File name:

fixo_trial_installer_20240304.17095621461165b928114.exe

Full analysis: https://app.any.run/tasks/31c7c753-926e-49c1-87c4-02907dc41c17
Verdict: Malicious activity
Analysis date: March 04, 2024, 14:24:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

1227BE0B0AF91E5C9EDA1DBEFDCE661E

SHA1:

EF2B36F5AB7346A5A69C54B1A56A186C0CB98153

SHA256:

374E6C3C7816C97390BE2BC4D80AF12A010BB8AA469B4DED37DAB5E14040FD95

SSDEEP:

98304:exh8ePH8GYolQmz0o4ZMx5mkphySJ0JOgnKGpORT9MacQ9i3jsDL5cDpZcEkcrX3:sn2MUBEg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fixo_trial_installer_20240304.17095621461165b928114.exe (PID: 3660)
      • fixo1.3.0_trial.exe (PID: 1864)
      • fixo1.3.0_trial.tmp (PID: 2248)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fixo_trial_installer_20240304.17095621461165b928114.exe (PID: 3660)
      • fixo1.3.0_trial.exe (PID: 1864)
      • fixo1.3.0_trial.tmp (PID: 2248)
    • Reads the Internet Settings

      • AliyunWrapExe.Exe (PID: 2304)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 968)
    • Reads security settings of Internet Explorer

      • AliyunWrapExe.Exe (PID: 2304)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 968)
    • Reads Microsoft Outlook installation path

      • EDownloader.exe (PID: 2964)
    • Reads Internet Explorer settings

      • EDownloader.exe (PID: 2964)
    • Reads the Windows owner or organization settings

      • fixo1.3.0_trial.tmp (PID: 2248)
    • The process drops C-runtime libraries

      • fixo1.3.0_trial.tmp (PID: 2248)
    • Process drops legitimate windows executable

      • fixo1.3.0_trial.tmp (PID: 2248)
  • INFO

    • Checks supported languages

      • fixo_trial_installer_20240304.17095621461165b928114.exe (PID: 3660)
      • EDownloader.exe (PID: 2964)
      • InfoForSetup.exe (PID: 3228)
      • InfoForSetup.exe (PID: 3304)
      • AliyunWrapExe.Exe (PID: 2304)
      • InfoForSetup.exe (PID: 2420)
      • InfoForSetup.exe (PID: 2672)
      • InfoForSetup.exe (PID: 3164)
      • InfoForSetup.exe (PID: 1972)
      • InfoForSetup.exe (PID: 680)
      • InfoForSetup.exe (PID: 2336)
      • InfoForSetup.exe (PID: 1352)
      • fixo1.3.0_trial.exe (PID: 1864)
      • InfoForSetup.exe (PID: 3404)
      • fixo1.3.0_trial.tmp (PID: 2248)
      • InfoForSetup.exe (PID: 3980)
      • AliyunWrapExe.Exe (PID: 968)
      • InfoForSetup.exe (PID: 2632)
      • InfoForSetup.exe (PID: 2128)
      • InfoForSetup.exe (PID: 1404)
    • Reads the computer name

      • fixo_trial_installer_20240304.17095621461165b928114.exe (PID: 3660)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 2304)
      • fixo1.3.0_trial.tmp (PID: 2248)
      • AliyunWrapExe.Exe (PID: 968)
    • Create files in a temporary directory

      • fixo_trial_installer_20240304.17095621461165b928114.exe (PID: 3660)
      • InfoForSetup.exe (PID: 3304)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 2304)
      • fixo1.3.0_trial.exe (PID: 1864)
      • fixo1.3.0_trial.tmp (PID: 2248)
      • AliyunWrapExe.Exe (PID: 968)
    • Checks proxy server information

      • AliyunWrapExe.Exe (PID: 2304)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 968)
    • Reads the machine GUID from the registry

      • AliyunWrapExe.Exe (PID: 2304)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 968)
    • Creates files or folders in the user directory

      • AliyunWrapExe.Exe (PID: 2304)
      • AliyunWrapExe.Exe (PID: 968)
    • Creates files in the program directory

      • fixo1.3.0_trial.tmp (PID: 2248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 03:57:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 186368
UninitializedDataSize: 2048
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
21
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start fixo_trial_installer_20240304.17095621461165b928114.exe edownloader.exe infoforsetup.exe no specs infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs fixo1.3.0_trial.exe fixo1.3.0_trial.tmp infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs fixo_trial_installer_20240304.17095621461165b928114.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680 /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"290.77KB\",\"Cdn\":\"https://d2.easeus.com/fixo/trial/fixo1.3.0_trial.exe\",\"Elapsedtime\":\"165\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
968C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-rrnfo.tmp\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\is-rrnfo.tmp\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
1352 /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"0.00B\",\"Cdn\":\"https://d1.easeus.com/fixo/trial/fixo1.3.0_trial.exe\",\"Elapsedtime\":\"120\",\"Errorinfo\":\"228\",\"Result\":\"Failed\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1404"C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe" /SendInfo "Window" "Selectadditionaltasks" "Activity" "Click_Install" "Attribute" "{\"Test_id\":\"TR1300-0123\",\"Version\":\"Trial_trial\",\"Num\":\"1.3.0.0\",\"Language\":\"en\"}"C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exefixo1.3.0_trial.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-rrnfo.tmp\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1864 /verysilent /DIR="C:\Program Files\EaseUS\Fixo" /LANG=en agreeImprove= GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=17095621461165b928114 C:\Users\admin\AppData\Local\Temp\fixo1.3.0_trial.exe
EDownloader.exe
User:
admin
Company:
EaseUS
Integrity Level:
HIGH
Description:
EaseUS Fixo Setup
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\fixo1.3.0_trial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1972 /SendInfo Window "Home_Installer" Activity "Click_Install" Attribute "{\"Country\":\"United States\",\"Install_Path\":\"C:/Program Files/EaseUS/Fixo\",\"Language\":\"English\",\"Os\":\"Microsoft Windows 7\",\"Pageid\":\"17095621461165b928114\",\"Timezone\":\"GMT-00:00\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2128"C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exe" /SendInfo "Window" "Selectdestinationlocation" "Activity" "Click_Confirm" "Attribute" "{\"Path\":\"C:/Program Files/EaseUS/Fixo\"}"C:\Users\admin\AppData\Local\Temp\is-RRNFO.tmp\InfoForSetup.exefixo1.3.0_trial.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\is-rrnfo.tmp\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2248"C:\Users\admin\AppData\Local\Temp\is-6SE7M.tmp\fixo1.3.0_trial.tmp" /SL5="$C0172,48467844,199168,C:\Users\admin\AppData\Local\Temp\fixo1.3.0_trial.exe" /verysilent /DIR="C:\Program Files\EaseUS\Fixo" /LANG=en agreeImprove= GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=17095621461165b928114 C:\Users\admin\AppData\Local\Temp\is-6SE7M.tmp\fixo1.3.0_trial.tmp
fixo1.3.0_trial.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6se7m.tmp\fixo1.3.0_trial.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2304C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2336 /SendInfo Window "Installing" Activity "Info_Start_Install_Program"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\47trial\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
8 237
Read events
8 148
Write events
73
Delete events
16

Modification events

(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2304) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
144
Suspicious files
78
Text files
1 338
Unknown types
9

Dropped files

PID
Process
Filename
Type
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Arabic.initext
MD5:C49AEBF32F3EBC1E4568D2D511BF1517
SHA256:D5DD4E63B33F5F7A7D38E1AB1FDBF8A1F61C1DC2FEBD05DB3049275A70CBD412
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\ChineseTrad.initext
MD5:9D7BFB9FF8352272069E19FAFAB73C57
SHA256:E97F9585058E674BBD2B221D53E67014D076E610C50463EBDD31EE8AD2F32687
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Chinese.initext
MD5:CCB341B717F6786E7851BB1B48DFB30A
SHA256:21F3C8D6992FE4173A6525DB3E21F3696EDA655FAB364B0FE08D9B9C4B913B2E
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\EDownloader.exeexecutable
MD5:8A192497176460B98777E545E454B672
SHA256:EEED1AF1C339A29D5B34DAABB3AB626323D8387C1B71EFAB4BC15CFF43CF22F0
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\skin.zipcompressed
MD5:D1F4FFF5EA05B22C505D084A7FFB59C5
SHA256:F0B5B961786310BF9032E0E453FE32E7A2A8FCED3C5D645663ABBE686CDE0885
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\German.initext
MD5:AE7921B0253C10FD5487F0FA448F7452
SHA256:BE441670CB86302253817D01246F9206A3C9D1591FFBE828AD70C123B5815F31
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Dutch.initext
MD5:705A32AB54C60D60634ED6C9DCB9C2F7
SHA256:6FED91288CE417F8678A070218F8B514EC69C9DDC065F66572BCB36019F7A522
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\French.initext
MD5:1D5ABE4C8EEE6031F56EA13B944FC906
SHA256:B8693E75894C1DFC96101E4EF5061F7ADBE18400F82DC6D62E7E677F548F170A
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Korean.initext
MD5:A1709E1A41210ADB01B62AFFE10AAAA3
SHA256:528CB80A13D888CF7607A8C244F27069C1E35E70AE6A6C3286290EEEFC11B973
3660fixo_trial_installer_20240304.17095621461165b928114.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\47trial\Norwegian.initext
MD5:A381ED66D272DCC65A7AD43CF19BC0C0
SHA256:C2CD6D0CF024AA9A3278960F43AA016B481839B641327527A191DD6EF4B72159
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
35
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
968
AliyunWrapExe.Exe
POST
200
47.252.97.9:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_ip/shards/lb
unknown
unknown
968
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_ip/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
POST
200
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=47
unknown
binary
21 b
unknown
2964
EDownloader.exe
POST
200
143.204.98.3:80
http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
unknown
binary
484 b
unknown
2304
AliyunWrapExe.Exe
POST
200
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
POST
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
POST
200
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
POST
200
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
2304
AliyunWrapExe.Exe
POST
200
47.252.97.10:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_fixo_downloader/shards/lb
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2964
EDownloader.exe
143.204.98.3:80
download.easeus.com
AMAZON-02
US
whitelisted
2304
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
2304
AliyunWrapExe.Exe
47.252.97.10:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
2964
EDownloader.exe
18.66.112.38:443
d1.easeus.com
AMAZON-02
US
unknown
2964
EDownloader.exe
216.58.206.36:443
www.google.com
GOOGLE
US
whitelisted
2964
EDownloader.exe
18.66.112.6:443
d1.easeus.com
AMAZON-02
US
unknown
2304
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
download.easeus.com
  • 143.204.98.3
  • 143.204.98.38
  • 143.204.98.21
  • 143.204.98.43
unknown
track.easeus.com
  • 163.171.156.15
unknown
easeusinfo.us-east-1.log.aliyuncs.com
  • 47.252.97.10
  • 47.252.97.9
  • 47.252.97.8
  • 47.252.97.13
  • 47.252.97.11
  • 47.252.97.12
  • 47.252.97.212
  • 47.252.97.15
  • 47.252.97.14
unknown
d1.easeus.com
  • 18.66.112.38
  • 18.66.112.125
  • 18.66.112.6
  • 18.66.112.111
unknown
www.google.com
  • 216.58.206.36
whitelisted
d2.easeus.com
  • 18.66.112.6
  • 18.66.112.125
  • 18.66.112.111
  • 18.66.112.38
unknown

Threats

No threats detected
Process
Message
EDownloader.exe
[2840]-14:24:59:602 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=fixo_trial_installer_20240304.17095621461165b928114.exe ||| DOWNLOAD_VERSION=trial ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
EDownloader.exe
[2840]-14:24:59:633 Install recomand return=259
EDownloader.exe
[2840]-14:24:59:898 Install recomand return=259
EDownloader.exe
[3428]-14:25:00:008 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17095621461165b928114&lang=English&pcVersion=home&pid=47&tid=1&version=trial
EDownloader.exe
[2840]-14:25:42:273 Install recomand return=259
EDownloader.exe
[3428]-14:25:57:602 PostData end
EDownloader.exe
[3428]-14:25:57:602 Json parse Data Start
EDownloader.exe
[3428]-14:25:57:602 Json parse Data end
EDownloader.exe
[2840]-14:25:57:602 CHttpHelper::GetDownloadInfo 45 download info code:0
EDownloader.exe
[2840]-14:25:57:602 Install recomand return=259