File name: | Wondershare Filmora X 1351 Crack License Key Free 2024.exe |
Full analysis: | https://app.any.run/tasks/67abc93f-6a55-42ec-888f-42bd96054917 |
Verdict: | Malicious activity |
Analysis date: | July 29, 2024, 14:29:04 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 33BCB7894ABCE38380C1757EB2C24B4A |
SHA1: | 0EAAFEF2BC46328144F43E434DC9B8DA43EC930E |
SHA256: | 7C7B89F9BB99CD522DAB7860F9B886581C5658F2E2A4AC22D8B3EC2D20AB2B92 |
SSDEEP: | 49152:hdixrq3BdwVSYUJ/42v76k4RFrSnIhVha3DzNvSmG5PmaHX5Y7+rAM5QFLY7Yph+:Wrq3BdwRwXD6k4RFroI8fZG5j35s+rT3 |
.exe | | | Inno Setup installer (53.5) |
---|---|---|
.exe | | | InstallShield setup (21) |
.exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
.exe | | | Win32 Executable (generic) (2.1) |
.exe | | | Win16/32 Executable Delphi generic (1) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:06:10 14:47:11+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 685056 |
InitializedDataSize: | 90112 |
UninitializedDataSize: | - |
EntryPoint: | 0xa83bc |
OSVersion: | 6.1 |
ImageVersion: | - |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 6.5.0.0 |
ProductVersionNumber: | 6.5.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | |
FileDescription: | Wondershare Filmora X 1351 Crack License Key Free 2024.exe |
FileVersion: | 6.5.0.0 |
LegalCopyright: | Wondershare Filmora X 1351 Crack License Key Free 2024.exe |
OriginalFileName: | |
ProductName: | Wondershare Filmora X 1351 Crack License Key Free 2024.exe |
ProductVersion: | 6.5.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1112 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x328,0x32c,0x330,0x320,0x338,0x7ffeffa05fd8,0x7ffeffa05fe4,0x7ffeffa05ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
1128 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3440 --field-trial-handle=2372,i,14676883063690979535,14359758164039464081,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
1156 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4040 --field-trial-handle=2372,i,14676883063690979535,14359758164039464081,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
2284 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2292 | "C:\Users\admin\AppData\Local\Temp\Wondershare Filmora X 1351 Crack License Key Free 2024.exe" /SPAWNWND=$9046C /NOTIFYWND=$E0228 | C:\Users\admin\AppData\Local\Temp\Wondershare Filmora X 1351 Crack License Key Free 2024.exe | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Wondershare Filmora X 1351 Crack License Key Free 2024.exe Exit code: 0 Version: 6.5.0.0 Modules
| |||||||||||||||
2368 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://canvaspart.icu/tracker/thank_you.php?trk=2816 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
2984 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2632 --field-trial-handle=2372,i,14676883063690979535,14359758164039464081,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
3536 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2312 --field-trial-handle=2316,i,891589076061965233,13756487724620500070,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
3548 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4980 --field-trial-handle=2300,i,11130238420511565767,15696956800957912834,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
3588 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=4408 --field-trial-handle=2300,i,11130238420511565767,15696956800957912834,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
|
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: D41B0000E3FE07B0C3E1DA01 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: ADCA65C601795A84DC2CE546D61B93F0176B16E1C620F555264F02918BCC39B0 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wondershare Filmora X 1351 Crack License Key F~65F4CCCE_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.3.1 | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wondershare Filmora X 1351 Crack License Key F~65F4CCCE_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files (x86)\Setup | |||
(PID) Process: | (7124) Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wondershare Filmora X 1351 Crack License Key F~65F4CCCE_is1 |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\Setup\ |
PID | Process | Filename | Type | |
---|---|---|---|---|
2292 | Wondershare Filmora X 1351 Crack License Key Free 2024.exe | C:\Users\admin\AppData\Local\Temp\is-MGGVJ.tmp\Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | executable | |
MD5:7D691556003B149E1464369915AB67C0 | SHA256:98CC6C874A4CD4C1FF86FD61C8578C882BA52FD61D3E891D2B32492DD6B4FA46 | |||
6804 | Wondershare Filmora X 1351 Crack License Key Free 2024.exe | C:\Users\admin\AppData\Local\Temp\is-S6G79.tmp\Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | executable | |
MD5:7D691556003B149E1464369915AB67C0 | SHA256:98CC6C874A4CD4C1FF86FD61C8578C882BA52FD61D3E891D2B32492DD6B4FA46 | |||
7124 | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 | der | |
MD5:971C514F84BBA0785F80AA1C23EDFD79 | SHA256:F157ED17FCAF8837FA82F8B69973848C9B10A02636848F995698212A08F31895 | |||
7124 | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | C:\Users\admin\AppData\Local\Temp\is-8690H.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
7124 | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | C:\Users\admin\AppData\Local\Temp\is-8690H.tmp\idp.dll | executable | |
MD5:55C310C0319260D798757557AB3BF636 | SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED | |||
6736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1cbf11.TMP | — | |
MD5:— | SHA256:— | |||
2368 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | binary | |
MD5:FEFB24EF6405E214E37D2825BF75D733 | SHA256:235B87C97CE252C3A1D8865D38ADB951308AD9B4ADECF041C9991EC9EF779D81 | |||
7124 | Wondershare Filmora X 1351 Crack License Key Free 2024.tmp | C:\Program Files (x86)\Setup\unins000.dat | dat | |
MD5:2992D4F881A3416F7A3EFF1372E03D68 | SHA256:82145457DFBBE87205CDDC8D00052C4F76785A1E06402A82ACF761B57388077A | |||
6736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1cbf21.TMP | — | |
MD5:— | SHA256:— | |||
6736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4132 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
3868 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4172 | SystemSettings.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2984 | msedge.exe | GET | 204 | 13.107.6.158:80 | http://edge-http.microsoft.com/captiveportal/generate_204 | unknown | — | — | whitelisted |
3796 | svchost.exe | GET | 206 | 23.48.23.192:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e7a90c69-0fe9-4d18-85b0-7a0d1d7b3697?P1=1722844702&P2=404&P3=2&P4=UZaWf8EOH%2bSnaYd42DNIbRMz7UGoqL0EXKCxqzP2pui8UivKC9Cs%2bUBUpdIe3MSPzi3Wb11uSvW4dNkXEUApvg%3d%3d | unknown | — | — | whitelisted |
4172 | SystemSettings.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3796 | svchost.exe | HEAD | 200 | 23.48.23.192:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e7a90c69-0fe9-4d18-85b0-7a0d1d7b3697?P1=1722844702&P2=404&P3=2&P4=UZaWf8EOH%2bSnaYd42DNIbRMz7UGoqL0EXKCxqzP2pui8UivKC9Cs%2bUBUpdIe3MSPzi3Wb11uSvW4dNkXEUApvg%3d%3d | unknown | — | — | whitelisted |
3796 | svchost.exe | GET | 206 | 23.48.23.192:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e7a90c69-0fe9-4d18-85b0-7a0d1d7b3697?P1=1722844702&P2=404&P3=2&P4=UZaWf8EOH%2bSnaYd42DNIbRMz7UGoqL0EXKCxqzP2pui8UivKC9Cs%2bUBUpdIe3MSPzi3Wb11uSvW4dNkXEUApvg%3d%3d | unknown | — | — | whitelisted |
3796 | svchost.exe | GET | 206 | 23.48.23.192:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e7a90c69-0fe9-4d18-85b0-7a0d1d7b3697?P1=1722844702&P2=404&P3=2&P4=UZaWf8EOH%2bSnaYd42DNIbRMz7UGoqL0EXKCxqzP2pui8UivKC9Cs%2bUBUpdIe3MSPzi3Wb11uSvW4dNkXEUApvg%3d%3d | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5368 | SearchApp.exe | 104.126.37.162:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5368 | SearchApp.exe | 131.253.33.254:443 | a-ring-fallback.msedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
5812 | slui.exe | 40.91.76.224:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6728 | slui.exe | 40.91.76.224:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4372 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3944 | slui.exe | 40.91.76.224:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5368 | SearchApp.exe | 13.107.246.60:443 | fp-afd-nocache-ccp.azureedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
---|---|---|
t-ring-fdv2.msedge.net |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
a-ring-fallback.msedge.net |
| unknown |
google.com |
| whitelisted |
fp-afd-nocache-ccp.azureedge.net |
| whitelisted |
fp.msedge.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Suspicious Domain (*.icu) in TLS SNI |
— | — | Potentially Bad Traffic | ET INFO DNS Query for Suspicious .icu Domain |