File name:

winzip18-lan_en.exe

Full analysis: https://app.any.run/tasks/ba3fbe37-70ee-4ddf-8f35-1cf4b51b2b71
Verdict: Malicious activity
Analysis date: May 12, 2025, 08:52:36
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

29DCC95BA4D7287A1D5E542C9B4A5C28

SHA1:

C44DB75E0A35D8B6ADE5B367C9F6044E9D7992F4

SHA256:

F9CE64AB2B3387876CAD5F5362A20C72076237862E4603F9E6D76D8709DAA1C7

SSDEEP:

24576:kmTEEt9uTjitJDjFFnVEVOt00zZx1kzDnWWnUIJcXj+wDnBEtMz/CNOfMbtJJJD:kmzt9uTjitJDjFFnVMw00zZxkDWWnUOb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Reads security settings of Internet Explorer

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Application launched itself

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Reads Microsoft Outlook installation path

      • winzip18-lan_en.exe (PID: 7520)
    • Reads Internet Explorer settings

      • winzip18-lan_en.exe (PID: 7520)
    • There is functionality for taking screenshot (YARA)

      • winzip18-lan_en.exe (PID: 7520)
  • INFO

    • Checks supported languages

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
    • Process checks whether UAC notifications are on

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Reads the computer name

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
      • winzip18-lan_en.exe (PID: 7760)
    • Create files in a temporary directory

      • winzip18-lan_en.exe (PID: 7384)
      • winzip18-lan_en.exe (PID: 7520)
    • Process checks computer location settings

      • winzip18-lan_en.exe (PID: 7384)
    • Reads the machine GUID from the registry

      • winzip18-lan_en.exe (PID: 7520)
    • Checks proxy server information

      • winzip18-lan_en.exe (PID: 7520)
      • slui.exe (PID: 4224)
    • Creates files in the program directory

      • winzip18-lan_en.exe (PID: 7520)
    • Detects InnoSetup installer (YARA)

      • winzip18-lan_en.exe (PID: 7520)
    • UPX packer has been detected

      • winzip18-lan_en.exe (PID: 7520)
    • Compiled with Borland Delphi (YARA)

      • winzip18-lan_en.exe (PID: 7520)
    • Reads the software policy settings

      • slui.exe (PID: 7720)
      • slui.exe (PID: 4224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (62.3)
.exe | Win32 EXE PECompact compressed (generic) (23.6)
.exe | Win32 Executable Delphi generic (8)
.exe | Win32 Executable (generic) (2.5)
.exe | Win16/32 Executable Delphi generic (1.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 42496
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winzip18-lan_en.exe winzip18-lan_en.exe sppextcomobj.exe no specs slui.exe winzip18-lan_en.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
4224C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7384"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7520"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /RSFC:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe
winzip18-lan_en.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7688C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7760"C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exe" /_ShowProgress /PrTxt:TG9hZGluZy4uLg==C:\Users\admin\AppData\Local\Temp\winzip18-lan_en.exewinzip18-lan_en.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
259
Version:
Modules
Images
c:\users\admin\appdata\local\temp\winzip18-lan_en.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
2 240
Read events
2 235
Write events
3
Delete events
2

Modification events

(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(7520) winzip18-lan_en.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
Executable files
17
Suspicious files
9
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\0010C0F0.logtext
MD5:8ED0C8FB3FBA88F1819D701701C1BDC0
SHA256:6BF932FAF179F04ACE7C2B26B1E0A7D66BAC33EB816B8F57428CCEF7A6E89B0D
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\button.csstext
MD5:37E1FF96E084EC201F0D95FEEF4D5E94
SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\ie6_main.csstext
MD5:2A9D6A4B9B87C780EB5DB7A45D792FC3
SHA256:35530721CE143D19B5886C581FDE2F2B0A2BA629D2E6A9B39C49974719535F19
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\browse.csstext
MD5:6009D6E864F60AEA980A9DF94C1F7E1C
SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\css\sdk-ui\images\button-bg.pngimage
MD5:98B1DE48DFA64DC2AA1E52FACFBEE3B0
SHA256:2693930C474FE640E2FE8D6EF98ABE2ECD303D2392C3D8B2E006E8942BA8F534
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\Close.pngimage
MD5:FDD8888A29583266A1E6ED7EF9AB183E
SHA256:232915906AD3EA666117B4FEA965B6889593DA5EF86A81B108A62EBC7F56F5FE
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\Grey_Button.pngbinary
MD5:7738C15F1D77C96F2AE9AFC030C6CC7D
SHA256:1802739A9AB1222ADED467C3F08954D382DE6AE6F3612EFC1852C479DCC65FDA
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\BG.pngimage
MD5:302122820F433BD5B3071D96E7844812
SHA256:BE58706B90E8B4984E43FB522BB3DAC17EC888F35B039F9C9AD8AEC4B9BD9631
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\Color_Button_Hover.pngimage
MD5:360733265596A19E4BABAAB84FD22381
SHA256:8E1A9A21F3672006D9BD29B41F868A1734A951C7AB55E9A27EC75535CD4456C5
7384winzip18-lan_en.exeC:\Users\admin\AppData\Local\Temp\ish1097984\images\Close_Hover.pngimage
MD5:21D636C05F16CE05904F7400BE17DBB3
SHA256:DE58A6E90567998D380F6FA62068BEECB2F93F1D84B6B59180AA7BA05699D6B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2136
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2136
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2136
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 23.35.229.160
whitelisted
rp.dinipip.com
unknown
login.live.com
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.129
  • 20.190.159.130
  • 40.126.31.0
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
info.dinipip.com
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
os.dinipip.com
unknown
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info