File name:

NCH VideoPad Video Editor Professional v8.00 Beta Keygen [hN].zip

Full analysis: https://app.any.run/tasks/f1653cca-4c36-4880-a8c2-f1a12aad9043
Verdict: Malicious activity
Analysis date: February 15, 2020, 14:02:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

DA16B9E99357CEED930EBE956BC15CA4

SHA1:

BC8BA065D86468EFAD608F5F60EF8CDFDBEE4BD5

SHA256:

8BEE21A72B4E214CBEE52414CE5C6EAB080965D3F04CD1C3FD2F46CF5B17A11E

SSDEEP:

98304:ZcQxTns54nz72gK+OogKByl7SkpPvaIsAWXtgT:ibWqgK+DgKBkr3sdXtm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • videopad.exe (PID: 2824)
      • mp3el2.exe (PID: 3876)
      • videopad.exe (PID: 3212)
      • vppsetup.exe (PID: 2684)
      • vppsetup.exe (PID: 2864)
      • videopad.exe (PID: 792)
      • nchsetup.exe (PID: 816)
      • Keygen.exe (PID: 1140)
      • Keygen.exe (PID: 1092)
    • Loads the Task Scheduler COM API

      • nchsetup.exe (PID: 816)
      • videopad.exe (PID: 3212)
      • videopad.exe (PID: 2824)
      • videopad.exe (PID: 792)
    • Writes to the hosts file

      • Keygen.exe (PID: 1092)
    • Changes the autorun value in the registry

      • nchsetup.exe (PID: 816)
  • SUSPICIOUS

    • Creates files in the program directory

      • nchsetup.exe (PID: 816)
      • mp3el2.exe (PID: 3876)
    • Executable content was dropped or overwritten

      • vppsetup.exe (PID: 2864)
      • nchsetup.exe (PID: 816)
      • mp3el2.exe (PID: 3876)
    • Creates a software uninstall entry

      • nchsetup.exe (PID: 816)
    • Starts itself from another location

      • nchsetup.exe (PID: 816)
    • Starts Internet Explorer

      • videopad.exe (PID: 2824)
      • videopad.exe (PID: 792)
    • Creates files in the user directory

      • nchsetup.exe (PID: 816)
      • videopad.exe (PID: 2824)
      • videopad.exe (PID: 792)
    • Modifies the open verb of a shell class

      • nchsetup.exe (PID: 816)
    • Application launched itself

      • WinRAR.exe (PID: 2548)
    • Reads Internet Cache Settings

      • videopad.exe (PID: 792)
  • INFO

    • Manual execution by user

      • vppsetup.exe (PID: 2684)
      • videopad.exe (PID: 792)
      • Keygen.exe (PID: 1092)
      • Keygen.exe (PID: 1140)
      • WinRAR.exe (PID: 2316)
      • vppsetup.exe (PID: 2864)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 4012)
      • iexplore.exe (PID: 2540)
      • iexplore.exe (PID: 660)
      • iexplore.exe (PID: 3152)
      • iexplore.exe (PID: 3120)
      • iexplore.exe (PID: 552)
    • Changes internet zones settings

      • iexplore.exe (PID: 4012)
      • iexplore.exe (PID: 660)
      • iexplore.exe (PID: 3120)
    • Application launched itself

      • iexplore.exe (PID: 660)
      • iexplore.exe (PID: 4012)
    • Reads the hosts file

      • Keygen.exe (PID: 1092)
    • Reads internet explorer settings

      • iexplore.exe (PID: 552)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3152)
      • iexplore.exe (PID: 552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: None
ZipModifyDate: 2020:02:15 14:00:29
ZipCRC: 0x899ddfa5
ZipCompressedSize: 585
ZipUncompressedSize: 585
ZipFileName: NCH VideoPad Video Editor Professional v8.00 Beta Keygen [hN]/[TGx]Downloaded from torrentgalaxy.to .txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
19
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe no specs winrar.exe no specs vppsetup.exe no specs vppsetup.exe nchsetup.exe mp3el2.exe videopad.exe videopad.exe no specs iexplore.exe no specs iexplore.exe iexplore.exe no specs iexplore.exe winrar.exe no specs notepad.exe no specs keygen.exe no specs keygen.exe videopad.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
552"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3120 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
660"C:\Program Files\Internet Explorer\iexplore.exe" https://www.nchsoftware.com/software/thanks.html?software=VideoPad&appname=VideoPad%20Video%20Editor&version=8.00&base=videopad&domain=nchsoftware&buyoffer=videopad&pclass=plus&rgst=0&svar=LLIBControlonVIDEOPADNarrationtitleonVIDEOPADBalloonsonVIDEOPADSnowonVIDEOPADNarrationtoolbaroffVIDEOPADFsbuttononVIDEOPADPlayoverlayonVIDEOPADShowlockbuttononVIDEOPADLockcomplexoffVIDEOPADAudiotextsimpleonVIDEOPADLhninvoff&antivirus=expired&instby=dl&iid=MaevBEoAVFI&help=0&usage=0B5501&usechoice=memory(3583)C:\Program Files\Internet Explorer\iexplore.exevideopad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
792"C:\Program Files\NCH Software\VideoPad\videopad.exe" C:\Program Files\NCH Software\VideoPad\videopad.exe
explorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
VideoPad Video Editor
Exit code:
0
Version:
8.00+
Modules
Images
c:\program files\nch software\videopad\videopad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
816"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\Desktop\Setup\vppsetup.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
vppsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
VideoPad Video Editor
Exit code:
0
Version:
8.00+
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1092"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exe
explorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
HIGH
Description:
NCH Software Keygen
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
1140"C:\Users\admin\Desktop\Keygen.exe" C:\Users\admin\Desktop\Keygen.exeexplorer.exe
User:
admin
Company:
RadiXX11
Integrity Level:
MEDIUM
Description:
NCH Software Keygen
Exit code:
3221226540
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\keygen.exe
c:\systemroot\system32\ntdll.dll
2316"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Keygen\NCHSK.1.6.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2540"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4012 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2548"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NCH VideoPad Video Editor Professional v8.00 Beta Keygen [hN].zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2684"C:\Users\admin\Desktop\Setup\vppsetup.exe" C:\Users\admin\Desktop\Setup\vppsetup.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
VideoPad Video Editor
Exit code:
3221226540
Version:
8.00+
Modules
Images
c:\users\admin\desktop\setup\vppsetup.exe
c:\systemroot\system32\ntdll.dll
Total events
9 202
Read events
5 940
Write events
3 255
Delete events
7

Modification events

(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2548) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NCH VideoPad Video Editor Professional v8.00 Beta Keygen [hN].zip
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
7
Suspicious files
35
Text files
484
Unknown types
30

Dropped files

PID
Process
Filename
Type
3600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3600.41133\Keygen\NCHSK.1.6.zip
MD5:
SHA256:
3600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3600.41688\Setup\vppsetup.exe
MD5:
SHA256:
2864vppsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.cab
MD5:
SHA256:
2864vppsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cabcompressed
MD5:
SHA256:
2548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2548.40578\NCH VideoPad Video Editor Professional 8.00 Beta Keygen.zipcompressed
MD5:
SHA256:
2864vppsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.datbinary
MD5:
SHA256:
2864vppsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:
SHA256:
816nchsetup.exeC:\Program Files\NCH Software\VideoPad\videopad.exeexecutable
MD5:
SHA256:
816nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\multititle\dvb.fontindexxml
MD5:AFC7F706CBB1E96CCA6B4A27A312068F
SHA256:245E18F99F0D41542FD03ADFC9BA50FE3D30E25F66DE18B2AFD537BB68AA9630
816nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\multititle\00000.jarjava
MD5:14F0215F660805E2FBDAA8E618AAF994
SHA256:65E98A9301AF0AE9FB3444600FC0FB0B4733059352AB61A47CB8D17F914BEE54
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
23
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
552
iexplore.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
3152
iexplore.exe
GET
200
93.184.220.29:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR3enuod9bxDxzpICGW%2B2sabjf17QQUkFj%2FsJx1qFFUd7Ht8qNDFjiebMUCEAy6QZ6ygHKQIu9F0DGBQho%3D
US
der
471 b
whitelisted
3152
iexplore.exe
GET
200
93.184.220.29:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR3enuod9bxDxzpICGW%2B2sabjf17QQUkFj%2FsJx1qFFUd7Ht8qNDFjiebMUCEAy6QZ6ygHKQIu9F0DGBQho%3D
US
der
471 b
whitelisted
3152
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
3152
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D
US
der
471 b
whitelisted
552
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
US
der
471 b
whitelisted
552
iexplore.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDx9it%2Fyk0DxwgAAAAALC4g
US
der
472 b
whitelisted
552
iexplore.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
552
iexplore.exe
GET
200
172.217.22.35:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDx9it%2Fyk0DxwgAAAAALC4g
US
der
472 b
whitelisted
552
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3152
iexplore.exe
66.39.83.155:443
www.nchsoftware.com
pair Networks
US
suspicious
552
iexplore.exe
66.117.15.144:443
www.nchsoftware.com
InMotion Hosting, Inc.
US
suspicious
552
iexplore.exe
172.217.16.142:443
www.google-analytics.com
Google Inc.
US
whitelisted
2540
iexplore.exe
66.39.83.155:443
www.nchsoftware.com
pair Networks
US
suspicious
552
iexplore.exe
185.60.216.35:443
www.facebook.com
Facebook, Inc.
IE
whitelisted
552
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3152
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
552
iexplore.exe
172.217.22.35:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2824
videopad.exe
184.106.10.72:443
www.livehelpnow.net
Rackspace Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
www.nchsoftware.com
  • 66.39.83.155
  • 54.149.5.211
  • 66.117.15.144
malicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.livehelpnow.net
  • 184.106.10.72
unknown
ocsp.digicert.com
  • 93.184.220.29
whitelisted
status.geotrust.com
  • 93.184.220.29
whitelisted
www.google-analytics.com
  • 172.217.16.142
whitelisted
ocsp.pki.goog
  • 172.217.22.35
whitelisted
www.facebook.com
  • 185.60.216.35
whitelisted

Threats

No threats detected
No debug info