File name:

CyberLink_PowerDVD_Downloader.exe

Full analysis: https://app.any.run/tasks/72394889-7ec6-4076-80fd-5e52a3a834ef
Verdict: Malicious activity
Analysis date: February 28, 2020, 10:01:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3E4BA1883CA08652B0910198E820B14A

SHA1:

F1E05FD519EE7E7CC91E1312B57BC4DA8C02C303

SHA256:

6FF5B38F96325A7021B7A3816766785F4661629B1F2E50B5B1D039A3D2F0426F

SSDEEP:

24576:+MkU4waNLeWCAqWVxOZRRarXVhP5AcTOy3jqKSj4coCYHb0YLPF:cJKWV6RRabOyTqKSUcopht

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • setup.exe (PID: 1024)
      • 7z.exe (PID: 3820)
      • vcredist_x86.exe (PID: 3152)
      • vcredist_x86.exe (PID: 944)
      • 7z.exe (PID: 1792)
      • 7z.exe (PID: 348)
      • 7z.exe (PID: 3452)
      • 7z.exe (PID: 2564)
      • 7z.exe (PID: 3752)
      • 7z.exe (PID: 2436)
      • 7z.exe (PID: 2828)
      • 7z.exe (PID: 3284)
      • PowerDVDUtil.exe (PID: 1448)
      • FebEditor.exe (PID: 3752)
      • SearchProtocolHost.exe (PID: 3548)
      • explorer.exe (PID: 372)
      • Regsvr32.exe (PID: 3800)
      • PowerDVDUtil.exe (PID: 2532)
      • Regsvr32.exe (PID: 3024)
      • PowerDVD.exe (PID: 2524)
      • MediaEspresso.exe (PID: 1840)
      • PowerDVD.exe (PID: 2796)
      • PDVDLP.exe (PID: 3304)
      • PowerDVD.exe (PID: 3664)
    • Changes settings of System certificates

      • setup.exe (PID: 1024)
      • vcredist_x86.exe (PID: 3552)
    • Application was dropped or rewritten from another process

      • 7z.exe (PID: 3820)
      • setup.exe (PID: 2720)
      • setup.exe (PID: 1024)
      • vcredist_x86.exe (PID: 3152)
      • vcredist_x86.exe (PID: 3552)
      • 7z.exe (PID: 1792)
      • vcredist_x86.exe (PID: 2468)
      • vcredist_x86.exe (PID: 944)
      • 7z.exe (PID: 348)
      • 7z.exe (PID: 3452)
      • 7z.exe (PID: 2564)
      • 7z.exe (PID: 3284)
      • 7z.exe (PID: 3752)
      • 7z.exe (PID: 2436)
      • 7z.exe (PID: 2828)
      • nsC2E0.tmp (PID: 2748)
      • GenRNKey.exe (PID: 4052)
      • nsE83C.tmp (PID: 3468)
      • nsFA00.tmp (PID: 1744)
      • PowerDVDUtil.exe (PID: 1448)
      • PowerDVDUtil.exe (PID: 2532)
      • MediaEspresso.exe (PID: 1840)
      • PowerDVD.exe (PID: 2524)
      • PowerDVD.exe (PID: 2796)
      • TaskScheduler.exe (PID: 3612)
      • nsAF8.tmp (PID: 780)
      • PowerDVD.exe (PID: 3664)
      • FebEditor.exe (PID: 3752)
      • PDVDLP.exe (PID: 3304)
    • Changes the autorun value in the registry

      • vcredist_x86.exe (PID: 3552)
      • setup.exe (PID: 1024)
      • RUNDLL32.EXE (PID: 2788)
    • Registers / Runs the DLL via REGSVR32.EXE

      • setup.exe (PID: 1024)
    • Loads the Task Scheduler COM API

      • TaskScheduler.exe (PID: 3612)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
      • setup.exe (PID: 1024)
      • PowerDVDUtil.exe (PID: 1448)
      • PowerDVDUtil.exe (PID: 2532)
      • PowerDVD.exe (PID: 2524)
      • PowerDVD.exe (PID: 2796)
      • PowerDVD.exe (PID: 3664)
    • Reads internet explorer settings

      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
    • Executable content was dropped or overwritten

      • PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe (PID: 3356)
      • setup.exe (PID: 1024)
      • 7z.exe (PID: 3820)
      • vcredist_x86.exe (PID: 3152)
      • vcredist_x86.exe (PID: 3552)
      • vcredist_x86.exe (PID: 944)
      • 7z.exe (PID: 1792)
      • msiexec.exe (PID: 2496)
      • 7z.exe (PID: 2564)
      • 7z.exe (PID: 3284)
      • 7z.exe (PID: 2436)
      • 7z.exe (PID: 2828)
      • 7z.exe (PID: 3452)
      • RUNDLL32.EXE (PID: 2788)
    • Creates files in the program directory

      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
      • 7z.exe (PID: 3820)
      • vcredist_x86.exe (PID: 3552)
      • setup.exe (PID: 1024)
      • 7z.exe (PID: 348)
      • 7z.exe (PID: 2564)
      • 7z.exe (PID: 1792)
      • 7z.exe (PID: 3284)
      • 7z.exe (PID: 3752)
      • 7z.exe (PID: 2436)
      • 7z.exe (PID: 2828)
      • PowerDVDUtil.exe (PID: 1448)
      • FebEditor.exe (PID: 3752)
      • GenRNKey.exe (PID: 4052)
      • 7z.exe (PID: 3452)
      • PowerDVDUtil.exe (PID: 2532)
      • PowerDVD.exe (PID: 2524)
      • MediaEspresso.exe (PID: 1840)
    • Reads the cookies of Google Chrome

      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
      • setup.exe (PID: 1024)
      • PowerDVDUtil.exe (PID: 1448)
      • PowerDVDUtil.exe (PID: 2532)
      • PowerDVD.exe (PID: 2524)
      • PowerDVD.exe (PID: 3664)
      • PowerDVD.exe (PID: 2796)
    • Reads the cookies of Mozilla Firefox

      • setup.exe (PID: 1024)
      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
    • Creates files in the user directory

      • setup.exe (PID: 1024)
      • CyberLink_PowerDVD_Downloader.exe (PID: 3736)
    • Adds / modifies Windows certificates

      • setup.exe (PID: 1024)
      • vcredist_x86.exe (PID: 3552)
    • Searches for installed software

      • vcredist_x86.exe (PID: 3552)
      • vcredist_x86.exe (PID: 3152)
      • vcredist_x86.exe (PID: 944)
    • Executed as Windows Service

      • vssvc.exe (PID: 2664)
    • Creates a software uninstall entry

      • vcredist_x86.exe (PID: 3552)
      • setup.exe (PID: 1024)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 2496)
      • RUNDLL32.EXE (PID: 2788)
    • Application launched itself

      • vcredist_x86.exe (PID: 2468)
    • Loads Python modules

      • PowerDVDUtil.exe (PID: 1448)
      • FebEditor.exe (PID: 3752)
      • PowerDVDUtil.exe (PID: 2532)
      • PowerDVD.exe (PID: 2524)
      • MediaEspresso.exe (PID: 1840)
      • PowerDVD.exe (PID: 3664)
      • PowerDVD.exe (PID: 2796)
    • Uses REG.EXE to modify Windows registry

      • setup.exe (PID: 1024)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • setup.exe (PID: 1024)
    • Starts application with an unusual extension

      • setup.exe (PID: 1024)
    • Creates COM task schedule object

      • Regsvr32.exe (PID: 3800)
    • Modifies the open verb of a shell class

      • PowerDVD.exe (PID: 2524)
    • Changes IE settings (feature browser emulation)

      • PowerDVD.exe (PID: 2524)
    • Removes files from Windows directory

      • RUNDLL32.EXE (PID: 2788)
    • Uses RUNDLL32.EXE to load library

      • setup.exe (PID: 1024)
    • Creates files in the driver directory

      • RUNDLL32.EXE (PID: 2788)
    • Executed via Task Scheduler

      • PowerDVD.exe (PID: 2796)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe (PID: 3356)
      • vcredist_x86.exe (PID: 3552)
      • msiexec.exe (PID: 2496)
      • 7z.exe (PID: 3452)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2664)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2496)
    • Reads settings of System Certificates

      • vcredist_x86.exe (PID: 3552)
      • PowerDVDUtil.exe (PID: 1448)
      • PowerDVDUtil.exe (PID: 2532)
      • PowerDVD.exe (PID: 2524)
      • setup.exe (PID: 1024)
      • PowerDVD.exe (PID: 2796)
      • PowerDVD.exe (PID: 3664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:04:16 09:57:52+02:00
PEType: PE32
LinkerVersion: 11
CodeSize: 636928
InitializedDataSize: 520192
UninitializedDataSize: -
EntryPoint: 0x8596e
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.2816
ProductVersionNumber: 3.0.0.2816
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: CyberLink
FileDescription: CyberLink Downloader
FileVersion: 3.0.0.2816
InternalName: CLDownloader
LegalCopyright: Copyright (C) CyberLink Corporation. All rights reserved
OriginalFileName: CLDownloader.exe
ProductName: CLDownloader
ProductVersion: 3.0.0.2816
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
64
Malicious processes
21
Suspicious processes
10

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start cyberlink_powerdvd_downloader.exe powerdvd_19.0.2022.62_essential_dvd190822-02.exe setup.exe no specs setup.exe 7z.exe vcredist_x86.exe vcredist_x86.exe vssvc.exe no specs msiexec.exe vcredist_x86.exe no specs vcredist_x86.exe 7z.exe 7z.exe no specs 7z.exe 7z.exe 7z.exe 7z.exe no specs 7z.exe 7z.exe powerdvdutil.exe febeditor.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs searchprotocolhost.exe no specs explorer.exe no specs regedit.exe regedit.exe regedit.exe regedit.exe regedit.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe no specs nsc2e0.tmp no specs genrnkey.exe no specs regsvr32.exe no specs regsvr32.exe nse83c.tmp no specs powerdvdutil.exe nsfa00.tmp no specs powerdvd.exe nsaf8.tmp no specs mediaespresso.exe no specs rundll32.exe runonce.exe no specs grpconv.exe no specs taskscheduler.exe no specs powerdvd.exe pdvdlp.exe no specs powerdvd.exe

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Windows\Regedit.exe" /s "C:\Program Files\CyberLink\PowerDVD19\discProfile.reg"C:\Windows\Regedit.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
348"C:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exe" x "C:\Users\admin\AppData\Local\Temp\RarSFX0\Data2.7z" -o"C:\Program Files\CyberLink\PowerDVD19\MediaEspresso" -aoaC:\Users\admin\AppData\Local\Temp\RarSFX0\7z.exesetup.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\7z.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
372C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
780"C:\Users\admin\AppData\Local\Temp\nsu823F.tmp\nsAF8.tmp" C:\Program Files\CyberLink\PowerDVD19\MediaEspresso\MediaEspresso.exe install koanpath="C:\Program Files\CyberLink\PowerDVD19\Common\Koan"C:\Users\admin\AppData\Local\Temp\nsu823F.tmp\nsAF8.tmpsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsu823f.tmp\nsaf8.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
940"C:\Windows\system32\reg.exe" unload HKEY_USERS\PowerDVD_HIVEC:\Windows\system32\reg.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
944"C:\Users\admin\AppData\Local\Temp\RarSFX0\Setup\RunTime\VC2017_x86\vcredist_x86.exe" /quiet /norestart -burn.unelevated BurnPipe.{C80C105D-405D-4C32-9B5B-A8F59C671E29} {823BCCFC-4B18-40FB-B339-ACBF1E8F49F7} 2468C:\Users\admin\AppData\Local\Temp\RarSFX0\Setup\RunTime\VC2017_x86\vcredist_x86.exe
vcredist_x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325
Exit code:
1638
Version:
14.11.25325.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\setup\runtime\vc2017_x86\vcredist_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1024"C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\setup.exe
PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
User:
admin
Company:
CyberLink Corp.
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1168"C:\Windows\Regedit.exe" /s "C:\Program Files\CyberLink\PowerDVD19\Kanten.reg"C:\Windows\Regedit.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1448"C:\Program Files\CyberLink\PowerDVD19\PowerDVDUtil.exe" febeditor "C:\Program Files\CyberLink\PowerDVD19\SRExport.ini"C:\Program Files\CyberLink\PowerDVD19\PowerDVDUtil.exe
setup.exe
User:
admin
Company:
CyberLink Corp.
Integrity Level:
HIGH
Description:
PowerDVD 19
Exit code:
0
Version:
19.0.50846.10308
Modules
Images
c:\program files\cyberlink\powerdvd19\powerdvdutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1744"C:\Users\admin\AppData\Local\Temp\nsu823F.tmp\nsFA00.tmp" C:\Program Files\CyberLink\PowerDVD19\PowerDVD.exe installC:\Users\admin\AppData\Local\Temp\nsu823F.tmp\nsFA00.tmpsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsu823f.tmp\nsfa00.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
6 002
Read events
3 582
Write events
2 369
Delete events
51

Modification events

(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\CyberLink\CBE
Operation:writeName:UUID
Value:
S-1-5-21-1302019708-1500728564-335382590-1000-4C8AA8E3-3CD5-4B3C-BC3A-AFA3BD27BB5A
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3736) CyberLink_PowerDVD_Downloader.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\PloreYvax_CbjreQIQ_Qbjaybnqre.rkr
Value:
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
Executable files
703
Suspicious files
480
Text files
2 226
Unknown types
333

Dropped files

PID
Process
Filename
Type
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Local\Temp\Cab8C0C.tmp
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Local\Temp\Tar8C0D.tmp
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\MH99SGTD.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\DVDIF4D8.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\AMQLX44Y.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\V2M74TCE.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\G10JZVFE.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\5O7DEXY5.txt
MD5:
SHA256:
3736CyberLink_PowerDVD_Downloader.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\IUDZ9PGM.txt
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
44
TCP/UDP connections
39
DNS requests
21
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3736
CyberLink_PowerDVD_Downloader.exe
GET
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
GET
206
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
binary
4.00 Mb
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
GET
200
2.16.106.186:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.4 Kb
whitelisted
3736
CyberLink_PowerDVD_Downloader.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D
US
der
727 b
whitelisted
3736
CyberLink_PowerDVD_Downloader.exe
GET
206
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
binary
4.00 Mb
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
GET
304
2.16.106.186:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.4 Kb
whitelisted
3736
CyberLink_PowerDVD_Downloader.exe
GET
206
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
binary
4.00 Mb
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
GET
206
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
binary
4.00 Mb
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEQDr6RCTje23Ge7S31mlTAMY
US
der
472 b
whitelisted
3736
CyberLink_PowerDVD_Downloader.exe
GET
206
216.66.85.86:80
http://update.cyberlink.com/Retail/PowerDVD/OFXOZBBEB6T2/PowerDVD_19.0.2022.62_Essential_DVD190822-02.exe
US
binary
4.00 Mb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3736
CyberLink_PowerDVD_Downloader.exe
52.27.166.0:443
dna.cyberlink.com
Amazon.com, Inc.
US
unknown
3736
CyberLink_PowerDVD_Downloader.exe
63.34.151.173:443
downloader.cyberlink.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
unknown
3736
CyberLink_PowerDVD_Downloader.exe
151.139.128.14:80
ocsp.usertrust.com
Highwinds Network Group, Inc.
US
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
2.16.106.186:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
3736
CyberLink_PowerDVD_Downloader.exe
216.66.85.86:80
update.cyberlink.com
Hurricane Electric, Inc.
US
suspicious
3736
CyberLink_PowerDVD_Downloader.exe
65.19.143.73:443
liveupdate.cyberlink.com
Hurricane Electric, Inc.
US
unknown
1024
setup.exe
52.88.16.80:443
dna.cyberlink.com
Amazon.com, Inc.
US
unknown
3552
vcredist_x86.exe
2.16.186.120:80
crl.microsoft.com
Akamai International B.V.
whitelisted
1448
PowerDVDUtil.exe
52.27.166.0:443
dna.cyberlink.com
Amazon.com, Inc.
US
unknown
1448
PowerDVDUtil.exe
203.73.25.229:443
crc.cyberlink.com
Digital United Inc.
TW
unknown

DNS requests

Domain
IP
Reputation
dna.cyberlink.com
  • 52.27.166.0
  • 35.164.180.174
  • 52.88.16.80
suspicious
downloader.cyberlink.com
  • 63.34.151.173
malicious
ocsp.usertrust.com
  • 151.139.128.14
whitelisted
ocsp.comodoca.com
  • 151.139.128.14
whitelisted
www.download.windowsupdate.com
  • 2.16.106.186
  • 2.16.106.233
whitelisted
update.cyberlink.com
  • 216.66.85.86
  • 65.19.143.105
suspicious
www.cyberlink.com
  • 63.34.151.173
suspicious
liveupdate.cyberlink.com
  • 65.19.143.73
unknown
track.cyberlink.com
  • 63.34.151.173
suspicious
ocsp.msocsp.com
  • 104.18.24.243
  • 104.18.25.243
whitelisted

Threats

PID
Process
Class
Message
3736
CyberLink_PowerDVD_Downloader.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3736
CyberLink_PowerDVD_Downloader.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
setup.exe
[UpdateThread] Image: 655694, Title: 262624, Wording: 262628, Show: 1
setup.exe
[UpdateThread] Patch INI:
setup.exe
[UpdateThread] Image Folder: C:\Users\admin\AppData\Local\Temp\RarSFX0\Setup\Utility\Promotion\image
setup.exe
[UpdateThread] Page 1 Wording: The next wave in superior definition entertainment is here with 8K video. PowerDVD supports both 4K, HDR && now 8K video file playback.
setup.exe
[UpdateThread] Install Path C:\Program Files\CyberLink\PowerDVD19, Total File count 3136
setup.exe
[UpdateThread] Page 1 Image: C:\Users\admin\AppData\Local\Temp\RarSFX0\Setup\Utility\Promotion\image\image_001.jpg
setup.exe
[UpdateThread] Page Count: 5, Freq: 5
setup.exe
[UpdateThread] Image Width: 450, Height: 309
setup.exe
[UpdateThread] StartUpdate
setup.exe
[UpdateThread] Image Folder: C:\Users\admin\AppData\Local\Temp\RarSFX0\Setup\Utility\Promotion\image