| File name: | uniconverter14_64bit_setup_full14204.exe |
| Full analysis: | https://app.any.run/tasks/af95fee4-add5-43d3-a828-5e1da73bcdf1 |
| Verdict: | Malicious activity |
| Analysis date: | July 05, 2022, 17:08:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0BDEF17675A16595A823E9451BE7A98A |
| SHA1: | 175FA97B1ECF5BD8998D38EAF3AB1727E6398EED |
| SHA256: | 1C6821F58449C0D4DB10B54B1023B01600CCA90599AB3C8D085783CF1FC63F4F |
| SSDEEP: | 49152:UxmSK2OadDPcPrODJppzG9eOB2h/LbmoTgvhhINkNDs747HSM:UDdDPTpzGrB2h/mINkN22 |
| .exe | | | Win64 Executable (generic) (17.3) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (4.1) |
| .exe | | | Win32 Executable (generic) (2.8) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| ProductVersion: | 14.0.0 |
|---|---|
| ProductName: | Wondershare UniConverter 14 for Windows |
| LegalCopyright: | Copyright©2022 Wondershare. All rights reserved. |
| FileVersion: | 3.0.5.6 |
| FileDescription: | wondershare-uniconverter-14-for-windows_setup_full14204.exe |
| CharacterSet: | Unicode |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0017 |
| ProductVersionNumber: | 3.0.5.6 |
| FileVersionNumber: | 3.0.5.6 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0xd621b |
| UninitializedDataSize: | - |
| InitializedDataSize: | 553984 |
| CodeSize: | 1070592 |
| LinkerVersion: | 10 |
| PEType: | PE32 |
| TimeStamp: | 2022:06:29 02:58:04+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 844 | "C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe" | C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Description: wondershare-uniconverter-14-for-windows_setup_full14204.exe Exit code: 0 Version: 3.0.5.6 Modules
| |||||||||||||||
| 2228 | "C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe" | C:\Users\admin\AppData\Local\Temp\uniconverter14_64bit_setup_full14204.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: wondershare-uniconverter-14-for-windows_setup_full14204.exe Exit code: 3221226540 Version: 3.0.5.6 Modules
| |||||||||||||||
| 2280 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\californiatook.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2368 | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | — | uniconverter14_64bit_setup_full14204.exe | |||||||||||
User: admin Company: Wondershare Integrity Level: HIGH Description: .NET Framework Checker Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WafCX |
| Operation: | write | Name: | (default) |
Value: sku-ween | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WafCX |
| Operation: | write | Name: | 14204 |
Value: sku-ween | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact |
| Operation: | write | Name: | ClientSign |
Value: {5c6984ae-6bf1-4982-bc9f-404051c36a72G} | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF |
| Operation: | write | Name: | ClientSign |
Value: {5c6984ae-6bf1-4982-bc9f-404051c36a72G} | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (844) uniconverter14_64bit_setup_full14204.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\Public\Documents\Wondershare\video-converter-ultimate_32bit_full495.exe.~P2S | — | |
MD5:— | SHA256:— | |||
| 2280 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRCFCA.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\admin\AppData\Local\Temp\Wondershare\WAE\wsWAE.log | text | |
MD5:— | SHA256:— | |||
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_86C2A03C133240EC4C95180B9FD368BB | der | |
MD5:— | SHA256:— | |||
| 2280 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:— | SHA256:— | |||
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_86C2A03C133240EC4C95180B9FD368BB | binary | |
MD5:— | SHA256:— | |||
| 2280 | WINWORD.EXE | C:\Users\admin\Desktop\~$liforniatook.rtf | pgc | |
MD5:— | SHA256:— | |||
| 2280 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\californiatook.rtf.LNK | lnk | |
MD5:— | SHA256:— | |||
| 844 | uniconverter14_64bit_setup_full14204.exe | C:\Users\admin\AppData\Local\Temp\wsduilib.log | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
844 | uniconverter14_64bit_setup_full14204.exe | GET | — | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | — | 47.91.67.36:80 | http://platform.wondershare.com/rest/v2/downloader/runtime/?client_sign={5c6984ae-6bf1-4982-bc9f-404051c36a72G}&product_id=14204&wae=3.0.5 | US | — | — | suspicious |
844 | uniconverter14_64bit_setup_full14204.exe | HEAD | 200 | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | HEAD | 200 | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | — | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | — | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | — | 47.246.48.207:80 | http://download.wondershare.com/cbs_down/video-converter-ultimate_32bit_full495.exe | US | — | — | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEAoxT8BiH05nIMdjYufAt2U%3D | US | der | 471 b | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | 200 | 142.251.36.3:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCqm%2FLZVwk%2FcRLv5CtSZANu | US | der | 472 b | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | GET | 200 | 142.251.36.3:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | US | der | 1.41 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
844 | uniconverter14_64bit_setup_full14204.exe | 47.91.67.36:80 | platform.wondershare.com | Alibaba (China) Technology Co., Ltd. | US | suspicious |
844 | uniconverter14_64bit_setup_full14204.exe | 47.246.48.207:80 | download.wondershare.com | — | US | malicious |
— | — | 47.246.48.207:80 | download.wondershare.com | — | US | malicious |
844 | uniconverter14_64bit_setup_full14204.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | 142.250.179.202:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | 142.251.36.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | 142.250.179.163:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
844 | uniconverter14_64bit_setup_full14204.exe | 47.246.48.209:443 | wae.wondershare.cc | — | US | suspicious |
844 | uniconverter14_64bit_setup_full14204.exe | 47.254.152.240:443 | prod-web.wondershare.cc | Alibaba (China) Technology Co., Ltd. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
platform.wondershare.com |
| suspicious |
prod-web.wondershare.cc |
| suspicious |
download.wondershare.com |
| whitelisted |
wae.wondershare.cc |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
844 | uniconverter14_64bit_setup_full14204.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
844 | uniconverter14_64bit_setup_full14204.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
844 | uniconverter14_64bit_setup_full14204.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
844 | uniconverter14_64bit_setup_full14204.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |