| File name: | DRW_Ad_Google_Installer_20211011.387080.exe |
| Full analysis: | https://app.any.run/tasks/a38828d4-cdec-4bc6-b407-572bcbc5cf3b |
| Verdict: | Malicious activity |
| Analysis date: | October 11, 2021, 21:04:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 3595689432C5E3F604EE27F522E2DE03 |
| SHA1: | 13E8BEFB92535BADE66DD5477032E53782AC0079 |
| SHA256: | D67D017A77BFAF9FC89FFE578AC07F3D5B4B51629B20992B78C132CAA7C363A2 |
| SSDEEP: | 49152:S/eviMJKDPTn92FW6HgprKebEQVkZPGOdCRyBin8dYMH:FHJEPTn274bjWfdCRKi8ug |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 04:57:48+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 30-Jan-2018 03:57:48 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 30-Jan-2018 03:57:48 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006627 | 0x00006800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.45224 |
.rdata | 0x00008000 | 0x0000149A | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.00708 |
.data | 0x0000A000 | 0x0002AFF8 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.03532 |
.ndata | 0x00035000 | 0x00010000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00045000 | 0x00010D40 | 0x00010E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.14037 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.28733 | 841 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 4.86193 | 9640 | UNKNOWN | English - United States | RT_ICON |
3 | 5.0916 | 4264 | UNKNOWN | English - United States | RT_ICON |
4 | 3.68334 | 3752 | UNKNOWN | English - United States | RT_ICON |
5 | 3.86293 | 2216 | UNKNOWN | English - United States | RT_ICON |
6 | 3.67461 | 1640 | UNKNOWN | English - United States | RT_ICON |
7 | 3.5329 | 1384 | UNKNOWN | English - United States | RT_ICON |
8 | 5.22737 | 1128 | UNKNOWN | English - United States | RT_ICON |
9 | 3.99637 | 744 | UNKNOWN | English - United States | RT_ICON |
10 | 3.53259 | 296 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | /SendInfo Window "Loading" Activity "Info_Powershell_Getphysicaldisk" Attribute "[\"Get_PhysicalDisk _ The term _Get_PhysicalDisk_ is not recognized as the name __of a cmdlet_ function_ script file_ or operable program. Check the spelling of __the name_ or if a path was included_ verify that the path is correct and try __again.__At line_1 char_1___ Get_PhysicalDisk _ Format_Table _AutoSize___ __________________ _ CategoryInfo _ ObjectNotFound_ _Get_PhysicalDisk_String_ ___ Co __ mmandNotFoundException__ _ FullyQualifiedErrorId _ CommandNotFoundException__ __\"]" | C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\aliyun\InfoForSetup.exe | — | DRWUI.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 332 | /SendInfo Window "Home_Installer" Activity "Click_Install" Attribute "{\"Install_Path\":\"C:/Program Files/EaseUS/EaseUS Data Recovery Wizard\",\"Language\":\"English\",\"Os\":\"Microsoft Windows 7\",\"Pageid\":\"387080\",\"Timezone\":\"GMT-00:00\"}" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 776 | "C:\Users\admin\AppData\Local\Temp\DRW_Ad_Google_Installer_20211011.387080.exe" | C:\Users\admin\AppData\Local\Temp\DRW_Ad_Google_Installer_20211011.387080.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 920 | /SendInfo Window "Loading" Activity "Info_Start" | C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\aliyun\InfoForSetup.exe | — | DRWUI.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1160 | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\aliyun\AliyunWrapExe.Exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\aliyun\AliyunWrapExe.Exe | InfoForSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1264 | "C:\Users\admin\AppData\Local\Temp\is-ET6N0.tmp\drw_trial.tmp" /SL5="$1014A,47224918,192512,C:\Users\admin\AppData\Local\Temp\drw_trial.exe" /verysilent /DIR="C:\Program Files\EaseUS\EaseUS Data Recovery Wizard" /LANG=en agreeImprove= GUID=S-1-5-21-1302019708-1500728564-335382590-1000 xurlID=387080 TestID=AG14400-08261 | C:\Users\admin\AppData\Local\Temp\is-ET6N0.tmp\drw_trial.tmp | drw_trial.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1300 | "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\EUUnZip.exe" "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard/InnerBuyRSS.zip" "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard/InnerBuyRSS" | C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\EUUnZip.exe | — | DRWUI.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1476 | "C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\aliyun\InfoForSetup.exe" /SendInfo "Window" "Install" "Activity" "Info_Userinfo" "Attribute" "{\"Language\":\"en\",\"Version\":\"Ad_Google\",\"Version_Num\":\"14.4.0.0\",\"UE\":\"Off\",\"Country\":\"United States\",\"Timezone\":\"GMT-00:00\",\"OS\":\"Microsoft Windows 7 32-bit Service Pack 1 (6.1.7601.1.256)\",\"Test_id\":\"AG14400-08261\"}" | C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\aliyun\InfoForSetup.exe | — | SetupUE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1604 | /SendInfo Window "Install_Finish" Activity "Click_Startnow" | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\aliyun\InfoForSetup.exe | — | EDownloader.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1840 | /SendInfo Window "Loading" Activity "Info_Wmic_Diskdrive" Attribute "[\"Availability BytesPerSector Capabilities CapabilityDescriptions Caption CompressionMethod ConfigManagerErrorCode ConfigManagerUserConfig CreationClassName DefaultBlockSize Description DeviceID ErrorCleared ErrorDescription ErrorMethodology FirmwareRevision Index InstallDate InterfaceType LastErrorCode Manufacturer MaxBlockSize MaxMediaSize MediaLoaded MediaType MinBlockSize Model Name NeedsCleaning NumberOfMediaSupported Partitions PNPDeviceID PowerManagementCapabilities PowerManagementSupported SCSIBus SCSILogicalUnit SCSIPort SCSITargetId SectorsPerTrack SerialNumber Signature Size Status StatusInfo SystemCreationClassName SystemName TotalCylinders TotalHeads TotalSectors TotalTracks TracksPerCylinder ___ 512 _3_ 4_ 10_ __Random Access__ _Supports Writing__ _SMART Notification__ WDC WD20EARS ATA Device 0 FALSE Win32_DiskDrive Disk drive //./PHYSICALDRIVE0 1.1.0 0 IDE _Standard disk drives_ TRUE Fixed hard disk media WDC WD20EARS ATA Device //./PHYSICALDRIVE0 2 IDE/DISKWDC_WD20EARS____________________________1.1.0___/5&2770A7AF&0&0.0.0 0 0 0 0 63 4d51303030302031202020202020202020202020 1660034144 274872407040 OK Win32_ComputerSystem USER_PC 33418 255 536860170 8521590 255 ______\"]" | C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\aliyun\InfoForSetup.exe | — | DRWUI.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000042010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1160) AliyunWrapExe.Exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{C36CCF59-F508-4223-8EB4-3C3308728550} |
| Operation: | write | Name: | WpadDecisionReason |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\skin.zip | compressed | |
MD5:— | SHA256:— | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\InitConfigure.ini | text | |
MD5:— | SHA256:— | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Danish.ini | text | |
MD5:C9FBA9B8994227CA7A44FE8C23DAA4CC | SHA256:D4813AA54C5C36C4C1EF8021B463C624B543A651B448F0D3A552C9D1CD5F1F20 | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Japanese.ini | text | |
MD5:C8ABAF56082F7DC95CBEF96ED45796D5 | SHA256:2E56CA201793AE96190C93D07B4E2FE3AC93100C8ECA7291957589BDDA3E55AA | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Dutch.ini | text | |
MD5:0FC061F6D883E8BF41216D8686E252E5 | SHA256:24BB88CC4046509351DBB9C6FD968794BD76ABB9533535C07D4BD0642D354D08 | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Italian.ini | text | |
MD5:DB6C872DC6F1B72A63C17C95CED3317D | SHA256:8B10170EFD13107098361AAC7135D4986879B9F90198FC359CA03E94FC79A229 | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Arabic.ini | text | |
MD5:034B2B7CEFB6DDD4D83622643278A956 | SHA256:691CDCDA47CD6C5334614D6F977E694DA7BC5FE05298A12E421B30C8FA2DFFCC | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\LanguageTransfor.ini | text | |
MD5:FFE692A67871185785EC705B1CC12C81 | SHA256:373BEC6E7976324FF879C2988BAB772C69336D7BCB9A32386A6021568350A824 | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Mungarian.ini | text | |
MD5:3AE5A1C7EEB896D95D0C32E04C5BA9D0 | SHA256:FE8EED515E5F7610B307759201C4B5538C1D0484A442B924AB02650E54AAC397 | |||
| 3880 | DRW_Ad_Google_Installer_20211011.387080.exe | C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\2Ad_Google\Indonesian.ini | text | |
MD5:BCA8911FE628126C07C32E3B8E059FCD | SHA256:4B4BB629172DDE80AAD1373E87A35989521943CC3214F51ADA87DE94B2C1819A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3996 | EDownloader.exe | GET | — | 69.16.175.42:80 | http://download.easeus.com/ad/drw_trial.exe | US | — | — | malicious |
3996 | EDownloader.exe | GET | — | 69.16.175.42:80 | http://download.easeus.com/ad/drw_trial.exe | US | — | — | malicious |
3996 | EDownloader.exe | GET | — | 69.16.175.42:80 | http://download.easeus.com/ad/drw_trial.exe | US | — | — | malicious |
3996 | EDownloader.exe | GET | — | 69.16.175.42:80 | http://download.easeus.com/ad/drw_trial.exe | US | — | — | malicious |
1160 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | US | — | — | unknown |
1160 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | US | — | — | unknown |
1160 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | US | — | — | unknown |
1160 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | US | — | — | unknown |
1160 | AliyunWrapExe.Exe | POST | 200 | 47.252.97.212:80 | http://easeusinfo.us-east-1.log.aliyuncs.com/logstores/logstore_drw_ip/shards/lb | US | — | — | unknown |
3996 | EDownloader.exe | GET | 206 | 69.16.175.42:80 | http://download.easeus.com/ad/drw_trial.exe | US | binary | 5.55 Mb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1160 | AliyunWrapExe.Exe | 216.92.47.198:80 | track.easeus.com | pair Networks | US | suspicious |
1160 | AliyunWrapExe.Exe | 47.252.97.212:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba (China) Technology Co., Ltd. | US | unknown |
— | — | 47.252.97.212:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba (China) Technology Co., Ltd. | US | unknown |
3996 | EDownloader.exe | 69.16.175.42:80 | download.easeus.com | Highwinds Network Group, Inc. | US | malicious |
2932 | AliyunWrapExe.Exe | 216.92.47.198:80 | track.easeus.com | pair Networks | US | suspicious |
2932 | AliyunWrapExe.Exe | 47.252.97.212:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba (China) Technology Co., Ltd. | US | unknown |
3024 | AliyunWrapExe.Exe | 216.92.47.198:80 | track.easeus.com | pair Networks | US | suspicious |
2932 | AliyunWrapExe.Exe | 47.252.97.9:80 | easeusinfo.us-east-1.log.aliyuncs.com | Alibaba (China) Technology Co., Ltd. | US | unknown |
3844 | ensserver.exe | 205.185.216.42:443 | update.easeus.com | Highwinds Network Group, Inc. | US | whitelisted |
3844 | ensserver.exe | 67.27.158.126:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
download.easeus.com |
| malicious |
track.easeus.com |
| suspicious |
easeusinfo.us-east-1.log.aliyuncs.com |
| unknown |
dns.msftncsi.com |
| shared |
update.easeus.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
android.clients.google.com |
| whitelisted |
fcm.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3996 | EDownloader.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3996 | EDownloader.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
EDownloader.exe | [3988]-22:04:39:222 ParseCmdLine param=EXEDIR=C:\Users\admin\AppData\Local\Temp ||| EXENAME=DRW_Ad_Google_Installer_20211011.387080.exe ||| DOWNLOAD_VERSION=Ad_Google ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
|
EDownloader.exe | [3988]-22:04:39:253 Install recomand return=259
|
EDownloader.exe | [3988]-22:04:39:488 Install recomand return=259
|
EDownloader.exe | [2776]-22:04:39:566 PostData Start download url=http://download.easeus.com/api2/index.php/Apicp/Drwdl202004/index/?exeNumber=387080&lang=English&pcVersion=home&pid=2&tid=1&version=Ad_Google
|
EDownloader.exe | [2776]-22:04:43:675 PostData end
|
EDownloader.exe | [2776]-22:04:43:675 Json parse Data Start
|
EDownloader.exe | [2776]-22:04:43:675 Json parse Data end
|
EDownloader.exe | [3988]-22:04:43:675 CHttpHelper::GetDownloadInfo 45 download info code:0
|
EDownloader.exe | [3988]-22:04:43:675 Install recomand return=259
|
EDownloader.exe | [3988]-22:04:47:550 Install recomand return=259
|