| URL: | https://www.dvdvideosoft.com/products/dvd/Free-Video-Flip-and-Rotate.htm |
| Full analysis: | https://app.any.run/tasks/d31cf502-7137-4a1b-92b8-daa762f16f4c |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | June 25, 2020, 07:51:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 7A73290AC10B1056F129EA55C1AD066B |
| SHA1: | 7CF31B52B987394E5205A993E03E48A2F0AA3A70 |
| SHA256: | 0E930C4C1261F026BF97A16E58A3CE01BC819CBCEDC4DD32450683C80A4F0DB7 |
| SSDEEP: | 3:N8DSLbAtNX9aQGRWaTBLAIgteaIKRNLUn:2OLbAtdQRWsxVajLUn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | "C:\Users\admin\Downloads\FreeVideoFlipAndRotate_1.1.35.831_d.exe" | C:\Users\admin\Downloads\FreeVideoFlipAndRotate_1.1.35.831_d.exe | firefox.exe | ||||||||||||
User: admin Company: Digital Wave Ltd Integrity Level: MEDIUM Description: Free Video Flip and Rotate Setup Exit code: 0 Version: 1.1.35.831 Modules
| |||||||||||||||
| 860 | "C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe" | C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe | services.exe | ||||||||||||
User: SYSTEM Company: Digital Wave Ltd. Integrity Level: SYSTEM Description: Digital Wave Update Service Exit code: 0 Version: 1,0,66,315 Modules
| |||||||||||||||
| 1772 | "C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe" --upd | C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe | — | FreeVideoFlipAndRotate_1.1.35.831_d.tmp | |||||||||||
User: admin Company: Digital Wave Ltd Integrity Level: MEDIUM Description: Free Video Flip and Rotate Exit code: 3 Version: 1,1,35,831 Modules
| |||||||||||||||
| 1872 | "C:\Users\admin\AppData\Local\Temp\is-C5FC7.tmp\FreeVideoFlipAndRotate_1.1.35.831_d.tmp" /SL5="$3017A,33139708,240640,C:\Users\admin\Downloads\FreeVideoFlipAndRotate_1.1.35.831_d.exe" /SPAWNWND=$2017C /NOTIFYWND=$4013A | C:\Users\admin\AppData\Local\Temp\is-C5FC7.tmp\FreeVideoFlipAndRotate_1.1.35.831_d.tmp | FreeVideoFlipAndRotate_1.1.35.831_d.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1900 | "C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe" | C:\Program Files\DVDVideoSoft\Free Video Flip and Rotate\FreeVideoFlipAndRotate.exe | — | explorer.exe | |||||||||||
User: admin Company: Digital Wave Ltd Integrity Level: MEDIUM Description: Free Video Flip and Rotate Exit code: 3 Version: 1,1,35,831 Modules
| |||||||||||||||
| 2584 | "C:\Windows\System32\wbem\WMIC.exe" /Namespace:\\root\default Path SystemRestore Call CreateRestorePoint "DVDVideoSoftRestorePoint", 100, 12 | C:\Windows\System32\wbem\WMIC.exe | — | FreeVideoFlipAndRotate_1.1.35.831_d.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2608 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3296 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2776 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3720.0.1283252083\263671489" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3720 "\\.\pipe\gecko-crash-server-pipe.3720" 1128 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2812 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://www.dvdvideosoft.com/products/dvd/Free-Video-Flip-and-Rotate.htm" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2928 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 0E5A750300000000 | |||
| (PID) Process: | (2812) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 0D5A750300000000 | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\p2pcollab.dll,-8042 |
Value: Peer to Peer Trust | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\qagentrt.dll,-10 |
Value: System Health Authentication | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\dnsapi.dll,-103 |
Value: Domain Name System (DNS) Server Trust | |||
| (PID) Process: | (3720) firefox.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\fveui.dll,-843 |
Value: BitLocker Drive Encryption | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3720 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3720 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3720 | firefox.exe | POST | 200 | 172.217.22.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
3720 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3720 | firefox.exe | GET | 200 | 94.31.29.128:80 | http://sc.dvdvideosoft.net/FreeVideoFlipAndRotate_1.1.35.831_d.exe | GB | executable | 32.1 Mb | malicious |
3720 | firefox.exe | POST | 200 | 172.217.22.99:80 | http://ocsp.pki.goog/gts1o1 | US | der | 471 b | whitelisted |
3720 | firefox.exe | POST | 200 | 172.217.22.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
2608 | iexplore.exe | GET | 301 | 104.238.186.214:80 | http://www.dvdvideosoft.com/r/AfterInstall.aspx?ProgramName=FreeVideoFlipAndRotate | GB | html | 206 b | unknown |
3720 | firefox.exe | POST | 200 | 2.16.186.27:80 | http://ocsp.int-x3.letsencrypt.org/ | unknown | der | 527 b | whitelisted |
2608 | iexplore.exe | GET | 200 | 2.16.186.11:80 | http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D | unknown | der | 1.46 Kb | whitelisted |
3720 | firefox.exe | POST | 200 | 172.217.22.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 471 b | whitelisted |
3720 | firefox.exe | POST | 200 | 172.217.22.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3720 | firefox.exe | 2.16.107.40:80 | detectportal.firefox.com | Akamai International B.V. | — | malicious |
3720 | firefox.exe | 52.26.114.88:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
3720 | firefox.exe | 104.238.186.214:443 | www.dvdvideosoft.com | Choopa, LLC | GB | unknown |
3720 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3720 | firefox.exe | 216.58.210.10:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
3720 | firefox.exe | 172.217.22.99:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3720 | firefox.exe | 2.16.186.27:80 | ocsp.int-x3.letsencrypt.org | Akamai International B.V. | — | whitelisted |
3720 | firefox.exe | 2.16.186.49:443 | use.typekit.net | Akamai International B.V. | — | whitelisted |
3720 | firefox.exe | 216.58.212.168:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
3720 | firefox.exe | 172.217.22.106:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
a1089.dscd.akamai.net |
| whitelisted |
www.dvdvideosoft.com |
| unknown |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
tiles.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1048 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
1048 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .cloud TLD |
3720 | firefox.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
app_updater.exe | [dvs.update.service] [08:53:54:728] Main ...
|
app_updater.exe | [dvs.update.service] [08:53:54:728] Start service ...
|
app_updater.exe | [dvs.update.service] [08:53:54:931] Try to start service ...
|
app_updater.exe | [dvs.update.service] [08:53:55:056] [ERROR] [monitor] Failed to get settings (ver ...). Error: 2
|
app_updater.exe | [dvs.update.service] [08:53:55:056] [monitor] Thread was started
|
app_updater.exe | [dvs.update.service] [08:53:55:056] [ERROR] [monitor] Failed to get settings (n...). Error: 2
|
app_updater.exe | [dvs.update.service] [08:53:55:056] [monitor] Try to check version ...
|
app_updater.exe | [dvs.update.service] [08:53:55:165] IPC-server was started. Port: 45777.
|
app_updater.exe | [dvs.update.service] [08:53:55:228] [ERROR] Failed to read the value (auto d...) from registry. Error: 2
|
app_updater.exe | [dvs.update.service] [08:53:55:228] [install.db] [init] Dir: C:\ProgramData\DigitalWave.ApplicationUpdater_files
|