File name: | epm_free_installer.17145678618828b292.exe |
Full analysis: | https://app.any.run/tasks/db464b07-e00a-45cd-9d82-e06fba21e119 |
Verdict: | Malicious activity |
Analysis date: | May 01, 2024, 13:01:15 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | D33BDE2AC7340BC96E5920A7307E363B |
SHA1: | 4E1C33B945A1453636287739CCD6D21BC660AD6B |
SHA256: | 3F18740138451CBB4116270120B4F7EEAC62F80923F5CDF6614D42977CE074E2 |
SSDEEP: | 98304:nnCTzRnymY2wmc0OLwFRdXfSV7JHIuh6xR+vSUQiRLQFr+Uf33vOYnb8iise+Eak:eoRd |
.exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (14.2) |
.exe | | | Win32 Executable (generic) (9.7) |
.exe | | | Generic Win/DOS Executable (4.3) |
.exe | | | DOS Executable Generic (4.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2018:01:30 03:57:48+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 26624 |
InitializedDataSize: | 186368 |
UninitializedDataSize: | 2048 |
EntryPoint: | 0x338f |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
524 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
748 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
864 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.easeus.com/thankyou/install-partition-master-free.htm | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | epm_free_support_16.5.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
920 | net stop swprv | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
924 | C:\Windows\system32\net1 stop swprv | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
952 | cscript "C:\Program Files\EaseUS\EaseUS Partition Master\DC\bin\\register_app.vbs" -unregister "EPMVssEaseusProvider" | C:\Windows\System32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
1020 | "C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\EDownloader.exe" EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=epm_free_installer.17145678618828b292.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=2.2.0 ||| INSTALL_TYPE=0 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\EDownloader.exe | epm_free_installer.17145678618828b292.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
1116 | /SendInfo Window "Web_Installer" Activity "Result_Run_Installer" Attribute "{\"Country\":\"United States\",\"Pageid\":\"17145678618828b292\",\"Timezone\":\"GMT-00:00\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1116 | "C:\Program Files\EaseUS\EaseUS Partition Master\bin\EUinApp.exe" Main.exe | C:\Program Files\EaseUS\EaseUS Partition Master\bin\EUinApp.exe | — | epm_free_support_16.5.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1132 | /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Downloadfrom\":\"https://d1.easeus.com/epm/free/epm_free_support_16.5.exe\",\"Pageid\":\"17145678618828b292\",\"Testid\":\"\",\"Version\":\"Free\",\"Versionnumber\":\"18.5\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
|
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | ProxyServer |
Value: | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | ProxyOverride |
Value: | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | delete value | Name: | AutoDetect |
Value: | |||
(PID) Process: | (748) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\ChineseTrad.ini | text | |
MD5:EE9F9E88AAD4014304D5557962D07B48 | SHA256:0F66AA4B69A8988C63AD09977762734283519D696F100278C42D1B974C6AC69F | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Arabic.ini | text | |
MD5:222D1DAF8C455F3EC75E43D62EB42C3C | SHA256:337E36B65069C3E00FF69299D6EDDF61F89B3441BB1E2B19B5F987E74D4E74AC | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\EDownloader.exe | executable | |
MD5:53C0827201258E09E71BAC8838B90C92 | SHA256:877CC70DD9B075BD34A76FD18956AC54B271BB1DAC11159FA253F6318527ECB4 | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\InitConfigure.ini | ini | |
MD5:D5A1BDAA9A7D406CD36FEBC0A49DEF1F | SHA256:18DB7EF980A52A9B43CAD34AB2BB854CFE66444740ABF807C8EFF7091A2328D9 | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\skin.zip | compressed | |
MD5:85D86B4A38D993082B1F6C5DCD4AAF39 | SHA256:6047DE478C219AD42EA91D461D81886966C653DA9DB1F28107880FA991075732 | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Danish.ini | text | |
MD5:EB86F54C30CF78DCBDB6917A03C1ECD4 | SHA256:624384BE61561AB4455F6AFC4FB49BFAEAC1B6DABBAE76D9BF5CAF4EF1B17401 | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\French.ini | text | |
MD5:25EA7511C5F3C88EBE6F329B6BEBB69F | SHA256:92E4741A9C9ED34FD1760CFB236437ED60A724FD36485D721E64FA28FC0175AA | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Korean.ini | text | |
MD5:DA99A47B4A3F7E3770201403E6F0233E | SHA256:55D20E3FDA64806BDE92BEAA15941103692BF7F59DBD6375FAEE14BCF77881A9 | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\Dutch.ini | text | |
MD5:32E8AB5BD9243CA333C007DD5274FC6E | SHA256:9E6F6A6FE0CA269D68F3B0D9C4116AA6914291A783959CD6E8A2D5A6ED22C6DF | |||
4084 | epm_free_installer.17145678618828b292.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\German.ini | text | |
MD5:BEFDB0294BB4D7ECF66BC8FA82185364 | SHA256:BD3DF746CE443B93733933C73C3D3C44E0D2CE6D22AED536F83B92A304AB1EB3 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1020 | EDownloader.exe | POST | 200 | 18.172.112.123:80 | http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ | unknown | — | — | — |
748 | AliyunWrapExe.Exe | GET | 200 | 163.171.128.150:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=19 | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
— | — | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.9:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.11:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
748 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.11:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_epm_downloader/shards/lb | unknown | — | — | — |
3576 | AliyunWrapExe.Exe | GET | — | 163.171.128.150:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0 | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1020 | EDownloader.exe | 18.172.112.123:80 | download.easeus.com | — | US | unknown |
748 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
748 | AliyunWrapExe.Exe | 47.252.97.9:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1020 | EDownloader.exe | 18.66.112.111:443 | d1.easeus.com | AMAZON-02 | US | unknown |
748 | AliyunWrapExe.Exe | 47.252.97.11:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
3576 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
3928 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
1292 | AliyunWrapExe.Exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
Domain | IP | Reputation |
---|---|---|
download.easeus.com |
| unknown |
track.easeus.com |
| unknown |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
d1.easeus.com |
| unknown |
update.easeus.com |
| unknown |
Process | Message |
---|---|
EDownloader.exe | [928]-14:01:27:087 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=epm_free_installer.17145678618828b292.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=2.2.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [928]-14:01:27:087 CTools::loadIni configPath=C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5free\InitConfigure.ini
|
EDownloader.exe | [1872]-14:01:27:946 Json parse Data Start
|
EDownloader.exe | [1872]-14:01:27:946 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17145678618828b292&lang=English&pcVersion=home&pid=5&tid=1&version=free
|
EDownloader.exe | [1872]-14:01:27:946 Json url: http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17145678618828b292&lang=English&pcVersion=home&pid=5&tid=1&version=free
|
EDownloader.exe | [1872]-14:01:37:274 Json parse Data end(code=0)
|
EDownloader.exe | [1872]-14:01:37:274 PostData end
|
EDownloader.exe | [1872]-14:01:37:274 StartPost Error parse tuijian
|
EDownloader.exe | [1872]-14:01:37:274 Json response: {"check":1,"msg":"\u6210\u529f","data":{"pid":"5","download":"https:\/\/d1.easeus.com\/epm\/free\/epm18.5_free.exe","download2":"https:\/\/d2.easeus.com\/epm\/free\/epm18.5_free.exe","download3":"https:\/\/d3.easeus.com\/epm\/free\/epm18.5_free.exe","version":"free","curNum":"18.5","testid":"","url":["https:\/\/d1.easeus.com\/epm\/free\/epm_free_support_16.5.exe"],"md5":"052A86B300616D09DCB41BE5CA52A517","tj_download":"test","referNumber":"1000000","killSwitch":"true","WriteLogSwitch":"false","configid":""},"time":1714568489}
|
EDownloader.exe | [928]-14:01:37:290 CHttpHelper::GetDownloadInfo 56 download info code:0
|