| File name: | epm_free_installer.17145678618828b292.exe |
| Full analysis: | https://app.any.run/tasks/db464b07-e00a-45cd-9d82-e06fba21e119 |
| Verdict: | Malicious activity |
| Analysis date: | May 01, 2024, 13:01:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | D33BDE2AC7340BC96E5920A7307E363B |
| SHA1: | 4E1C33B945A1453636287739CCD6D21BC660AD6B |
| SHA256: | 3F18740138451CBB4116270120B4F7EEAC62F80923F5CDF6614D42977CE074E2 |
| SSDEEP: | 98304:nnCTzRnymY2wmc0OLwFRdXfSV7JHIuh6xR+vSUQiRLQFr+Uf33vOYnb8iise+Eak:eoRd |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 03:57:48+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 524 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 748 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 864 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.easeus.com/thankyou/install-partition-master-free.htm | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | epm_free_support_16.5.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 920 | net stop swprv | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 924 | C:\Windows\system32\net1 stop swprv | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 952 | cscript "C:\Program Files\EaseUS\EaseUS Partition Master\DC\bin\\register_app.vbs" -unregister "EPMVssEaseusProvider" | C:\Windows\System32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 1020 | "C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\EDownloader.exe" EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=epm_free_installer.17145678618828b292.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=2.2.0 ||| INSTALL_TYPE=0 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\EDownloader.exe | epm_free_installer.17145678618828b292.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 1116 | /SendInfo Window "Web_Installer" Activity "Result_Run_Installer" Attribute "{\"Country\":\"United States\",\"Pageid\":\"17145678618828b292\",\"Timezone\":\"GMT-00:00\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1116 | "C:\Program Files\EaseUS\EaseUS Partition Master\bin\EUinApp.exe" Main.exe | C:\Program Files\EaseUS\EaseUS Partition Master\bin\EUinApp.exe | — | epm_free_support_16.5.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1132 | /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Downloadfrom\":\"https://d1.easeus.com/epm/free/epm_free_support_16.5.exe\",\"Pageid\":\"17145678618828b292\",\"Testid\":\"\",\"Version\":\"Free\",\"Versionnumber\":\"18.5\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\skin.zip | compressed | |
MD5:85D86B4A38D993082B1F6C5DCD4AAF39 | SHA256:6047DE478C219AD42EA91D461D81886966C653DA9DB1F28107880FA991075732 | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Dutch.ini | text | |
MD5:32E8AB5BD9243CA333C007DD5274FC6E | SHA256:9E6F6A6FE0CA269D68F3B0D9C4116AA6914291A783959CD6E8A2D5A6ED22C6DF | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\ChineseTrad.ini | text | |
MD5:EE9F9E88AAD4014304D5557962D07B48 | SHA256:0F66AA4B69A8988C63AD09977762734283519D696F100278C42D1B974C6AC69F | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\InitConfigure_epms.ini | ini | |
MD5:398367EFD0613214E3AE77B113EA9D2B | SHA256:C44D56BFD888832B610677426C78211D2811FE3F74FBB4E3E5846DC54EA85B8D | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Portuguese.ini | text | |
MD5:AA06C1D742B5304534848D4DB958259F | SHA256:EF8E757D203FD029F899459FF6AC28F4F269681F4FD1B9C00ADDBAF01CCC6DE2 | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\French.ini | text | |
MD5:25EA7511C5F3C88EBE6F329B6BEBB69F | SHA256:92E4741A9C9ED34FD1760CFB236437ED60A724FD36485D721E64FA28FC0175AA | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Italian.ini | text | |
MD5:D8228001A210BD49D45087AAEA8D187F | SHA256:D359DA5D3A4C0AE6EE0A17EC799365B38F4788C7F56BD4A23FF7254419940182 | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\InitConfigure.ini | ini | |
MD5:D5A1BDAA9A7D406CD36FEBC0A49DEF1F | SHA256:18DB7EF980A52A9B43CAD34AB2BB854CFE66444740ABF807C8EFF7091A2328D9 | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\German.ini | text | |
MD5:BEFDB0294BB4D7ECF66BC8FA82185364 | SHA256:BD3DF746CE443B93733933C73C3D3C44E0D2CE6D22AED536F83B92A304AB1EB3 | |||
| 4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\LanguageTransfor.ini | text | |
MD5:8EBF0F0B4966FEB8915100E42FA05EF8 | SHA256:E84AAAA5938F1DC9B7E420F791AF443A8B876A9205D8EAF6ED0749CD09A0E840 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
748 | AliyunWrapExe.Exe | GET | 200 | 163.171.128.150:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=19 | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
1020 | EDownloader.exe | POST | 200 | 18.172.112.123:80 | http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
— | — | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.11:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.11:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.11:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1020 | EDownloader.exe | 18.172.112.123:80 | download.easeus.com | — | US | unknown |
748 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
748 | AliyunWrapExe.Exe | 47.252.97.9:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1020 | EDownloader.exe | 18.66.112.111:443 | d1.easeus.com | AMAZON-02 | US | unknown |
748 | AliyunWrapExe.Exe | 47.252.97.11:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
3576 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
3928 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
1292 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
download.easeus.com |
| unknown |
track.easeus.com |
| unknown |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
d1.easeus.com |
| unknown |
update.easeus.com |
| unknown |
Process | Message |
|---|---|
EDownloader.exe | [928]-14:01:27:087 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=epm_free_installer.17145678618828b292.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=2.2.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [928]-14:01:27:087 CTools::loadIni configPath=C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\InitConfigure.ini
|
EDownloader.exe | [1872]-14:01:27:946 Json parse Data Start
|
EDownloader.exe | [1872]-14:01:27:946 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17145678618828b292&lang=English&pcVersion=home&pid=5&tid=1&version=free
|
EDownloader.exe | [1872]-14:01:27:946 Json url: http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17145678618828b292&lang=English&pcVersion=home&pid=5&tid=1&version=free
|
EDownloader.exe | [1872]-14:01:37:274 Json parse Data end(code=0)
|
EDownloader.exe | [1872]-14:01:37:274 PostData end
|
EDownloader.exe | [1872]-14:01:37:274 StartPost Error parse tuijian
|
EDownloader.exe | [1872]-14:01:37:274 Json response: {"check":1,"msg":"\u6210\u529f","data":{"pid":"5","download":"https:\/\/d1.easeus.com\/epm\/free\/epm18.5_free.exe","download2":"https:\/\/d2.easeus.com\/epm\/free\/epm18.5_free.exe","download3":"https:\/\/d3.easeus.com\/epm\/free\/epm18.5_free.exe","version":"free","curNum":"18.5","testid":"","url":["https:\/\/d1.easeus.com\/epm\/free\/epm_free_support_16.5.exe"],"md5":"052A86B300616D09DCB41BE5CA52A517","tj_download":"test","referNumber":"1000000","killSwitch":"true","WriteLogSwitch":"false","configid":""},"time":1714568489}
|
EDownloader.exe | [928]-14:01:37:290 CHttpHelper::GetDownloadInfo 56 download info code:0
|