download:

easeus-data-recovery-wizard-crack

Full analysis: https://app.any.run/tasks/6d57d299-cfff-44fd-af56-8b83496321c0
Verdict: No threats detected
Analysis date: October 04, 2019, 03:02:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5:

5027A7239C09860C2A8263F2B882985E

SHA1:

7B2BC6C2D66C05003B4B81BF3C2E9D0F88037095

SHA256:

D4FE06AF2EC25CF1A1A119B2B4F2B373A299318354F37BD0596B13D4A2286B88

SSDEEP:

1536:ilN3O8QsHDadZ3yTdSjaOtf1LHjmyLmVHdYdRhiQaHI+qIerkeyteJLezM7FGEb3:ilg/Z3yTVse9UqzM75MQzRXBwbl2i/O1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 952)
    • Application launched itself

      • iexplore.exe (PID: 2680)
    • Changes internet zones settings

      • iexplore.exe (PID: 2680)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 952)
    • Changes settings of System certificates

      • iexplore.exe (PID: 952)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 952)
    • Creates files in the user directory

      • iexplore.exe (PID: 952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.htm/html | HyperText Markup Language with DOCTYPE (80.6)
.html | HyperText Markup Language (19.3)

EXIF

HTML

googleSiteVerification: bjyXmv_fnM4RuJcJnjW-C7aZjZ_biqQaoeTBxcLEQgM
viewport: width=device-width, initial-scale=1
propeller: 66c5bbf57f6f0caff72e81e1a67bdf26
Title: EaseUS Data Recovery Wizard 12.9.1 Crack + License Code {2019}
Description: EaseUS Data Recovery Wizard Crack + License Code {2019} EaseUS Data Recovery Wizard 12.9.1 Crack with Key makes data retrieval easy for any user if you.
twitterCard: summary_large_image
twitterDescription: EaseUS Data Recovery Wizard Crack + License Code {2019} EaseUS Data Recovery Wizard 12.9.1 Crack with Key makes data retrieval easy for any user if you.
twitterTitle: EaseUS Data Recovery Wizard 12.9.1 Crack + License Code {2019}
twitterImage: https://i0.wp.com/activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg?fit=602%2C414
shareaholicSite_name: Activation Keys
shareaholicLanguage: en-US
shareaholicUrl: http://activationkeys.co/easeus-data-recovery-wizard-crack/
shareaholicKeywords: easeus data recovery activation code, easeus data recovery activation key, easeus data recovery activation key 2019, easeus data recovery crack, easeus data recovery crack file, easeus data recovery crack version free download, easeus data recovery key, easeus data recovery wizard 12.9.0 crack, easeus data recovery wizard 2019, easeus data recovery wizard 2019 crack, easeus data recovery wizard activation code 2019, easeus data recovery wizard activation key, easeus data recovery wizard code, easeus data recovery wizard crack, easeus data recovery wizard crack 2019, easeus data recovery wizard crack file download, easeus data recovery wizard crack mac, easeus data recovery wizard free 12.9 key, easeus data recovery wizard free edition serial key, easeus data recovery wizard free license code, easeus data recovery wizard full crack, easeus data recovery wizard key, easeus data recovery wizard key code, easeus data recovery wizard key crack, easeus data recovery wizard license code, easeus data recovery wizard professional crack, easeus data recovery wizard serial key crack, easeus data recovery wizard 12.9.1 crack, data recovery, post
shareaholicArticle_published_time: 2019-09-18T02:16:10+00:00
shareaholicArticle_modified_time: 2019-09-22T17:15:41+00:00
shareaholicShareable_page:
shareaholicArticle_author_name: farooq khokhar
shareaholicSite_id: a5c37fe9e24f020ed6f97986ea73e032
shareaholicWp_version: 8.13.10
shareaholicImage: https://i0.wp.com/activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg?fit=602%2C414
Generator: WordPress 5.2.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2680 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2680"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\easeus-data-recovery-wizard-crack.htmC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
435
Read events
349
Write events
84
Delete events
2

Modification events

(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{6F653AD3-E653-11E9-AB4C-5254004A04AF}
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070A0005000400030002002D008200
Executable files
0
Suspicious files
0
Text files
49
Unknown types
3

Dropped files

PID
Process
Filename
Type
2680iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2680iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\lockers.020307.min[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\table-of-content-frontend[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\style[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\style[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@addtoany[1].txttext
MD5:
SHA256:
2680iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\EaseUS-Data-Recovery-Keygen-1[1].jpgimage
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\style.min[1].csstext
MD5:375BD65D60FF3C8723FCCC343AFB1B9B
SHA256:4B8FE5C3D0E5EF7A6582185CBF5C535B5D369C8DF1DA98C03ED69833E55F474D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
34
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/cm-table-of-content/assets/css/table-of-content-frontend.css?ver=5.2.3
US
text
288 b
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/social-locker/bizpanda/assets/css/lockers.020307.min.css?ver=5.2.3
US
text
12.4 Kb
malicious
952
iexplore.exe
GET
304
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/social-locker/bizpanda/assets/css/lockers.020307.min.css?ver=5.2.3
US
compressed
12.4 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/all-in-one-schemaorg-rich-snippets/css/style.css?ver=5.2.3
US
text
748 b
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg
US
image
48.0 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/js/jorvik-custom.js?ver=1.0
US
text
1.34 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/style.css?ver=5.2.3
US
text
11.1 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/add-to-any/addtoany.min.css?ver=1.15
US
text
459 b
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-includes/js/wp-emoji-release.min.js?ver=5.2.3
US
text
4.50 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/all-in-one-schemaorg-rich-snippets/css/jquery.rating.css?ver=5.2.3
US
text
428 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
151.139.128.10:445
cdn.shareaholic.net
Highwinds Network Group, Inc.
US
malicious
2680
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
4
System
151.139.128.10:139
cdn.shareaholic.net
Highwinds Network Group, Inc.
US
malicious
952
iexplore.exe
104.18.45.23:80
activationkeys.co
Cloudflare Inc
US
shared
952
iexplore.exe
192.0.77.37:443
c0.wp.com
Automattic, Inc
US
suspicious
4
System
88.85.66.229:445
pushosub.com
Webzilla B.V.
NL
suspicious
4
System
88.85.66.222:445
pushosub.com
Webzilla B.V.
NL
suspicious
88.85.66.222:137
pushosub.com
Webzilla B.V.
NL
suspicious
952
iexplore.exe
5.79.96.116:443
feboni.info
LeaseWeb Netherlands B.V.
NL
unknown
952
iexplore.exe
192.0.73.2:443
1.gravatar.com
Automattic, Inc
US
whitelisted

DNS requests

Domain
IP
Reputation
cdn.shareaholic.net
  • 151.139.128.10
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
fonts.googleapis.com
  • 172.217.22.74
whitelisted
c0.wp.com
  • 192.0.77.37
whitelisted
activationkeys.co
  • 104.18.45.23
  • 104.18.44.23
malicious
wordpress.com
  • 192.0.78.17
  • 192.0.78.9
whitelisted
static.addtoany.com
  • 104.20.111.39
  • 104.20.110.39
whitelisted
pushosub.com
  • 88.85.66.229
  • 88.85.66.222
suspicious
feboni.info
  • 5.79.96.116
suspicious

Threats

No threats detected
No debug info