File name:

YTD Video Downloader Pro.zip

Full analysis: https://app.any.run/tasks/786ddaba-c6d2-4487-9653-c7b3435ed6e6
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: June 25, 2020, 16:28:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C00A82D812B27B415548FF3082E74B35

SHA1:

D8D8934A866FF8C96C9025548A8D79C295943F60

SHA256:

394C1369480554C196A66ED5BE20A7FFA1CFC677B16F667F16ED4B5466024FF3

SSDEEP:

196608:0gldQD3EpvzmLoS2E2+aYpBaMNHnRayafjZXIjOte353/OfzSBR7p:fldQLEpvarJ2lYpB3HnEPdIjOSEQv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • YTDSetup.exe (PID: 3196)
      • ytd.exe (PID: 4064)
      • ytd.exe (PID: 3556)
    • Application was dropped or rewritten from another process

      • YTDSetup.exe (PID: 3196)
      • YTDSetup.exe (PID: 320)
      • ytd.exe (PID: 4064)
      • ytd.exe (PID: 3556)
    • Connects to CnC server

      • YTDSetup.exe (PID: 3196)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3660)
      • YTDSetup.exe (PID: 3196)
      • DllHost.exe (PID: 3048)
    • Executed via COM

      • explorer.exe (PID: 3436)
      • explorer.exe (PID: 3532)
      • DllHost.exe (PID: 3048)
    • Starts Internet Explorer

      • explorer.exe (PID: 3436)
    • Creates a software uninstall entry

      • YTDSetup.exe (PID: 3196)
    • Reads Internet Cache Settings

      • ytd.exe (PID: 4064)
      • ytd.exe (PID: 3556)
    • Creates files in the program directory

      • ytd.exe (PID: 4064)
      • YTDSetup.exe (PID: 3196)
    • Reads internet explorer settings

      • ytd.exe (PID: 4064)
      • ytd.exe (PID: 3556)
    • Creates files in the user directory

      • ytd.exe (PID: 4064)
      • ytd.exe (PID: 3556)
  • INFO

    • Manual execution by user

      • YTDSetup.exe (PID: 320)
      • YTDSetup.exe (PID: 3196)
      • ytd.exe (PID: 3556)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2492)
      • iexplore.exe (PID: 2540)
    • Changes internet zones settings

      • iexplore.exe (PID: 2492)
    • Application launched itself

      • iexplore.exe (PID: 2492)
    • Creates files in the user directory

      • iexplore.exe (PID: 2540)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2540)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:05:20 11:30:14
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: YTD Video Downloader Pro/Crack UZ1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe ytdsetup.exe no specs ytdsetup.exe explorer.exe no specs explorer.exe no specs explorer.exe no specs explorer.exe no specs iexplore.exe no specs ytd.exe iexplore.exe Copy/Move/Rename/Delete/Link Object ytd.exe

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Users\admin\Desktop\YTD Video Downloader Pro\YTDSetup.exe" C:\Users\admin\Desktop\YTD Video Downloader Pro\YTDSetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
YTD Video Downloader Application
Exit code:
3221226540
Version:
5.9.18.2
Modules
Images
c:\users\admin\desktop\ytd video downloader pro\ytdsetup.exe
c:\systemroot\system32\ntdll.dll
1940"C:\Windows\explorer.exe" "http://www.ytddownloader.com/thankyou.html?isn=D9D6866BBF7148919C998DE51FAA79B5&lang=1033&cid=b8c47e36061a092184ea8cb9b1a64aa2&oldVer=&newVer=5.9.18&kt=ytdd&pv=0"C:\Windows\explorer.exeYTDSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2492"C:\Program Files\Internet Explorer\iexplore.exe" http://www.ytddownloader.com/thankyou.html?isn=D9D6866BBF7148919C998DE51FAA79B5&lang=1033&cid=b8c47e36061a092184ea8cb9b1a64aa2&oldVer=&newVer=5.9.18&kt=ytdd&pv=0C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2540"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2492 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3048C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\system32\DllHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3196"C:\Users\admin\Desktop\YTD Video Downloader Pro\YTDSetup.exe" C:\Users\admin\Desktop\YTD Video Downloader Pro\YTDSetup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
YTD Video Downloader Application
Exit code:
0
Version:
5.9.18.2
Modules
Images
c:\users\admin\desktop\ytd video downloader pro\ytdsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3436C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3532C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3556"C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe" C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe
explorer.exe
User:
admin
Company:
GreenTree Applications SRL
Integrity Level:
MEDIUM
Description:
Video Downloader Crack UZ1
Exit code:
0
Version:
5, 9, 18, 2
Modules
Images
c:\program files\greentree applications\ytd video downloader\ytd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3564"C:\Windows\explorer.exe" "C:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe"C:\Windows\explorer.exeYTDSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 666
Read events
1 539
Write events
123
Delete events
4

Modification events

(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3660) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3660) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\YTD Video Downloader Pro.zip
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3660) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3196) YTDSetup.exeKey:HKEY_CURRENT_USER\Software\GreenTree Applications\YTD
Operation:writeName:ISN
Value:
D9D6866BBF7148919C998DE51FAA79B5
Executable files
27
Suspicious files
22
Text files
59
Unknown types
12

Dropped files

PID
Process
Filename
Type
3196YTDSetup.exeC:\Users\admin\AppData\Local\Temp\nsw4026.tmp\inst_start.txt
MD5:
SHA256:
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.38912\YTD Video Downloader Pro\Crack UZ1\ytd.exeexecutable
MD5:
SHA256:
3660WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3660.38912\YTD Video Downloader Pro\YTDSetup.exeexecutable
MD5:
SHA256:
3196YTDSetup.exeC:\Users\admin\AppData\Local\Temp\nsw4026.tmp\NSISHelper.dllexecutable
MD5:
SHA256:
3196YTDSetup.exeC:\Program Files\GreenTree Applications\YTD Video Downloader\scripts.ydsbinary
MD5:
SHA256:
3196YTDSetup.exeC:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exeexecutable
MD5:
SHA256:
3196YTDSetup.exeC:\Users\admin\AppData\Local\Temp\nsw4026.tmp\nsisdl.dllexecutable
MD5:BA2CC9634EBED71CEA697A31144AF802
SHA256:9A3C2FE5490C34F73F1A05899EF60CFEF05E0C9599CD704E524EF7A46EAD67BA
3196YTDSetup.exeC:\Program Files\GreenTree Applications\YTD Video Downloader\manual.battext
MD5:AAE0878136D8C1559FAC69F5C5B895E2
SHA256:FD8839722BA7FFD3FBE48149FD909DB3E66E9A5213FA88E511286214BE109B9D
3196YTDSetup.exeC:\Users\admin\AppData\Local\Temp\nsw4026.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
3196YTDSetup.exeC:\Users\admin\AppData\Local\Temp\nsw4026.tmp\modern-header.bmpimage
MD5:3FD933AE9F031241E079AF6BAC356206
SHA256:3EDA2CF101377503BAE145E54351636DD117A89D9D680A3D49ED7F6026485590
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
30
DNS requests
21
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3196
YTDSetup.exe
GET
3.124.215.174:80
http://www.ytddownloader.com/images/pixel.gif?action=install&point=finish&oldver=&version=5.9.18&lngid=1033&cid=b8c47e36061a092184ea8cb9b1a64aa2&isn=D9D6866BBF7148919C998DE51FAA79B5&kt=ytdd&ai=0&lt=0
US
suspicious
3196
YTDSetup.exe
GET
3.124.215.174:80
http://www.ytddownloader.com/images/pixel.gif?action=install&point=start&version=5.9.18&lngid=1033&cid=b8c47e36061a092184ea8cb9b1a64aa2&isn=D9D6866BBF7148919C998DE51FAA79B5&kt=ytdd&lt=0
US
suspicious
2540
iexplore.exe
GET
200
35.158.201.39:80
http://www.ytddownloader.com/styles2v.css?20200604
DE
text
4.59 Kb
suspicious
2540
iexplore.exe
GET
200
35.158.201.39:80
http://www.ytddownloader.com/js/main.js?20200604
DE
text
4.94 Kb
suspicious
4064
ytd.exe
GET
200
3.124.215.174:80
http://www.ytddownloader.com/scripts/win/scripts-20200616.yds
US
binary
215 Kb
suspicious
2540
iexplore.exe
GET
200
35.158.201.39:80
http://www.ytddownloader.com/images/ultravpn.jpg
DE
image
79.9 Kb
suspicious
4064
ytd.exe
GET
200
3.124.215.174:80
http://www.ytddownloader.com/ads/2020sah/win.php?inst=2020-06-25&kt=ytdd&isn=D9D6866BBF7148919C998DE51FAA79B5&lt=6&ver=5.9.18
US
html
1.80 Kb
suspicious
2540
iexplore.exe
GET
200
35.158.201.39:80
http://www.ytddownloader.com/thankyou.html?isn=D9D6866BBF7148919C998DE51FAA79B5&lang=1033&cid=b8c47e36061a092184ea8cb9b1a64aa2&oldVer=&newVer=5.9.18&kt=ytdd&pv=0
DE
html
2.23 Kb
suspicious
4064
ytd.exe
GET
200
143.204.208.79:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
4064
ytd.exe
GET
200
3.124.215.174:80
http://www.ytddownloader.com/ads/2020sah/win-bg-80.gif
US
image
5.70 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3196
YTDSetup.exe
3.124.215.174:80
www.ytddownloader.com
US
malicious
2540
iexplore.exe
35.158.201.39:80
www.ytddownloader.com
Amazon.com, Inc.
DE
unknown
2540
iexplore.exe
172.217.23.100:443
www.google.com
Google Inc.
US
whitelisted
4064
ytd.exe
3.124.215.174:80
www.ytddownloader.com
US
malicious
4064
ytd.exe
172.217.23.170:80
ajax.googleapis.com
Google Inc.
US
whitelisted
4064
ytd.exe
64.233.166.156:443
stats.g.doubleclick.net
Google Inc.
US
whitelisted
4064
ytd.exe
172.217.23.100:443
www.google.com
Google Inc.
US
whitelisted
2540
iexplore.exe
216.58.212.170:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2540
iexplore.exe
216.58.212.138:443
ajax.googleapis.com
Google Inc.
US
whitelisted
4064
ytd.exe
216.58.207.35:443
www.google.de
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.ytddownloader.com
  • 3.124.215.174
  • 35.158.201.39
suspicious
o.ss2.us
  • 143.204.208.79
  • 143.204.208.165
  • 143.204.208.160
  • 143.204.208.127
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.35.253.198
  • 13.35.253.185
  • 13.35.253.5
  • 13.35.253.148
whitelisted
fonts.googleapis.com
  • 216.58.212.170
whitelisted
ajax.googleapis.com
  • 216.58.212.138
  • 172.217.23.170
whitelisted
www.google.com
  • 172.217.23.100
malicious
www.googletagmanager.com
  • 172.217.18.8
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.35.253.5
  • 13.35.253.148
  • 13.35.253.185
  • 13.35.253.198
shared

Threats

PID
Process
Class
Message
A Network Trojan was detected
ET MALWARE Win32/YTDDownloader.F Variant CnC Activity
Misc activity
ADWARE [PTsecurity] Spigot (Ytdownloader)
Misc activity
ADWARE [PTsecurity] Spigot (Ytdownloader)
4 ETPRO signatures available at the full report
No debug info