File name:

CyberLink_Promeo_Downloader.exe

Full analysis: https://app.any.run/tasks/e41a5d1b-f9b2-496b-ad95-b86232bea9f9
Verdict: Malicious activity
Analysis date: November 28, 2023, 01:09:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

137C8080F61AEF8DFD7D55EEDC3A31A9

SHA1:

91B288355045696540F087C5668D71D7DB04797D

SHA256:

00614252720F2E145A8F1626E060C076804FA0B4472689A5978EC6B79A6D499A

SSDEEP:

49152:51eti4dhPa8thJM0ErNd1/vwcGncBplLcOUKA3lVBZqx8r9Qlf0dAeQQcu:51eticPa8tArNdibKplQ13lrZqm2lfOh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Steals credentials from Web Browsers

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Checks Windows Trust Settings

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Reads settings of System Certificates

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Reads the Internet Settings

      • CyberLink_Promeo_Downloader.exe (PID: 3176)
      • CyberLink_Promeo_Downloader.exe (PID: 4028)
    • Reads browser cookies

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
  • INFO

    • Checks supported languages

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
      • wmpnscfg.exe (PID: 2584)
    • Reads the computer name

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • wmpnscfg.exe (PID: 2584)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Creates files in the program directory

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
    • Process checks computer location settings

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Creates files or folders in the user directory

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Create files in a temporary directory

      • CyberLink_Promeo_Downloader.exe (PID: 4028)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 2584)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
      • CyberLink_Promeo_Downloader.exe (PID: 4028)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2584)
      • CyberLink_Promeo_Downloader.exe (PID: 3176)
    • Checks proxy server information

      • CyberLink_Promeo_Downloader.exe (PID: 3176)
      • CyberLink_Promeo_Downloader.exe (PID: 4028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:18 18:18:08+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 640000
InitializedDataSize: 520704
UninitializedDataSize: -
EntryPoint: 0x863ba
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.9118
ProductVersionNumber: 3.0.0.9118
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: CyberLink
FileDescription: CyberLink Downloader
FileVersion: 3.0.0.9118
InternalName: CLDownloader
LegalCopyright: Copyright (C) CyberLink Corporation. All rights reserved
OriginalFileName: CLDownloader.exe
ProductName: CLDownloader
ProductVersion: 3.0.0.9118
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cyberlink_promeo_downloader.exe wmpnscfg.exe no specs cyberlink_promeo_downloader.exe cyberlink_promeo_downloader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2584"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2980"C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exe" C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exeexplorer.exe
User:
admin
Company:
CyberLink
Integrity Level:
MEDIUM
Description:
CyberLink Downloader
Exit code:
3221226540
Version:
3.0.0.9118
Modules
Images
c:\users\admin\appdata\local\temp\cyberlink_promeo_downloader.exe
c:\windows\system32\ntdll.dll
3176"C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exe" C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exe
explorer.exe
User:
admin
Company:
CyberLink
Integrity Level:
HIGH
Description:
CyberLink Downloader
Exit code:
0
Version:
3.0.0.9118
Modules
Images
c:\users\admin\appdata\local\temp\cyberlink_promeo_downloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
4028"C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exe" C:\Users\admin\AppData\Local\Temp\CyberLink_Promeo_Downloader.exe
explorer.exe
User:
admin
Company:
CyberLink
Integrity Level:
HIGH
Description:
CyberLink Downloader
Exit code:
0
Version:
3.0.0.9118
Modules
Images
c:\users\admin\appdata\local\temp\cyberlink_promeo_downloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
Total events
12 267
Read events
12 170
Write events
94
Delete events
3

Modification events

(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(4028) CyberLink_Promeo_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
B018B88A9721DA01
Executable files
0
Suspicious files
23
Text files
93
Unknown types
4

Dropped files

PID
Process
Filename
Type
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_D93C575AD9E9AF9B95268A3CB953B5A1der
MD5:781ACFB1E2D42E29956C9FECC649E9CC
SHA256:F4C204514EEC61A4487F015F7708889A2176D7E344CA5A904AC2120438870788
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\9GVNML0L.txttext
MD5:7A7CD63390E9B7E92B75E353917864FE
SHA256:
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9915FBCE5ECE56452A09FB65EDE2FAD2_8F7D75A9886FCC7456204A535FDA93D2binary
MD5:C14BE4C1301E0BD73DC85DDC42D7FA38
SHA256:
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9915FBCE5ECE56452A09FB65EDE2FAD2_8F7D75A9886FCC7456204A535FDA93D2der
MD5:511AF2C325815E170C6A585B69F30BA8
SHA256:
4028CyberLink_Promeo_Downloader.exeC:\ProgramData\CyberLink\CBE\D8D760AC-ACA2-493e-9623-61E9D47DE89C\CyberLink_Promeo_Downloader.exe_v2\UNO.initext
MD5:BE9D6EFBD8632E482C64618F00A701FA
SHA256:D94FD0C7E43DF0A03014A44D79653C0845ADB29E6222CA47718C46AF90847B84
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\U20J14KP.txttext
MD5:E1BE0CE9331C7D5596DE16FF6A8838DE
SHA256:
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\6P7UI6RA.txttext
MD5:61A0B7A261AE3C733AE004C39D0417BC
SHA256:
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\Local\Temp\f56284e7-496e-4658-a580-b059514be574.jsonbinary
MD5:99914B932BD37A50B983C5E7C90AE93B
SHA256:44136FA355B3678A1146AD16F7E8649E94FB4FC21FE77E8310C060F61CAAFF8A
4028CyberLink_Promeo_Downloader.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
72
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4028
CyberLink_Promeo_Downloader.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?69835f913cf8ac2b
unknown
4.66 Kb
unknown
4028
CyberLink_Promeo_Downloader.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f96c9c0907b9ecd4
unknown
4.66 Kb
unknown
4028
CyberLink_Promeo_Downloader.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJaiu8Zb34NbCEEshrmcCs%3D
unknown
471 b
unknown
1080
svchost.exe
GET
200
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?68971ffabf4767b1
unknown
61.6 Kb
unknown
4028
CyberLink_Promeo_Downloader.exe
GET
200
192.229.221.95:80
http://status.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFvn094QJ%2BcWGTwWWEy%2BBXPZkW8AQUo8heZVTlMHjBBeoHCmpZzLn%2B3loCEAnOrRNxqwzZwccRJ7GTMmg%3D
unknown
471 b
unknown
1080
svchost.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8c278ce706dba7cc
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
4028
CyberLink_Promeo_Downloader.exe
54.213.190.95:443
dna.cyberlink.com
AMAZON-02
US
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
4028
CyberLink_Promeo_Downloader.exe
75.2.35.53:443
downloader.cyberlink.com
AMAZON-02
US
unknown
4028
CyberLink_Promeo_Downloader.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4028
CyberLink_Promeo_Downloader.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
1080
svchost.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
4028
CyberLink_Promeo_Downloader.exe
18.66.147.66:443
fcs.cyberlink.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
dna.cyberlink.com
  • 54.213.190.95
  • 34.211.90.44
  • 100.20.177.156
unknown
downloader.cyberlink.com
  • 75.2.35.53
  • 99.83.161.79
unknown
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
status.thawte.com
  • 192.229.221.95
unknown
fcs.cyberlink.com
  • 18.66.147.66
  • 18.66.147.16
  • 18.66.147.28
  • 18.66.147.86
unknown
liveupdate.cyberlink.com
  • 34.210.216.118
  • 35.80.131.217
  • 52.35.51.172
unknown
www.cyberlink.com
  • 75.2.35.53
  • 99.83.161.79
unknown

Threats

No threats detected
No debug info