File name:

winzip18-lan_en.exe

Full analysis: https://app.any.run/tasks/ba3fbe37-70ee-4ddf-8f35-1cf4b51b2b71
Verdict: Malicious activity
Analysis date: May 12, 2025, 08:52:36
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

29DCC95BA4D7287A1D5E542C9B4A5C28

SHA1:

C44DB75E0A35D8B6ADE5B367C9F6044E9D7992F4

SHA256:

F9CE64AB2B3387876CAD5F5362A20C72076237862E4603F9E6D76D8709DAA1C7

SSDEEP:

24576:kmTEEt9uTjitJDjFFnVEVOt00zZx1kzDnWWnUIJcXj+wDnBEtMz/CNOfMbtJJJD:kmzt9uTjitJDjFFnVMw00zZxkDWWnUOb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Executable content was dropped or overwritten

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Application launched itself

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Reads Microsoft Outlook installation path

      • winzip18-lan_en.exe (PID: 7520)
    • Reads Internet Explorer settings

      • winzip18-lan_en.exe (PID: 7520)
    • There is functionality for taking screenshot (YARA)

      • winzip18-lan_en.exe (PID: 7520)
  • INFO

    • Create files in a temporary directory

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Process checks whether UAC notifications are on

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Checks supported languages

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
    • Reads the computer name

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
    • Process checks computer location settings

      • winzip18-lan_en.exe (PID: 7384)
    • Reads the machine GUID from the registry

      • winzip18-lan_en.exe (PID: 7520)
    • Checks proxy server information

      • winzip18-lan_en.exe (PID: 7520)
      • slui.exe (PID: 4224)
    • Creates files in the program directory

      • winzip18-lan_en.exe (PID: 7520)
    • Detects InnoSetup installer (YARA)

      • winzip18-lan_en.exe (PID: 7520)
    • Reads the software policy settings

      • slui.exe (PID: 4224)
      • slui.exe (PID: 7720)
    • Compiled with Borland Delphi (YARA)

      • winzip18-lan_en.exe (PID: 7520)
    • UPX packer has been detected

      • winzip18-lan_en.exe (PID: 7520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (62.3)
.exe | Win32 EXE PECompact compressed (generic) (23.6)
.exe | Win32 Executable Delphi generic (8)
.exe | Win32 Executable (generic) (2.5)
.exe | Win16/32 Executable Delphi generic (1.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 42496
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winzip18-lan_en.exe winzip18-lan_en.exe sppextcomobj.exe no specs slui.exe winzip18-lan_en.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
4224C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7384"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7520"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /RSFC:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe
winzip18-lan_en.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7688C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7760"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /_ShowProgress /PrTxt:TG9hZGluZy4uLg==C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exewinzip18-lan_en.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
259
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
2 240
Read events
2 235
Write events
3
Delete events
2

Modification events

(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
Executable files
17
Suspicious files
9
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\images\button-bg.pngimage
MD5:98B1DE48DFA64DC2AA1E52FACFBEE3B0
SHA256:2693930C474FE640E2FE8D6EF98ABE2ECD303D2392C3D8B2E006E8942BA8F534
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\0010C0F0.logtext
MD5:8ED0C8FB3FBA88F1819D701701C1BDC0
SHA256:6BF932FAF179F04ACE7C2B26B1E0A7D66BAC33EB816B8F57428CCEF7A6E89B0D
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\browse.csstext
MD5:6009D6E864F60AEA980A9DF94C1F7E1C
SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\checkbox.csstext
MD5:64773C6B0E3413C81AEBC46CCE8C9318
SHA256:B09504C1BF0486D3EC46500592B178A3A6C39284672AF8815C3687CC3D29560D
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\button.csstext
MD5:37E1FF96E084EC201F0D95FEEF4D5E94
SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\images\progress-bg-corner.pngimage
MD5:608F1F20CD6CA9936EAA7E8C14F366BE
SHA256:86B6E6826BCDE2955D64D4600A4E01693522C1FDDF156CE31C4BA45B3653A7BD
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\images\progress-bg2.pngimage
MD5:B582D9A67BFE77D523BA825FD0B9DAE3
SHA256:AB4EEB3EA1EEF4E84CB61ECCB0BA0998B32108D70B3902DF3619F4D9393F74C3
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\main.csstext
MD5:245F1E09119B77893084DB07D98D88E8
SHA256:7F3C24865B663144021348986ECD00E20889BEAFAE52553C9FE9CC3C38DB6622
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\csshover3.htcbinary
MD5:52FA0DA50BF4B27EE625C80D36C67941
SHA256:E37E99DDFC73AC7BA774E23736B2EF429D9A0CB8C906453C75B14C029BDD5493
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\Close_Hover.pngimage
MD5:21D636C05F16CE05904F7400BE17DBB3
SHA256:DE58A6E90567998D380F6FA62068BEECB2F93F1D84B6B59180AA7BA05699D6B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2136
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2136
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2136
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 23.35.229.160
whitelisted
rp.dinipip.com
unknown
login.live.com
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.129
  • 20.190.159.130
  • 40.126.31.0
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
info.dinipip.com
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
os.dinipip.com
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info