| URL: | http://download.freemake.net/products/83C7EDEFEEE7B3427DA57671C097DF4B/FreemakeVideoDownloaderSetup.exe?customName=FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.exe |
| Full analysis: | https://app.any.run/tasks/0fd2ffd3-7e1e-4226-bf8f-6caf0cde83a5 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | March 04, 2020, 18:19:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | F57D1A8FFA5B90659290D31D812A4C5C |
| SHA1: | 7162955FB7B02A7409D5E4F9091CA0F8BF9E9E69 |
| SHA256: | AF50F6B30E2AF8D9CB86291462717D15F47D722060A304725FFAA5D99751ED50 |
| SSDEEP: | 3:N1KaKElLAuIs9aQGRWQThwmxSyHLmhKZIEOAzABf2X2Q/eAYr3OAzABf2X28ibtn:Ca5LQ7TRWQzxSbhxEOWAVs/eAAOWAVJp |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 376 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Freemake\COM\1.1\FMMediaFormats.dll" | C:\Windows\system32\regsvr32.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 440 | "net" start "Freemake Improver" | C:\Windows\system32\net.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 580 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Freemake\COM\1.1\FMMediaUtils.dll" | C:\Windows\system32\regsvr32.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 608 | tasklist | C:\Windows\system32\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Freemake\COM\1.1\FMMediaSource.dll" | C:\Windows\system32\regsvr32.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 940 | "C:\Windows\system32\netsh.exe" http add urlacl url=http://+:11425/ user=\everyone | C:\Windows\system32\netsh.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1136 | C:\Windows\system32\net1 start "Freemake Improver" | C:\Windows\system32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1544 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\is-HNFMH.tmp\CheckRunningInstance.cmd"" | C:\Windows\system32\cmd.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1744 | "C:\Users\admin\AppData\Local\Temp\FreemakeVideoDownloaderFull.exe" /LANG=en /dotnet=0 locale=FR /DIR="C:\Program Files\Freemake" /autoinstall | C:\Users\admin\AppData\Local\Temp\FreemakeVideoDownloaderFull.exe | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | ||||||||||||
User: admin Company: Ellora Assets Corporation Integrity Level: HIGH Description: Freemake Video Downloader Setup Exit code: 0 Version: 3.8.4.68 Modules
| |||||||||||||||
| 1780 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Freemake\COM\1.1\FMTransformBase.dll" | C:\Windows\system32\regsvr32.exe | — | FreemakeVideoDownloaderFull.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 2292268318 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30798417 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2884) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2884 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF1E8CD77D5EACA979.TMP | — | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.exe.qcw5v5x.partial:Zone.Identifier | — | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\CabE5B.tmp | — | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\TarE5C.tmp | — | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\LXR9A16F.txt | — | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\GPLZMY03.txt | — | |
MD5:— | SHA256:— | |||
| 2656 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.exe.qcw5v5x.partial | executable | |
MD5:— | SHA256:— | |||
| 2656 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b[1].exe | executable | |
MD5:— | SHA256:— | |||
| 2884 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{B4603A39-5E44-11EA-972D-5254004A04AF}.dat | binary | |
MD5:— | SHA256:— | |||
| 2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | C:\Users\admin\AppData\Local\Temp\is-OJHN5.tmp\freemake_dl.dll | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | HEAD | 200 | 94.31.29.8:80 | http://download.freemake.net/products/AC7916432EA5EB3611941EC3348668DA/FreemakeVideoDownloaderFull.exe | GB | — | — | whitelisted |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | GET | 200 | 34.192.103.139:80 | http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoDownloader&language=en&version=3.8.4.68&exit_step=FINISH_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=false&statistics=1&country=FR&guid={138A905D-3A72-4DA3-B6A0-CBE3D2919849}&errorcode=0&adv=0 | US | — | — | suspicious |
2576 | FreemakeVideoDownloaderFull.tmp | GET | 200 | 34.192.103.139:80 | http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoDownloader&language=en&version=3.8.4.68&exit_step=FINISH&is_net_before=&is_net_after=&install_type=Full&is_toolbar_checked=false&statistics=1&country=FR&guid={138A905D-3A72-4DA3-B6A0-CBE3D2919849}&errorcode=0&adv= | US | — | — | suspicious |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | GET | 200 | 34.192.103.139:80 | http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoDownloader&language=en&version=3.8.4.68&exit_step=START_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=false&statistics=1&country=FR&guid={138A905D-3A72-4DA3-B6A0-CBE3D2919849}&errorcode=0&adv=0 | US | — | — | suspicious |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | GET | 200 | 34.192.103.139:80 | http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoDownloader&language=en&version=3.8.4.68&exit_step=BINDING_FAILED&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=false&statistics=1&country=FR&guid={138A905D-3A72-4DA3-B6A0-CBE3D2919849}&errorcode=0&adv=0 | US | — | — | suspicious |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | GET | 200 | 94.31.29.8:80 | http://download.freemake.net/products/AC7916432EA5EB3611941EC3348668DA/FreemakeVideoDownloaderFull.exe | GB | executable | 21.6 Mb | whitelisted |
2628 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D | US | der | 471 b | whitelisted |
2628 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D | US | der | 471 b | whitelisted |
2656 | iexplore.exe | GET | 200 | 94.31.29.8:80 | http://download.freemake.net/products/83C7EDEFEEE7B3427DA57671C097DF4B/FreemakeVideoDownloaderSetup.exe?customName=FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.exe | GB | executable | 987 Kb | whitelisted |
2884 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | iexplore.exe | 94.31.29.8:80 | — | netDNA | GB | malicious |
2884 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2884 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | 34.192.103.139:80 | geoip.freemake.com | Amazon.com, Inc. | US | suspicious |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | 3.232.136.89:80 | releases.freemake.com | — | US | unknown |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | 34.192.103.139:443 | geoip.freemake.com | Amazon.com, Inc. | US | suspicious |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | 94.31.29.8:80 | — | netDNA | GB | malicious |
2884 | iexplore.exe | 204.79.197.200:443 | ieonline.microsoft.com | Microsoft Corporation | US | whitelisted |
2560 | FreemakeVD.exe | 34.192.103.139:443 | geoip.freemake.com | Amazon.com, Inc. | US | suspicious |
2576 | FreemakeVideoDownloaderFull.tmp | 34.192.103.139:80 | geoip.freemake.com | Amazon.com, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
download.freemake.net |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
geoip.freemake.com |
| unknown |
crl3.digicert.com |
| whitelisted |
installreport.freemake.com |
| suspicious |
data.freemake.com |
| suspicious |
releases.freemake.com |
| unknown |
ieonline.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2656 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2656 | iexplore.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | Misc activity | ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2108 | FreemakeVideoDownloaderSetup_9eab57bf-deed-be10-55b9-44499db2c35b.tmp | Misc activity | ET INFO EXE - Served Attached HTTP |