download: | FreeAudioEditor.exe |
Full analysis: | https://app.any.run/tasks/58600db6-dc67-46a7-a00d-0ac05f7f1ed2 |
Verdict: | Malicious activity |
Analysis date: | July 13, 2020, 02:07:05 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 2235D4AB9B8F19DBA66C1EBB17E64E0C |
SHA1: | 39C04B3136AD727B446AD27470A5C9D74E2041DE |
SHA256: | 66EF16F550FD33DE251C62AFA0D76D7D72AD2350A95731CA1E03A7DC16C61E0C |
SSDEEP: | 393216:prfbV3G51J0FK7bnkAyLDeKrl3A2CWT+a9moMv83T1zhLiNHjsWh/8uBVQL4FTR:FfuJ7zyLnNCSlMkhRiNHjJ3QkFTR |
.exe | | | Win32 Executable (generic) (42.6) |
---|---|---|
.exe | | | Win16/32 Executable Delphi generic (19.5) |
.exe | | | Generic Win/DOS Executable (18.9) |
.exe | | | DOS Executable Generic (18.9) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2013:10:13 10:19:32+02:00 |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 65024 |
InitializedDataSize: | 53248 |
UninitializedDataSize: | - |
EntryPoint: | 0x113bc |
OSVersion: | 5 |
ImageVersion: | 6 |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.10.805 |
ProductVersionNumber: | 1.0.10.805 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | DVDVideoSoft Ltd. |
FileDescription: | Free Audio Editor Setup |
FileVersion: | 1.0.10.805 |
LegalCopyright: | |
ProductName: | Free Audio Editor |
ProductVersion: | 1.0.10.805 |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 13-Oct-2013 08:19:32 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | DVDVideoSoft Ltd. |
FileDescription: | Free Audio Editor Setup |
FileVersion: | 1.0.10.805 |
LegalCopyright: | - |
ProductName: | Free Audio Editor |
ProductVersion: | 1.0.10.805 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 8 |
Time date stamp: | 13-Oct-2013 08:19:32 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000F12C | 0x0000F200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39148 |
.itext | 0x00011000 | 0x00000B44 | 0x00000C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.73207 |
.data | 0x00012000 | 0x00000C88 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.24631 |
.bss | 0x00013000 | 0x000056B4 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00019000 | 0x00000DD0 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.97188 |
.tls | 0x0001A000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0001B000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.204488 |
.rsrc | 0x0001C000 | 0x0000B200 | 0x0000B200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.13164 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.11919 | 1512 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4091 | 2.56031 | 104 | UNKNOWN | UNKNOWN | RT_STRING |
4092 | 3.25287 | 212 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 3.26919 | 164 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.33268 | 684 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.34579 | 844 | UNKNOWN | UNKNOWN | RT_STRING |
4096 | 3.28057 | 660 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3884 | "C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe" | C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe | explorer.exe | |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: MEDIUM Description: Free Audio Editor Setup Exit code: 0 Version: 1.0.10.805 | ||||
2296 | "C:\Users\admin\AppData\Local\Temp\is-I4GGB.tmp\FreeAudioEditor.tmp" /SL5="$20138,28256553,119296,C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe" | C:\Users\admin\AppData\Local\Temp\is-I4GGB.tmp\FreeAudioEditor.tmp | — | FreeAudioEditor.exe |
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
1464 | "C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe" /SPAWNWND=$20132 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe | FreeAudioEditor.tmp | |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: HIGH Description: Free Audio Editor Setup Exit code: 0 Version: 1.0.10.805 | ||||
2176 | "C:\Users\admin\AppData\Local\Temp\is-06C3R.tmp\FreeAudioEditor.tmp" /SL5="$3013A,28256553,119296,C:\Users\admin\AppData\Local\Temp\FreeAudioEditor.exe" /SPAWNWND=$20132 /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\is-06C3R.tmp\FreeAudioEditor.tmp | FreeAudioEditor.exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
1540 | "C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer.exe" /pumplogs | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer.exe | — | FreeAudioEditor.tmp |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: HIGH Description: Helper installation utility Version: 2,0,5,805 | ||||
312 | "C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer.exe" | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer.exe | — | FreeAudioEditor.tmp |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: HIGH Description: Helper installation utility Exit code: 0 Version: 2,0,5,805 | ||||
2812 | RunDll32.exe "C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\OCSetupHlp.dll",_RPPID0726RPEng2@16 2176,C2EC3ADE958A478B8974F68704ED0773,DACD3D89F4094897B503E64C9E33862B,00965AACECBB424FB216346169CEF3D5 | C:\Windows\system32\RunDll32.exe | — | FreeAudioEditor.tmp |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3412 | "C:\Program Files\DVDVideoSoft\Free Audio Editor\FreeAudioEditor.exe" --upd | C:\Program Files\DVDVideoSoft\Free Audio Editor\FreeAudioEditor.exe | — | FreeAudioEditor.tmp |
User: admin Company: Digital Wave Ltd. Integrity Level: MEDIUM Description: Free Audio Editor Version: 1,0,10,805 | ||||
2544 | dummy -t stat | C:\Program Files\Common Files\DVDVideoSoft\lib\updhelper.exe | FreeAudioEditor.exe | |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: MEDIUM Description: updhelper Exit code: 0 Version: 1,0,23,805 | ||||
2540 | dummy -t checkver -i 58 -v 1.0.10.805 | C:\Program Files\Common Files\DVDVideoSoft\lib\updhelper.exe | — | FreeAudioEditor.exe |
User: admin Company: DVDVideoSoft Ltd. Integrity Level: MEDIUM Description: updhelper Exit code: 0 Version: 1,0,23,805 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\DVDVideoSoft.SubscriptionMgr.dll | executable | |
MD5:F37CD955358F7D4EFFB6BE835C2A16A9 | SHA256:E945A7DC12B2CC5BDE388ADCE3280F99F205FFD1AD1115F09E1A25D8AE8BCC96 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer_client.dll | executable | |
MD5:7563AA9E2859D7B588C24412F943426E | SHA256:4ACF5A7FBED181320F3019D61985DA2378742FF4B7CD3F49C03B1C7601F67780 | |||
3884 | FreeAudioEditor.exe | C:\Users\admin\AppData\Local\Temp\is-I4GGB.tmp\FreeAudioEditor.tmp | executable | |
MD5:2742F74893E7F35305B64F49C65B4183 | SHA256:9884AE2A23B02866156A5D1285F9A1BB63F94F62908AD47D815E867FECFB57D4 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\ux_optimizer.exe | executable | |
MD5:344D699892ADE7C19C44932CE6CF72D2 | SHA256:62FFC029E108ABF3D48DE378230F8994EFBAB7551B66C5858550EED75E5AD930 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\DVDVideoSoft.EnceladusUtils.dll | executable | |
MD5:FCC07989B8F2F043566F1E3FE49FCC48 | SHA256:AFCC337391E6AE77E2E4A2D6DE980476275D189D4345E3B0378A409D4F50F876 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\SubscriptionMgrBridge.dll | executable | |
MD5:C84643887F1D686057483A6C50D7B8E2 | SHA256:C8500168F9532FF8C075C5B528E92380F03142F258453BACF7063616BF3675D7 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\dvssyshelper.dll | executable | |
MD5:50058DA9BF43DD0454AC62E864F9AED0 | SHA256:593857CA0A952D0F1B9C5ED85269622C3CBAC397BF0CD6243347AD5F50FEEA88 | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\sscrmgr.dll | executable | |
MD5:29F4A03C28421BFF5CF3F2032305A4AC | SHA256:805BD83299EE2B6DF36CEB3596957FE183C875B6490F9AE661CB0743C2D362DC | |||
2176 | FreeAudioEditor.tmp | C:\Users\admin\AppData\Local\Temp\is-36OSK.tmp\msvcm90.dll | executable | |
MD5:399F27D4BF1028EC06CA23D80BA2959B | SHA256:C6C4755C92D52F0B61AB67AC4BFF8F33BE8F91E0F8FC11DB4CEEF3FDE4698219 | |||
1464 | FreeAudioEditor.exe | C:\Users\admin\AppData\Local\Temp\is-06C3R.tmp\FreeAudioEditor.tmp | executable | |
MD5:2742F74893E7F35305B64F49C65B4183 | SHA256:9884AE2A23B02866156A5D1285F9A1BB63F94F62908AD47D815E867FECFB57D4 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2544 | updhelper.exe | GET | 200 | 94.31.29.128:80 | http://tools.dvdvideosoft.com/updates/versions.gz | GB | compressed | 340 b | suspicious |
576 | iexplore.exe | GET | 301 | 104.238.186.214:80 | http://www.dvdvideosoft.com/r/AfterInstall.aspx?ProgramName=FreeAudioEditor&advType=oc | GB | html | 214 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2544 | updhelper.exe | 94.31.29.128:80 | tools.dvdvideosoft.com | netDNA | GB | malicious |
576 | iexplore.exe | 104.238.186.214:443 | www.dvdvideosoft.com | Choopa, LLC | GB | unknown |
576 | iexplore.exe | 104.238.186.214:80 | www.dvdvideosoft.com | Choopa, LLC | GB | unknown |
Domain | IP | Reputation |
---|---|---|
log.dvdvideosoft.com |
| unknown |
api.recommendedsw.com |
| malicious |
tools.dvdvideosoft.com |
| suspicious |
www.dvdvideosoft.com |
| unknown |