| URL: | https://www.dvdvideosoft.com/en12 |
| Full analysis: | https://app.any.run/tasks/869b2a0e-6cfd-4e75-8130-5d74cc694103 |
| Verdict: | Malicious activity |
| Analysis date: | February 23, 2024, 22:32:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 7298EB6C69F00319EA5CCD61F3B0077A |
| SHA1: | 8A85ADB706DB8042A6338910C2EE7EB67446FA7A |
| SHA256: | 14886B2B98DE8BD641604EBBBB00AF1974FC4FB27AFF79B40713A87E64255BA7 |
| SSDEEP: | 3:N8DSLbAtNXbX:2OLbAtdbX |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 560 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2196 --field-trial-handle=1220,i,5432873507158686976,8424684925435990707,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3716 --field-trial-handle=1220,i,5432873507158686976,8424684925435990707,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 864 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1240 --field-trial-handle=1384,i,6033955704427968775,13210798877354937087,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 948 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\FreeCodecPack\Haali\mp4.x64.dll" | C:\Windows\System32\regsvr32.exe | — | FreeYouTubeToMP3Converter_4.3.111.220_d_123ec5d1-98eb-4a9d-b6bb-b88a03347cf2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 952 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3164 --field-trial-handle=1220,i,5432873507158686976,8424684925435990707,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 984 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\FreeCodecPack\LAV\LAVSplitter.ax" | C:\Windows\System32\regsvr32.exe | — | FreeYouTubeToMP3Converter_4.3.111.220_d_123ec5d1-98eb-4a9d-b6bb-b88a03347cf2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1036 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\FreeCodecPack\Haali\mkx.dll" | C:\Windows\System32\regsvr32.exe | — | FreeYouTubeToMP3Converter_4.3.111.220_d_123ec5d1-98eb-4a9d-b6bb-b88a03347cf2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1112 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4084 --field-trial-handle=1220,i,5432873507158686976,8424684925435990707,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1168 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1572 --field-trial-handle=1384,i,6033955704427968775,13210798877354937087,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1592 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\FreeCodecPack\Haali\mp4.dll" | C:\Windows\System32\regsvr32.exe | — | FreeYouTubeToMP3Converter_4.3.111.220_d_123ec5d1-98eb-4a9d-b6bb-b88a03347cf2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 649300176 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31090344 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 949307676 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31090344 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (4052) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:21E8D51E0ED1F40CE18536FD5FAD9075 | SHA256:9FE61C538B918F8E6B2B3A52EAA35C3C25476C45CA067C0956244B76DE93059B | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\dvsa.ajax.min[1].js | text | |
MD5:FCB989C28C8B174424B50086D9BD8D86 | SHA256:0A1B91A01B54B2F6A3161DD99500A763DB0F745F0078D1F9B13EAEB1892722E9 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\F3UCA0S0.txt | text | |
MD5:4D05E9F1DFAA82955AC1731F5C961277 | SHA256:FDBE658A828A3C5E553CED637CD2FC92D81990F3BB1B327DBEC6E6748672BED3 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\BHEU5Y8V.txt | text | |
MD5:09966F32DEFDE2F6F3826627C7CC2909 | SHA256:B6A8FE1A7F04C2B257ADAC13F8EB3A493C875CB44A6E67889A163A8792C5592B | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419 | binary | |
MD5:70218B6CD0C7B23791EC56E58402970C | SHA256:D4BC35391236A58FE1F7DDAEE73BE15FAAF5AE64D025CACE2C7969F1A6F08018 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\en12[1].htm | html | |
MD5:E7498AC0ABBF8A3E505FCEBC242A8074 | SHA256:AECE402EEE4453410AF6443F068EB66CA9AF339AC324F1372FF7BC123B6484E9 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\cookie.min[1].js | text | |
MD5:A28A5FD122837C21202BEE2DC4E3018D | SHA256:40D51DE0A14F532D8ADA085D22DBCC03127E648B12C8B0370D625E9E768E27C7 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\375RQGMT.txt | text | |
MD5:0B091503C28F87AFD9B37B4F82BD064E | SHA256:77766A1880E2D699EADE54B1F5D055EF46871F3FB17474CD67926EE4C8D51BAA | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:FDCFF398251420342FC59F4D3D94B8F6 | SHA256:D0228439A5E986865FF8BC23487E92C15985F8BE66E0D73C40F9727C97155FE5 | |||
| 2920 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\Free_YouTube_Download_2021_small[1].png | image | |
MD5:65A8CA4A90E5B6C0FB5286641AC1A9C2 | SHA256:B7886BBE4407BED905268D02DFD9CED827A9C6F1080625C7D073A0A9F3F493A6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2920 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6 | unknown | — | — | unknown |
2920 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f78d505714a595e3 | unknown | — | — | unknown |
2920 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | binary | 471 b | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.179.163:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.179.163:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
2920 | iexplore.exe | GET | 200 | 142.250.179.163:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEH1ZfRmkcbmIEJt1GKpWSOU%3D | unknown | binary | 471 b | unknown |
4052 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?719f0b64dcb4a601 | unknown | — | — | unknown |
4052 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2c922bd02ca2cb72 | unknown | — | — | unknown |
4052 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b0be6f4ad90be2e5 | unknown | — | — | unknown |
4052 | iexplore.exe | GET | 304 | 84.53.175.122:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6fdaa9f1391a781b | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2920 | iexplore.exe | 95.179.240.76:443 | www.dvdvideosoft.com | AS-CHOOPA | DE | unknown |
2920 | iexplore.exe | 84.53.175.122:80 | ctldl.windowsupdate.com | Akamai International B.V. | NL | whitelisted |
2920 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2920 | iexplore.exe | 142.250.179.200:443 | www.googletagmanager.com | GOOGLE | US | unknown |
2920 | iexplore.exe | 142.250.179.163:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
4052 | iexplore.exe | 95.179.240.76:443 | www.dvdvideosoft.com | AS-CHOOPA | DE | unknown |
4052 | iexplore.exe | 2.22.54.105:443 | www.bing.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
www.dvdvideosoft.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
cdnsrc.dvdvideosoft.com |
| unknown |
x1.c.lencr.org |
| whitelisted |
Process | Message |
|---|---|
vidnotifier.exe | Timeout in secs: 1800
|
FreeYouTubeToMP3Converter.exe | QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
|
FreeYouTubeToMP3Converter.exe | QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available
|
FreeYouTubeToMP3Converter.exe | Failed to load opengl32sw.dll (The specified module could not be found.)
|
FreeYouTubeToMP3Converter.exe | Failed to load and resolve WGL/OpenGL functions
|
FreeYouTubeToMP3Converter.exe | libpng warning: iCCP: known incorrect sRGB profile
|
FreeYouTubeToMP3Converter.exe | libpng warning: iCCP: cHRM chunk does not match sRGB
|
FreeYouTubeToMP3Converter.exe | libpng warning: iCCP: known incorrect sRGB profile
|
FreeYouTubeToMP3Converter.exe | libpng warning: iCCP: cHRM chunk does not match sRGB
|
FreeYouTubeToMP3Converter.exe | libpng warning: iCCP: known incorrect sRGB profile
|