File name:

hitpaw-video-converter_11724588917790083601.exe

Full analysis: https://app.any.run/tasks/d1d01361-322f-4c2b-8923-5a2937e04b16
Verdict: Malicious activity
Analysis date: August 25, 2024, 12:46:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

98371061B6E911DAB7951B4A0B009493

SHA1:

8A60162578369C6E1B38D74606322056A54BF945

SHA256:

58C40D074E0C2D03D045925964727C94274DF8CFCFED73FA44EB0A14C4B57AC1

SSDEEP:

98304:nTKdmVALQ0wLJhlwH64Wf4jLZyWDplVHJdVmyRLoOhVmLY3ippdtHQpoLJNpZYV+:TVSQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Reads security settings of Internet Explorer

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Checks Windows Trust Settings

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Checks for external IP

      • svchost.exe (PID: 2256)
      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Potential Corporate Privacy Violation

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
  • INFO

    • Reads Environment values

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Checks supported languages

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Reads the machine GUID from the registry

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Reads the computer name

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Checks proxy server information

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Reads the software policy settings

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Create files in a temporary directory

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Creates files or folders in the user directory

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • Creates files in the program directory

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
    • UPX packer has been detected

      • hitpaw-video-converter_11724588917790083601.exe (PID: 7124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:15 07:04:22+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1597440
InitializedDataSize: 614400
UninitializedDataSize: 1572864
EntryPoint: 0x306910
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.20.1
ProductVersionNumber: 2.7.20.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: HitPaw
FileDescription: HitPaw Video Converter
FileVersion: 2.7.20.1
LegalCopyright: Copyright © 2021-2024 HITPAW CO.,LIMITED All Rights Reserved.
ProductName: 20240115150358
ProductVersion: 2.7.20.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT hitpaw-video-converter_11724588917790083601.exe svchost.exe hitpaw-video-converter_11724588917790083601.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
7048"C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exeexplorer.exe
User:
admin
Company:
HitPaw
Integrity Level:
MEDIUM
Description:
HitPaw Video Converter
Exit code:
3221226540
Version:
2.7.20.1
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-video-converter_11724588917790083601.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7124"C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-video-converter_11724588917790083601.exe
explorer.exe
User:
admin
Company:
HitPaw
Integrity Level:
HIGH
Description:
HitPaw Video Converter
Version:
2.7.20.1
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-video-converter_11724588917790083601.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
1 311
Read events
1 300
Write events
11
Delete events
0

Modification events

(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
AF2CCD08-4CFC-4A8A-803C-358AA354FF3D
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
(PID) Process:(7124) hitpaw-video-converter_11724588917790083601.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
Executable files
0
Suspicious files
2
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
7124hitpaw-video-converter_11724588917790083601.exeC:\Users\admin\AppData\Local\Temp\hitpawvideoconverter_hitpaw\galog.jsonbinary
MD5:1E4D7264CFF74F9ED2148FC103A704CC
SHA256:672AB05001B9E26C69B4B7481186B7FA4B54BC1547C64E3D30D56E2D7C1734E1
7124hitpaw-video-converter_11724588917790083601.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cder
MD5:E9C585C40622CC2DDF6247511987F33A
SHA256:C7E6BA4765E1A4EBE2779D5706BBFD45704BBF8C707CA1FCE523F376CD207E93
7124hitpaw-video-converter_11724588917790083601.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:BB33F72F5FC03B43790FA37FE52134B1
SHA256:2C2C930B18441C90942B4961019198F21456C6036B57AA44ED90BE1F9E5F8E0E
7124hitpaw-video-converter_11724588917790083601.exeC:\Users\admin\AppData\Local\Temp\hitpawvideoconverter_hitpaw\hitpawvideoconverter_hitpaw_4.3.3.exe.xmltext
MD5:8E766266433DD0C327BE8133565394D8
SHA256:1F05C5936FC52F029012C96D2BCF5FC14F98D5F96D77461292F5799EBD58A136
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
47
DNS requests
17
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7124
hitpaw-video-converter_11724588917790083601.exe
GET
301
104.17.192.141:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
whitelisted
7124
hitpaw-video-converter_11724588917790083601.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
7124
hitpaw-video-converter_11724588917790083601.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
shared
6564
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6564
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
7124
hitpaw-video-converter_11724588917790083601.exe
104.17.192.141:80
www.tenorshare.com
CLOUDFLARENET
unknown
7124
hitpaw-video-converter_11724588917790083601.exe
104.17.192.141:443
www.tenorshare.com
CLOUDFLARENET
unknown
7124
hitpaw-video-converter_11724588917790083601.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
7124
hitpaw-video-converter_11724588917790083601.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
7124
hitpaw-video-converter_11724588917790083601.exe
104.18.25.249:443
update.tenorshare.com
CLOUDFLARENET
unknown
7124
hitpaw-video-converter_11724588917790083601.exe
172.217.18.14:443
www.google-analytics.com
GOOGLE
US
whitelisted
7124
hitpaw-video-converter_11724588917790083601.exe
104.18.2.37:443
analytics.afirstsoft.cn
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 172.217.16.142
whitelisted
www.tenorshare.com
  • 104.17.192.141
  • 104.17.207.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
update.tenorshare.com
  • 104.18.25.249
  • 104.18.24.249
unknown
www.google-analytics.com
  • 172.217.18.14
whitelisted
analytics.afirstsoft.cn
  • 104.18.2.37
  • 104.18.3.37
unknown
download.hitpaw.com
  • 104.18.24.102
  • 104.18.25.102
unknown
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

PID
Process
Class
Message
7124
hitpaw-video-converter_11724588917790083601.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2256
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
7124
hitpaw-video-converter_11724588917790083601.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
7124
hitpaw-video-converter_11724588917790083601.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2256
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
2 ETPRO signatures available at the full report
No debug info