File name:

Wondershare Video Uniconverter Ultimate v10.4.2.194 - Ita (18 Gennaio 2019) By Grisu.rar

Full analysis: https://app.any.run/tasks/0c0e103f-cad3-4a6f-b4ec-020cd34522dd
Verdict: Malicious activity
Analysis date: April 10, 2020, 18:40:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D9EB875325CF5B3475B2BDFFC81176B6

SHA1:

7F0FF9F5CA94464227C4E49C9EE518FAD62C51A6

SHA256:

E05256564862B97CE042D52C9318003B70435F07B1B2116B38A602DD32196F61

SSDEEP:

24576:buHq71wCQytDzpBTDdrpInUjaTqEMAG+QNFHdX/jYy:buK71SQD3Zry4a+v+QNVx/Ey

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • video-converter-ultimate_setup_full1093.exe (PID: 2712)
    • Reads internet explorer settings

      • video-converter-ultimate_setup_full1093.exe (PID: 2712)
    • Reads Internet Cache Settings

      • video-converter-ultimate_setup_full1093.exe (PID: 2712)
  • INFO

    • Manual execution by user

      • video-converter-ultimate_setup_full1093.exe (PID: 2712)
      • video-converter-ultimate_setup_full1093.exe (PID: 3828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs video-converter-ultimate_setup_full1093.exe no specs video-converter-ultimate_setup_full1093.exe nfwchk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304C:\Users\Public\Documents\Wondershare\NFWCHK.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exevideo-converter-ultimate_setup_full1093.exe
User:
admin
Company:
Wondershare
Integrity Level:
HIGH
Description:
.NET Framework Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\public\documents\wondershare\nfwchk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2712"C:\Users\admin\Desktop\Wondershare Uni Video Converter Ultimate\video-converter-ultimate_setup_full1093.exe" C:\Users\admin\Desktop\Wondershare Uni Video Converter Ultimate\video-converter-ultimate_setup_full1093.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
video-converter-ultimate_setup_full1093.exe
Exit code:
0
Version:
2.0.9.2
Modules
Images
c:\users\admin\desktop\wondershare uni video converter ultimate\video-converter-ultimate_setup_full1093.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3768"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Wondershare Video Uniconverter Ultimate v10.4.2.194 - Ita (18 Gennaio 2019) By Grisu.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3828"C:\Users\admin\Desktop\Wondershare Uni Video Converter Ultimate\video-converter-ultimate_setup_full1093.exe" C:\Users\admin\Desktop\Wondershare Uni Video Converter Ultimate\video-converter-ultimate_setup_full1093.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
video-converter-ultimate_setup_full1093.exe
Exit code:
3221226540
Version:
2.0.9.2
Modules
Images
c:\users\admin\desktop\wondershare uni video converter ultimate\video-converter-ultimate_setup_full1093.exe
c:\systemroot\system32\ntdll.dll
Total events
573
Read events
537
Write events
36
Delete events
0

Modification events

(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3768) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Wondershare Video Uniconverter Ultimate v10.4.2.194 - Ita (18 Gennaio 2019) By Grisu.rar
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3768) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
0
Suspicious files
0
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
3768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3768.36435\Wondershare Uni Video Converter Ultimate\Patch.exe
MD5:
SHA256:
3768WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3768.36435\Wondershare Uni Video Converter Ultimate\video-converter-ultimate_setup_full1093.exe
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\Public\Documents\Wondershare\NFWCHK.exe.config
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\Public\Documents\Wondershare\video-converter-ultimate_full1093.exe.~P2S
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\1093-20180810162624[1].htm
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\1093-20180810162624[1].htmhtml
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\it_4[1].jpgimage
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\it_3[1].jpgimage
MD5:
SHA256:
2712video-converter-ultimate_setup_full1093.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\jquery-1.4.4.min[1].jstext
MD5:3A7AC86D2B0DC289466CF3E04033E0FA
SHA256:9059865307145AC7B94FF58B35AB3CA5F216FBC8256C255BFE8F69A04409E01D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
22
DNS requests
3
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2712
video-converter-ultimate_setup_full1093.exe
HEAD
200
163.171.132.115:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
HEAD
200
163.171.132.122:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.115:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
HEAD
200
163.171.132.19:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.19:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.18:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.115:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.122:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
GET
163.171.132.122:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
HEAD
200
163.171.132.18:80
http://download-it.wondershare.com/cbs_down/video-converter-ultimate_full1093.exe
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2712
video-converter-ultimate_setup_full1093.exe
47.91.67.36:80
platform.wondershare.com
Alibaba (China) Technology Co., Ltd.
US
suspicious
2712
video-converter-ultimate_setup_full1093.exe
163.171.132.19:80
download-it.wondershare.com
US
suspicious
2712
video-converter-ultimate_setup_full1093.exe
163.171.132.18:80
download-it.wondershare.com
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
163.171.132.115:80
download-it.wondershare.com
US
malicious
2712
video-converter-ultimate_setup_full1093.exe
163.171.132.122:80
download-it.wondershare.com
US
suspicious

DNS requests

Domain
IP
Reputation
platform.wondershare.com
  • 47.91.67.36
suspicious
download-it.wondershare.com
  • 163.171.132.19
  • 163.171.132.122
  • 163.171.132.115
  • 163.171.132.18
malicious
dlinst.wondershare.com
  • 47.91.67.36
suspicious

Threats

PID
Process
Class
Message
2712
video-converter-ultimate_setup_full1093.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info