| URL: | http://ssl-download.wondershare.com/filmora_full846.exe |
| Full analysis: | https://app.any.run/tasks/109759f8-2343-4ce1-a696-c202e5477f0d |
| Verdict: | Malicious activity |
| Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
| Analysis date: | November 20, 2019, 16:22:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 1EC10EF73BA12285B73D87F02B1F51E1 |
| SHA1: | 1492D73DC959C509DA6D65C9777701CEAFA92CB5 |
| SHA256: | ACAAAA50C8512CE84AF7E89A9A666644EC6A03AAB7205E890B383E2BA3826808 |
| SSDEEP: | 3:N1KNWW5IQLGKzAXI1L4An:CEW5IQLG7ykAn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | "C:\Users\admin\AppData\Local\Temp\is-6TIR9.tmp\Wondershare Helper Compact.tmp" /SL5="$A0124,2104196,54272,C:\Program Files\Wondershare\Wondershare Filmora\Wondershare Helper Compact.exe" /VERYSILENT /SP- | C:\Users\admin\AppData\Local\Temp\is-6TIR9.tmp\Wondershare Helper Compact.tmp | Wondershare Helper Compact.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 992 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://ssl-download.wondershare.com/filmora_full846.exe" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 996 | "C:\Windows\system32\TASKKILL.exe" /F /IM ImageHost.exe | C:\Windows\system32\TASKKILL.exe | — | filmora_full846.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1104 | "C:\Windows\system32\regsvr32.exe" /s CFDecode2.ax | C:\Windows\system32\regsvr32.exe | — | filmora_full846.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1528 | "C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" /regserver | C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe | — | Wondershare Helper Compact.tmp | |||||||||||
User: admin Company: Wondershare Integrity Level: HIGH Description: Wondershare Studio Exit code: 0 Version: 2.5.2.3 Modules
| |||||||||||||||
| 2204 | "C:\Users\Public\Documents\Wondershare\filmora_full846.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare Filmora.log" /installpath: "C:\Program Files\Wondershare\Wondershare Filmora\" /DIR="C:\Program Files\Wondershare\Wondershare Filmora\" | C:\Users\Public\Documents\Wondershare\filmora_full846.exe | filmora_setup_full846[1].exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Wondershare Filmora Setup Exit code: 0 Version: 7.8.9.1 Modules
| |||||||||||||||
| 2236 | "C:\Users\admin\AppData\Local\Temp\is-CM055.tmp\filmora_full846.tmp" /SL5="$4012E,169119532,361984,C:\Users\Public\Documents\Wondershare\filmora_full846.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-Wondershare Filmora.log" /installpath: "C:\Program Files\Wondershare\Wondershare Filmora\" /DIR="C:\Program Files\Wondershare\Wondershare Filmora\" | C:\Users\admin\AppData\Local\Temp\is-CM055.tmp\filmora_full846.tmp | filmora_full846.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2396 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\filmora_setup_full846[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\filmora_setup_full846[1].exe | iexplore.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: wondershare-filmora_setup_full846.exe Exit code: 0 Version: 2.0.15.2 Modules
| |||||||||||||||
| 2440 | "C:\Program Files\Wondershare\Wondershare Filmora\Wondershare Helper Compact.exe" /VERYSILENT /SP- | C:\Program Files\Wondershare\Wondershare Filmora\Wondershare Helper Compact.exe | filmora_full846.tmp | ||||||||||||
User: admin Company: Wondershare Integrity Level: HIGH Description: Wondershare Helper Compact Exit code: 0 Version: 2.5.2.3 Modules
| |||||||||||||||
| 2524 | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | — | filmora_setup_full846[1].exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {EC13211B-0BB1-11EA-AB41-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 2 | |||
| (PID) Process: | (992) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E3070B00030014001000160013003403 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 992 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 992 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 992 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF014A7CFFD5040DC8.TMP | — | |
MD5:— | SHA256:— | |||
| 992 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF6AF85F4785DA3225.TMP | — | |
MD5:— | SHA256:— | |||
| 992 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EC13211B-0BB1-11EA-AB41-5254004A04AF}.dat | — | |
MD5:— | SHA256:— | |||
| 3304 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@cbs.wondershare[1].txt | text | |
MD5:— | SHA256:— | |||
| 2396 | filmora_setup_full846[1].exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\846-20191113183402[1].htm | — | |
MD5:— | SHA256:— | |||
| 3304 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat | dat | |
MD5:— | SHA256:— | |||
| 3304 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019112020191121\index.dat | dat | |
MD5:— | SHA256:— | |||
| 3304 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat | dat | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2396 | filmora_setup_full846[1].exe | GET | — | 63.159.217.165:80 | http://dlinst.wondershare.com/player/style/orbit-1.3.0.css | US | — | — | suspicious |
3304 | iexplore.exe | GET | 302 | 47.246.43.204:80 | http://ssl-download.wondershare.com/filmora_full846.exe | US | — | — | malicious |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.83:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.83:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.83:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.90:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.90:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.83:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | — | 2.16.186.90:80 | http://download.wondershare.com/cbs_down/filmora_full846.exe | unknown | — | — | whitelisted |
2396 | filmora_setup_full846[1].exe | GET | 200 | 63.159.217.165:80 | http://dlinst.wondershare.com/player/846-20191113183402.html | US | html | 889 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3304 | iexplore.exe | 47.246.43.204:80 | ssl-download.wondershare.com | — | US | suspicious |
992 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3304 | iexplore.exe | 47.91.89.199:80 | cbs.wondershare.com | Alibaba (China) Technology Co., Ltd. | US | malicious |
3304 | iexplore.exe | 47.91.76.37:80 | cbs.wondershare.com | Alibaba (China) Technology Co., Ltd. | US | malicious |
3304 | iexplore.exe | 2.16.186.83:80 | download.wondershare.com | Akamai International B.V. | — | whitelisted |
2396 | filmora_setup_full846[1].exe | 2.16.186.83:80 | download.wondershare.com | Akamai International B.V. | — | whitelisted |
2396 | filmora_setup_full846[1].exe | 47.91.67.36:80 | platform.wondershare.com | Alibaba (China) Technology Co., Ltd. | US | suspicious |
2396 | filmora_setup_full846[1].exe | 2.16.186.90:80 | download.wondershare.com | Akamai International B.V. | — | whitelisted |
2396 | filmora_setup_full846[1].exe | 63.159.217.165:80 | dlinst.wondershare.com | QUANTIL, INC | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ssl-download.wondershare.com |
| malicious |
www.bing.com |
| whitelisted |
cbs.wondershare.com |
| whitelisted |
download.wondershare.com |
| whitelisted |
platform.wondershare.com |
| suspicious |
dlinst.wondershare.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
3304 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2396 | filmora_setup_full846[1].exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2396 | filmora_setup_full846[1].exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2236 | filmora_full846.tmp | A Network Trojan was detected | ET TROJAN Possible Win32/Get2 Downloader Activity |