | |
MD5:D0C5F56C7B3F63742F3455B43447547B | SHA256:4DB4066A459F73E58BB6F4E0859A256C58887997EF826225AE886EA32040ACAF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 192.168.100.74:49165 | — | — | — | unknown |