URL:

https://free-audio-editor.com/FreeAudioEditor.exe

Full analysis: https://app.any.run/tasks/ed41302c-091e-4b7f-986b-5ad8447c0639
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 05, 2019, 07:01:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
adware
installcore
pup
innotools
loader
Indicators:
MD5:

973B04DA4FBB13F1A844681C0F3D26C5

SHA1:

C494F00F443723DA59C569542E22D212B5AF2B63

SHA256:

E4C912CF8DE61A29C161E54B4A6929C128E67FE522B103A6B4F7492BB5DD4B7B

SSDEEP:

3:N8856TILFX+gL5A:2856TI0M5A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FreeAudioEditor.exe (PID: 2176)
      • FreeAudioEditor.exe (PID: 2704)
    • Changes settings of System certificates

      • FreeAudioEditor.tmp (PID: 3076)
    • INSTALLCORE was detected

      • FreeAudioEditor.tmp (PID: 3076)
    • Connects to CnC server

      • FreeAudioEditor.tmp (PID: 3076)
    • Downloads executable files from the Internet

      • FreeAudioEditor.tmp (PID: 3076)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2504)
      • FreeAudioEditor.exe (PID: 2704)
      • chrome.exe (PID: 2224)
      • FreeAudioEditor.tmp (PID: 3076)
      • FreeAudioEditor.exe (PID: 2176)
    • Reads Environment values

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads internet explorer settings

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads Windows owner or organization settings

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads the machine GUID from the registry

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads CPU info

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads the Windows organization settings

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads Windows Product ID

      • FreeAudioEditor.tmp (PID: 3076)
    • Adds / modifies Windows certificates

      • FreeAudioEditor.tmp (PID: 3076)
  • INFO

    • Changes settings of System certificates

      • chrome.exe (PID: 2504)
    • Application launched itself

      • chrome.exe (PID: 2504)
    • Application was dropped or rewritten from another process

      • FreeAudioEditor.tmp (PID: 2944)
      • FreeAudioEditor.tmp (PID: 3076)
    • Loads dropped or rewritten executable

      • FreeAudioEditor.tmp (PID: 3076)
    • Creates files in the program directory

      • FreeAudioEditor.tmp (PID: 3076)
    • Reads settings of System Certificates

      • FreeAudioEditor.tmp (PID: 3076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
14
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs freeaudioeditor.exe freeaudioeditor.tmp no specs freeaudioeditor.exe #INSTALLCORE freeaudioeditor.tmp chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=73.0.3683.75 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6fa10f18,0x6fa10f28,0x6fa10f34C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2176"C:\Users\admin\Downloads\FreeAudioEditor.exe" C:\Users\admin\Downloads\FreeAudioEditor.exe
chrome.exe
User:
admin
Company:
Copyright© 2005-2019 FAEMedia, Inc.
Integrity Level:
MEDIUM
Description:
Free Audio Editor 2019 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\freeaudioeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2224"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=940,11803774206547213923,26424685011001398,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=17883279227519665500 --mojo-platform-channel-handle=1528 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2504"C:\Program Files\Google\Chrome\Application\chrome.exe" https://free-audio-editor.com/FreeAudioEditor.exeC:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2572"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,11803774206547213923,26424685011001398,131072 --enable-features=PasswordImport --service-pipe-token=6177644152843696516 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6177644152843696516 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1972 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2704"C:\Users\admin\Downloads\FreeAudioEditor.exe" /SPAWNWND=$2015C /NOTIFYWND=$3012C C:\Users\admin\Downloads\FreeAudioEditor.exe
FreeAudioEditor.tmp
User:
admin
Company:
Copyright© 2005-2019 FAEMedia, Inc.
Integrity Level:
HIGH
Description:
Free Audio Editor 2019 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\downloads\freeaudioeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2944"C:\Users\admin\AppData\Local\Temp\is-RMO2V.tmp\FreeAudioEditor.tmp" /SL5="$3012C,1335443,121344,C:\Users\admin\Downloads\FreeAudioEditor.exe" C:\Users\admin\AppData\Local\Temp\is-RMO2V.tmp\FreeAudioEditor.tmpFreeAudioEditor.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rmo2v.tmp\freeaudioeditor.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2956"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=940,11803774206547213923,26424685011001398,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=16686206532860351563 --mojo-platform-channel-handle=1864 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3048"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=940,11803774206547213923,26424685011001398,131072 --enable-features=PasswordImport --service-pipe-token=1923156766253048545 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1923156766253048545 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1948 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
73.0.3683.75
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3076"C:\Users\admin\AppData\Local\Temp\is-MP5D8.tmp\FreeAudioEditor.tmp" /SL5="$3015A,1335443,121344,C:\Users\admin\Downloads\FreeAudioEditor.exe" /SPAWNWND=$2015C /NOTIFYWND=$3012C C:\Users\admin\AppData\Local\Temp\is-MP5D8.tmp\FreeAudioEditor.tmp
FreeAudioEditor.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mp5d8.tmp\freeaudioeditor.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
1 385
Read events
1 282
Write events
100
Delete events
3

Modification events

(PID) Process:(4068) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2504-13198921301961625
Value:
259
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3488-13197474229333984
Value:
0
(PID) Process:(2504) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
10
Suspicious files
18
Text files
131
Unknown types
1

Dropped files

PID
Process
Filename
Type
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\49d4f399-36df-47b7-b3fb-97c503347a13.tmp
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp
MD5:
SHA256:
2504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
21
DNS requests
15
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3076
FreeAudioEditor.tmp
HEAD
200
85.159.237.103:80
http://cdneu.appuniverseapplication.com/ofr/Solululadul/icut_v2_2.cis
NL
malicious
3076
FreeAudioEditor.tmp
HEAD
200
85.159.237.103:80
http://cdneu.appuniverseapplication.com/ofr/Niniwic/YL/Niniwic_Tefenece_12Apr16.cis
NL
malicious
3076
FreeAudioEditor.tmp
GET
200
165.193.78.234:80
http://post.securestudies.com/packages/RI1034/ContentI3.exe
US
executable
412 Kb
malicious
3076
FreeAudioEditor.tmp
GET
200
165.193.78.234:80
http://post.securestudies.com/packages/RV0267/ContentV3.exe
US
executable
577 Kb
malicious
3076
FreeAudioEditor.tmp
POST
200
52.51.129.59:80
http://os.appuniverseapplication.com/FusionFreeAudioVideo/
IE
binary
444 Kb
malicious
3076
FreeAudioEditor.tmp
GET
200
192.96.201.162:80
http://img.appuniverseapplication.com/img/Tefenece/Tefenece_logo_black_wh.png
US
image
1.34 Kb
malicious
3076
FreeAudioEditor.tmp
POST
200
54.194.149.175:80
http://rp.appuniverseapplication.com/
IE
malicious
3076
FreeAudioEditor.tmp
GET
200
192.96.201.162:80
http://img.appuniverseapplication.com/img/Sibarasawi/logo_comp.png
US
image
12.4 Kb
malicious
3076
FreeAudioEditor.tmp
GET
200
192.96.201.162:80
http://img.appuniverseapplication.com/img/Sibarasawi/bg_comp.png
US
image
25.2 Kb
malicious
3076
FreeAudioEditor.tmp
GET
200
192.96.201.162:80
http://img.appuniverseapplication.com/img/Jimomoromoj/Jimomoromoj_logo.png
US
image
2.10 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2224
chrome.exe
172.217.22.99:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
2224
chrome.exe
172.217.18.174:443
sb-ssl.google.com
Google Inc.
US
whitelisted
2224
chrome.exe
173.255.199.130:443
free-audio-editor.com
Linode, LLC
US
malicious
2224
chrome.exe
172.217.18.99:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3076
FreeAudioEditor.tmp
54.194.149.175:80
rp.appuniverseapplication.com
Amazon.com, Inc.
IE
malicious
2504
chrome.exe
91.199.212.52:80
crt.comodoca.com
Comodo CA Ltd
GB
suspicious
3076
FreeAudioEditor.tmp
52.51.129.59:80
os.appuniverseapplication.com
Amazon.com, Inc.
IE
malicious
3076
FreeAudioEditor.tmp
165.193.78.234:80
post.securestudies.com
Savvis
US
malicious
3076
FreeAudioEditor.tmp
192.96.201.162:80
img.appuniverseapplication.com
Leaseweb USA, Inc.
US
malicious
3076
FreeAudioEditor.tmp
85.159.237.103:80
cdneu.appuniverseapplication.com
NForce Entertainment B.V.
NL
malicious

DNS requests

Domain
IP
Reputation
free-audio-editor.com
  • 173.255.199.130
suspicious
clientservices.googleapis.com
  • 172.217.22.99
whitelisted
accounts.google.com
  • 172.217.22.45
shared
sb-ssl.google.com
  • 172.217.18.174
whitelisted
crt.comodoca.com
  • 91.199.212.52
whitelisted
ssl.gstatic.com
  • 172.217.18.99
whitelisted
rp.appuniverseapplication.com
  • 54.194.149.175
  • 52.214.73.247
malicious
os.appuniverseapplication.com
  • 52.51.129.59
  • 52.50.98.206
  • 52.31.245.195
malicious
post.securestudies.com
  • 165.193.78.234
malicious
img.appuniverseapplication.com
  • 192.96.201.162
malicious

Threats

PID
Process
Class
Message
Generic Protocol Command Decode
SURICATA STREAM excessive retransmissions
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
Generic Protocol Command Decode
SURICATA STREAM excessive retransmissions
Misc activity
ADWARE [PTsecurity] InnoTools Download PE file
Misc activity
ADWARE [PTsecurity] InnoTools Downloader
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Misc activity
ADWARE [PTsecurity] InnoTools Download PE file
9 ETPRO signatures available at the full report
No debug info