File name:

voicewave_installer_20240128.952567.exe

Full analysis: https://app.any.run/tasks/ba15084d-9812-48b0-bf62-d415153a284c
Verdict: Malicious activity
Analysis date: January 29, 2024, 02:44:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

B9C9B4EDF5B65D3C91F8A4555587EBF2

SHA1:

9B09FB75266F44CA2A893D787BBE679AADD4F402

SHA256:

D101B0A989E1B3001A705A5151AA47E837B6070ED0C0823284A90518EDC17773

SSDEEP:

98304:87VERwrWzXcao6n7LoyEnZKDxUQAKDTS4MZ6N2mp5EaxbGnl+tNf/xUKkO:xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • devconX86.exe (PID: 1316)
      • evw_free_easeus.tmp (PID: 2656)
      • drvinst.exe (PID: 956)
    • Actions looks like stealing of personal data

      • evw_free_easeus.tmp (PID: 2656)
      • easeus.voicewave.exe (PID: 3476)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 956)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads the Internet Settings

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • powershell.exe (PID: 3644)
      • evw_free_easeus.tmp (PID: 2656)
      • AliyunWrapExe.Exe (PID: 3804)
    • Reads Microsoft Outlook installation path

      • EDownloader.exe (PID: 1880)
    • Reads Internet Explorer settings

      • EDownloader.exe (PID: 1880)
    • Reads the Windows owner or organization settings

      • evw_free_easeus.tmp (PID: 2656)
    • Process drops legitimate windows executable

      • evw_free_easeus.tmp (PID: 2656)
    • Drops a system driver (possible attempt to evade defenses)

      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 3644)
    • Starts POWERSHELL.EXE for commands execution

      • evw_free_easeus.tmp (PID: 2656)
    • The process drops C-runtime libraries

      • evw_free_easeus.tmp (PID: 2656)
    • Searches for installed software

      • EDownloader.exe (PID: 1880)
    • Reads security settings of Internet Explorer

      • devconX86.exe (PID: 1316)
    • Checks Windows Trust Settings

      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads settings of System Certificates

      • devconX86.exe (PID: 1316)
    • Creates files in the driver directory

      • drvinst.exe (PID: 956)
  • INFO

    • Checks supported languages

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2780)
      • InfoForSetup.exe (PID: 2388)
      • AliyunWrapExe.Exe (PID: 568)
      • InfoForSetup.exe (PID: 2064)
      • InfoForSetup.exe (PID: 3400)
      • evw_free_easeus.exe (PID: 1408)
      • InfoForSetup.exe (PID: 3040)
      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 128)
      • InfoForSetup.exe (PID: 3052)
      • EUinApp.exe (PID: 3608)
      • FireWallAssist.exe (PID: 3928)
      • FireWallAssist.exe (PID: 3480)
      • SetupUE.exe (PID: 4012)
      • InfoForSetup.exe (PID: 2996)
      • InfoForSetup.exe (PID: 2132)
      • AliyunWrapExe.Exe (PID: 3804)
      • InfoForSetup.exe (PID: 2044)
      • InfoForSetup.exe (PID: 3956)
      • InfoForSetup.exe (PID: 3148)
      • InfoForSetup.exe (PID: 2472)
      • InfoForSetup.exe (PID: 2524)
      • EuDownload.exe (PID: 3052)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 2372)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1044)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3012)
      • drvinst.exe (PID: 996)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 3696)
    • Reads the computer name

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 568)
      • evw_free_easeus.tmp (PID: 2656)
      • FireWallAssist.exe (PID: 3928)
      • FireWallAssist.exe (PID: 3480)
      • InfoForSetup.exe (PID: 2996)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 3052)
      • EuDownload.exe (PID: 2372)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1044)
      • devconX86.exe (PID: 1316)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 2068)
      • drvinst.exe (PID: 956)
      • drvinst.exe (PID: 996)
      • EuDownload.exe (PID: 3012)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 3116)
    • Create files in a temporary directory

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2388)
      • AliyunWrapExe.Exe (PID: 568)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • easeus.voicewave.exe (PID: 3476)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 3012)
    • Checks proxy server information

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
    • Reads the machine GUID from the registry

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • easeus.voicewave.exe (PID: 3476)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Creates files or folders in the user directory

      • AliyunWrapExe.Exe (PID: 568)
      • AliyunWrapExe.Exe (PID: 3804)
      • easeus.evw.vchanger.exe (PID: 3132)
    • Creates files in the program directory

      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 2132)
      • AliyunWrapExe.Exe (PID: 3804)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 3052)
      • EuDownload.exe (PID: 2372)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
    • Application launched itself

      • msedge.exe (PID: 2932)
      • msedge.exe (PID: 3620)
    • Manual execution by a user

      • msedge.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:48+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 186368
UninitializedDataSize: 2048
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
59
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start voicewave_installer_20240128.952567.exe edownloader.exe infoforsetup.exe no specs infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs evw_free_easeus.exe evw_free_easeus.tmp euinapp.exe no specs powershell.exe no specs firewallassist.exe firewallassist.exe setupue.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs msedge.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs easeus.voicewave.exe eudownload.exe msedge.exe no specs eudownload.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs easeus.evw.vchanger.exe msedge.exe no specs msedge.exe no specs devconx86.exe no specs devconx86.exe drvinst.exe rundll32.exe no specs drvinst.exe no specs rundll32.exe no specs eudownload.exe eudownload.exe eudownload.exe eudownload.exe eudownload.exe voicewave_installer_20240128.952567.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128 /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Downloadfrom\":\"https://d1.easeus.com/evw/free/voicewave2.6.1_free.exe\",\"Pageid\":\"952567\",\"Testid\":\"\",\"Version\":\"free\",\"Versionnumber\":\"2.6.1\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
568C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
876"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1548 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{46030924-64b9-6e81-e5b8-7c57d4c65547}\virtualmic.inf" "0" "677c6effb" "000005D0" "WinSta0\Default" "00000550" "208" "c:\program files\easeus\voicewave\bin\driver\x86"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096964
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1072 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
996DrvInst.exe "3" "201" "ROOT\MEDIA\0000" "" "" "677c6effb" "000005D0" "000005FC" "000005F8"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096921
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1044"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" remove "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exeeaseus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2304 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1316"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" install "C:\Program Files\EaseUS\VoiceWave\bin\Driver\X86\VirtualMic.inf" "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe
easeus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
2
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1348rundll32.exe C:\Windows\system32\newdev.dll,pDiDeviceInstallNotification \\.\pipe\PNP_Device_Install_Pipe_1.{3e58ec8a-ffa5-460b-858c-17daa641b3c7} "(null)"C:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
14 557
Read events
14 385
Write events
166
Delete events
6

Modification events

(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
54DA2A255D52DA01
Executable files
356
Suspicious files
197
Text files
1 190
Unknown types
0

Dropped files

PID
Process
Filename
Type
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\skin.zipcompressed
MD5:FAC982630F0164A0A84202D09FF449BB
SHA256:A19130389B44E30F7C54CA71A4A6C161B5B6A9E81EFDBC25BA976CE6628C2927
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\German.initext
MD5:AC1825EE5C31C4594A0C98951480B706
SHA256:759508635384FC8956CECB09117AAA7F7EBA2C905C8810802F0DE67C247C59EB
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\EDownloader.exeexecutable
MD5:4EF50A03EDFEFBF87998B95C222B80F9
SHA256:21E80AF367881F498233263275C57C6063999111FF5105011EAFBACC00964230
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\ChineseTrad.initext
MD5:34F74F7BB6E392399882B0A0DCA6AE8F
SHA256:297DF2C127C86C7AF8B40B974681E0EDE66569F9EA117A8B345E5CE27277CFAD
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe.temp
MD5:
SHA256:
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe
MD5:
SHA256:
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Japanese.initext
MD5:AD5ECE381DB4106E13640E46ADE6C460
SHA256:020526525424A57FEC4101997D272DFC2B83A8D57456C2C245A56D68E4B4E317
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Italian.initext
MD5:ECD3A477C69A9AC24C0CE38FA4EC6228
SHA256:31CA5A5F382CAEDAD0883FA8FF3D3CA039056497D8D9EA05AE82230CD0D63185
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\InitConfigure.initext
MD5:334125B792E1A2B158E87241E63FC5BA
SHA256:CE2C9D7DDFEFB1D9C0CEF83649DFC4A76C570562DA835CEC804E1F3CEAD0BA21
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Korean.initext
MD5:594D500E3CDF46B312E7313F377A0643
SHA256:641691364D7E9B324CFB61C1FF1C8C5C90B068012DBB18D073D088A2E3F3FC23
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
101
DNS requests
65
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1880
EDownloader.exe
POST
200
143.204.98.3:80
http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
US
binary
491 b
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
US
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
US
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
US
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
US
unknown
568
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
DE
binary
21 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
US
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
US
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
US
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1880
EDownloader.exe
143.204.98.3:80
download.easeus.com
AMAZON-02
US
whitelisted
568
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
568
AliyunWrapExe.Exe
47.252.97.15:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
1880
EDownloader.exe
18.66.112.6:443
d1.easeus.com
AMAZON-02
US
unknown
568
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
3804
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
3804
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
download.easeus.com
  • 143.204.98.3
  • 143.204.98.21
  • 143.204.98.43
  • 143.204.98.38
unknown
track.easeus.com
  • 163.171.156.15
unknown
easeusinfo.us-east-1.log.aliyuncs.com
  • 47.252.97.15
  • 47.252.97.14
  • 47.252.97.13
  • 47.252.97.12
  • 47.252.97.11
  • 47.252.97.10
  • 47.252.97.9
  • 47.252.97.8
  • 47.252.97.212
unknown
d1.easeus.com
  • 18.66.112.6
  • 18.66.112.125
  • 18.66.112.38
  • 18.66.112.111
unknown
multimedia.easeus.com
  • 104.18.2.193
  • 104.18.3.193
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.166.151.106
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted
www.easeus.com
  • 104.18.18.71
  • 104.18.19.71
whitelisted

Threats

No threats detected
Process
Message
EDownloader.exe
[2724]-02:44:56:485 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=voicewave_installer_20240128.952567.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
EDownloader.exe
[2724]-02:44:56:516 Install recomand return=259
EDownloader.exe
[2724]-02:44:56:813 Install recomand return=259
EDownloader.exe
[2316]-02:44:56:844 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ param=exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data Start
EDownloader.exe
[2724]-02:44:57:954 download parm : exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data end
EDownloader.exe
[2724]-02:44:57:954 CHttpHelper::GetDownloadInfo 45 download info code:0
EDownloader.exe
[2724]-02:44:57:954 download url : http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
EDownloader.exe
[2724]-02:44:57:954 Install recomand return=259