File name:

uniconverter14_64bit_setup_full14204.exe

Full analysis: https://app.any.run/tasks/af95fee4-add5-43d3-a828-5e1da73bcdf1
Verdict: Malicious activity
Analysis date: July 05, 2022, 17:08:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0BDEF17675A16595A823E9451BE7A98A

SHA1:

175FA97B1ECF5BD8998D38EAF3AB1727E6398EED

SHA256:

1C6821F58449C0D4DB10B54B1023B01600CCA90599AB3C8D085783CF1FC63F4F

SSDEEP:

49152:UxmSK2OadDPcPrODJppzG9eOB2h/LbmoTgvhhINkNDs747HSM:UDdDPTpzGrB2h/mINkN22

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • NFWCHK.exe (PID: 2368)
    • Drops executable file immediately after starts

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Changes settings of System certificates

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Checks supported languages

      • NFWCHK.exe (PID: 2368)
      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Reads Microsoft Outlook installation path

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Drops a file with a compile date too recent

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Reads the computer name

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
      • NFWCHK.exe (PID: 2368)
    • Reads internet explorer settings

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Adds / modifies Windows certificates

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
  • INFO

    • Checks supported languages

      • WINWORD.EXE (PID: 2280)
    • Checks Windows Trust Settings

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Reads the computer name

      • WINWORD.EXE (PID: 2280)
    • Reads settings of System Certificates

      • uniconverter14_64bit_setup_full14204.exe (PID: 844)
    • Manual execution by user

      • WINWORD.EXE (PID: 2280)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2280)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (17.3)
.dll | Win32 Dynamic Link Library (generic) (4.1)
.exe | Win32 Executable (generic) (2.8)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

ProductVersion: 14.0.0
ProductName: Wondershare UniConverter 14 for Windows
LegalCopyright: Copyright©2022 Wondershare. All rights reserved.
FileVersion: 3.0.5.6
FileDescription: wondershare-uniconverter-14-for-windows_setup_full14204.exe
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x0017
ProductVersionNumber: 3.0.5.6
FileVersionNumber: 3.0.5.6
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0xd621b
UninitializedDataSize: -
InitializedDataSize: 553984
CodeSize: 1070592
LinkerVersion: 10
PEType: PE32
TimeStamp: 2022:06:29 02:58:04+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start uniconverter14_64bit_setup_full14204.exe nfwchk.exe no specs winword.exe no specs uniconverter14_64bit_setup_full14204.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844"C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe" C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
wondershare-uniconverter-14-for-windows_setup_full14204.exe
Exit code:
0
Version:
3.0.5.6
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\uniconverter14_64bit_setup_full14204.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2228"C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe" C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
wondershare-uniconverter-14-for-windows_setup_full14204.exe
Exit code:
3221226540
Version:
3.0.5.6
Modules
Images
c:\users\admin\appdata\local\temp\uniconverter14_64bit_setup_full14204.exe
c:\windows\system32\ntdll.dll
2280"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\californiatook.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\gdi32.dll
2368C:\Users\Public\Documents\Wondershare\NFWCHK.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exeuniconverter14_64bit_setup_full14204.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
.NET Framework Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\public\documents\wondershare\nfwchk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
9 713
Read events
9 324
Write events
245
Delete events
144

Modification events

(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:(default)
Value:
sku-ween
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:14204
Value:
sku-ween
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact
Operation:writeName:ClientSign
Value:
{5c6984ae-6bf1-4982-bc9f-404051c36a72G}
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF
Operation:writeName:ClientSign
Value:
{5c6984ae-6bf1-4982-bc9f-404051c36a72G}
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(844) uniconverter14_64bit_setup_full14204.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
1
Suspicious files
9
Text files
15
Unknown types
13

Dropped files

PID
Process
Filename
Type
844uniconverter14_64bit_setup_full14204.exeC:\Users\Public\Documents\Wondershare\video-converter-ultimate_32bit_full495.exe.~P2S
MD5:
SHA256:
2280WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRCFCA.tmp.cvr
MD5:
SHA256:
844uniconverter14_64bit_setup_full14204.exeC:\Users\admin\AppData\Local\Temp\Wondershare\WAE\wsWAE.logtext
MD5:
SHA256:
844uniconverter14_64bit_setup_full14204.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
844uniconverter14_64bit_setup_full14204.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_86C2A03C133240EC4C95180B9FD368BBder
MD5:
SHA256:
2280WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:
SHA256:
844uniconverter14_64bit_setup_full14204.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_86C2A03C133240EC4C95180B9FD368BBbinary
MD5:
SHA256:
2280WINWORD.EXEC:\Users\admin\Desktop\~$liforniatook.rtfpgc
MD5:
SHA256:
2280WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\californiatook.rtf.LNKlnk
MD5:
SHA256:
844uniconverter14_64bit_setup_full14204.exeC:\Users\admin\AppData\Local\Temp\wsduilib.logtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
24
DNS requests
12
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
844
uniconverter14_64bit_setup_full14204.exe
GET
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
47.91.67.36:80
http://platform.wondershare.com/rest/v2/downloader/runtime/?client_sign={5c6984ae-6bf1-4982-bc9f-404051c36a72G}&product_id=14204&wae=3.0.5
US
suspicious
844
uniconverter14_64bit_setup_full14204.exe
HEAD
200
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
HEAD
200
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
47.246.48.207:80
http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEAoxT8BiH05nIMdjYufAt2U%3D
US
der
471 b
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
200
142.251.36.3:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCqm%2FLZVwk%2FcRLv5CtSZANu
US
der
472 b
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
GET
200
142.251.36.3:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
844
uniconverter14_64bit_setup_full14204.exe
47.91.67.36:80
platform.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
844
uniconverter14_64bit_setup_full14204.exe
47.246.48.207:80
download.wondershare.com
US
malicious
47.246.48.207:80
download.wondershare.com
US
malicious
844
uniconverter14_64bit_setup_full14204.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
142.250.179.202:443
fonts.googleapis.com
Google Inc.
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
142.251.36.3:80
ocsp.pki.goog
Google Inc.
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
142.250.179.163:443
fonts.gstatic.com
Google Inc.
US
whitelisted
844
uniconverter14_64bit_setup_full14204.exe
47.246.48.209:443
wae.wondershare.cc
US
suspicious
844
uniconverter14_64bit_setup_full14204.exe
47.254.152.240:443
prod-web.wondershare.cc
Alibaba (China) Technology Co., Ltd.
US
suspicious

DNS requests

Domain
IP
Reputation
platform.wondershare.com
  • 47.91.67.36
suspicious
prod-web.wondershare.cc
  • 47.254.152.240
suspicious
download.wondershare.com
  • 47.246.48.207
whitelisted
wae.wondershare.cc
  • 47.246.48.209
malicious
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
fonts.googleapis.com
  • 142.250.179.202
whitelisted
ocsp.pki.goog
  • 142.251.36.3
whitelisted
fonts.gstatic.com
  • 142.250.179.163
whitelisted

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query for .cc TLD
844
uniconverter14_64bit_setup_full14204.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
844
uniconverter14_64bit_setup_full14204.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
844
uniconverter14_64bit_setup_full14204.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
844
uniconverter14_64bit_setup_full14204.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
Potentially Bad Traffic
ET DNS Query for .cc TLD
Potentially Bad Traffic
ET DNS Query for .cc TLD
2 ETPRO signatures available at the full report
No debug info