File name:

voicewave_installer_20240128.952567.exe

Full analysis: https://app.any.run/tasks/ba15084d-9812-48b0-bf62-d415153a284c
Verdict: Malicious activity
Analysis date: January 29, 2024, 02:44:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

B9C9B4EDF5B65D3C91F8A4555587EBF2

SHA1:

9B09FB75266F44CA2A893D787BBE679AADD4F402

SHA256:

D101B0A989E1B3001A705A5151AA47E837B6070ED0C0823284A90518EDC17773

SSDEEP:

98304:87VERwrWzXcao6n7LoyEnZKDxUQAKDTS4MZ6N2mp5EaxbGnl+tNf/xUKkO:xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Actions looks like stealing of personal data

      • evw_free_easeus.tmp (PID: 2656)
      • easeus.voicewave.exe (PID: 3476)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 956)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads the Internet Settings

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • powershell.exe (PID: 3644)
      • AliyunWrapExe.Exe (PID: 3804)
      • evw_free_easeus.tmp (PID: 2656)
    • Reads Internet Explorer settings

      • EDownloader.exe (PID: 1880)
    • Reads Microsoft Outlook installation path

      • EDownloader.exe (PID: 1880)
    • Reads the Windows owner or organization settings

      • evw_free_easeus.tmp (PID: 2656)
    • Process drops legitimate windows executable

      • evw_free_easeus.tmp (PID: 2656)
    • Drops a system driver (possible attempt to evade defenses)

      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Starts POWERSHELL.EXE for commands execution

      • evw_free_easeus.tmp (PID: 2656)
    • The process drops C-runtime libraries

      • evw_free_easeus.tmp (PID: 2656)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 3644)
    • Searches for installed software

      • EDownloader.exe (PID: 1880)
    • Reads security settings of Internet Explorer

      • devconX86.exe (PID: 1316)
    • Checks Windows Trust Settings

      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads settings of System Certificates

      • devconX86.exe (PID: 1316)
    • Creates files in the driver directory

      • drvinst.exe (PID: 956)
  • INFO

    • Reads the computer name

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 568)
      • evw_free_easeus.tmp (PID: 2656)
      • FireWallAssist.exe (PID: 3480)
      • FireWallAssist.exe (PID: 3928)
      • InfoForSetup.exe (PID: 2996)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 3052)
      • EuDownload.exe (PID: 2372)
      • devconX86.exe (PID: 1044)
      • devconX86.exe (PID: 1316)
      • easeus.evw.vchanger.exe (PID: 3132)
      • drvinst.exe (PID: 996)
      • drvinst.exe (PID: 956)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 3012)
    • Create files in a temporary directory

      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2388)
      • AliyunWrapExe.Exe (PID: 568)
      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.tmp (PID: 2656)
      • evw_free_easeus.exe (PID: 1408)
      • easeus.voicewave.exe (PID: 3476)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 3012)
      • EuDownload.exe (PID: 3696)
    • Checks supported languages

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2780)
      • InfoForSetup.exe (PID: 2388)
      • InfoForSetup.exe (PID: 2064)
      • AliyunWrapExe.Exe (PID: 568)
      • InfoForSetup.exe (PID: 3400)
      • InfoForSetup.exe (PID: 128)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 3052)
      • InfoForSetup.exe (PID: 3040)
      • FireWallAssist.exe (PID: 3928)
      • FireWallAssist.exe (PID: 3480)
      • EUinApp.exe (PID: 3608)
      • InfoForSetup.exe (PID: 2132)
      • InfoForSetup.exe (PID: 3956)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • InfoForSetup.exe (PID: 2996)
      • InfoForSetup.exe (PID: 2044)
      • InfoForSetup.exe (PID: 2472)
      • InfoForSetup.exe (PID: 2524)
      • easeus.voicewave.exe (PID: 3476)
      • InfoForSetup.exe (PID: 3148)
      • EuDownload.exe (PID: 2372)
      • EuDownload.exe (PID: 3052)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1044)
      • devconX86.exe (PID: 1316)
      • EuDownload.exe (PID: 1820)
      • drvinst.exe (PID: 996)
      • drvinst.exe (PID: 956)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3012)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 3116)
    • Checks proxy server information

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
    • Reads the machine GUID from the registry

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • easeus.voicewave.exe (PID: 3476)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Creates files or folders in the user directory

      • AliyunWrapExe.Exe (PID: 568)
      • AliyunWrapExe.Exe (PID: 3804)
      • easeus.evw.vchanger.exe (PID: 3132)
    • Creates files in the program directory

      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 2132)
      • AliyunWrapExe.Exe (PID: 3804)
      • EuDownload.exe (PID: 3052)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 2372)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
    • Application launched itself

      • msedge.exe (PID: 2932)
      • msedge.exe (PID: 3620)
    • Manual execution by a user

      • msedge.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:48+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 186368
UninitializedDataSize: 2048
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
59
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start voicewave_installer_20240128.952567.exe edownloader.exe infoforsetup.exe no specs infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs evw_free_easeus.exe evw_free_easeus.tmp euinapp.exe no specs powershell.exe no specs firewallassist.exe firewallassist.exe setupue.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs msedge.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs easeus.voicewave.exe eudownload.exe msedge.exe no specs eudownload.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs easeus.evw.vchanger.exe msedge.exe no specs msedge.exe no specs devconx86.exe no specs devconx86.exe drvinst.exe rundll32.exe no specs drvinst.exe no specs rundll32.exe no specs eudownload.exe eudownload.exe eudownload.exe eudownload.exe eudownload.exe voicewave_installer_20240128.952567.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128 /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Downloadfrom\":\"https://d1.easeus.com/evw/free/voicewave2.6.1_free.exe\",\"Pageid\":\"952567\",\"Testid\":\"\",\"Version\":\"free\",\"Versionnumber\":\"2.6.1\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
568C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
876"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1548 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{46030924-64b9-6e81-e5b8-7c57d4c65547}\virtualmic.inf" "0" "677c6effb" "000005D0" "WinSta0\Default" "00000550" "208" "c:\program files\easeus\voicewave\bin\driver\x86"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096964
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1072 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
996DrvInst.exe "3" "201" "ROOT\MEDIA\0000" "" "" "677c6effb" "000005D0" "000005FC" "000005F8"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096921
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1044"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" remove "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exeeaseus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2304 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1316"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" install "C:\Program Files\EaseUS\VoiceWave\bin\Driver\X86\VirtualMic.inf" "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe
easeus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
2
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1348rundll32.exe C:\Windows\system32\newdev.dll,pDiDeviceInstallNotification \\.\pipe\PNP_Device_Install_Pipe_1.{3e58ec8a-ffa5-460b-858c-17daa641b3c7} "(null)"C:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
14 557
Read events
14 385
Write events
166
Delete events
6

Modification events

(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
54DA2A255D52DA01
Executable files
356
Suspicious files
197
Text files
1 190
Unknown types
0

Dropped files

PID
Process
Filename
Type
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\German.initext
MD5:AC1825EE5C31C4594A0C98951480B706
SHA256:759508635384FC8956CECB09117AAA7F7EBA2C905C8810802F0DE67C247C59EB
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Japanese.initext
MD5:AD5ECE381DB4106E13640E46ADE6C460
SHA256:020526525424A57FEC4101997D272DFC2B83A8D57456C2C245A56D68E4B4E317
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\EDownloader.exeexecutable
MD5:4EF50A03EDFEFBF87998B95C222B80F9
SHA256:21E80AF367881F498233263275C57C6063999111FF5105011EAFBACC00964230
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Italian.initext
MD5:ECD3A477C69A9AC24C0CE38FA4EC6228
SHA256:31CA5A5F382CAEDAD0883FA8FF3D3CA039056497D8D9EA05AE82230CD0D63185
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe.temp
MD5:
SHA256:
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe
MD5:
SHA256:
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\LanguageTransfor.initext
MD5:5B9180CA7B92EAF3FC02C35E78E66CBD
SHA256:A4433BED3D227249D08D37B84C84A001E443586D5CD2CD63F3FEDE48D282BAE8
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\english.initext
MD5:29F27C125DD3A42C9144C13BFD8C798C
SHA256:1E6F09D26AC1F99C4D3C10AF77312E903A56240526247540E6335F79C03567B6
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Spanish.initext
MD5:145296CDE8F91D3D2E38825966DC06CB
SHA256:812B079B1988194AA67F5729BA4E945A81DB9B004A29500F9AD951DAEE097829
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Portuguese.initext
MD5:2C4973DA07C2C9F28C28C09B82A26623
SHA256:D8D06021018D4C88EF181202B888BA18E29912788E31E8B9F791C7A0F54F8375
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
101
DNS requests
65
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1880
EDownloader.exe
POST
200
143.204.98.3:80
http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
unknown
binary
491 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
unknown
binary
21 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
3804
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
unknown
binary
21 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1880
EDownloader.exe
143.204.98.3:80
download.easeus.com
AMAZON-02
US
whitelisted
568
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
568
AliyunWrapExe.Exe
47.252.97.15:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
1880
EDownloader.exe
18.66.112.6:443
d1.easeus.com
AMAZON-02
US
unknown
568
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
3804
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
3804
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
download.easeus.com
  • 143.204.98.3
  • 143.204.98.21
  • 143.204.98.43
  • 143.204.98.38
unknown
track.easeus.com
  • 163.171.156.15
unknown
easeusinfo.us-east-1.log.aliyuncs.com
  • 47.252.97.15
  • 47.252.97.14
  • 47.252.97.13
  • 47.252.97.12
  • 47.252.97.11
  • 47.252.97.10
  • 47.252.97.9
  • 47.252.97.8
  • 47.252.97.212
unknown
d1.easeus.com
  • 18.66.112.6
  • 18.66.112.125
  • 18.66.112.38
  • 18.66.112.111
unknown
multimedia.easeus.com
  • 104.18.2.193
  • 104.18.3.193
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.166.151.106
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted
www.easeus.com
  • 104.18.18.71
  • 104.18.19.71
whitelisted

Threats

No threats detected
Process
Message
EDownloader.exe
[2724]-02:44:56:485 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=voicewave_installer_20240128.952567.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
EDownloader.exe
[2724]-02:44:56:516 Install recomand return=259
EDownloader.exe
[2724]-02:44:56:813 Install recomand return=259
EDownloader.exe
[2316]-02:44:56:844 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ param=exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data Start
EDownloader.exe
[2724]-02:44:57:954 download parm : exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data end
EDownloader.exe
[2724]-02:44:57:954 CHttpHelper::GetDownloadInfo 45 download info code:0
EDownloader.exe
[2724]-02:44:57:954 download url : http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
EDownloader.exe
[2724]-02:44:57:954 Install recomand return=259