File name:

hitpaw-video-enhancer.exe

Full analysis: https://app.any.run/tasks/cad04ac6-ae90-40bb-b7e3-ec869beea317
Verdict: Malicious activity
Analysis date: September 20, 2024, 09:03:38
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

998C5BD07C484197E895129D6CF6D6D9

SHA1:

9263E52580C2C8D6D5DF84F5E54E1E69683DB7F4

SHA256:

9FAD6A9776D766723FD5B8E0D8FD1FAA803F195712ACF5C75D7F18278E9BBC0A

SSDEEP:

98304:yTKdmVALQ0wLJhlwH64Wf4jLZyWD3ORIFpQrEEj9zS69PdbYwTMZ6SFv3Mj/DyAo:mVs06h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Checks for external IP

      • svchost.exe (PID: 2256)
      • hitpaw-video-enhancer.exe (PID: 2844)
    • Checks Windows Trust Settings

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Potential Corporate Privacy Violation

      • hitpaw-video-enhancer.exe (PID: 2844)
  • INFO

    • Checks supported languages

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Checks proxy server information

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Reads the computer name

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Reads the software policy settings

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Creates files or folders in the user directory

      • hitpaw-video-enhancer.exe (PID: 2844)
    • UPX packer has been detected

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Creates files in the program directory

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Create files in a temporary directory

      • hitpaw-video-enhancer.exe (PID: 2844)
    • Reads the machine GUID from the registry

      • hitpaw-video-enhancer.exe (PID: 2844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:30 09:15:51+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2252800
InitializedDataSize: 614400
UninitializedDataSize: 1638400
EntryPoint: 0x3b5ec0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.20.1
ProductVersionNumber: 2.7.20.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: HitPaw
FileDescription: HitPaw Video Enhancer
FileVersion: 2.7.20.1
LegalCopyright: Copyright © 2021-2024 HITPAW CO.,LIMITED All Rights Reserved.
ProductName: 20240830171527
ProductVersion: 2.7.20.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT hitpaw-video-enhancer.exe svchost.exe sppextcomobj.exe no specs slui.exe no specs hitpaw-video-enhancer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1148"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1452C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2844"C:\Users\admin\AppData\Local\Temp\hitpaw-video-enhancer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-video-enhancer.exe
explorer.exe
User:
admin
Company:
HitPaw
Integrity Level:
HIGH
Description:
HitPaw Video Enhancer
Version:
2.7.20.1
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-video-enhancer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7116"C:\Users\admin\AppData\Local\Temp\hitpaw-video-enhancer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-video-enhancer.exeexplorer.exe
User:
admin
Company:
HitPaw
Integrity Level:
MEDIUM
Description:
HitPaw Video Enhancer
Exit code:
3221226540
Version:
2.7.20.1
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-video-enhancer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 186
Read events
1 183
Write events
3
Delete events
0

Modification events

(PID) Process:(2844) hitpaw-video-enhancer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(2844) hitpaw-video-enhancer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
4DDFBEB5-EA0E-4428-AC56-7FC71FD2F476
(PID) Process:(2844) hitpaw-video-enhancer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
Executable files
0
Suspicious files
3
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2844hitpaw-video-enhancer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:D3D6FE7B445987B1EBFEE1AE08FF194D
SHA256:7175021EB0415747EE76EF9FCD1AFCD8101BAC16D8877E56726BD1D7DAE74D5D
2844hitpaw-video-enhancer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:A70098D9B9D31A7F7BB352824BFF6B9E
SHA256:24B40A5CE0AEEA88A3D575AE2480DFFE03C6C84C1150BBB76EF883D6F2BAE7C6
2844hitpaw-video-enhancer.exeC:\Users\admin\AppData\Local\Temp\hitpawvideoenhancer_hitpawnet\hitpawvideoenhancer_hitpawnet_3.5.1.exe.xmltext
MD5:6441E24720FC2DA54243E21D494696F7
SHA256:A2F8CD2750CB9CA25A2C475DD768EEC6C8C632B6667C7078C2EFBD2A1B8CF0A9
2844hitpaw-video-enhancer.exeC:\Users\admin\AppData\Local\Temp\hitpawvideoenhancer_hitpawnet\galog.jsonbinary
MD5:C4A24F4574D17E54D4C5AEE022F23FC5
SHA256:F37960BF1F8A9061F11D0C9AA1E727DBD7DEA840EF4013AE4FAFB131F96C0C07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
61
DNS requests
21
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2844
hitpaw-video-enhancer.exe
GET
301
104.17.207.155:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
whitelisted
2844
hitpaw-video-enhancer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
2624
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2624
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
740
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2844
hitpaw-video-enhancer.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
shared
2824
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
740
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5744
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.23.209.180:443
Akamai International B.V.
GB
unknown
13.89.179.11:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
2844
hitpaw-video-enhancer.exe
104.17.207.155:80
www.tenorshare.com
CLOUDFLARENET
whitelisted
2844
hitpaw-video-enhancer.exe
104.17.207.155:443
www.tenorshare.com
CLOUDFLARENET
whitelisted
2844
hitpaw-video-enhancer.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.tenorshare.com
  • 104.17.207.155
  • 104.17.192.141
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
update.tenorshare.com
  • 104.18.25.249
  • 104.18.24.249
unknown
www.google-analytics.com
  • 142.250.185.110
whitelisted
analytics.afirstsoft.cn
  • 104.18.3.37
  • 104.18.2.37
unknown
www.microsoft.com
  • 23.35.229.160
whitelisted
download.hitpaw.net
  • 104.18.27.3
  • 104.18.26.3
unknown

Threats

PID
Process
Class
Message
2844
hitpaw-video-enhancer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2844
hitpaw-video-enhancer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2844
hitpaw-video-enhancer.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2256
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
2256
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
2 ETPRO signatures available at the full report
No debug info