File name:

WinaeroTweaker-1.55.0.0-setup.exe

Full analysis: https://app.any.run/tasks/b1f44277-dad4-4585-85af-dec90ced48b9
Verdict: Malicious activity
Analysis date: April 30, 2024, 17:20:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F5D05EF3F28537C91B3A512203BAB7BA

SHA1:

F742FA8FCD8A099A40D82FA9A742C94818607D03

SHA256:

F74FBE93E3181D3FA1758B576BF46B7F6E46F17EE70085F20BCEDE563F143C5A

SSDEEP:

98304:nkLONs7qpXS+XbsmhsVOLwtfKmSOPsxUzCBnQX5FHin1KToob:cOy74RLlhrwEksxUzynMFa1KXb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 3972)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1200)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 3972)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1200)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
    • Reads the Windows owner or organization settings

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
    • Reads security settings of Internet Explorer

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
      • WinaeroTweaker.exe (PID: 1824)
      • WinaeroTweaker.exe (PID: 1212)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1036)
      • cmd.exe (PID: 1136)
    • Reads the Internet Settings

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
      • WinaeroTweaker.exe (PID: 1212)
      • WinaeroTweaker.exe (PID: 1824)
    • Starts CMD.EXE for commands execution

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
    • Application launched itself

      • WinaeroTweaker.exe (PID: 1824)
    • Reads settings of System Certificates

      • WinaeroTweaker.exe (PID: 1212)
    • Adds/modifies Windows certificates

      • WinaeroTweaker.exe (PID: 1212)
    • Reads Internet Explorer settings

      • WinaeroTweaker.exe (PID: 1212)
  • INFO

    • Checks supported languages

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3988)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 3972)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1200)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
      • WinaeroTweaker.exe (PID: 1824)
      • WinaeroTweaker.exe (PID: 1212)
      • WinaeroTweakerHelper.exe (PID: 2600)
      • wmpnscfg.exe (PID: 2472)
    • Create files in a temporary directory

      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 3972)
      • WinaeroTweaker-1.55.0.0-setup.exe (PID: 1200)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
    • Reads the computer name

      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 3988)
      • WinaeroTweaker-1.55.0.0-setup.tmp (PID: 928)
      • WinaeroTweaker.exe (PID: 1824)
      • WinaeroTweaker.exe (PID: 1212)
      • wmpnscfg.exe (PID: 2472)
    • Reads the machine GUID from the registry

      • WinaeroTweaker.exe (PID: 1824)
      • WinaeroTweaker.exe (PID: 1212)
    • Reads Environment values

      • WinaeroTweaker.exe (PID: 1212)
    • Reads the software policy settings

      • WinaeroTweaker.exe (PID: 1212)
    • Manual execution by a user

      • WinaeroTweaker.exe (PID: 1824)
      • wmpnscfg.exe (PID: 2472)
    • Reads CPU info

      • WinaeroTweaker.exe (PID: 1212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89088
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.55.0.0
ProductVersionNumber: 1.55.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Winaero
FileDescription: Winaero Tweaker
FileVersion: 1.55.0.0
LegalCopyright: Winaero
OriginalFileName:
ProductName: Winaero Tweaker
ProductVersion: 1.55.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
12
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winaerotweaker-1.55.0.0-setup.exe winaerotweaker-1.55.0.0-setup.tmp no specs winaerotweaker-1.55.0.0-setup.exe winaerotweaker-1.55.0.0-setup.tmp cmd.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs winaerotweaker.exe no specs winaerotweaker.exe winaerotweakerhelper.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
928"C:\Users\admin\AppData\Local\Temp\is-I27IE.tmp\WinaeroTweaker-1.55.0.0-setup.tmp" /SL5="$2013C,3507132,832000,C:\Users\admin\AppData\Local\Temp\WinaeroTweaker-1.55.0.0-setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\is-I27IE.tmp\WinaeroTweaker-1.55.0.0-setup.tmp
WinaeroTweaker-1.55.0.0-setup.exe
User:
admin
Company:
Winaero
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-i27ie.tmp\winaerotweaker-1.55.0.0-setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1036"C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweaker.exe /fC:\Windows\System32\cmd.exeWinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1136"C:\Windows\System32\cmd.exe" /c taskkill /im winaerotweakerhelper.exe /fC:\Windows\System32\cmd.exeWinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1200"C:\Users\admin\AppData\Local\Temp\WinaeroTweaker-1.55.0.0-setup.exe" /SPAWNWND=$20130 /NOTIFYWND=$20138 C:\Users\admin\AppData\Local\Temp\WinaeroTweaker-1.55.0.0-setup.exe
WinaeroTweaker-1.55.0.0-setup.tmp
User:
admin
Company:
Winaero
Integrity Level:
HIGH
Description:
Winaero Tweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\users\admin\appdata\local\temp\winaerotweaker-1.55.0.0-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1212"C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker.exe" -profile="C:\Users\admin" -sid="S-1-5-21-1302019708-1500728564-335382590-1000" -muil="en-US"C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker.exe
WinaeroTweaker.exe
User:
admin
Company:
https://winaero.com
Integrity Level:
HIGH
Description:
WinaeroTweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\users\admin\desktop\winaero tweaker\winaerotweaker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1824"C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker.exe" C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker.exeexplorer.exe
User:
admin
Company:
https://winaero.com
Integrity Level:
MEDIUM
Description:
WinaeroTweaker
Exit code:
0
Version:
1.55.0.0
Modules
Images
c:\users\admin\desktop\winaero tweaker\winaerotweaker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1876taskkill /im winaerotweakerhelper.exe /fC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2044taskkill /im winaerotweaker.exe /fC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2472"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2600"C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweakerHelper.exe" -C:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweakerHelper.exeWinaeroTweaker.exe
User:
admin
Company:
http://winaero.com
Integrity Level:
HIGH
Description:
Winaero Tweaker 32bit support process
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\winaero tweaker\winaerotweakerhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\gdi32.dll
Total events
11 607
Read events
11 523
Write events
73
Delete events
11

Modification events

(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A00300000068EFC7229BDA01
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
FCF2EEA2DF7C237D5B04C8C1621561563D0FBB1CE0FB66DE6D20EC657E759624
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Winaero.com\Winaero Tweaker
Operation:writeName:SetupDir
Value:
C:\Users\admin\Desktop\Winaero Tweaker
(PID) Process:(928) WinaeroTweaker-1.55.0.0-setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\Desktop\Winaero Tweaker\WinaeroControls.dll
Executable files
17
Suspicious files
1
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
1200WinaeroTweaker-1.55.0.0-setup.exeC:\Users\admin\AppData\Local\Temp\is-I27IE.tmp\WinaeroTweaker-1.55.0.0-setup.tmpexecutable
MD5:86703BD9DE2D284E858A60A09E5B9ADC
SHA256:74B32D4954EE2AA19E9D6C71F9797889F4BA6D838A5D50C5C8AE298BD89D702C
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker_i386.dllexecutable
MD5:BB3935CACCEA6DC73487045C7640AE7A
SHA256:A921DD143B295DFF3F4C1343A085980A50006A55797E239AB8AC1C0DA64E1BBE
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\AppData\Local\Temp\is-V32BO.tmp\_isetup\_iscrypt.dllexecutable
MD5:A69559718AB506675E907FE49DEB71E9
SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\is-MJP5E.tmpexecutable
MD5:8E0AEC38406AFACFF9487529ADD32C74
SHA256:C789872A6141E19F9CB71ABB8260C8303A2AC48DFD86F36912A4649800A78D39
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\WinaeroTweaker.exeexecutable
MD5:23C3E2111BE79604C718B474500213B8
SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\Elevator.exeexecutable
MD5:DF2708F6C7B1D60CFCF071142519A834
SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\is-JFO1V.tmpexecutable
MD5:DF2708F6C7B1D60CFCF071142519A834
SHA256:4AAB16C2765C4BBD729D41617ED6FBA08893CC3C71C9D250B3CBCBD600114749
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\WinaeroControls.dllexecutable
MD5:E5EE2251D3CE665D15579D31F7504BF5
SHA256:632D7523E50A34C2A201C7D263B87CB4D96696BE91D6573A2A7BA964C9E573EA
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\is-VJJR0.tmpexecutable
MD5:FB6E5BD898E6D6369F29A3FE0EDA0198
SHA256:100AC04E146983684553D9FEDC8442E7B0C619A832A1CF414F2482334ED472C9
928WinaeroTweaker-1.55.0.0-setup.tmpC:\Users\admin\Desktop\Winaero Tweaker\is-IFA90.tmpexecutable
MD5:23C3E2111BE79604C718B474500213B8
SHA256:0C4B4FB9C424A158939D4CFA492E16226EDFAEA1DFE6B5C242B833C4DCB9EA5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1212
WinaeroTweaker.exe
68.183.112.81:443
winaero.com
DIGITALOCEAN-ASN
US
unknown

DNS requests

Domain
IP
Reputation
winaero.com
  • 68.183.112.81
whitelisted

Threats

No threats detected
No debug info