analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

FreemakeVideoConverterSetup.exe.zip

Full analysis: https://app.any.run/tasks/03beae7d-2aa6-4c1d-b674-0479dafb1412
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 23, 2019, 16:23:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

36586512B042B22C35B5592E06665D8A

SHA1:

11679567EE8A749ECA3E59251C2B3E9C049B4009

SHA256:

1EFBB7864E6D023713DA4A12307737930E41823F45A855EDC1F104DEB49D987F

SSDEEP:

12288:dQhOpmmH/X3juZwvwoMD4gXhePTM6j/BmjXxzzg3m19ADHcE1mcE7ZuDLGatNf4:bbH/5w+0hePT7Mh435DHhq7ZAJh4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FreemakeVideoConverterSetup.exe (PID: 2560)
      • FreemakeVideoConverterSetup.exe (PID: 2072)
      • FileAssociationTool.exe (PID: 3984)
      • FreemakeUtilsService.exe (PID: 2376)
      • FreemakeVC.exe (PID: 1032)
      • FreemakeVideoConverter.exe (PID: 592)
      • ProductUpdater.exe (PID: 3380)
    • Downloads executable files from the Internet

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
    • Starts NET.EXE for service management

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Changes the autorun value in the registry

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Registers / Runs the DLL via REGSVR32.EXE

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 3232)
      • regsvr32.exe (PID: 2852)
      • regsvr32.exe (PID: 2664)
      • regsvr32.exe (PID: 2576)
      • regsvr32.exe (PID: 1360)
      • regsvr32.exe (PID: 344)
      • regsvr32.exe (PID: 1880)
      • FileAssociationTool.exe (PID: 3984)
      • ProductUpdater.exe (PID: 3380)
      • FreemakeVC.exe (PID: 1032)
      • FreemakeUtilsService.exe (PID: 2376)
    • Changes settings of System certificates

      • ProductUpdater.exe (PID: 3380)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3924)
      • FreemakeVideoConverterSetup.exe (PID: 2072)
      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterSetup.exe (PID: 2560)
      • FreemakeVideoConverterFull.exe.exe (PID: 3408)
      • FreemakeVideoConverterFull.exe.exe (PID: 2780)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Reads Windows owner or organization settings

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Reads the Windows organization settings

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Uses RUNDLL32.EXE to load library

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
    • Reads Internet Cache Settings

      • rundll32.exe (PID: 2500)
    • Creates files in the user directory

      • rundll32.exe (PID: 2500)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Uses NETSH.EXE for network configuration

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1808)
    • Uses TASKLIST.EXE to query information about running processes

      • cmd.exe (PID: 1732)
      • cmd.exe (PID: 1692)
      • cmd.exe (PID: 3044)
      • cmd.exe (PID: 124)
      • cmd.exe (PID: 320)
      • cmd.exe (PID: 3216)
    • Starts CMD.EXE for commands execution

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 2576)
      • regsvr32.exe (PID: 2852)
      • regsvr32.exe (PID: 1360)
      • regsvr32.exe (PID: 344)
      • regsvr32.exe (PID: 3232)
      • regsvr32.exe (PID: 2664)
      • regsvr32.exe (PID: 1880)
    • Starts SC.EXE for service management

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Reads Environment values

      • ProductUpdater.exe (PID: 3380)
      • FreemakeVC.exe (PID: 1032)
    • Creates files in the program directory

      • FreemakeVC.exe (PID: 1032)
      • ProductUpdater.exe (PID: 3380)
    • Modifies the open verb of a shell class

      • FileAssociationTool.exe (PID: 3984)
    • Adds / modifies Windows certificates

      • ProductUpdater.exe (PID: 3380)
    • Searches for installed software

      • FreemakeVC.exe (PID: 1032)
  • INFO

    • Application was dropped or rewritten from another process

      • FreemakeVideoConverterSetup.tmp (PID: 284)
      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterFull.exe.tmp (PID: 2140)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
      • MigrationTool.exe (PID: 1220)
    • Loads dropped or rewritten executable

      • FreemakeVideoConverterSetup.tmp (PID: 2056)
      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Dropped object may contain Bitcoin addresses

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Creates a software uninstall entry

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Application launched itself

      • chrome.exe (PID: 3264)
    • Creates files in the program directory

      • FreemakeVideoConverterFull.exe.tmp (PID: 3680)
    • Reads settings of System Certificates

      • ProductUpdater.exe (PID: 3380)
      • chrome.exe (PID: 3264)
    • Adds / modifies Windows certificates

      • chrome.exe (PID: 3264)
    • Changes settings of System certificates

      • chrome.exe (PID: 3264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: FreemakeVideoConverterSetup.exe
ZipUncompressedSize: 1011632
ZipCompressedSize: 676828
ZipCRC: 0x408bf6ac
ZipModifyDate: 2019:04:23 15:52:20
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
124
Monitored processes
67
Malicious processes
20
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe freemakevideoconvertersetup.exe freemakevideoconvertersetup.tmp no specs freemakevideoconvertersetup.exe freemakevideoconvertersetup.tmp rundll32.exe no specs freemakevideoconverterfull.exe.exe netsh.exe no specs freemakevideoconverterfull.exe.tmp no specs netsh.exe no specs freemakevideoconverterfull.exe.exe freemakevideoconverterfull.exe.tmp net.exe no specs cmd.exe no specs net1.exe no specs taskkill.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs migrationtool.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs netsh.exe no specs netsh.exe no specs fileassociationtool.exe no specs freemakevideoconverter.exe no specs freemakevc.exe sc.exe no specs sc.exe no specs net.exe no specs chrome.exe productupdater.exe net1.exe no specs chrome.exe no specs freemakeutilsservice.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3924"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterSetup.exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2072"C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe
WinRAR.exe
User:
admin
Company:
Mixbyte Inc.
Integrity Level:
MEDIUM
Description:
Freemake Video Converter Setup
Exit code:
0
Version:
4.1.10.215
284"C:\Users\admin\AppData\Local\Temp\is-I1964.tmp\FreemakeVideoConverterSetup.tmp" /SL5="$5013E,492641,402432,C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe" C:\Users\admin\AppData\Local\Temp\is-I1964.tmp\FreemakeVideoConverterSetup.tmpFreemakeVideoConverterSetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
2560"C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe" /SPAWNWND=$40154 /NOTIFYWND=$5013E C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe
FreemakeVideoConverterSetup.tmp
User:
admin
Company:
Mixbyte Inc.
Integrity Level:
HIGH
Description:
Freemake Video Converter Setup
Exit code:
0
Version:
4.1.10.215
2056"C:\Users\admin\AppData\Local\Temp\is-51Q91.tmp\FreemakeVideoConverterSetup.tmp" /SL5="$70108,492641,402432,C:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exe" /SPAWNWND=$40154 /NOTIFYWND=$5013E C:\Users\admin\AppData\Local\Temp\is-51Q91.tmp\FreemakeVideoConverterSetup.tmp
FreemakeVideoConverterSetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
2500"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\wininet.dll",DispatchAPICall 1 C:\Windows\system32\rundll32.exeFreemakeVideoConverterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3408"C:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe.exe" /LANG=es /dotnet=0 /skip_welcome /SourcedBrowser=Chrome /noBrowserExperiment locale=es /DIR="C:\Program Files\Freemake" /autoinstall C:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe.exe
FreemakeVideoConverterSetup.tmp
User:
admin
Company:
Mixbyte Inc.
Integrity Level:
MEDIUM
Description:
Freemake Video Converter
Exit code:
0
Version:
4.1.10.215
2700"C:\Windows\system32\netsh.exe" http add urlacl url=http://+:11425/ user=adminC:\Windows\system32\netsh.exeFreemakeVideoConverterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2140"C:\Users\admin\AppData\Local\Temp\is-MNIJ4.tmp\FreemakeVideoConverterFull.exe.tmp" /SL5="$201C8,39494177,402432,C:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe.exe" /LANG=es /dotnet=0 /skip_welcome /SourcedBrowser=Chrome /noBrowserExperiment locale=es /DIR="C:\Program Files\Freemake" /autoinstall C:\Users\admin\AppData\Local\Temp\is-MNIJ4.tmp\FreemakeVideoConverterFull.exe.tmpFreemakeVideoConverterFull.exe.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
2496"C:\Windows\system32\netsh.exe" http add urlacl url=http://+:11425/ user=\everyoneC:\Windows\system32\netsh.exeFreemakeVideoConverterSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
4 537
Read events
1 923
Write events
0
Delete events
0

Modification events

No data
Executable files
378
Suspicious files
11
Text files
546
Unknown types
12

Dropped files

PID
Process
Filename
Type
2056FreemakeVideoConverterSetup.tmpC:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe
MD5:
SHA256:
2056FreemakeVideoConverterSetup.tmpC:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe.exe
MD5:
SHA256:
3924WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3924.16127\FreemakeVideoConverterSetup.exeexecutable
MD5:0982F93A01C95F901B01F53A227E668E
SHA256:D8AB9D108ADC60F7F25ADB2A86A1D09B0527D574AEA9B22574DAD51629174156
2500rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
2056FreemakeVideoConverterSetup.tmpC:\Users\admin\AppData\Local\Temp\Setup Log 2019-04-23 #001.txttext
MD5:57BFD82473A31F70B6E82F330180E8EF
SHA256:05D46BB78823F15004DED9F7758F74B6A27F0D588C0B202130B06EB110CF007E
2500rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:53E8AE80130BD646A76F9135A1A13DC9
SHA256:E614E315AA2A54A8E4343A8CA7C8DA91E1047A2466D24B80CBF12AC3DA55B2F5
2056FreemakeVideoConverterSetup.tmpC:\Users\admin\AppData\Local\Temp\is-7C0FD.tmp\freemake_dl.dllexecutable
MD5:93F94CE569B83795C7D6D7A61C00A00C
SHA256:2053C493B3ADABFB5E213B98C126B5BDD9508B175194324823B1A46CE4F79B3D
2500rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKZVGOQA\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
2056FreemakeVideoConverterSetup.tmpC:\Users\admin\AppData\Local\Temp\~DF6483780CB7C147B8.TMP
MD5:
SHA256:
2500rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\04B55FJX\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
52
DNS requests
35
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3680
FreemakeVideoConverterFull.exe.tmp
GET
34.192.103.139:80
http://geoip.freemake.com/geoip.php
US
suspicious
2056
FreemakeVideoConverterSetup.tmp
GET
200
34.192.103.139:80
http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoConverter&language=es&version=4.1.10.215[GT]&exit_step=FINISH_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=0&statistics=1&country=es&guid={FC72FA24-6AF7-47F9-91D4-B226B94A0955}&errorcode=0&adv=0
US
suspicious
3680
FreemakeVideoConverterFull.exe.tmp
GET
200
34.192.103.139:80
http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoConverter&language=es&version=4.1.10.215[GT]&exit_step=FINISH&is_net_before=&is_net_after=&install_type=Full&is_toolbar_checked=&statistics=1&country=ES&guid={FC72FA24-6AF7-47F9-91D4-B226B94A0955}&errorcode=0&adv=
US
suspicious
2056
FreemakeVideoConverterSetup.tmp
GET
200
34.192.103.139:80
http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoConverter&language=es&version=4.1.10.215[GT]&exit_step=START_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=0&statistics=1&country=es&guid={FC72FA24-6AF7-47F9-91D4-B226B94A0955}&errorcode=0&adv=0
US
suspicious
2056
FreemakeVideoConverterSetup.tmp
GET
200
34.192.103.139:80
http://geoip.freemake.com/geoip.php
US
suspicious
2056
FreemakeVideoConverterSetup.tmp
HEAD
200
94.31.29.3:80
http://download.freemake.net/products/DF585285843F5DFE5F917B9DF101E5E0/FreemakeVideoConverterFull.exe
GB
whitelisted
1032
FreemakeVC.exe
GET
200
34.192.103.139:80
http://appsettings.freemake.com/fvc/analytics.php
US
text
123 b
suspicious
1032
FreemakeVC.exe
GET
200
34.192.103.139:80
http://fvc-statistics.freemake.com/configs/user.config
US
text
131 b
suspicious
2056
FreemakeVideoConverterSetup.tmp
GET
200
94.31.29.3:80
http://download.freemake.net/products/DF585285843F5DFE5F917B9DF101E5E0/FreemakeVideoConverterFull.exe
GB
executable
38.1 Mb
whitelisted
1032
FreemakeVC.exe
GET
200
34.192.103.139:80
http://geoip.freemake.com/geoip_detailed.php
US
text
36 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3264
chrome.exe
216.58.210.4:443
www.google.com
Google Inc.
US
whitelisted
3264
chrome.exe
216.58.206.8:443
ssl.google-analytics.com
Google Inc.
US
whitelisted
2056
FreemakeVideoConverterSetup.tmp
52.3.211.135:80
releases.freemake.com
Amazon.com, Inc.
US
unknown
3680
FreemakeVideoConverterFull.exe.tmp
34.192.103.139:80
geoip.freemake.com
Amazon.com, Inc.
US
suspicious
1032
FreemakeVC.exe
34.192.103.139:443
geoip.freemake.com
Amazon.com, Inc.
US
suspicious
3264
chrome.exe
172.217.21.205:443
accounts.google.com
Google Inc.
US
whitelisted
2056
FreemakeVideoConverterSetup.tmp
94.31.29.3:80
download.freemake.net
netDNA
GB
malicious
2056
FreemakeVideoConverterSetup.tmp
34.192.103.139:80
geoip.freemake.com
Amazon.com, Inc.
US
suspicious
3264
chrome.exe
93.184.220.66:443
platform.twitter.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3264
chrome.exe
94.31.29.9:443
www.freemake.com
netDNA
GB
malicious

DNS requests

Domain
IP
Reputation
geoip.freemake.com
  • 34.192.103.139
unknown
installreport.freemake.com
  • 34.192.103.139
suspicious
releases.freemake.com
  • 52.3.211.135
  • 52.71.107.147
unknown
download.freemake.net
  • 94.31.29.3
whitelisted
users.freemake.com
  • 52.71.107.147
  • 52.3.211.135
unknown
clientservices.googleapis.com
  • 216.58.207.67
whitelisted
www.freemake.com
  • 94.31.29.9
unknown
accounts.google.com
  • 172.217.21.205
shared
fvc-statistics.freemake.com
  • 34.192.103.139
suspicious
appsettings.freemake.com
  • 34.192.103.139
suspicious

Threats

PID
Process
Class
Message
2056
FreemakeVideoConverterSetup.tmp
Misc activity
ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent
2056
FreemakeVideoConverterSetup.tmp
Misc activity
ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent
2056
FreemakeVideoConverterSetup.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2056
FreemakeVideoConverterSetup.tmp
Misc activity
ET INFO EXE - Served Attached HTTP
2056
FreemakeVideoConverterSetup.tmp
Generic Protocol Command Decode
SURICATA STREAM excessive retransmissions
No debug info