File name: | drw_google_trial_installer.27584.exe |
Full analysis: | https://app.any.run/tasks/0859df39-e8b8-4d57-85ed-cf488b7a17a1 |
Verdict: | Malicious activity |
Analysis date: | August 14, 2024, 23:56:48 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | 789E380FB028EAE5575B11ABF440D4CD |
SHA1: | B37E989E4F185D8606B6F66494F816A4278C5BEE |
SHA256: | 8F6A60DBC178B95D6099FE381FA21E0F22F1EA4BB5EF77B2253848A2A191A44D |
SSDEEP: | 98304:3R6kCNJtOBr9cFj83wAqNYoMmZGKHZ9/RoMt5Wr8ufGlzny2xwIw/NLS17e0z0tL:16Ny3 |
.exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (14.2) |
.exe | | | Win32 Executable (generic) (9.7) |
.exe | | | Generic Win/DOS Executable (4.3) |
.exe | | | DOS Executable Generic (4.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2018:01:30 03:57:48+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 26624 |
InitializedDataSize: | 186368 |
UninitializedDataSize: | 2048 |
EntryPoint: | 0x338f |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1640 | "C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe" /SendInfo "Window" "Langsel" "Activity" "Click_Confirm" "Attribute" "{\"Language\":\"en\"}" | C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe | — | drw19.0.0.0_ad_google_trial.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2224 | "C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe" /SendInfo "Window" "Licenseagreement" "Activity" "Click_Accept" | C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe | — | drw19.0.0.0_ad_google_trial.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2268 | "C:\Users\admin\AppData\Local\Temp\is-09OJ7.tmp\drw19.0.0.0_ad_google_trial.tmp" /SL5="$5026E,78068482,192512,C:\Users\admin\Desktop\drw19.0.0.0_ad_google_trial.exe" /verysilent /DIR="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard" /LANG=en agreeImprove= GUID=S-1-5-21-1693682860-607145093-2874071422-1001 xurlID=27584 TestID=AG190_2024729newcert-07245 | C:\Users\admin\AppData\Local\Temp\is-09OJ7.tmp\drw19.0.0.0_ad_google_trial.tmp | drw19.0.0.0_ad_google_trial.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.1052.0.0 Modules
| |||||||||||||||
2272 | "C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe" /SendInfo "Window" "Selectadditionaltasks" "Activity" "Click_Install" "Attribute" "{\"Test_id\":\"AG190_2024729newcert-07245\",\"Version\":\"Ad_Google_Trial_trial\",\"Num\":\"19.0.0.0\",\"Language\":\"en\"}" | C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\InfoForSetup.exe | — | drw19.0.0.0_ad_google_trial.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
3292 | C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\is-VTBAL.tmp\AliyunWrapExe.exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
4276 | /SendInfo Window "Downloading" Activity "Result_Download_Program" Attribute "{\"Average_Networkspeed\":\"1.67MB\",\"Cdn\":\"https://d1.easeus.com/drw/ad/drw19.0.0.0_ad_google_trial.exe\",\"Elapsedtime\":\"45\",\"Errorinfo\":\"0\",\"Result\":\"Success\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
6244 | "C:\Users\admin\Desktop\drw_google_trial_installer.27584.exe" | C:\Users\admin\Desktop\drw_google_trial_installer.27584.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
6388 | "C:\Users\admin\Desktop\drw_google_trial_installer.27584.exe" | C:\Users\admin\Desktop\drw_google_trial_installer.27584.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
6436 | "C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\EDownloader.exe" EXEDIR=C:\Users\admin\Desktop ||| EXENAME=drw_google_trial_installer.27584.exe ||| DOWNLOAD_VERSION=ad_google_trial ||| PRODUCT_VERSION=2.0.0 ||| INSTALL_TYPE=0 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\EDownloader.exe | drw_google_trial_installer.27584.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
6460 | /Uid "S-1-5-21-1693682860-607145093-2874071422-1001" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
|
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (6524) AliyunWrapExe.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (6436) EDownloader.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (6436) EDownloader.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (6436) EDownloader.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\EDownloader.exe | executable | |
MD5:8A250A75859FE52116E706A640E6D77C | SHA256:823AB6955052EF34218559B53D4F15224B5A850B532672FA33A7634DC74981DC | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Danish.ini | text | |
MD5:EB6CB6A1EA028CAC7AE61DADC568C2F9 | SHA256:4524116093969EE206FA4F04D84346349ED551B4D7B87D4206E9A12D32AF5D61 | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Arabic.ini | text | |
MD5:B334764EB0A1069F6BA04C8E1F088CD0 | SHA256:D9A87257F203A80489756B8B31628FFF8D10AAB229D20A637A083059233DC54C | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\skin.zip | compressed | |
MD5:784C6F9B53521F4CB115532F49B67A36 | SHA256:A0951464134E2AF94ECD389EA9C0F3D784BAE909F60EB2F45D7764B4DBDE7A73 | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Dutch.ini | text | |
MD5:E4E098A3E165FC5ECB4CB806B7E6E9D8 | SHA256:3FE882930B7C5299290AE6C0C20AE065BD915984B381436B1C3D1D1CBFC67127 | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\ChineseTrad.ini | text | |
MD5:FE7AD6D1DD07AEAFEECE921ECB23F3E7 | SHA256:7EF907A793D9087AA804A688BDDDECF33A76011E4D820E7332533C070277507F | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Malay.ini | text | |
MD5:534A5DFA634D7B7DF7A581D4E1D08F78 | SHA256:984E71C01CB1C2DFB260AE1C0F764F6BDF91E4F523F5DC4161B3D19456993CBB | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Japanese.ini | text | |
MD5:76E3CFD74C8A8C99CCD461F17CBABD4D | SHA256:64EFC20036A6CAD10DDBDB014444C55B6DB93A481EE5FE84210DEB2377918BB8 | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\LanguageTransfor.ini | text | |
MD5:FFE692A67871185785EC705B1CC12C81 | SHA256:373BEC6E7976324FF879C2988BAB772C69336D7BCB9A32386A6021568350A824 | |||
6388 | drw_google_trial_installer.27584.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\2.0.0\2ad_google_trial\Norwegian.ini | text | |
MD5:74F6E38B2B7AC3893B1AB6C092B854D1 | SHA256:9692FECB48E8745F26C235C8925F106E56E862CD1B7B8CA8C84B8CB751B7A748 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
6524 | AliyunWrapExe.exe | POST | 200 | 47.252.97.12:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | unknown | — | — | — |
6524 | AliyunWrapExe.exe | GET | 200 | 163.171.128.150:80 | http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=2 | unknown | — | — | malicious |
6524 | AliyunWrapExe.exe | POST | 200 | 47.252.97.12:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | unknown | — | — | — |
6436 | EDownloader.exe | POST | 200 | 18.172.112.32:80 | http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ | unknown | — | — | — |
2872 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6524 | AliyunWrapExe.exe | POST | 200 | 47.252.97.12:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | unknown | — | — | — |
6524 | AliyunWrapExe.exe | POST | 200 | 47.252.97.12:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | unknown | — | — | — |
6524 | AliyunWrapExe.exe | POST | 200 | 47.252.97.12:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | unknown | — | — | — |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2872 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
5900 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5388 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4324 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6524 | AliyunWrapExe.exe | 163.171.128.150:80 | track.easeus.com | QUANTILNETWORKS | DE | unknown |
6524 | AliyunWrapExe.exe | 47.252.97.12:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba US Technology Co., Ltd. | US | unknown |
6436 | EDownloader.exe | 18.172.112.32:80 | download.easeus.com | — | US | unknown |
6436 | EDownloader.exe | 13.35.58.28:443 | d1.easeus.com | — | US | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
track.easeus.com |
| unknown |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
download.easeus.com |
| unknown |
d1.easeus.com |
| unknown |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Misc activity | ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com) |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
— | — | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
Process | Message |
---|---|
EDownloader.exe | [6440]-23:57:02:692 ParseCmdLine param=EXEDIR=C:\Users\admin\Desktop ||| EXENAME=drw_google_trial_installer.27584.exe ||| DOWNLOAD_VERSION=ad_google_trial ||| PRODUCT_VERSION=2.0.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [6440]-23:57:02:771 Install recomand return=259
|
EDownloader.exe | [6440]-23:57:03:771 Install recomand return=259
|
EDownloader.exe | [6440]-23:57:07:019 Install recomand return=259
|
EDownloader.exe | [6440]-23:57:07:019 Install recomand return=259
|
EDownloader.exe | [6796]-23:57:07:035 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=27584&lang=English&pcVersion=home&pid=2&tid=1&version=ad_google_trial
|
EDownloader.exe | [6796]-23:57:08:378 PostData end
|
EDownloader.exe | [6796]-23:57:08:378 Json parse Data Start
|
EDownloader.exe | [6796]-23:57:08:378 Json parse Data end
|
EDownloader.exe | [6440]-23:57:08:378 CHttpHelper::GetDownloadInfo 45 download info code:0
|