download:

easeus-data-recovery-wizard-crack

Full analysis: https://app.any.run/tasks/6d57d299-cfff-44fd-af56-8b83496321c0
Verdict: No threats detected
Analysis date: October 04, 2019, 03:02:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5:

5027A7239C09860C2A8263F2B882985E

SHA1:

7B2BC6C2D66C05003B4B81BF3C2E9D0F88037095

SHA256:

D4FE06AF2EC25CF1A1A119B2B4F2B373A299318354F37BD0596B13D4A2286B88

SSDEEP:

1536:ilN3O8QsHDadZ3yTdSjaOtf1LHjmyLmVHdYdRhiQaHI+qIerkeyteJLezM7FGEb3:ilg/Z3yTVse9UqzM75MQzRXBwbl2i/O1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2680)
    • Changes settings of System certificates

      • iexplore.exe (PID: 952)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 952)
    • Reads internet explorer settings

      • iexplore.exe (PID: 952)
    • Changes internet zones settings

      • iexplore.exe (PID: 2680)
    • Creates files in the user directory

      • iexplore.exe (PID: 952)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.htm/html | HyperText Markup Language with DOCTYPE (80.6)
.html | HyperText Markup Language (19.3)

EXIF

HTML

googleSiteVerification: bjyXmv_fnM4RuJcJnjW-C7aZjZ_biqQaoeTBxcLEQgM
viewport: width=device-width, initial-scale=1
propeller: 66c5bbf57f6f0caff72e81e1a67bdf26
Title: EaseUS Data Recovery Wizard 12.9.1 Crack + License Code {2019}
Description: EaseUS Data Recovery Wizard Crack + License Code {2019} EaseUS Data Recovery Wizard 12.9.1 Crack with Key makes data retrieval easy for any user if you.
twitterCard: summary_large_image
twitterDescription: EaseUS Data Recovery Wizard Crack + License Code {2019} EaseUS Data Recovery Wizard 12.9.1 Crack with Key makes data retrieval easy for any user if you.
twitterTitle: EaseUS Data Recovery Wizard 12.9.1 Crack + License Code {2019}
twitterImage: https://i0.wp.com/activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg?fit=602%2C414
shareaholicSite_name: Activation Keys
shareaholicLanguage: en-US
shareaholicUrl: http://activationkeys.co/easeus-data-recovery-wizard-crack/
shareaholicKeywords: easeus data recovery activation code, easeus data recovery activation key, easeus data recovery activation key 2019, easeus data recovery crack, easeus data recovery crack file, easeus data recovery crack version free download, easeus data recovery key, easeus data recovery wizard 12.9.0 crack, easeus data recovery wizard 2019, easeus data recovery wizard 2019 crack, easeus data recovery wizard activation code 2019, easeus data recovery wizard activation key, easeus data recovery wizard code, easeus data recovery wizard crack, easeus data recovery wizard crack 2019, easeus data recovery wizard crack file download, easeus data recovery wizard crack mac, easeus data recovery wizard free 12.9 key, easeus data recovery wizard free edition serial key, easeus data recovery wizard free license code, easeus data recovery wizard full crack, easeus data recovery wizard key, easeus data recovery wizard key code, easeus data recovery wizard key crack, easeus data recovery wizard license code, easeus data recovery wizard professional crack, easeus data recovery wizard serial key crack, easeus data recovery wizard 12.9.1 crack, data recovery, post
shareaholicArticle_published_time: 2019-09-18T02:16:10+00:00
shareaholicArticle_modified_time: 2019-09-22T17:15:41+00:00
shareaholicShareable_page:
shareaholicArticle_author_name: farooq khokhar
shareaholicSite_id: a5c37fe9e24f020ed6f97986ea73e032
shareaholicWp_version: 8.13.10
shareaholicImage: https://i0.wp.com/activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg?fit=602%2C414
Generator: WordPress 5.2.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2680 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2680"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\easeus-data-recovery-wizard-crack.htmC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
435
Read events
349
Write events
84
Delete events
2

Modification events

(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{6F653AD3-E653-11E9-AB4C-5254004A04AF}
Value:
0
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2680) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070A0005000400030002002D008200
Executable files
0
Suspicious files
0
Text files
49
Unknown types
3

Dropped files

PID
Process
Filename
Type
2680iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2680iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\lockers.020307.min[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\style[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@addtoany[1].txttext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\table-of-content-frontend[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\style[1].csstext
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\EaseUS-Data-Recovery-Keygen-1[1].jpgimage
MD5:
SHA256:
2680iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\jquery.rating.min[1].jstext
MD5:136C745E6D222776FF48F5BAF3568739
SHA256:554F3FF96CBA4F2F33FF2C37C48282006AB24A85CF9CA0AC8B22B0A06126C1D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
34
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
952
iexplore.exe
GET
304
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/social-locker/bizpanda/assets/css/lockers.020307.min.css?ver=5.2.3
US
compressed
12.4 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/social-locker/bizpanda/assets/css/lockers.020307.min.css?ver=5.2.3
US
text
12.4 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/all-in-one-schemaorg-rich-snippets/css/style.css?ver=5.2.3
US
text
748 b
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/css/font-awesome.min.css?ver=5.2.3
US
text
6.71 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/uploads/2018/12/EaseUS-Data-Recovery-Keygen-1.jpg
US
image
48.0 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/js/jorvik-custom.js?ver=1.0
US
text
1.34 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/images/select-arrow.png
US
image
312 b
malicious
2680
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/plugins/all-in-one-schemaorg-rich-snippets/js/jquery.rating.min.js?ver=5.2.3
US
text
10.0 Kb
malicious
952
iexplore.exe
GET
200
104.18.45.23:80
http://activationkeys.co/wp-content/themes/jorvik/css/fonts/fontawesome-webfont.eot?
US
eot
96.6 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
151.139.128.10:445
cdn.shareaholic.net
Highwinds Network Group, Inc.
US
malicious
2680
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
4
System
151.139.128.10:139
cdn.shareaholic.net
Highwinds Network Group, Inc.
US
malicious
952
iexplore.exe
192.0.78.17:443
wordpress.com
Automattic, Inc
US
unknown
4
System
88.85.66.229:445
pushosub.com
Webzilla B.V.
NL
suspicious
952
iexplore.exe
104.20.111.39:443
static.addtoany.com
Cloudflare Inc
US
shared
4
System
88.85.66.222:445
pushosub.com
Webzilla B.V.
NL
suspicious
88.85.66.222:137
pushosub.com
Webzilla B.V.
NL
suspicious
952
iexplore.exe
5.79.96.116:443
feboni.info
LeaseWeb Netherlands B.V.
NL
unknown
952
iexplore.exe
192.0.77.2:443
i0.wp.com
Automattic, Inc
US
suspicious

DNS requests

Domain
IP
Reputation
cdn.shareaholic.net
  • 151.139.128.10
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
fonts.googleapis.com
  • 172.217.22.74
whitelisted
c0.wp.com
  • 192.0.77.37
whitelisted
activationkeys.co
  • 104.18.45.23
  • 104.18.44.23
malicious
wordpress.com
  • 192.0.78.17
  • 192.0.78.9
whitelisted
static.addtoany.com
  • 104.20.111.39
  • 104.20.110.39
whitelisted
pushosub.com
  • 88.85.66.229
  • 88.85.66.222
suspicious
feboni.info
  • 5.79.96.116
suspicious

Threats

No threats detected
No debug info