| File name: | filmora-win_setup_full2073.exe |
| Full analysis: | https://app.any.run/tasks/f797226e-b988-45cc-84d0-8fdb402fa5e8 |
| Verdict: | Malicious activity |
| Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
| Analysis date: | March 07, 2019, 13:48:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 61DD1BC516CD38D965ABD6CE22E04B18 |
| SHA1: | DC80AC086BCA3D81641DC3212F2AF8A514F1B366 |
| SHA256: | EC606A683542B09A4F56FFFAB0757EF98DD5687D5F7A2AB31C260027EDE47988 |
| SSDEEP: | 24576:Gw9QoT3iwh6lcmlm9Yw0W7UFvv+c/34rEH7j:k63iw0Dl4YAUNm+3b |
| .exe | | | Win32 Executable MS Visual C++ (generic) (16.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (14.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.4) |
| .exe | | | Win32 Executable (generic) (2.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:01 05:42:12+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 451072 |
| InitializedDataSize: | 572928 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x51167 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.9.2 |
| ProductVersionNumber: | 2.0.9.2 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | filmora-video-editor-(cpc)_setup_full2073.exe |
| FileVersion: | 2.0.9.2 |
| LegalCopyright: | Copyright©2017 Wondershare. All rights reserved. |
| ProductName: | Filmora Video Editor (CPC) |
| ProductVersion: | 8.5.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | \??\C:\Windows\system32\conhost.exe | C:\Windows\system32\conhost.exe | — | csrss.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 272 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3788 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 308 | "C:\Windows\system32\TASKKILL.exe" /F /IM Filmora.exe | C:\Windows\system32\TASKKILL.exe | — | filmora-win_full2073.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1024 | "C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" /regserver | C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe | — | Wondershare Helper Compact.tmp | |||||||||||
User: admin Company: Wondershare Integrity Level: HIGH Description: Wondershare Studio Exit code: 0 Version: 2.5.2.3 Modules
| |||||||||||||||
| 1104 | "C:\Program Files\Wondershare\Filmora Video Editor (CPC)\CheckGraphicsType.exe" | C:\Program Files\Wondershare\Filmora Video Editor (CPC)\CheckGraphicsType.exe | — | filmora-win_full2073.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1508 | "C:\Windows\system32\TASKKILL.exe" /F /IM CheckGraphicsType.exe | C:\Windows\system32\TASKKILL.exe | — | filmora-win_full2073.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1728 | "C:\Windows\system32\TASKKILL.exe" /F /IM ImageHost.exe | C:\Windows\system32\TASKKILL.exe | — | filmora-win_full2073.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2200 | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | C:\Users\Public\Documents\Wondershare\NFWCHK.exe | — | filmora-win_setup_full2073.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2220 | cmd.exe /c rd /S /Q "C:\Program Files\Wondershare\Filmora Video Editor (CPC)\BugSplat.dll.dat" | C:\Windows\system32\cmd.exe | — | Filmora.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 267 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2284 | cmd.exe /c del /F /Q "C:\Program Files\Wondershare\Filmora Video Editor (CPC)\BugSplat.dll.dat" | C:\Windows\system32\cmd.exe | — | Filmora.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WafCX |
| Operation: | write | Name: | |
Value: sku-ppc | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WafCX |
| Operation: | write | Name: | 2073 |
Value: sku-ppc | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact |
| Operation: | write | Name: | ClientSign |
Value: {C4BA3647-0000-0QM0-0001-5254004A04AF} | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\WAF |
| Operation: | write | Name: | ClientSign |
Value: {C4BA3647-0000-0QM0-0001-5254004A04AF} | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\filmora-win_setup_full2073_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\filmora-win_setup_full2073_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\filmora-win_setup_full2073_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (3868) filmora-win_setup_full2073.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\filmora-win_setup_full2073_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Qemu-ga\libglib-2.0-0.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Qemu-ga\intl.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Qemu-ga\libgcc_s_sjlj-1.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Qemu-ga\libssp-0.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Qemu-ga\qemu-ga.exe.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Program Files\Internet Explorer\ieproxy.dll.tmp | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Users\Public\Documents\Wondershare\filmora-win_full2073.exe.~P2S | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Users\Public\Documents\Wondershare\filmora-win_full2073.exe | — | |
MD5:— | SHA256:— | |||
| 3868 | filmora-win_setup_full2073.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\5[1].jpg | image | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3868 | filmora-win_setup_full2073.exe | HEAD | — | 2.16.186.64:80 | http://download.iskysoft.us/cbs_down/filmora-win_full2073.exe | unknown | — | — | whitelisted |
3868 | filmora-win_setup_full2073.exe | GET | — | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/style/orbit-1.3.0.css | US | — | — | suspicious |
3868 | filmora-win_setup_full2073.exe | HEAD | 200 | 2.16.186.59:80 | http://download.iskysoft.us/cbs_down/filmora-win_full2073.exe | unknown | — | — | whitelisted |
3868 | filmora-win_setup_full2073.exe | GET | — | 2.16.186.59:80 | http://download.iskysoft.us/cbs_down/filmora-win_full2073.exe | unknown | — | — | whitelisted |
3868 | filmora-win_setup_full2073.exe | GET | 200 | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/2073-20190214171055.html | US | html | 891 b | suspicious |
3868 | filmora-win_setup_full2073.exe | GET | 200 | 47.91.67.36:80 | http://platform.wondershare.com/rest/v2/downloader/runtime/?client_sign={C4BA3647-0000-0QM0-0001-5254004A04AF}&product_id=2073 | US | xml | 1.59 Kb | suspicious |
3868 | filmora-win_setup_full2073.exe | GET | 200 | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/2073-20190214171055.html | US | html | 891 b | suspicious |
3868 | filmora-win_setup_full2073.exe | GET | 200 | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/style/jquery.orbit.min.js | US | text | 2.66 Kb | suspicious |
3868 | filmora-win_setup_full2073.exe | GET | — | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/2073-20190214171055/3.jpg?t=20190214171055 | US | — | — | suspicious |
3868 | filmora-win_setup_full2073.exe | GET | 200 | 63.159.217.165:80 | http://dlinst.iskysoft.com/player/style/orbit-1.3.0.css | US | text | 855 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3868 | filmora-win_setup_full2073.exe | 47.91.67.36:80 | platform.wondershare.com | Alibaba (China) Technology Co., Ltd. | US | suspicious |
3868 | filmora-win_setup_full2073.exe | 63.159.217.165:80 | dlinst.iskysoft.com | QUANTIL, INC | US | unknown |
3868 | filmora-win_setup_full2073.exe | 2.16.186.64:80 | download.iskysoft.us | Akamai International B.V. | — | whitelisted |
3868 | filmora-win_setup_full2073.exe | 2.16.186.59:80 | download.iskysoft.us | Akamai International B.V. | — | whitelisted |
3868 | filmora-win_setup_full2073.exe | 104.200.23.95:80 | www.aieov.com | Linode, LLC | US | malicious |
Domain | IP | Reputation |
|---|---|---|
platform.wondershare.com |
| suspicious |
5isohu.com |
| whitelisted |
download.iskysoft.us |
| whitelisted |
dlinst.iskysoft.com |
| suspicious |
www.aieov.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3868 | filmora-win_setup_full2073.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3868 | filmora-win_setup_full2073.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3868 | filmora-win_setup_full2073.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3868 | filmora-win_setup_full2073.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
Filmora.exe |
Media Streaming Kit for Windows Version V15.4 'Patriot' ( 0x20150306 )
Copyright (c) Rocket Division Software 2001-2010. All rights reserved.
Copyright (c) StarBurn Software 2009-2010. All rights reserved.
|
Filmora.exe | Http Request Host: resource.wondershare.com, URL: /002/153/Category.xml |
Filmora.exe | HTTP/1.1 200 OK |
WSHelper.exe | HTTP/1.1 200 OK |
WSHelper.exe | HTTP/1.1 200 OK |
WSHelper.exe | HTTP/1.1 404 Not Found |
WSHelper.exe | HTTP/1.1 200 OK |
WSHelper.exe | HTTP/1.1 404 Not Found |
WSResDownloader.exe | Http Request Host: resource.wondershare.com, URL: /001/536/Online2_3.zip |
WSResDownloader.exe | HTTP/1.1 200 OK |