| File name: | hitpaw-video-converter_11724588917790083601.exe |
| Full analysis: | https://app.any.run/tasks/d1d01361-322f-4c2b-8923-5a2937e04b16 |
| Verdict: | Malicious activity |
| Analysis date: | August 25, 2024, 12:46:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 98371061B6E911DAB7951B4A0B009493 |
| SHA1: | 8A60162578369C6E1B38D74606322056A54BF945 |
| SHA256: | 58C40D074E0C2D03D045925964727C94274DF8CFCFED73FA44EB0A14C4B57AC1 |
| SSDEEP: | 98304:nTKdmVALQ0wLJhlwH64Wf4jLZyWDplVHJdVmyRLoOhVmLY3ippdtHQpoLJNpZYV+:TVSQ |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:01:15 07:04:22+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 1597440 |
| InitializedDataSize: | 614400 |
| UninitializedDataSize: | 1572864 |
| EntryPoint: | 0x306910 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.7.20.1 |
| ProductVersionNumber: | 2.7.20.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | HitPaw |
| FileDescription: | HitPaw Video Converter |
| FileVersion: | 2.7.20.1 |
| LegalCopyright: | Copyright © 2021-2024 HITPAW CO.,LIMITED All Rights Reserved. |
| ProductName: | 20240115150358 |
| ProductVersion: | 2.7.20.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2256 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7048 | "C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe" | C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe | — | explorer.exe | |||||||||||
User: admin Company: HitPaw Integrity Level: MEDIUM Description: HitPaw Video Converter Exit code: 3221226540 Version: 2.7.20.1 Modules
| |||||||||||||||
| 7124 | "C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe" | C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe | explorer.exe | ||||||||||||
User: admin Company: HitPaw Integrity Level: HIGH Description: HitPaw Video Converter Version: 2.7.20.1 Modules
| |||||||||||||||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold |
| Operation: | write | Name: | guid |
Value: AF2CCD08-4CFC-4A8A-803C-358AA354FF3D | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold |
| Operation: | write | Name: | user_id |
Value: 1001 | |||
| (PID) Process: | (7124) hitpaw-video-converter_11724588917790083601.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0 |
| Operation: | write | Name: | GA_PC |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7124 | hitpaw-video-converter_11724588917790083601.exe | C:\Users\admin\AppData\Local\Temp\hitpawvideoconverter_hitpaw\galog.json | binary | |
MD5:1E4D7264CFF74F9ED2148FC103A704CC | SHA256:672AB05001B9E26C69B4B7481186B7FA4B54BC1547C64E3D30D56E2D7C1734E1 | |||
| 7124 | hitpaw-video-converter_11724588917790083601.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97C | der | |
MD5:E9C585C40622CC2DDF6247511987F33A | SHA256:C7E6BA4765E1A4EBE2779D5706BBFD45704BBF8C707CA1FCE523F376CD207E93 | |||
| 7124 | hitpaw-video-converter_11724588917790083601.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97C | binary | |
MD5:BB33F72F5FC03B43790FA37FE52134B1 | SHA256:2C2C930B18441C90942B4961019198F21456C6036B57AA44ED90BE1F9E5F8E0E | |||
| 7124 | hitpaw-video-converter_11724588917790083601.exe | C:\Users\admin\AppData\Local\Temp\hitpawvideoconverter_hitpaw\hitpawvideoconverter_hitpaw_4.3.3.exe.xml | text | |
MD5:8E766266433DD0C327BE8133565394D8 | SHA256:1F05C5936FC52F029012C96D2BCF5FC14F98D5F96D77461292F5799EBD58A136 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7124 | hitpaw-video-converter_11724588917790083601.exe | GET | 301 | 104.17.192.141:80 | http://www.tenorshare.com/downloads/service/softwarelog.txt | unknown | — | — | whitelisted |
7124 | hitpaw-video-converter_11724588917790083601.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D | unknown | — | — | whitelisted |
7124 | hitpaw-video-converter_11724588917790083601.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/csv | unknown | — | — | shared |
6564 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6564 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7124 | hitpaw-video-converter_11724588917790083601.exe | 104.17.192.141:80 | www.tenorshare.com | CLOUDFLARENET | — | unknown |
7124 | hitpaw-video-converter_11724588917790083601.exe | 104.17.192.141:443 | www.tenorshare.com | CLOUDFLARENET | — | unknown |
7124 | hitpaw-video-converter_11724588917790083601.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
7124 | hitpaw-video-converter_11724588917790083601.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
7124 | hitpaw-video-converter_11724588917790083601.exe | 104.18.25.249:443 | update.tenorshare.com | CLOUDFLARENET | — | unknown |
7124 | hitpaw-video-converter_11724588917790083601.exe | 172.217.18.14:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
7124 | hitpaw-video-converter_11724588917790083601.exe | 104.18.2.37:443 | analytics.afirstsoft.cn | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.tenorshare.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ip-api.com |
| shared |
update.tenorshare.com |
| unknown |
www.google-analytics.com |
| whitelisted |
analytics.afirstsoft.cn |
| unknown |
download.hitpaw.com |
| unknown |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7124 | hitpaw-video-converter_11724588917790083601.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
2256 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Check (ip-api .com) |
7124 | hitpaw-video-converter_11724588917790083601.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
7124 | hitpaw-video-converter_11724588917790083601.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
2256 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |