| File name: | winzip18-lan_en.exe |
| Full analysis: | https://app.any.run/tasks/ba3fbe37-70ee-4ddf-8f35-1cf4b51b2b71 |
| Verdict: | Malicious activity |
| Analysis date: | May 12, 2025, 08:52:36 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | 29DCC95BA4D7287A1D5E542C9B4A5C28 |
| SHA1: | C44DB75E0A35D8B6ADE5B367C9F6044E9D7992F4 |
| SHA256: | F9CE64AB2B3387876CAD5F5362A20C72076237862E4603F9E6D76D8709DAA1C7 |
| SSDEEP: | 24576:kmTEEt9uTjitJDjFFnVEVOt00zZx1kzDnWWnUIJcXj+wDnBEtMz/CNOfMbtJJJD:kmzt9uTjitJDjFFnVMw00zZxkDWWnUOb |
| .exe | | | Inno Setup installer (62.3) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (23.6) |
| .exe | | | Win32 Executable Delphi generic (8) |
| .exe | | | Win32 Executable (generic) (2.5) |
| .exe | | | Win16/32 Executable Delphi generic (1.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37888 |
| InitializedDataSize: | 42496 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9c40 |
| OSVersion: | 1 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | |
| ProductVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4224 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7384 | "C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" | C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Exit code: 0 Version: Modules
| |||||||||||||||
| 7520 | "C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /RSF | C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe | winzip18-lan_en.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Exit code: 0 Version: Modules
| |||||||||||||||
| 7688 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7720 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7760 | "C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /_ShowProgress /PrTxt:TG9hZGluZy4uLg== | C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe | — | winzip18-lan_en.exe | |||||||||||
User: admin Company: Integrity Level: HIGH Description: Exit code: 259 Version: Modules
| |||||||||||||||
| (PID) Process: | (7520) winzip18-lan_en.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7520) winzip18-lan_en.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7520) winzip18-lan_en.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7520) winzip18-lan_en.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (7520) winzip18-lan_en.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\0010C0F0.log | text | |
MD5:8ED0C8FB3FBA88F1819D701701C1BDC0 | SHA256:6BF932FAF179F04ACE7C2B26B1E0A7D66BAC33EB816B8F57428CCEF7A6E89B0D | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\button.css | text | |
MD5:37E1FF96E084EC201F0D95FEEF4D5E94 | SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534 | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\css\ie6_main.css | text | |
MD5:2A9D6A4B9B87C780EB5DB7A45D792FC3 | SHA256:35530721CE143D19B5886C581FDE2F2B0A2BA629D2E6A9B39C49974719535F19 | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\browse.css | text | |
MD5:6009D6E864F60AEA980A9DF94C1F7E1C | SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\images\button-bg.png | image | |
MD5:98B1DE48DFA64DC2AA1E52FACFBEE3B0 | SHA256:2693930C474FE640E2FE8D6EF98ABE2ECD303D2392C3D8B2E006E8942BA8F534 | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\images\Close.png | image | |
MD5:FDD8888A29583266A1E6ED7EF9AB183E | SHA256:232915906AD3EA666117B4FEA965B6889593DA5EF86A81B108A62EBC7F56F5FE | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\images\Grey_Button.png | binary | |
MD5:7738C15F1D77C96F2AE9AFC030C6CC7D | SHA256:1802739A9AB1222ADED467C3F08954D382DE6AE6F3612EFC1852C479DCC65FDA | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\images\BG.png | image | |
MD5:302122820F433BD5B3071D96E7844812 | SHA256:BE58706B90E8B4984E43FB522BB3DAC17EC888F35B039F9C9AD8AEC4B9BD9631 | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\images\Color_Button_Hover.png | image | |
MD5:360733265596A19E4BABAAB84FD22381 | SHA256:8E1A9A21F3672006D9BD29B41F868A1734A951C7AB55E9A27EC75535CD4456C5 | |||
| 7384 | winzip18-lan_en.exe | C:\Users\admin\AppData\Local\Temp\ish1097984\images\Close_Hover.png | image | |
MD5:21D636C05F16CE05904F7400BE17DBB3 | SHA256:DE58A6E90567998D380F6FA62068BEECB2F93F1D84B6B59180AA7BA05699D6B1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.19.11.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2136 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2136 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.19.11.120:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6544 | svchost.exe | 20.190.159.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2136 | SIHClient.exe | 4.175.87.197:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
rp.dinipip.com |
| unknown |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
info.dinipip.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
os.dinipip.com |
| unknown |
slscr.update.microsoft.com |
| whitelisted |