| File name: | Ninite WizTree Installer.exe |
| Full analysis: | https://app.any.run/tasks/7b7256f5-fc78-43ea-9cf9-46dafb340966 |
| Verdict: | Malicious activity |
| Analysis date: | January 19, 2025, 01:02:37 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 3D8701BB10CD0D54DD76AEE7C24B2054 |
| SHA1: | A0528D488718E14F0CB6809B3EA9373EA52BD4B0 |
| SHA256: | CF7F27BC0172829ED137E7963DA3322DA251B9595FC907EAF25F52FD90F2CA78 |
| SSDEEP: | 12288:GLVP603RQX2pyf+cnci2N9pKKfyeo+pW1KKRyzE8:YVP60BM2pMUN9keo+c+zE8 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:04:12 00:19:47+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 233472 |
| InitializedDataSize: | 182272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1a53a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.1.1.1183 |
| ProductVersionNumber: | 0.1.1.1183 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Secure By Design Inc. |
| FileDescription: | Ninite |
| FileVersion: | 0,1,1,1183 |
| InternalName: | Ninite |
| LegalCopyright: | Copyright (C) 2009 Secure By Design Inc |
| OriginalFileName: | - |
| ProductName: | Ninite |
| ProductVersion: | 0,1,1,1183 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4888 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4792 -prefMapHandle 4732 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {76b0de12-dfff-4b90-8002-a0fa2cc26ea6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca650a6d10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2744 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3524 | "C:\Program Files\WizTree\WizTree64.exe" -setlanguage en | C:\Program Files\WizTree\WizTree64.exe | — | target.tmp | |||||||||||
User: admin Company: Antibody Software Limited Integrity Level: HIGH Description: WizTree Exit code: 0 Version: 4.23.0.0 Modules
| |||||||||||||||
| 3560 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6160 -childID 8 -isForBrowser -prefsHandle 6296 -prefMapHandle 6300 -prefsLen 31324 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {cfaed4bc-2952-4ab6-bb78-6b165c29baf2} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca69b3c850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3652 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2628 -childID 5 -isForBrowser -prefsHandle 5328 -prefMapHandle 5332 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9ad28a41-75dc-4b40-a44b-460c714f6e9a} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3692 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5140 -childID 3 -isForBrowser -prefsHandle 5136 -prefMapHandle 5132 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3eab185f-90a7-4c3a-ba53-f61cdc0ccee6} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68923bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3736 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5868 -childID 6 -isForBrowser -prefsHandle 5824 -prefMapHandle 5856 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e3257ca-5904-4e87-9b61-8ab5b939f755} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca68d244d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 5536 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 5892 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1824 -parentBuildID 20240213221259 -prefsHandle 1852 -prefMapHandle 1840 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4fba9fd9-5294-43c6-ac9f-7c80c39448bb} 5536 "\\.\pipe\gecko-crash-server-pipe.5536" 1ca5ddeab10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.8 (u) | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\WizTree | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\WizTree\ | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: WizTree | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: Selected Tasks |
Value: desktopicon,quicklaunchicon | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: Deselected Tasks |
Value: | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | Inno Setup: Language |
Value: en | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | DisplayName |
Value: WizTree v4.23 | |||
| (PID) Process: | (6984) target.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WizTree_is1 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\WizTree\WizTree.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 | binary | |
MD5:2B44D1584874F492B6406BFCED95A748 | SHA256:B9065996A719949883B09F18E0BBFB8D2F691AC1C1581F850F27764306910CDE | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41C | binary | |
MD5:9F86BE1CD0CB7E200442CED32BD3BB3B | SHA256:9956928C14211725B9FE12AB3349D36F95A2C949D34E18B4A11384B1D7101763 | |||
| 6656 | Ninite.exe | C:\Users\admin\AppData\Local\Temp\16e4151a-d601-11ef-b4ea-18f7786f96ee\target.exe_16e4151b-d601-11ef-b4ea-18f7786f96ee | executable | |
MD5:DEAE8661F3643AB1FA58774589459880 | SHA256:EDE889913A2B3819B2AA642A1BC46185A91202D854FA3EEC141C6E8E64EDD5C5 | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275F | binary | |
MD5:2BB9EBF580E7F882CC30F32EB1481741 | SHA256:47765859EB79927B1B1A2647F406F58680F2646C29F1D62503BBE2692281A255 | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\Local\Temp\150b2203-d601-11ef-b4ea-18f7786f96ee\Ninite.exe | executable | |
MD5:AECEA03AB75EA848DC8BB0511A3DFD83 | SHA256:168C0280421EC2CEA8ADCF34A22056839F32DF0AC3575B08F98001A10AD587C9 | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50385F8EB1F713E33924A830D7A2A41C | binary | |
MD5:AFA6A8DDB88654619A8BEF685FC89BE5 | SHA256:F779A4937720CEE5AA89F526A3F43ACD4BBF520D7007EC3512ABCE43B1003E90 | |||
| 6960 | target.exe | C:\Users\admin\AppData\Local\Temp\is-S74G3.tmp\target.tmp | executable | |
MD5:E92523CCBE8DB70FFB5D575BC6AD5393 | SHA256:1E23CBBD9135490044F608163C867BB5101E70F6C0022EA14FDF7342480F9A31 | |||
| 6656 | Ninite.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_427CDB1C9AAC2BAE6B426DB11F126FA2 | binary | |
MD5:5F7D7C58A619CF10BAFDD602FBB94FE8 | SHA256:8B12B5E66235AA77EC36FC9C0593CC47A980C380B737A5B04112C902C3CF85B1 | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A1D627669EFC8CD4F21BCF387D97F9B5_BCCFCBC66B448214318C9391CA0E275F | binary | |
MD5:248C4A2BC827A486C8C486017AE6074C | SHA256:E70033CEC911EABD2CAD100CCB00D14E377BD8D5C6DF0CF951121CAB2A4AEB48 | |||
| 6212 | Ninite WizTree Installer.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_A784AE3E993E9BBF7162E8F9F9758D3D | binary | |
MD5:2A590CDD20C46F046A8FF795E6BE4F5F | SHA256:BDDE4AAA47FC2C90AEDBBC8CBDCD50CAE6D3BDCD55668854B42F204071C73FEF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6212 | Ninite WizTree Installer.exe | GET | 200 | 18.245.38.41:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D | unknown | — | — | whitelisted |
6212 | Ninite WizTree Installer.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6212 | Ninite WizTree Installer.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/codesigningrootr45/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEQCBTkIXoSl%2F7VrM1Bf4ka11 | unknown | — | — | whitelisted |
6656 | Ninite.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAkO6MXeW%2Fpi0q4v9wl8SFc%3D | unknown | — | — | whitelisted |
6656 | Ninite.exe | GET | 200 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
6212 | Ninite WizTree Installer.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsgccr45codesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLuA3ygnKW%2F7xuSx%2F09F%2BhHVuEUQQU2rONwCSQo2t30wygWd0hZ2R2C3gCDGPUxoqhhiZifL455A%3D%3D | unknown | — | — | whitelisted |
5536 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6212 | Ninite WizTree Installer.exe | 65.9.66.107:443 | ninite.com | AMAZON-02 | US | whitelisted |
6212 | Ninite WizTree Installer.exe | 18.245.38.41:80 | ocsp.rootca1.amazontrust.com | — | US | whitelisted |
5064 | SearchApp.exe | 104.126.37.170:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
6212 | Ninite WizTree Installer.exe | 104.18.20.226:80 | ocsp.globalsign.com | CLOUDFLARENET | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ninite.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
diskanalyzer.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5536 | firefox.exe | Device Retrieving External IP Address Detected | ET INFO Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
5536 | firefox.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ipinfo.io |
2192 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
2192 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
2192 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |