File name:

filmora_setup_full1084.exe

Full analysis: https://app.any.run/tasks/53bc4130-bdb5-4889-bd3a-323fb4f05da5
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 03, 2020, 15:17:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
trojan
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7C654BAD95F1E5F9932B9D37A0853B3B

SHA1:

DC983F69A502C0F860CCA63F2555F6FBC152A0E3

SHA256:

7D351C8B9FD85C9BBC6489AB61306C6B1EAF9B104ECFAB861E8B1E47DC05A342

SSDEEP:

12288:mNSf9piuF+sL/uN82Z1ygurK+1DsYwU0fClaLMumWSQPUtfvHB1+j0l7:Keb+1ygurK+tsYw0WDmiUFvv+YV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • NLEBuildFontProcess.exe (PID: 3172)
      • WSHelper.exe (PID: 3668)
      • ImageHost.exe (PID: 2636)
      • CheckGraphicsType.exe (PID: 2264)
      • Filmora.exe (PID: 2240)
      • Filmora.exe (PID: 3612)
      • WSHelper.exe (PID: 3976)
      • WSResDownloader.exe (PID: 3052)
    • Downloads executable files from the Internet

      • filmora_setup_full1084.exe (PID: 4008)
    • Application was dropped or rewritten from another process

      • NLEBuildFontProcess.exe (PID: 3172)
      • Wondershare Helper Compact.exe (PID: 2888)
      • CheckGraphicsType.exe (PID: 2264)
      • WSHelper.exe (PID: 3668)
      • ImageHost.exe (PID: 2636)
      • Filmora.exe (PID: 2240)
      • Filmora.exe (PID: 3612)
      • WSResDownloader.exe (PID: 3052)
      • WSHelper.exe (PID: 3976)
    • Changes the autorun value in the registry

      • filmora_full1084.tmp (PID: 3540)
      • Wondershare Helper Compact.tmp (PID: 3608)
    • Registers / Runs the DLL via REGSVR32.EXE

      • filmora_full1084.tmp (PID: 3540)
    • Changes settings of System certificates

      • filmora_full1084.tmp (PID: 3540)
  • SUSPICIOUS

    • Reads internet explorer settings

      • filmora_setup_full1084.exe (PID: 4008)
    • Low-level read access rights to disk partition

      • filmora_setup_full1084.exe (PID: 4008)
    • Reads Internet Cache Settings

      • filmora_setup_full1084.exe (PID: 4008)
      • WSHelper.exe (PID: 3976)
    • Reads the Windows organization settings

      • filmora_full1084.tmp (PID: 3540)
    • Executable content was dropped or overwritten

      • filmora_full1084.exe (PID: 4076)
      • Wondershare Helper Compact.exe (PID: 2888)
      • Wondershare Helper Compact.tmp (PID: 3608)
      • filmora_full1084.tmp (PID: 3540)
    • Uses TASKKILL.EXE to kill process

      • filmora_full1084.tmp (PID: 3540)
    • Reads Windows owner or organization settings

      • filmora_full1084.tmp (PID: 3540)
    • Creates files in the Windows directory

      • filmora_full1084.tmp (PID: 3540)
    • Modifies the open verb of a shell class

      • filmora_full1084.tmp (PID: 3540)
    • Changes IE settings (feature browser emulation)

      • filmora_full1084.tmp (PID: 3540)
    • Creates files in the program directory

      • NLEBuildFontProcess.exe (PID: 3172)
      • CheckGraphicsType.exe (PID: 2264)
      • Filmora.exe (PID: 2240)
      • WSHelper.exe (PID: 3976)
      • WSResDownloader.exe (PID: 3052)
    • Starts Internet Explorer

      • filmora_setup_full1084.exe (PID: 4008)
    • Executed via COM

      • WSHelper.exe (PID: 3976)
    • Reads CPU info

      • Filmora.exe (PID: 2240)
    • Adds / modifies Windows certificates

      • filmora_full1084.tmp (PID: 3540)
  • INFO

    • Loads dropped or rewritten executable

      • filmora_full1084.tmp (PID: 3540)
      • Wondershare Helper Compact.tmp (PID: 3608)
    • Application was dropped or rewritten from another process

      • filmora_full1084.tmp (PID: 3540)
      • Wondershare Helper Compact.tmp (PID: 3608)
    • Creates a software uninstall entry

      • filmora_full1084.tmp (PID: 3540)
      • Wondershare Helper Compact.tmp (PID: 3608)
    • Dropped object may contain Bitcoin addresses

      • filmora_full1084.tmp (PID: 3540)
    • Creates files in the program directory

      • Wondershare Helper Compact.tmp (PID: 3608)
      • filmora_full1084.tmp (PID: 3540)
    • Reads settings of System Certificates

      • filmora_full1084.tmp (PID: 3540)
      • CheckGraphicsType.exe (PID: 2264)
      • iexplore.exe (PID: 2628)
    • Manual execution by user

      • Filmora.exe (PID: 3612)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2312)
      • iexplore.exe (PID: 2628)
    • Reads the hosts file

      • Filmora.exe (PID: 2240)
      • Filmora.exe (PID: 3612)
    • Application launched itself

      • iexplore.exe (PID: 2312)
    • Changes internet zones settings

      • iexplore.exe (PID: 2312)
    • Creates files in the user directory

      • iexplore.exe (PID: 2628)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2628)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2628)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2628)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (16.3)
.exe | Win64 Executable (generic) (14.5)
.dll | Win32 Dynamic Link Library (generic) (3.4)
.exe | Win32 Executable (generic) (2.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:07:05 11:50:24+02:00
PEType: PE32
LinkerVersion: 9
CodeSize: 451072
InitializedDataSize: 575488
UninitializedDataSize: -
EntryPoint: 0x51167
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.10.2
ProductVersionNumber: 2.0.10.2
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: wondershare-filmora-(fr)_setup_full1084.exe
FileVersion: 2.0.10.2
LegalCopyright: Copyright©2017 Wondershare. All rights reserved.
ProductName: Wondershare Filmora (FR)
ProductVersion: 9.0.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
73
Monitored processes
25
Malicious processes
12
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start filmora_setup_full1084.exe nfwchk.exe no specs filmora_full1084.exe filmora_full1084.tmp taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs nlebuildfontprocess.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs wondershare helper compact.exe wondershare helper compact.tmp wshelper.exe no specs imagehost.exe no specs checkgraphicstype.exe no specs filmora.exe iexplore.exe filmora.exe iexplore.exe wshelper.exe wsresdownloader.exe filmora_setup_full1084.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
832"C:\Windows\system32\TASKKILL.exe" /F /IM CheckGraphicsType.exeC:\Windows\system32\TASKKILL.exefilmora_full1084.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1496"C:\Windows\system32\regsvr32.exe" /s atimpenc.dllC:\Windows\system32\regsvr32.exefilmora_full1084.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2112"C:\Windows\system32\TASKKILL.exe" /F /IM VEConverter.exeC:\Windows\system32\TASKKILL.exefilmora_full1084.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2240"C:\Program Files\Wondershare\Wondershare Filmora (FR)\Filmora.exe" C:\Program Files\Wondershare\Wondershare Filmora (FR)\Filmora.exe
filmora_setup_full1084.exe
User:
admin
Company:
Wondershare Software
Integrity Level:
HIGH
Description:
Wondershare Filmora
Exit code:
0
Version:
7.8.9.1
Modules
Images
c:\program files\wondershare\wondershare filmora (fr)\filmora.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2264"C:\Program Files\Wondershare\Wondershare Filmora (FR)\CheckGraphicsType.exe" C:\Program Files\Wondershare\Wondershare Filmora (FR)\CheckGraphicsType.exefilmora_full1084.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\wondershare\wondershare filmora (fr)\checkgraphicstype.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2312"C:\Program Files\Internet Explorer\iexplore.exe" http://cbs.wondershare.com/go.php?m=ic&back_url=https%3A%2F%2Fwww.wondershare.com%2Ffr%2Fthankyou%2Finstall-video-editor.html&client_sign={C4BA3647-0000-0QM0-0001-5254004A04AF}&m_nProductID=1084&installtime=1593789762C:\Program Files\Internet Explorer\iexplore.exe
filmora_setup_full1084.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2540"C:\Windows\system32\TASKKILL.exe" /F /IM ImageHost.exeC:\Windows\system32\TASKKILL.exefilmora_full1084.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2628"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2312 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2636"C:\Program Files\Wondershare\Wondershare Filmora (FR)\ImageHost.exe" /RegServerC:\Program Files\Wondershare\Wondershare Filmora (FR)\ImageHost.exefilmora_full1084.tmp
User:
admin
Company:
TODO: <Company name>
Integrity Level:
HIGH
Description:
TODO: <File description>
Exit code:
0
Version:
4, 8, 8, 0
Modules
Images
c:\program files\wondershare\wondershare filmora (fr)\imagehost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\wondershare\wondershare filmora (fr)\nleimageproc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2832"C:\Windows\system32\TASKKILL.exe" /F /IM VideoEditor.exeC:\Windows\system32\TASKKILL.exefilmora_full1084.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
2 911
Read events
1 352
Write events
1 555
Delete events
4

Modification events

(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:
Value:
sku-wefr-wefr
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WafCX
Operation:writeName:1084
Value:
sku-wefr-wefr
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact
Operation:writeName:ClientSign
Value:
{C4BA3647-0000-0QM0-0001-5254004A04AF}
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF
Operation:writeName:ClientSign
Value:
{C4BA3647-0000-0QM0-0001-5254004A04AF}
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4008) filmora_setup_full1084.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
250
Suspicious files
31
Text files
2 097
Unknown types
171

Dropped files

PID
Process
Filename
Type
4008filmora_setup_full1084.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\Public\Documents\Wondershare\filmora_full1084.exe.~P2S
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\dnserrordiagoff[1]
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\NewErrorPageTemplate[1]
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\errorPageStrings[1]
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\Public\Documents\Wondershare\filmora_full1084.exe
MD5:
SHA256:
4008filmora_setup_full1084.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\errorPageStrings[1]text
MD5:
SHA256:
3540filmora_full1084.tmpC:\Users\admin\AppData\Local\Temp\is-5PNIA.tmp\MediaInfo.dllexecutable
MD5:A8DBE189FB492E2FF9F2FE4337D81559
SHA256:0F15B3FD8A97BF0E6DAC45F4047370E87278DB8CFDAF52C25CAC4E60D1D0F776
3540filmora_full1084.tmpC:\Users\admin\AppData\Local\Temp\is-5PNIA.tmp\NLEBuildFontProcess.exeexecutable
MD5:FF77073ECB7E7FB25DADFCF31212BA2B
SHA256:9EDCECB27310B0168F1CD67C428E91AA6D5C298BB3D96E0EDC5549878373A895
4008filmora_setup_full1084.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe.configxml
MD5:AD0967A0AB95AA7D71B3DC92B71B8F7A
SHA256:9C1212BC648A2533B53A2D0AFCEC518846D97630AFB013742A9622F0DF7B04FC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
80
TCP/UDP connections
152
DNS requests
37
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4008
filmora_setup_full1084.exe
GET
163.171.132.19:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
HEAD
200
163.171.132.19:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.19:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
HEAD
200
163.171.132.18:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
malicious
4008
filmora_setup_full1084.exe
GET
206
163.171.132.19:80
http://download-fr.wondershare.com/cbs_down/filmora_full1084.exe
US
binary
531 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4008
filmora_setup_full1084.exe
47.91.67.36:80
platform.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
4008
filmora_setup_full1084.exe
163.171.132.18:80
download-fr.wondershare.com
US
malicious
4008
filmora_setup_full1084.exe
163.171.132.115:80
download-fr.wondershare.com
US
malicious
4008
filmora_setup_full1084.exe
163.171.132.19:80
download-fr.wondershare.com
US
suspicious
4008
filmora_setup_full1084.exe
163.171.132.122:80
download-fr.wondershare.com
US
suspicious
163.171.132.18:80
download-fr.wondershare.com
US
malicious
3540
filmora_full1084.tmp
47.91.89.199:80
cbs.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
malicious
163.171.132.19:80
download-fr.wondershare.com
US
suspicious
47.91.67.36:80
platform.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
2628
iexplore.exe
47.91.89.199:80
cbs.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
malicious

DNS requests

Domain
IP
Reputation
platform.wondershare.com
  • 47.91.67.36
suspicious
download-fr.wondershare.com
  • 163.171.132.18
  • 163.171.132.19
  • 163.171.132.122
  • 163.171.132.115
malicious
dlinst.wondershare.com
  • 47.91.67.36
suspicious
cbs.wondershare.com
  • 47.91.89.199
  • 47.91.76.37
  • 47.91.91.66
  • 47.91.89.20
whitelisted
filmora.wondershare.com
  • 104.108.55.202
suspicious
www.wondershare.com
  • 104.108.55.202
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
resource.wondershare.com
  • 47.246.43.206
malicious
static-fr.wondershare.com
  • 104.108.55.202
suspicious
images.wondershare.com
  • 104.108.55.202
whitelisted

Threats

PID
Process
Class
Message
4008
filmora_setup_full1084.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
4008
filmora_setup_full1084.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
4008
filmora_setup_full1084.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3540
filmora_full1084.tmp
A Network Trojan was detected
ET TROJAN Possible Win32/Get2 Downloader Activity
Process
Message
Filmora.exe
Media Streaming Kit for Windows Version V15.4 'Patriot' ( 0x20150306 ) Copyright (c) Rocket Division Software 2001-2010. All rights reserved. Copyright (c) StarBurn Software 2009-2010. All rights reserved.
Filmora.exe
Media Streaming Kit for Windows Version V15.4 'Patriot' ( 0x20150306 ) Copyright (c) Rocket Division Software 2001-2010. All rights reserved. Copyright (c) StarBurn Software 2009-2010. All rights reserved.
Filmora.exe
Http Request Host: resource.wondershare.com, URL: /002/153/Category.xml
Filmora.exe
HTTP/1.1 200 OK
WSHelper.exe
HTTP/1.1 200 OK
WSHelper.exe
HTTP/1.1 200 OK
WSHelper.exe
HTTP/1.1 404 Not Found
WSHelper.exe
HTTP/1.1 200 OK
WSHelper.exe
HTTP/1.1 404 Not Found
WSResDownloader.exe
Http Request Host: resource.wondershare.com, URL: /001/536/Online2_3.zip