File name:

repairit_setup_full5913.exe

Full analysis: https://app.any.run/tasks/97b73ea7-232e-4586-8128-ece8e5edd916
Verdict: Malicious activity
Analysis date: February 16, 2024, 21:54:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

82CC506825A4848AE5D590EBDAA14BCA

SHA1:

F922D994548B698D3C99EBE6221B7AA730537AAF

SHA256:

FE18AB75CA97E7D5F8989CE592A9E0F85B192ECAFDF4937BE4FE8537BF1A5655

SSDEEP:

98304:fJFfX3z+2Pwwgpzp5suNP4Uv5+/wDMXC7zKmfWOj:IF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • repairit_setup_full5913.exe (PID: 2036)
      • repairit_full5913.exe (PID: 980)
      • repairit_full5913.tmp (PID: 2484)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • repairit_setup_full5913.exe (PID: 2036)
    • Reads the Internet Settings

      • repairit_setup_full5913.exe (PID: 2036)
    • Reads Microsoft Outlook installation path

      • repairit_setup_full5913.exe (PID: 2036)
    • Reads Internet Explorer settings

      • repairit_setup_full5913.exe (PID: 2036)
    • Executable content was dropped or overwritten

      • repairit_setup_full5913.exe (PID: 2036)
      • repairit_full5913.exe (PID: 980)
      • repairit_full5913.tmp (PID: 2484)
    • Likely accesses (executes) a file from the Public directory

      • NFWCHK.exe (PID: 3276)
      • repairit_full5913.exe (PID: 980)
      • repairit_full5913.tmp (PID: 2484)
    • Process requests binary or script from the Internet

      • repairit_setup_full5913.exe (PID: 2036)
    • Connects to unusual port

      • repairit_setup_full5913.exe (PID: 2036)
    • Reads the Windows owner or organization settings

      • repairit_full5913.tmp (PID: 2484)
  • INFO

    • Checks supported languages

      • repairit_setup_full5913.exe (PID: 2036)
      • NFWCHK.exe (PID: 3276)
      • repairit_full5913.exe (PID: 980)
      • repairit_full5913.tmp (PID: 2484)
    • Create files in a temporary directory

      • repairit_setup_full5913.exe (PID: 2036)
      • repairit_full5913.exe (PID: 980)
      • repairit_full5913.tmp (PID: 2484)
    • Reads the machine GUID from the registry

      • repairit_setup_full5913.exe (PID: 2036)
      • NFWCHK.exe (PID: 3276)
    • Reads the computer name

      • repairit_setup_full5913.exe (PID: 2036)
      • NFWCHK.exe (PID: 3276)
    • Checks proxy server information

      • repairit_setup_full5913.exe (PID: 2036)
    • Creates files in the program directory

      • repairit_setup_full5913.exe (PID: 2036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (16.3)
.exe | Win64 Executable (generic) (14.5)
.dll | Win32 Dynamic Link Library (generic) (3.4)
.exe | Win32 Executable (generic) (2.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:13 08:19:46+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 1278976
InitializedDataSize: 700928
UninitializedDataSize: -
EntryPoint: 0x1069f0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 4.0.4.18
ProductVersionNumber: 4.0.4.18
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: wondershare-repairit_setup_full5913.exe
FileVersion: 4.0.4.18
LegalCopyright: Copyright©2023 Wondershare. All rights reserved.
ProductName: Wondershare Repairit
ProductVersion: 5.1.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start repairit_setup_full5913.exe nfwchk.exe no specs repairit_full5913.exe repairit_full5913.tmp repairit_setup_full5913.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
980"C:\Users\Public\Documents\Wondershare\repairit_full5913.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare Repairit.log" /installpath: "C:\Program Files\Wondershare\Wondershare Repairit\" /DIR="C:\Program Files\Wondershare\Wondershare Repairit\" /WAEWIN=F0214 /PID=5913C:\Users\Public\Documents\Wondershare\repairit_full5913.exe
repairit_setup_full5913.exe
User:
admin
Company:
Wondershare Software Co.,Ltd.
Integrity Level:
HIGH
Description:
Wondershare Repairit Setup
Exit code:
0
Version:
5.5.2.4
Modules
Images
c:\users\public\documents\wondershare\repairit_full5913.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2036"C:\Users\admin\AppData\Local\Temp\repairit_setup_full5913.exe" C:\Users\admin\AppData\Local\Temp\repairit_setup_full5913.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
wondershare-repairit_setup_full5913.exe
Exit code:
0
Version:
4.0.4.18
Modules
Images
c:\users\admin\appdata\local\temp\repairit_setup_full5913.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2472"C:\Users\admin\AppData\Local\Temp\repairit_setup_full5913.exe" C:\Users\admin\AppData\Local\Temp\repairit_setup_full5913.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
wondershare-repairit_setup_full5913.exe
Exit code:
3221226540
Version:
4.0.4.18
Modules
Images
c:\users\admin\appdata\local\temp\repairit_setup_full5913.exe
c:\windows\system32\ntdll.dll
2484"C:\Users\admin\AppData\Local\Temp\is-QMQKD.tmp\repairit_full5913.tmp" /SL5="$90292,164707538,386560,C:\Users\Public\Documents\Wondershare\repairit_full5913.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare Repairit.log" /installpath: "C:\Program Files\Wondershare\Wondershare Repairit\" /DIR="C:\Program Files\Wondershare\Wondershare Repairit\" /WAEWIN=F0214 /PID=5913C:\Users\admin\AppData\Local\Temp\is-QMQKD.tmp\repairit_full5913.tmp
repairit_full5913.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qmqkd.tmp\repairit_full5913.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3276C:\Users\Public\Documents\Wondershare\NFWCHK.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exerepairit_setup_full5913.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
.NET Framework Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\public\documents\wondershare\nfwchk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 753
Read events
1 739
Write events
14
Delete events
0

Modification events

(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:5913
Value:
sku-ween
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact
Operation:writeName:ClientSign
Value:
{2d96ec68-99c2-4ca3-b657-66c770e84a5aG}
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF
Operation:writeName:ClientSign
Value:
{2d96ec68-99c2-4ca3-b657-66c770e84a5aG}
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2036) repairit_setup_full5913.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
7
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2036repairit_setup_full5913.exeC:\Users\Public\Documents\Wondershare\repairit_full5913.exe.~P2S
MD5:
SHA256:
2036repairit_setup_full5913.exeC:\Users\Public\Documents\Wondershare\repairit_full5913.exe
MD5:
SHA256:
2036repairit_setup_full5913.exeC:\Users\admin\AppData\Local\Temp\Wondershare\WAE\wsWAE.logtext
MD5:59EB53F1FCBA0CFFF340B6396A577D99
SHA256:EB543A7CF525005EB7A35E40B42824B46436D15382DD5648E43903DB8E8C0E2D
2036repairit_setup_full5913.exeC:\Users\Public\Documents\Wondershare\WAE_DOWNTASK_5913.xmlxml
MD5:C15E9FD55D1ABC9C58726BCF1510494E
SHA256:4805296C89D1249BE3478986F2E8829545D373C97ADE9CA7C1BDCB48540DE140
2036repairit_setup_full5913.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exeexecutable
MD5:27CFB3990872CAA5930FA69D57AEFE7B
SHA256:43881549228975C7506B050BCE4D9B671412D3CDC08C7516C9DBBB7F50C25146
980repairit_full5913.exeC:\Users\admin\AppData\Local\Temp\is-QMQKD.tmp\repairit_full5913.tmpexecutable
MD5:E18E2CFD9573710EE7EA84341396CD17
SHA256:BCFA1343B6BD0176785ECACFEDA0C2EEFD2C391D0F7C21A9C465FDB9F5143F63
2036repairit_setup_full5913.exeC:\Users\admin\AppData\Local\Temp\wsduilib.logtext
MD5:A41CEB30721A7D9936F3F824A7A7C991
SHA256:5B27DF972787DCDD0AD14B0BAE52A1044D2E4E332694BEA9A6DB2021D7A76203
2036repairit_setup_full5913.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe.configxml
MD5:5BABF2A106C883A8E216F768DB99AD51
SHA256:9E676A617EB0D0535AC05A67C0AE0C0E12D4E998AB55AC786A031BFC25E28300
2484repairit_full5913.tmpC:\Users\admin\AppData\Local\Temp\is-29Q33.tmp\WebUtility.dllexecutable
MD5:062A82580214ED2CC2072341C658C1C7
SHA256:13CE758AF0B6476641760B705247A1B747A6E4D431F158E79BFD1A75E28DE4EF
2484repairit_full5913.tmpC:\Users\admin\AppData\Local\Temp\is-29Q33.tmp\UpdateIcon.dllexecutable
MD5:9DA5E5C13C7CDB9D40A6D48DC144F103
SHA256:06BC5482590C17DB6D3A8A2ED284D507ED93E239690E508A44A8AF6C461CD218
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
59
DNS requests
11
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2036
repairit_setup_full5913.exe
GET
206
23.32.238.107:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
text
2 b
unknown
2036
repairit_setup_full5913.exe
GET
206
23.32.238.107:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
binary
26.2 Mb
unknown
2036
repairit_setup_full5913.exe
GET
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
unknown
2036
repairit_setup_full5913.exe
GET
206
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
binary
17.2 Mb
unknown
2036
repairit_setup_full5913.exe
GET
23.32.238.107:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
unknown
2036
repairit_setup_full5913.exe
GET
206
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
binary
17.3 Mb
unknown
2036
repairit_setup_full5913.exe
GET
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
unknown
2036
repairit_setup_full5913.exe
GET
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
unknown
2036
repairit_setup_full5913.exe
GET
2.19.198.58:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
unknown
2036
repairit_setup_full5913.exe
GET
206
23.32.238.107:80
http://download.wondershare.com/cbs_down/repairit_full5913.exe
unknown
binary
996 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2036
repairit_setup_full5913.exe
8.209.72.213:443
pc-api.wondershare.cc
Alibaba US Technology Co., Ltd.
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2036
repairit_setup_full5913.exe
8.209.73.211:80
platform.wondershare.cc
Alibaba US Technology Co., Ltd.
DE
unknown
2036
repairit_setup_full5913.exe
47.91.89.51:443
prod-web.wondershare.cc
Alibaba US Technology Co., Ltd.
DE
unknown
2036
repairit_setup_full5913.exe
2.19.198.58:443
download.wondershare.com
Akamai International B.V.
DE
unknown
2036
repairit_setup_full5913.exe
47.91.90.244:8106
analytics.wondershare.cc
Alibaba US Technology Co., Ltd.
DE
unknown
2036
repairit_setup_full5913.exe
23.32.238.107:443
download.wondershare.com
Akamai International B.V.
DE
unknown
2036
repairit_setup_full5913.exe
2.19.198.58:80
download.wondershare.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
pc-api.wondershare.cc
  • 8.209.72.213
malicious
pc-api.300624.com
  • 8.209.72.213
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
platform.wondershare.cc
  • 8.209.73.211
unknown
prod-web.wondershare.cc
  • 47.91.89.51
unknown
download.wondershare.com
  • 2.19.198.58
  • 23.32.238.107
whitelisted
analytics.wondershare.cc
  • 47.91.90.244
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2036
repairit_setup_full5913.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2036
repairit_setup_full5913.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info