| URL: | easeus.com |
| Full analysis: | https://app.any.run/tasks/087a3949-77e9-4816-8d30-28385e7a4f62 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | July 17, 2025, 21:19:45 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | EAF9DE556349DB0CD65FDB5ED54BE0F8 |
| SHA1: | 9F5248E8838AB0664EECAC67E6CB9DD1B0293031 |
| SHA256: | 58E1B1B6E4C07E3042D658DB037FD883AF98F6FF8F7A5400D8A73837A044ED07 |
| SSDEEP: | 3:hW1z:Kz |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 420 | "taskkill.exe" /f /im AliyunWrapExe.exe | C:\Windows\System32\taskkill.exe | — | epm1960_trial_B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 480 | findstr /I "EPMUI.exe" | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 592 | cmd.exe /c tasklist /FI "IMAGENAME eq AliyunWrapExe.exe" | findstr /I "AliyunWrapExe.exe" | C:\Windows\SysWOW64\cmd.exe | — | epm1960_trial_B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 700 | "C:\Users\admin\AppData\Local\Temp\is-69R5Q.tmp\epm1960_trial_B.tmp" /SL5="$D0314,168312517,1216000,C:\Users\admin\Downloads\epm1960_trial_B.exe" /verysilent /norestart /log Installer /DIR="C:\Program Files\EaseUS\EaseUS Partition Master" /LANG=English agreeImprove=true GUID=S-1-5-21-1693682860-607145093-2874071422-1001 xurlID=17527872497731b393 TestID=b89 | C:\Users\admin\AppData\Local\Temp\is-69R5Q.tmp\epm1960_trial_B.tmp | epm1960_trial_B.exe | ||||||||||||
User: admin Company: EaseUS Integrity Level: HIGH Description: Setup/Uninstall Version: 51.1052.0.0 Modules
| |||||||||||||||
| 868 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=8776,i,13748674395944553403,10318754656495419291,262144 --variations-seed-version --mojo-platform-channel-handle=6592 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 1068 | helper 105 0x498 | C:\Users\admin\AppData\Local\Temp\is-EK88Q.tmp\_isetup\_setup64.tmp | — | epm1960_trial_B.tmp | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 1324 | "C:\Users\admin\Downloads\epm_trial_installer.17527872497731b393.exe" | C:\Users\admin\Downloads\epm_trial_installer.17527872497731b393.exe | — | msedge.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1356 | /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"6.47MB\",\"Cdn\":\"https://d1.easeus.com/epm/trial/epm1960_trial_B.exe\",\"Elapsedtime\":\"25\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1440 | /Uid "S-1-5-21-1693682860-607145093-2874071422-1001" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1512 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | taskkill.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 40FA90DABC982F00 | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {462F5A61-D855-4779-9DD5-9D4347D3D160} | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {AB29A217-9A28-4B30-A39D-CA2EAFFEA7D1} | |||
| (PID) Process: | (5436) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\394002 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {3A35E64B-F522-4B76-88C3-6FC4FFCE943E} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d982.TMP | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF18d982.TMP | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF18d9b1.TMP | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d9b1.TMP | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18d9c1.TMP | — | |
MD5:— | SHA256:— | |||
| 5436 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6264 | msedge.exe | GET | 200 | 150.171.28.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:j59dEBIlYuZ1qtlKty3ceLZmZNMhCTNuXLP1e4uaRMo&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
4912 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3108 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
3108 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7272 | svchost.exe | HEAD | 200 | 208.89.74.21:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1753351992&P2=404&P3=2&P4=GJFhCYGrKcMv5dSsAfEvHXlVn6hLeOEWtsG6HXJ3e6KII2qzmn%2fkPlL9%2bq1svRb%2fyjXP%2f4nE2JSo5HGhZVGTwQ%3d%3d | unknown | — | — | whitelisted |
1948 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
7272 | svchost.exe | GET | 206 | 208.89.74.21:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1753351992&P2=404&P3=2&P4=GJFhCYGrKcMv5dSsAfEvHXlVn6hLeOEWtsG6HXJ3e6KII2qzmn%2fkPlL9%2bq1svRb%2fyjXP%2f4nE2JSo5HGhZVGTwQ%3d%3d | unknown | — | — | whitelisted |
7272 | svchost.exe | GET | 206 | 208.89.74.21:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1753351992&P2=404&P3=2&P4=GJFhCYGrKcMv5dSsAfEvHXlVn6hLeOEWtsG6HXJ3e6KII2qzmn%2fkPlL9%2bq1svRb%2fyjXP%2f4nE2JSo5HGhZVGTwQ%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4172 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6264 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6264 | msedge.exe | 150.171.28.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6264 | msedge.exe | 54.190.248.124:443 | easeus.com | AMAZON-02 | US | unknown |
6264 | msedge.exe | 54.190.248.124:80 | easeus.com | AMAZON-02 | US | unknown |
6264 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
easeus.com |
| unknown |
copilot.microsoft.com |
| whitelisted |
www.easeus.com |
| whitelisted |
www.bing.com |
| whitelisted |
mail.easeus.com |
| unknown |
xpaywalletcdn.azureedge.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6264 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
Process | Message |
|---|---|
EDownloader.exe | [6544]-21:20:58:658 ParseCmdLine param=EXEDIR=C:\Users\admin\Downloads ||| EXENAME=epm_trial_installer.17527872497731b393.exe ||| DOWNLOAD_VERSION=trial ||| PRODUCT_VERSION=2.2.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [6544]-21:20:58:659 CTools::loadIni configPath=C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.2.0\5trial\InitConfigure.ini
|
EDownloader.exe | [3656]-21:20:59:117 Json parse Data Start
|
EDownloader.exe | [3656]-21:20:59:118 Json url: http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17527872497731b393&lang=English&pcVersion=home&pid=5&tid=1&version=trial
|
EDownloader.exe | [3656]-21:20:59:118 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=17527872497731b393&lang=English&pcVersion=home&pid=5&tid=1&version=trial
|
AliyunWrapExe.exe | PostLogResult->statusCode= |
AliyunWrapExe.exe | 200 |
AliyunWrapExe.exe | |
AliyunWrapExe.exe | PostLogResult->requestID= |
AliyunWrapExe.exe | x-log-requestid: 6879693CB2BEF1501352FAA9
|