File name:

voicewave_installer_20240128.952567.exe

Full analysis: https://app.any.run/tasks/ba15084d-9812-48b0-bf62-d415153a284c
Verdict: Malicious activity
Analysis date: January 29, 2024, 02:44:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

B9C9B4EDF5B65D3C91F8A4555587EBF2

SHA1:

9B09FB75266F44CA2A893D787BBE679AADD4F402

SHA256:

D101B0A989E1B3001A705A5151AA47E837B6070ED0C0823284A90518EDC17773

SSDEEP:

98304:87VERwrWzXcao6n7LoyEnZKDxUQAKDTS4MZ6N2mp5EaxbGnl+tNf/xUKkO:xh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Actions looks like stealing of personal data

      • evw_free_easeus.tmp (PID: 2656)
      • easeus.voicewave.exe (PID: 3476)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 956)
  • SUSPICIOUS

    • Reads the Internet Settings

      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 568)
      • powershell.exe (PID: 3644)
      • AliyunWrapExe.Exe (PID: 3804)
      • evw_free_easeus.tmp (PID: 2656)
    • Executable content was dropped or overwritten

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads Microsoft Outlook installation path

      • EDownloader.exe (PID: 1880)
    • Reads Internet Explorer settings

      • EDownloader.exe (PID: 1880)
    • Drops a system driver (possible attempt to evade defenses)

      • evw_free_easeus.tmp (PID: 2656)
      • drvinst.exe (PID: 956)
      • devconX86.exe (PID: 1316)
    • Starts POWERSHELL.EXE for commands execution

      • evw_free_easeus.tmp (PID: 2656)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 3644)
    • Process drops legitimate windows executable

      • evw_free_easeus.tmp (PID: 2656)
    • Reads the Windows owner or organization settings

      • evw_free_easeus.tmp (PID: 2656)
    • The process drops C-runtime libraries

      • evw_free_easeus.tmp (PID: 2656)
    • Searches for installed software

      • EDownloader.exe (PID: 1880)
    • Checks Windows Trust Settings

      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads security settings of Internet Explorer

      • devconX86.exe (PID: 1316)
    • Reads settings of System Certificates

      • devconX86.exe (PID: 1316)
    • Creates files in the driver directory

      • drvinst.exe (PID: 956)
  • INFO

    • Checks supported languages

      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2780)
      • InfoForSetup.exe (PID: 2388)
      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • AliyunWrapExe.Exe (PID: 568)
      • InfoForSetup.exe (PID: 2064)
      • InfoForSetup.exe (PID: 128)
      • InfoForSetup.exe (PID: 3040)
      • evw_free_easeus.exe (PID: 1408)
      • InfoForSetup.exe (PID: 3052)
      • InfoForSetup.exe (PID: 3400)
      • EUinApp.exe (PID: 3608)
      • FireWallAssist.exe (PID: 3928)
      • FireWallAssist.exe (PID: 3480)
      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 2996)
      • InfoForSetup.exe (PID: 2132)
      • InfoForSetup.exe (PID: 3956)
      • AliyunWrapExe.Exe (PID: 3804)
      • InfoForSetup.exe (PID: 2044)
      • SetupUE.exe (PID: 4012)
      • EuDownload.exe (PID: 3052)
      • InfoForSetup.exe (PID: 3148)
      • InfoForSetup.exe (PID: 2472)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 2372)
      • InfoForSetup.exe (PID: 2524)
      • devconX86.exe (PID: 1044)
      • devconX86.exe (PID: 1316)
      • easeus.evw.vchanger.exe (PID: 3132)
      • drvinst.exe (PID: 996)
      • drvinst.exe (PID: 956)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3012)
    • Create files in a temporary directory

      • EDownloader.exe (PID: 1880)
      • InfoForSetup.exe (PID: 2388)
      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • AliyunWrapExe.Exe (PID: 568)
      • evw_free_easeus.exe (PID: 1408)
      • evw_free_easeus.tmp (PID: 2656)
      • easeus.voicewave.exe (PID: 3476)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 3116)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3012)
      • EuDownload.exe (PID: 3696)
    • Creates files or folders in the user directory

      • AliyunWrapExe.Exe (PID: 568)
      • AliyunWrapExe.Exe (PID: 3804)
      • easeus.evw.vchanger.exe (PID: 3132)
    • Reads the machine GUID from the registry

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • easeus.voicewave.exe (PID: 3476)
      • devconX86.exe (PID: 1316)
      • drvinst.exe (PID: 956)
    • Reads the computer name

      • voicewave_installer_20240128.952567.exe (PID: 2692)
      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • evw_free_easeus.tmp (PID: 2656)
      • FireWallAssist.exe (PID: 3928)
      • InfoForSetup.exe (PID: 2996)
      • AliyunWrapExe.Exe (PID: 3804)
      • SetupUE.exe (PID: 4012)
      • FireWallAssist.exe (PID: 3480)
      • easeus.voicewave.exe (PID: 3476)
      • EuDownload.exe (PID: 3052)
      • EuDownload.exe (PID: 2372)
      • devconX86.exe (PID: 1316)
      • devconX86.exe (PID: 1044)
      • easeus.evw.vchanger.exe (PID: 3132)
      • drvinst.exe (PID: 996)
      • drvinst.exe (PID: 956)
      • EuDownload.exe (PID: 1820)
      • EuDownload.exe (PID: 3012)
      • EuDownload.exe (PID: 3696)
      • EuDownload.exe (PID: 2068)
      • EuDownload.exe (PID: 3116)
    • Checks proxy server information

      • AliyunWrapExe.Exe (PID: 568)
      • EDownloader.exe (PID: 1880)
      • AliyunWrapExe.Exe (PID: 3804)
    • Creates files in the program directory

      • evw_free_easeus.tmp (PID: 2656)
      • InfoForSetup.exe (PID: 2132)
      • AliyunWrapExe.Exe (PID: 3804)
      • EuDownload.exe (PID: 3052)
      • EuDownload.exe (PID: 2372)
      • easeus.voicewave.exe (PID: 3476)
      • easeus.evw.vchanger.exe (PID: 3132)
      • devconX86.exe (PID: 1316)
    • Application launched itself

      • msedge.exe (PID: 2932)
      • msedge.exe (PID: 3620)
    • Manual execution by a user

      • msedge.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:48+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 186368
UninitializedDataSize: 2048
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
59
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start voicewave_installer_20240128.952567.exe edownloader.exe infoforsetup.exe no specs infoforsetup.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs evw_free_easeus.exe evw_free_easeus.tmp euinapp.exe no specs powershell.exe no specs firewallassist.exe firewallassist.exe setupue.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs msedge.exe no specs aliyunwrapexe.exe infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs infoforsetup.exe no specs infoforsetup.exe no specs msedge.exe no specs infoforsetup.exe no specs easeus.voicewave.exe eudownload.exe msedge.exe no specs eudownload.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs easeus.evw.vchanger.exe msedge.exe no specs msedge.exe no specs devconx86.exe no specs devconx86.exe drvinst.exe rundll32.exe no specs drvinst.exe no specs rundll32.exe no specs eudownload.exe eudownload.exe eudownload.exe eudownload.exe eudownload.exe voicewave_installer_20240128.952567.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128 /SendInfo Window "Downloading" Activity "Info_Start_Download_Program" Attribute "{\"Downloadfrom\":\"https://d1.easeus.com/evw/free/voicewave2.6.1_free.exe\",\"Pageid\":\"952567\",\"Testid\":\"\",\"Version\":\"free\",\"Versionnumber\":\"2.6.1\"}"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\InfoForSetup.exeEDownloader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\infoforsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
568C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.ExeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\AliyunWrapExe.Exe
InfoForSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrapexe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\46free\aliyun\aliyunwrap.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
876"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1548 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{46030924-64b9-6e81-e5b8-7c57d4c65547}\virtualmic.inf" "0" "677c6effb" "000005D0" "WinSta0\Default" "00000550" "208" "c:\program files\easeus\voicewave\bin\driver\x86"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096964
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
984"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1072 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
996DrvInst.exe "3" "201" "ROOT\MEDIA\0000" "" "" "677c6effb" "000005D0" "000005FC" "000005F8"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096921
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1044"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" remove "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exeeaseus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
0
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2304 --field-trial-handle=1352,i,1188440511298948833,15837431497202935804,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1316"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe" install "C:\Program Files\EaseUS\VoiceWave\bin\Driver\X86\VirtualMic.inf" "Root\VirtualMic"C:\Program Files\EaseUS\VoiceWave\bin\devconX86.exe
easeus.voicewave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Device Console
Exit code:
2
Version:
10.0.22621.382 (WinBuild.160101.0800)
Modules
Images
c:\program files\easeus\voicewave\bin\devconx86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1348rundll32.exe C:\Windows\system32\newdev.dll,pDiDeviceInstallNotification \\.\pipe\PNP_Device_Install_Pipe_1.{3e58ec8a-ffa5-460b-858c-17daa641b3c7} "(null)"C:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
14 557
Read events
14 385
Write events
166
Delete events
6

Modification events

(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(568) AliyunWrapExe.ExeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
54DA2A255D52DA01
Executable files
356
Suspicious files
197
Text files
1 190
Unknown types
0

Dropped files

PID
Process
Filename
Type
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\EDownloader.exeexecutable
MD5:4EF50A03EDFEFBF87998B95C222B80F9
SHA256:21E80AF367881F498233263275C57C6063999111FF5105011EAFBACC00964230
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\english.initext
MD5:29F27C125DD3A42C9144C13BFD8C798C
SHA256:1E6F09D26AC1F99C4D3C10AF77312E903A56240526247540E6335F79C03567B6
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Chinese.initext
MD5:7097A291530EFC5F6339ADC8E272D621
SHA256:8DFEADAD705AC2CAEBCFDFAB1614BB603C27A3D784109BBB8FB3F702EC1086A5
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\LanguageTransfor.initext
MD5:5B9180CA7B92EAF3FC02C35E78E66CBD
SHA256:A4433BED3D227249D08D37B84C84A001E443586D5CD2CD63F3FEDE48D282BAE8
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe.temp
MD5:
SHA256:
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\evw_free_easeus.exe
MD5:
SHA256:
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\Italian.initext
MD5:ECD3A477C69A9AC24C0CE38FA4EC6228
SHA256:31CA5A5F382CAEDAD0883FA8FF3D3CA039056497D8D9EA05AE82230CD0D63185
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\ChineseTrad.initext
MD5:34F74F7BB6E392399882B0A0DCA6AE8F
SHA256:297DF2C127C86C7AF8B40B974681E0EDE66569F9EA117A8B345E5CE27277CFAD
1880EDownloader.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\EasyLog.logtext
MD5:5E6720D90CA5BD12FF6E9D1A804DA3F5
SHA256:8D2ABAD41DF08287119B330D57BB2F7DA68AD49D1AC46A49434C6D1680BC205C
2692voicewave_installer_20240128.952567.exeC:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\46free\aliyun\InfoForSetup.exeexecutable
MD5:AF8A1F5CAF9C8411D3EEE07007450910
SHA256:E23E375713EC4D7372DC3FABABFAA612ECCED4F207E7BD68CE5571A21499E2BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
101
DNS requests
65
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
568
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
unknown
binary
21 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
1880
EDownloader.exe
POST
200
143.204.98.3:80
http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
unknown
binary
491 b
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.15:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
3804
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_ip/shards/lb
unknown
unknown
568
AliyunWrapExe.Exe
POST
200
47.252.97.212:80
http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_voicewave_downloader/shards/lb
unknown
unknown
3804
AliyunWrapExe.Exe
GET
200
163.171.156.15:80
http://track.easeus.com/product/index.php?c=main&a=getstatus&pid=0
unknown
binary
21 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1880
EDownloader.exe
143.204.98.3:80
download.easeus.com
AMAZON-02
US
whitelisted
568
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
568
AliyunWrapExe.Exe
47.252.97.15:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
1880
EDownloader.exe
18.66.112.6:443
d1.easeus.com
AMAZON-02
US
unknown
568
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown
3804
AliyunWrapExe.Exe
163.171.156.15:80
track.easeus.com
QUANTILNETWORKS
DE
unknown
3804
AliyunWrapExe.Exe
47.252.97.212:80
easeusinfo.us-east-1.log.aliyuncs.com
Alibaba US Technology Co., Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
download.easeus.com
  • 143.204.98.3
  • 143.204.98.21
  • 143.204.98.43
  • 143.204.98.38
unknown
track.easeus.com
  • 163.171.156.15
unknown
easeusinfo.us-east-1.log.aliyuncs.com
  • 47.252.97.15
  • 47.252.97.14
  • 47.252.97.13
  • 47.252.97.12
  • 47.252.97.11
  • 47.252.97.10
  • 47.252.97.9
  • 47.252.97.8
  • 47.252.97.212
unknown
d1.easeus.com
  • 18.66.112.6
  • 18.66.112.125
  • 18.66.112.38
  • 18.66.112.111
unknown
multimedia.easeus.com
  • 104.18.2.193
  • 104.18.3.193
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.166.151.106
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.23.107.164
whitelisted
www.easeus.com
  • 104.18.18.71
  • 104.18.19.71
whitelisted

Threats

No threats detected
Process
Message
EDownloader.exe
[2724]-02:44:56:485 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=voicewave_installer_20240128.952567.exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
EDownloader.exe
[2724]-02:44:56:516 Install recomand return=259
EDownloader.exe
[2724]-02:44:56:813 Install recomand return=259
EDownloader.exe
[2316]-02:44:56:844 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/ param=exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data Start
EDownloader.exe
[2724]-02:44:57:954 download parm : exeNumber=952567&lang=English&pcVersion=home&pid=46&tid=1&version=free
EDownloader.exe
[2316]-02:44:57:954 Json parse Data end
EDownloader.exe
[2724]-02:44:57:954 CHttpHelper::GetDownloadInfo 45 download info code:0
EDownloader.exe
[2724]-02:44:57:954 download url : http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/
EDownloader.exe
[2724]-02:44:57:954 Install recomand return=259