File name:

TB_Free_Installer_20240309.8756.exe

Full analysis: https://app.any.run/tasks/9c6f91c0-0cca-436f-abd9-90610fea45a1
Verdict: Malicious activity
Analysis date: March 09, 2024, 19:13:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

B9A625522B3DBDE8B3DAF4CDA02AA696

SHA1:

A9D8CF95D8BB989FFAE0F9B07FEA292CA16D7A93

SHA256:

7898ACFCC553E78206FA6EF705BF1F1EABE04F3A37F774B03EA57D11163D669E

SSDEEP:

98304:OKEaB1r/sNZEbLyUdNqR5+8cPeEqO0qAVLgctuCuswgGe25sTwaT0o+ssv6OqIPl:T

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • TB_free_easeus.exe (PID: 2240)
      • TB_free_easeus.tmp (PID: 3540)
    • Actions looks like stealing of personal data

      • TB_free_easeus.tmp (PID: 3540)
    • Creates a writable file in the system directory

      • TB_free_easeus.tmp (PID: 3540)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • TB_free_easeus.tmp (PID: 3540)
      • TB_free_easeus.exe (PID: 2240)
    • Reads the Internet Settings

      • AliyunWrapExe.Exe (PID: 2624)
      • EDownloader.exe (PID: 2964)
    • Reads security settings of Internet Explorer

      • AliyunWrapExe.Exe (PID: 2624)
      • EDownloader.exe (PID: 2964)
    • Reads Internet Explorer settings

      • EDownloader.exe (PID: 2964)
    • Process drops legitimate windows executable

      • TB_free_easeus.tmp (PID: 3540)
    • Reads the Windows owner or organization settings

      • TB_free_easeus.tmp (PID: 3540)
    • Reads Microsoft Outlook installation path

      • EDownloader.exe (PID: 2964)
    • Drops a system driver (possible attempt to evade defenses)

      • TB_free_easeus.tmp (PID: 3540)
    • Drops 7-zip archiver for unpacking

      • TB_free_easeus.tmp (PID: 3540)
    • The process drops C-runtime libraries

      • TB_free_easeus.tmp (PID: 3540)
    • Creates files in the driver directory

      • TB_free_easeus.tmp (PID: 3540)
    • Process checks presence of unattended files

      • TB_free_easeus.tmp (PID: 3540)
  • INFO

    • Checks supported languages

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • EDownloader.exe (PID: 2964)
      • InfoForSetup.exe (PID: 3848)
      • InfoForSetup.exe (PID: 2328)
      • AliyunWrapExe.Exe (PID: 2624)
      • InfoForSetup.exe (PID: 116)
      • InfoForSetup.exe (PID: 3180)
      • TB_free_easeus.exe (PID: 2240)
      • InfoForSetup.exe (PID: 1340)
      • InfoForSetup.exe (PID: 2592)
      • TB_free_easeus.tmp (PID: 3540)
      • InfoForSetup.exe (PID: 3488)
    • Reads the computer name

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • EDownloader.exe (PID: 2964)
      • AliyunWrapExe.Exe (PID: 2624)
      • TB_free_easeus.tmp (PID: 3540)
    • Dropped object may contain TOR URL's

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • TB_free_easeus.tmp (PID: 3540)
    • Create files in a temporary directory

      • TB_Free_Installer_20240309.8756.exe (PID: 2036)
      • EDownloader.exe (PID: 2964)
      • InfoForSetup.exe (PID: 2328)
      • TB_free_easeus.exe (PID: 2240)
      • TB_free_easeus.tmp (PID: 3540)
      • AliyunWrapExe.Exe (PID: 2624)
    • Checks proxy server information

      • AliyunWrapExe.Exe (PID: 2624)
      • EDownloader.exe (PID: 2964)
    • Reads the machine GUID from the registry

      • AliyunWrapExe.Exe (PID: 2624)
      • EDownloader.exe (PID: 2964)
    • Creates files or folders in the user directory

      • AliyunWrapExe.Exe (PID: 2624)
    • Creates files in the program directory

      • TB_free_easeus.tmp (PID: 3540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 03:57:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 186368
UninitializedDataSize: 2048
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
13
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start tb_free_installer_20240309.8756.exe edownloader.exe infoforsetup.exe no specs infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs tb_free_easeus.exe infoforsetup.exe no specs tb_free_easeus.tmp tb_free_installer_20240309.8756.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116 /SendInfo Window "Home_Installer" Activity "Result_Download_Configurefile" Attribute "{\"CDN\":\"http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/\",\"Elapsed\":\"3\",\"Errorinfo\":\"0\",\"PostURL\":\"http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=8756&lang=English&pcVersion=home&pid=3&tid=1&version=free\",\"ResponseJson\":\"{\\"check\\":1,\\"msg\\":\\"\\u6210\\u529f\\",\\"data\\":{\\"pid\\":\\"3\\",\\"version\\":\\"free\\",\\"tj_download\\":\\"test\\",\\"referNumber\\":\\"1000000\\",\\"killSwitch\\":\\"true\\",\\"WriteLogSwitch\\":\\"false\\",\\"curNum\\":\\"2024\\",\\"testid\\":\\"123\\",\\"configid\\":\\"\\",\\"md5\\":\\"A78798643AC0FFE5765110D598F79549\\",\\"download\\":\\"https:\\/\\/d1.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"download2\\":\\"https:\\/\\/d2.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"download3\\":\\"https:\\/\\/d3.easeus.com\\/tb\\/free\\/TodoBackup16.1.1_free.exe\\",\\"url\\":[]},\\"time\\":1710011613}\",\"Result\":\"Success\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1340 /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"1.72MB\",\"Cdn\":\"https://d1.easeus.com/tb/free/TodoBackup16.1.1_free.exe\",\"Elapsedtime\":\"86\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2036"C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe" C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\tb_free_installer_20240309.8756.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2240 /verysilent /DIR="C:\Program Files\EaseUS\Todo Backup" /IMAGEPATH="C:\My Backups" /LANG=English agreeImprove=true GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=8756 C:\Users\admin\Desktop\TB_free_easeus.exe
EDownloader.exe
User:
admin
Company:
EaseUS
Integrity Level:
HIGH
Description:
EaseUS Todo Backup Free Setup
Exit code:
0
Version:
16.1
Modules
Images
c:\users\admin\desktop\tb_free_easeus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2328 /SendInfo Window "Web_Installer" Activity "Result_Run_Installer" Attribute "{\"Country\":\"United States\",\"Timezone\":\"GMT-00:00\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2472"C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exe" C:\Users\admin\Desktop\TB_Free_Installer_20240309.8756.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\tb_free_installer_20240309.8756.exe
c:\windows\system32\ntdll.dll
2592 /SendInfo Window "Installing" Activity "Info_Start_Install_Program"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2624C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2964"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\EDownloader.exe" EXEDIR=C:\Users\admin\Desktop ||| EXENAME=TB_Free_Installer_20240309.8756.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\EDownloader.exe
TB_Free_Installer_20240309.8756.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\edownloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3180 /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Pageid\":\"8756\",\"Version\":\"free\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\3free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
4 302
Read events
4 243
Write events
48
Delete events
11

Modification events

(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2624) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
1 180
Suspicious files
203
Text files
549
Unknown types
90

Dropped files

PID
Process
Filename
Type
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\skin.zipcompressed
MD5:6128C00BD164D955181B086094E5FC71
SHA256:93F8192AF82712DF7EEEADBBC8DDCBDD4F8338AF96015E4ED11EF7FC9AB09696
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Chinese.initext
MD5:2C1109202C5BD64CFBD15440DBFB9E15
SHA256:503DED4C87EC70CF80920CD35985A34A7F7DF4280E8ACD2915BB105140057AA4
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\French.initext
MD5:5CF7184F2D6C19608D287EAE33B1D678
SHA256:7AB67D4EB16F742235309A0A55EAFAC60B39A79D842C84A285A1D62061A9D7EB
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Malay.initext
MD5:AA4398D7E7503A3EDDEF6A62CC6079BF
SHA256:8848BF068AC126D90F8FD3A4A376F2F386414C8C64AB7430C19085DDB0EA835A
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\German.initext
MD5:11847D6DED619EF00FE65D073DCA2395
SHA256:432729DF19211765091F56578437A3564667572430B36DFF2BF48B28F15A0C06
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\InitConfigure.iniini
MD5:A85F9ACC64DF19C2295A51EABE505AC5
SHA256:211A2504C0CFE8E28BC32DE9FC6065150E1D94B24573A96B43684CB0A1A6D258
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Italian.initext
MD5:528492B1C61DD427C0030AF1E85021CB
SHA256:2E31D7ACE9D3417EBA9BC93E44C645D5783C23F2C6570807BCC48E94ADE2C857
2036TB_Free_Installer_20240309.8756.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\3free\Japanese.initext
MD5:D7E405065BB8CBF3666DB39FBD1FA1D1
SHA256:31493DBDF2D62781A76AD0785F33E83EADFC7C201AFC9ADF6ACFDAD6C9F3555A
2964EDownloader.exeC:\Users\admin\Desktop\TB_free_easeus.exe.temp
MD5:
SHA256:
2964EDownloader.exeC:\Users\admin\Desktop\TB_free_easeus.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
28
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2964
EDownloader.exe
POST
200
18.172.112.107:80
http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
unknown
binary
495 b
unknown
2624
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
2624
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
2624
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
2624
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
unknown
binary
21 b
unknown
2624
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_tbp_downloader/shards/lb
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2964
EDownloader.exe
18.172.112.107:80
download.easeus.com
US
unknown
2624
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
2624
AliyunWrapExe.Exe
47.252.97.15:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
2964
EDownloader.exe
108.156.60.68:443
d1.easeus.com
AMAZON-02
US
unknown
2964
EDownloader.exe
18.164.52.41:443
d1.easeus.com
US
unknown
2964
EDownloader.exe
18.164.52.75:443
d1.easeus.com
US
unknown

DNS requests

Domain
IP
Reputation
download.easeus.com
  • 18.172.112.107
  • 18.172.112.32
  • 18.172.112.26
  • 18.172.112.123
unknown
track.easeus.com
  • 163.171.156.15
unknown
easeusinfo.us-east-1.log.aliyuncs.com
  • 47.252.97.15
  • 47.252.97.9
  • 47.252.97.12
  • 47.252.97.8
  • 47.252.97.212
  • 47.252.97.13
  • 47.252.97.11
  • 47.252.97.14
  • 47.252.97.10
unknown
d1.easeus.com
  • 108.156.60.68
  • 108.156.60.101
  • 108.156.60.9
  • 108.156.60.79
  • 18.164.52.41
  • 18.164.52.75
  • 18.164.52.19
  • 18.164.52.73
unknown

Threats

No threats detected
No debug info