File name:

EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC].zip_

Full analysis: https://app.any.run/tasks/84b1a09c-e783-4692-9445-af4eba11b371
Verdict: Malicious activity
Analysis date: November 02, 2023, 15:17:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

475C989840C1690C3080C8A1B272D9BB

SHA1:

865B5322CAD1FDA923D3CB1D7725B3162E0A2E6E

SHA256:

261B6813FEB72410EDE16BDB7BBF17EE45D58A3EC3FFC618B8EB6D72403099DF

SSDEEP:

196608:8buu3lFfwxxoMVv4/OVszYZMrPoS9vUYh23:8bfuxJVvmOV6YZSPoSB+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • drw_trial.exe (PID: 1660)
      • drw_trial.tmp (PID: 1356)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • drw_trial.tmp (PID: 1356)
    • Process drops legitimate windows executable

      • drw_trial.tmp (PID: 1356)
    • Reads the Internet Settings

      • drw_trial.tmp (PID: 1356)
      • DRWUI.exe (PID: 3468)
    • The process drops C-runtime libraries

      • drw_trial.tmp (PID: 1356)
    • Checks Windows Trust Settings

      • DRWUI.exe (PID: 3468)
    • Reads security settings of Internet Explorer

      • DRWUI.exe (PID: 3468)
    • Reads settings of System Certificates

      • DRWUI.exe (PID: 3468)
  • INFO

    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3428)
      • wmpnscfg.exe (PID: 3432)
      • DRWUI.exe (PID: 3468)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3428)
      • drw_trial.tmp (PID: 1356)
      • wmpnscfg.exe (PID: 3432)
      • DRWUI.exe (PID: 3468)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3428)
      • drw_trial.exe (PID: 1660)
      • drw_trial.tmp (PID: 1356)
      • wmpnscfg.exe (PID: 3432)
      • DRW.exe (PID: 3504)
      • DRWUI.exe (PID: 3468)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3496)
    • Manual execution by a user

      • drw_trial.exe (PID: 1660)
      • notepad.exe (PID: 916)
      • drw_trial.exe (PID: 1760)
      • msedge.exe (PID: 3816)
      • wmpnscfg.exe (PID: 3432)
    • Create files in a temporary directory

      • drw_trial.exe (PID: 1660)
      • drw_trial.tmp (PID: 1356)
      • DRWUI.exe (PID: 3468)
    • Creates files in the program directory

      • drw_trial.tmp (PID: 1356)
      • DRW.exe (PID: 3504)
      • DRWUI.exe (PID: 3468)
    • Reads Environment values

      • drw_trial.tmp (PID: 1356)
    • Reads product name

      • drw_trial.tmp (PID: 1356)
    • Creates files or folders in the user directory

      • DRWUI.exe (PID: 3468)
    • Checks proxy server information

      • DRWUI.exe (PID: 3468)
    • Application launched itself

      • msedge.exe (PID: 2336)
      • msedge.exe (PID: 3816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2016:05:07 06:17:38
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
80
Monitored processes
35
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs notepad.exe no specs drw_trial.exe no specs drw_trial.exe drw_trial.tmp msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs drw.exe no specs drwui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
788"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3784 --field-trial-handle=1232,i,13012188020154554902,14310800165523951185,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
908"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3936 --field-trial-handle=1232,i,13012188020154554902,14310800165523951185,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
916"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\Instructions Important !!!.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1356"C:\Users\admin\AppData\Local\Temp\is-THJTF.tmp\drw_trial.tmp" /SL5="$C016E,15032751,546816,C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exe" C:\Users\admin\AppData\Local\Temp\is-THJTF.tmp\drw_trial.tmp
drw_trial.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-thjtf.tmp\drw_trial.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1436"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3960 --field-trial-handle=1232,i,13012188020154554902,14310800165523951185,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exe" C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exe
explorer.exe
User:
admin
Company:
EaseUS
Integrity Level:
HIGH
Description:
EaseUS Data Recovery Wizard Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\easeus data recovery wizard technician 10.2.0 + keygen [sadeempc]\drw_trial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1760"C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exe" C:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exeexplorer.exe
User:
admin
Company:
EaseUS
Integrity Level:
MEDIUM
Description:
EaseUS Data Recovery Wizard Setup
Exit code:
3221226540
Version:
Modules
Images
c:\users\admin\desktop\easeus data recovery wizard technician 10.2.0 + keygen [sadeempc]\drw_trial.exe
c:\windows\system32\ntdll.dll
1760"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3960 --field-trial-handle=1232,i,13012188020154554902,14310800165523951185,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6b3ef598,0x6b3ef5a8,0x6b3ef5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1280 --field-trial-handle=1304,i,4970991793702394869,16392631602837651690,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 660
Read events
10 553
Write events
94
Delete events
13

Modification events

(PID) Process:(3428) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D765F926-B10B-4535-A09E-4A0BBE9CEFB4}\{857FCC3A-0138-40AB-8F87-FDA324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3428) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D765F926-B10B-4535-A09E-4A0BBE9CEFB4}
Operation:delete keyName:(default)
Value:
(PID) Process:(3428) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{CF6B7DA6-DD6D-4944-A393-9639369FCADE}
Operation:delete keyName:(default)
Value:
(PID) Process:(3496) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3496) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
73
Suspicious files
129
Text files
261
Unknown types
0

Dropped files

PID
Process
Filename
Type
3496WinRAR.exeC:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\Keygen\offline.cmdtext
MD5:AF2BB7F7964824CDF443003F92706CAF
SHA256:D1657193CB0AE89B381B7F76CA6CA84D66E9EA62A99394DE2C6B3CA96FD8F68C
1356drw_trial.tmpC:\Users\admin\AppData\Local\Temp\is-5Q614.tmp\BrowseWarning.bmpimage
MD5:391C6EBB2E18F854160F892C413EFE31
SHA256:636B1E54AE1BFB4AC14BD44014A299DFA2A585FD1AB4E8E586E1EB406FEF1C3C
1356drw_trial.tmpC:\Users\admin\AppData\Local\Temp\is-5Q614.tmp\uexper.dllexecutable
MD5:0E85B4A828FA22549257DCE22FAFA188
SHA256:B9D660117E18836E9103A2AB8EC3B58A95606F5B7E246F29434F60598254EC29
1660drw_trial.exeC:\Users\admin\AppData\Local\Temp\is-THJTF.tmp\drw_trial.tmpexecutable
MD5:353F79C20F61B1C268534F1EB2ED5832
SHA256:BBAD9B631F5685535FCF72D419956B2A2D2921E50096D8FB631B505098F82278
1356drw_trial.tmpC:\Program Files\EaseUS\EaseUS Data Recovery Wizard\is-FQFS1.tmpexecutable
MD5:353F79C20F61B1C268534F1EB2ED5832
SHA256:BBAD9B631F5685535FCF72D419956B2A2D2921E50096D8FB631B505098F82278
1356drw_trial.tmpC:\Users\admin\AppData\Local\Temp\is-5Q614.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1356drw_trial.tmpC:\Program Files\EaseUS\EaseUS Data Recovery Wizard\unins000.exeexecutable
MD5:353F79C20F61B1C268534F1EB2ED5832
SHA256:BBAD9B631F5685535FCF72D419956B2A2D2921E50096D8FB631B505098F82278
3496WinRAR.exeC:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\drw_trial.exeexecutable
MD5:B1C0BB58FF955EA05D3F0D4144D52695
SHA256:7952E217B9BDC176B1C924FB05BD75D7285F049FB698C1079A4F446CD37B6451
3496WinRAR.exeC:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\Instructions Important !!!.txttext
MD5:3BB76E1E05D1AC250301C4108C50B1F1
SHA256:D831C9C629257719D32271E42E34E35D84B02B89A00781EFECE9A853F319E2F6
3496WinRAR.exeC:\Users\admin\Desktop\EaseUS Data Recovery Wizard Technician 10.2.0 + Keygen [SadeemPC]\Keygen\Config.dattext
MD5:59D74C96DCC39E6870A7EC7E71CDCFD6
SHA256:145E34D9466828CE4D8AE0321C5C6E30CF59947E7142915FCD1518C6007AAA26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
48
DNS requests
77
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2844
msedge.exe
GET
301
104.18.18.71:80
http://www.easeus.com/thankyou/install-data-recovery-wizard-trial.htm
unknown
unknown
3468
DRWUI.exe
GET
301
104.18.18.71:80
http://www.easeus.com/update/drw_eng/drw.ini?time=133434119930460000
unknown
unknown
3468
DRWUI.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7e218a66623cea9e
unknown
compressed
4.66 Kb
unknown
1356
drw_trial.tmp
POST
200
163.171.156.15:80
http://track.easeus.com/product/index.php/?a=statistics&p_type=m_drw_infos
unknown
unknown
3468
DRWUI.exe
GET
200
172.217.16.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
3468
DRWUI.exe
GET
200
172.217.16.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1356
drw_trial.tmp
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
2844
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3816
msedge.exe
239.255.255.250:1900
whitelisted
2844
msedge.exe
104.18.18.71:80
www.easeus.com
CLOUDFLARENET
unknown
2844
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2844
msedge.exe
20.103.180.120:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
track.easeus.com
  • 163.171.156.15
unknown
www.easeus.com
  • 104.18.18.71
  • 104.18.19.71
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 172.217.16.195
whitelisted
update.easeus.com
  • 104.18.18.71
  • 104.18.19.71
whitelisted
www.googletagmanager.com
  • 216.58.206.40
whitelisted

Threats

No threats detected
Process
Message
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. SetValue. id=0x2 (2), val=1, inst=038CE858
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. top num =0
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. join=1
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. url=http://track.easeus.com/product/index.php/?a=statistics&p_type=m_drw_infos
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. InstallSpy. inst=038CE858
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. try send=1
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. send data=uid=3EB4B8A5-6EAD-41A5-B1AD-42D4AA5C221B&ue=1&codeinstall=1&processors=4&memory=3071&ipaddress=ip-test&os=Windows 7 Professional, Service Pack 1&timezone=GMT-00:00(GMT Standard Time)&install_version=DRW 10.2 Trial
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. log level=3
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. SetText. id=0x5101 (20737), text=DRW 10.2 Trial, inst=038CE858
drw_trial.tmp
2023-11-02 15:19:49:953[UE] --Info. SetText. id=0x3 (3), text=1, inst=038CE858