| File name: | TB_Free_Installer_20240309.8756.exe |
| Full analysis: | https://app.any.run/tasks/9c6f91c0-0cca-436f-abd9-90610fea45a1 |
| Verdict: | Malicious activity |
| Analysis date: | March 09, 2024, 19:13:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | B9A625522B3DBDE8B3DAF4CDA02AA696 |
| SHA1: | A9D8CF95D8BB989FFAE0F9B07FEA292CA16D7A93 |
| SHA256: | 7898ACFCC553E78206FA6EF705BF1F1EABE04F3A37F774B03EA57D11163D669E |
| SSDEEP: | 98304:OKEaB1r/sNZEbLyUdNqR5+8cPeEqO0qAVLgctuCuswgGe25sTwaT0o+ssv6OqIPl:T |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 03:57:48+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | /SendInfo Window "Home_Installer" Activity "Result_Download_Configurefile" Attribute "{\"CDN\":\"http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/\",\"Elapsed\":\"3\",\"Errorinfo\":\"0\",\"PostURL\":\"http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=8756&lang=English&pcVersion=home&pid=3&tid=1&version=free\",\"ResponseJson\":\"{\\"check\\":1,\\"msg\\":\\"\\u6210\\u529f\\",\\"data\\":{\\"pid\\":\\"3\\",\\"version\\":\\"free\\",\\"tj_download\\":\\"test\\",\\"referNumber\\":\\"1000000\\",\\"killSwitch\\":\\"true\\",\\"WriteLogSwitch\\":\\"false\\",\\"curNum\\":\\"2024\\",\\"testid\\":\\"123\\",\\"configid\\":\\"\\",\\"md5\\":\\"A78798643AC0FFE5765110D598F79549\\",\\"download\\":\\"https:\\/\\/d1.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"download2\\":\\"https:\\/\\/d2.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"download3\\":\\"https:\\/\\/d3.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"url\\":[]},\\"time\\":1710011613}\",\"Result\":\"Success\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1340 | /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"1.72MB\",\"Cdn\":\"https://d1.easeus.com/tb/free/TodoBackup16.1.1_free.exe\",\"Elapsedtime\":\"86\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2036 | "C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe" | C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2240 | /verysilent /DIR="C:\Program Files\EaseUS\Todo Backup" /IMAGEPATH="C:\My Backups" /LANG=English agreeImprove=true GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=8756 | C:\Users\admin\Desktop\TB_free_easeus.exe | EDownloader.exe | ||||||||||||
User: admin Company: EaseUS Integrity Level: HIGH Description: EaseUS Todo Backup Free Setup Exit code: 0 Version: 16.1 Modules
| |||||||||||||||
| 2328 | /SendInfo Window "Web_Installer" Activity "Result_Run_Installer" Attribute "{\"Country\":\"United States\",\"Timezone\":\"GMT-00:00\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe" | C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2592 | /SendInfo Window "Installing" Activity "Info_Start_Install_Program" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2624 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\EDownloader.exe" EXEDIR=C:\Users\admin\Desktop ||| EXENAME=TB_Free_Installer_20240309.8756.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\EDownloader.exe | TB_Free_Installer_20240309.8756.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3180 | /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Pageid\":\"8756\",\"Version\":\"free\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (2624) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\skin.zip | compressed | |
MD5:6128C00BD164D955181B086094E5FC71 | SHA256:93F8192AF82712DF7EEEADBBC8DDCBDD4F8338AF96015E4ED11EF7FC9AB09696 | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Chinese.ini | text | |
MD5:2C1109202C5BD64CFBD15440DBFB9E15 | SHA256:503DED4C87EC70CF80920CD35985A34A7F7DF4280E8ACD2915BB105140057AA4 | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\French.ini | text | |
MD5:5CF7184F2D6C19608D287EAE33B1D678 | SHA256:7AB67D4EB16F742235309A0A55EAFAC60B39A79D842C84A285A1D62061A9D7EB | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Malay.ini | text | |
MD5:AA4398D7E7503A3EDDEF6A62CC6079BF | SHA256:8848BF068AC126D90F8FD3A4A376F2F386414C8C64AB7430C19085DDB0EA835A | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\German.ini | text | |
MD5:11847D6DED619EF00FE65D073DCA2395 | SHA256:432729DF19211765091F56578437A3564667572430B36DFF2BF48B28F15A0C06 | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\InitConfigure.ini | ini | |
MD5:A85F9ACC64DF19C2295A51EABE505AC5 | SHA256:211A2504C0CFE8E28BC32DE9FC6065150E1D94B24573A96B43684CB0A1A6D258 | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Italian.ini | text | |
MD5:528492B1C61DD427C0030AF1E85021CB | SHA256:2E31D7ACE9D3417EBA9BC93E44C645D5783C23F2C6570807BCC48E94ADE2C857 | |||
| 2036 | TB_Free_Installer_20240309.8756.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Japanese.ini | text | |
MD5:D7E405065BB8CBF3666DB39FBD1FA1D1 | SHA256:31493DBDF2D62781A76AD0785F33E83EADFC7C201AFC9ADF6ACFDAD6C9F3555A | |||
| 2964 | EDownloader.exe | C:\Users\admin\Desktop\TB_free_easeus.exe.temp | — | |
MD5:— | SHA256:— | |||
| 2964 | EDownloader.exe | C:\Users\admin\Desktop\TB_free_easeus.exe | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2964 | EDownloader.exe | POST | 200 | 18.172.112.107:80 | http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ | unknown | binary | 495 b | unknown |
2624 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
2624 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
— | — | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
— | — | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
2624 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
2624 | AliyunWrapExe.Exe | GET | 200 | 163.171.156.15:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0 | unknown | binary | 21 b | unknown |
2624 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.15:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2964 | EDownloader.exe | 18.172.112.107:80 | download.easeus.com | — | US | unknown |
2624 | AliyunWrapExe.Exe | 163.171.156.15:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
2624 | AliyunWrapExe.Exe | 47.252.97.15:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
2964 | EDownloader.exe | 108.156.60.68:443 | d1.easeus.com | AMAZON-02 | US | unknown |
2964 | EDownloader.exe | 18.164.52.41:443 | d1.easeus.com | — | US | unknown |
2964 | EDownloader.exe | 18.164.52.75:443 | d1.easeus.com | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
download.easeus.com |
| unknown |
track.easeus.com |
| unknown |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
d1.easeus.com |
| unknown |