| File name: | fixo_trial_installer_20240304.17095621461165b928114.exe |
| Full analysis: | https://app.any.run/tasks/31c7c753-926e-49c1-87c4-02907dc41c17 |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2024, 14:24:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 1227BE0B0AF91E5C9EDA1DBEFDCE661E |
| SHA1: | EF2B36F5AB7346A5A69C54B1A56A186C0CB98153 |
| SHA256: | 374E6C3C7816C97390BE2BC4D80AF12A010BB8AA469B4DED37DAB5E14040FD95 |
| SSDEEP: | 98304:exh8ePH8GYolQmz0o4ZMx5mkphySJ0JOgnKGpORT9MacQ9i3jsDL5cDpZcEkcrX3:sn2MUBEg |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 03:57:48+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 680 | /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"290.77KB\",\"Cdn\":\"https://d2.easeus.com/fixo/trial/fixo1.3.0_trial.exe\",\"Elapsedtime\":\"165\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 968 | C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1352 | /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"0.00B\",\"Cdn\":\"https://d1.easeus.com/fixo/trial/fixo1.3.0_trial.exe\",\"Elapsedtime\":\"120\",\"Errorinfo\":\"228\",\"Result\":\"Failed\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1404 | "C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe" /SendInfo "Window" "Selectadditionaltasks" "Activity" "Click_Install" "Attribute" "{\"Test_id\":\"TR1300-0123\",\"Version\":\"Trial_trial\",\"Num\":\"1.3.0.0\",\"Language\":\"en\"}" | C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe | — | fixo1.3.0_trial.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1864 | /verysilent /DIR="C:\Program Files\EaseUS\Fixo" /LANG=en agreeImprove= GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=17095621461165b928114 | C:\Users\admin\AppData\Local\Temp\fixo1.3.0_trial.exe | EDownloader.exe | ||||||||||||
User: admin Company: EaseUS Integrity Level: HIGH Description: EaseUS Fixo Setup Exit code: 0 Version: 1.3.0.0 Modules
| |||||||||||||||
| 1972 | /SendInfo Window "Home_Installer" Activity "Click_Install" Attribute "{\"Country\":\"United States\",\"Install_Path\":\"C:/Program Files/EaseUS/Fixo\",\"Language\":\"English\",\"Os\":\"Microsoft Windows 7\",\"Pageid\":\"17095621461165b928114\",\"Timezone\":\"GMT-00:00\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2128 | "C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe" /SendInfo "Window" "Selectdestinationlocation" "Activity" "Click_Confirm" "Attribute" "{\"Path\":\"C:/Program Files/EaseUS/Fixo\"}" | C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe | — | fixo1.3.0_trial.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2248 | "C:\Users\admin\AppData\Local\Temp\is-6SE7M.tmp\fixo1.3.0_trial.tmp" /SL5="$C0172,48467844,199168,C:\Users\admin\AppData\Local\Temp\fixo1.3.0_trial.exe" /verysilent /DIR="C:\Program Files\EaseUS\Fixo" /LANG=en agreeImprove= GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=17095621461165b928114 | C:\Users\admin\AppData\Local\Temp\is-6SE7M.tmp\fixo1.3.0_trial.tmp | fixo1.3.0_trial.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2304 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2336 | /SendInfo Window "Installing" Activity "Info_Start_Install_Program" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (2304) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Arabic.ini | text | |
MD5:C49AEBF32F3EBC1E4568D2D511BF1517 | SHA256:D5DD4E63B33F5F7A7D38E1AB1FDBF8A1F61C1DC2FEBD05DB3049275A70CBD412 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\ChineseTrad.ini | text | |
MD5:9D7BFB9FF8352272069E19FAFAB73C57 | SHA256:E97F9585058E674BBD2B221D53E67014D076E610C50463EBDD31EE8AD2F32687 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Chinese.ini | text | |
MD5:CCB341B717F6786E7851BB1B48DFB30A | SHA256:21F3C8D6992FE4173A6525DB3E21F3696EDA655FAB364B0FE08D9B9C4B913B2E | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\EDownloader.exe | executable | |
MD5:8A192497176460B98777E545E454B672 | SHA256:EEED1AF1C339A29D5B34DAABB3AB626323D8387C1B71EFAB4BC15CFF43CF22F0 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\skin.zip | compressed | |
MD5:D1F4FFF5EA05B22C505D084A7FFB59C5 | SHA256:F0B5B961786310BF9032E0E453FE32E7A2A8FCED3C5D645663ABBE686CDE0885 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\German.ini | text | |
MD5:AE7921B0253C10FD5487F0FA448F7452 | SHA256:BE441670CB86302253817D01246F9206A3C9D1591FFBE828AD70C123B5815F31 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Dutch.ini | text | |
MD5:705A32AB54C60D60634ED6C9DCB9C2F7 | SHA256:6FED91288CE417F8678A070218F8B514EC69C9DDC065F66572BCB36019F7A522 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\French.ini | text | |
MD5:1D5ABE4C8EEE6031F56EA13B944FC906 | SHA256:B8693E75894C1DFC96101E4EF5061F7ADBE18400F82DC6D62E7E677F548F170A | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Korean.ini | text | |
MD5:A1709E1A41210ADB01B62AFFE10AAAA3 | SHA256:528CB80A13D888CF7607A8C244F27069C1E35E70AE6A6C3286290EEEFC11B973 | |||
| 3660 | fixo_trial_installer_20240304.17095621461165b928114.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Norwegian.ini | text | |
MD5:A381ED66D272DCC65A7AD43CF19BC0C0 | SHA256:C2CD6D0CF024AA9A3278960F43AA016B481839B641327527A191DD6EF4B72159 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
968 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_ip/shards/lb | unknown | — | — | unknown |
968 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_ip/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | GET | 200 | 163.171.156.15:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=47 | unknown | binary | 21 b | unknown |
2964 | EDownloader.exe | POST | 200 | 143.204.98.3:80 | http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ | unknown | binary | 484 b | unknown |
2304 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | POST | — | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
2304 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.10:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2964 | EDownloader.exe | 143.204.98.3:80 | download.easeus.com | AMAZON-02 | US | whitelisted |
2304 | AliyunWrapExe.Exe | 163.171.156.15:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
2304 | AliyunWrapExe.Exe | 47.252.97.10:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
2964 | EDownloader.exe | 18.66.112.38:443 | d1.easeus.com | AMAZON-02 | US | unknown |
2964 | EDownloader.exe | 216.58.206.36:443 | www.google.com | GOOGLE | US | whitelisted |
2964 | EDownloader.exe | 18.66.112.6:443 | d1.easeus.com | AMAZON-02 | US | unknown |
2304 | AliyunWrapExe.Exe | 47.252.97.212:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
download.easeus.com |
| unknown |
track.easeus.com |
| unknown |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
d1.easeus.com |
| unknown |
www.google.com |
| whitelisted |
d2.easeus.com |
| unknown |
Process | Message |
|---|---|
EDownloader.exe | [2840]-14:24:59:602 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=fixo_trial_installer_20240304.17095621461165b928114.exe ||| DOWNLOAD_VERSION=trial ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [2840]-14:24:59:633 Install recomand return=259
|
EDownloader.exe | [2840]-14:24:59:898 Install recomand return=259
|
EDownloader.exe | [3428]-14:25:00:008 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17095621461165b928114&lang=English&pcVersion=home&pid=47&tid=1&version=trial
|
EDownloader.exe | [2840]-14:25:42:273 Install recomand return=259
|
EDownloader.exe | [3428]-14:25:57:602 PostData end
|
EDownloader.exe | [3428]-14:25:57:602 Json parse Data Start
|
EDownloader.exe | [3428]-14:25:57:602 Json parse Data end
|
EDownloader.exe | [2840]-14:25:57:602 CHttpHelper::GetDownloadInfo 45 download info code:0
|
EDownloader.exe | [2840]-14:25:57:602 Install recomand return=259
|