URL:

http://download.freemake.net/products/B70A0A377487710FFFBB3F839DAEA921/FreemakeVideoConverterSetup.exe

Full analysis: https://app.any.run/tasks/295763a6-2ede-4119-9f7e-859afc7584a7
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 17, 2018, 11:29:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
adware
Indicators:
MD5:

1AABFC57B416B6215523DF67D37A16A4

SHA1:

801112474792DF1C9C9FDA908EFE79373DBD6BD2

SHA256:

F462E93F9F0FCEAE1AA895AE16E2A0BC5E30A92CB71A6B8A5EED7EACA56BC60A

SSDEEP:

3:N1KaKElLAuIs9aQGRWoCfnW5hp9P3OAzABMBlA2aA:Ca5LQ7TRW5fWBpOWAaBa2aA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FreemakeVideoConverterSetup[1].exe (PID: 2452)
      • FreemakeVideoConverterSetup[1].exe (PID: 3312)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3188)
      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Starts NET.EXE for service management

      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Registers / Runs the DLL via REGSVR32.EXE

      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Changes the autorun value in the registry

      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 1712)
      • regsvr32.exe (PID: 3444)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3188)
      • iexplore.exe (PID: 2924)
      • FreemakeVideoConverterSetup[1].exe (PID: 3312)
      • FreemakeVideoConverterSetup[1].exe (PID: 2452)
      • FreemakeVideoConverterFull.exe (PID: 3016)
      • FreemakeVideoConverterFull.tmp (PID: 2356)
      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Reads Windows owner or organization settings

      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Uses TASKLIST.EXE to query information about running processes

      • cmd.exe (PID: 4004)
      • cmd.exe (PID: 2276)
      • cmd.exe (PID: 3040)
      • cmd.exe (PID: 2440)
      • cmd.exe (PID: 2720)
      • cmd.exe (PID: 3140)
    • Starts CMD.EXE for commands execution

      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Reads the Windows organization settings

      • FreemakeVideoConverterFull.tmp (PID: 2356)
      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2304)
      • cmd.exe (PID: 2552)
      • cmd.exe (PID: 3988)
    • Uses NETSH.EXE for network configuration

      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Uses RUNDLL32.EXE to load library

      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Reads Internet Cache Settings

      • rundll32.exe (PID: 2508)
    • Creates files in the user directory

      • FreemakeVideoConverterFull.tmp (PID: 2356)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 1712)
      • regsvr32.exe (PID: 3444)
      • regsvr32.exe (PID: 3216)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3188)
      • iexplore.exe (PID: 2924)
    • Changes internet zones settings

      • iexplore.exe (PID: 2924)
    • Application launched itself

      • iexplore.exe (PID: 2924)
    • Application was dropped or rewritten from another process

      • FreemakeVideoConverterSetup[1].tmp (PID: 3516)
      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
      • FreemakeVideoConverterFull.tmp (PID: 2356)
      • MigrationTool.exe (PID: 2328)
    • Loads dropped or rewritten executable

      • FreemakeVideoConverterFull.tmp (PID: 2356)
      • FreemakeVideoConverterSetup[1].tmp (PID: 3736)
    • Creates files in the program directory

      • FreemakeVideoConverterFull.tmp (PID: 2356)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
91
Monitored processes
43
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start iexplore.exe iexplore.exe freemakevideoconvertersetup[1].exe freemakevideoconvertersetup[1].tmp no specs freemakevideoconvertersetup[1].exe freemakevideoconvertersetup[1].tmp rundll32.exe no specs freemakevideoconverterfull.exe netsh.exe no specs freemakevideoconverterfull.tmp netsh.exe no specs net.exe no specs cmd.exe no specs net1.exe no specs taskkill.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs tasklist.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs tasklist.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs migrationtool.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
712findstr "FreemakeVC.exe"C:\Windows\system32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
1712"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Freemake\COM\1.1\FMMediaFormats.dll"C:\Windows\system32\regsvr32.exeFreemakeVideoConverterFull.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2140taskkill /f /im FreemakeErrorReporter.exeC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2276"C:\Windows\system32\cmd.exe" /C tasklist | findstr "FreemakeVC.exe"C:\Windows\system32\cmd.exeFreemakeVideoConverterFull.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2304"C:\Windows\System32\cmd.exe" /C taskkill /F /IM ProductUpdater.exeC:\Windows\System32\cmd.exeFreemakeVideoConverterFull.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2328"C:\Users\admin\AppData\Local\Temp\is-U7QUL.tmp\MigrationTool.exe" C:\Users\admin\AppData\Local\Temp\is-U7QUL.tmp\MigrationTool.exeFreemakeVideoConverterFull.tmp
User:
admin
Integrity Level:
HIGH
Description:
MigrationTool
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u7qul.tmp\migrationtool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2356"C:\Users\admin\AppData\Local\Temp\is-U407M.tmp\FreemakeVideoConverterFull.tmp" /SL5="$40146,39776725,402432,C:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe" /LANG=es /dotnet=0 /skip_welcome /SourcedBrowser=Firefox locale=CH /DIR="C:\Program Files\Freemake" /autoinstall C:\Users\admin\AppData\Local\Temp\is-U407M.tmp\FreemakeVideoConverterFull.tmp
FreemakeVideoConverterFull.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u407m.tmp\freemakevideoconverterfull.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2404findstr "FreemakeAC | FreemakeVD | FreemakeMB | FreemakeVC | FreemakeYC | FreemakeYB"C:\Windows\system32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
2440"C:\Windows\system32\cmd.exe" /C tasklist | findstr "FreemakeAC.exe"C:\Windows\system32\cmd.exeFreemakeVideoConverterFull.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2452"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FreemakeVideoConverterSetup[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FreemakeVideoConverterSetup[1].exe
iexplore.exe
User:
admin
Company:
Mixbyte Inc.
Integrity Level:
MEDIUM
Description:
Freemake Video Converter Setup
Exit code:
0
Version:
4.1.10.137
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\freemakevideoconvertersetup[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 333
Read events
1 513
Write events
806
Delete events
14

Modification events

(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{FC57049D-01EE-11E9-834A-5254004A04AF}
Value:
0
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(2924) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E2070C00010011000B001D0011009701
Executable files
50
Suspicious files
1
Text files
14
Unknown types
2

Dropped files

PID
Process
Filename
Type
2924iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF907EA3DAFB83E648.TMP
MD5:
SHA256:
2924iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBEC836AB8B4E1941.TMP
MD5:
SHA256:
2924iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FC57049D-01EE-11E9-834A-5254004A04AF}.dat
MD5:
SHA256:
3736FreemakeVideoConverterSetup[1].tmpC:\Users\admin\AppData\Local\Temp\FreemakeVideoConverterFull.exe
MD5:
SHA256:
3736FreemakeVideoConverterSetup[1].tmpC:\Users\admin\AppData\Local\Temp\~DFBAD35BB837733B89.TMP
MD5:
SHA256:
2924iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\FreemakeVideoConverterSetup[1].exeexecutable
MD5:B70A0A377487710FFFBB3F839DAEA921
SHA256:4A0A3D42C8CD6D612BA5ECC71E46E9890DD4E7BEB72C4722BB442B87C6105F91
3188iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018121720181218\index.datdat
MD5:AF0AA261BC415052797C9C0A5A144D12
SHA256:9A983E3480736498D6BF88F886DF5BB8C05E84F48F5E41DC4E275BAFFB2205E3
3188iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\FreemakeVideoConverterSetup[1].exeexecutable
MD5:B70A0A377487710FFFBB3F839DAEA921
SHA256:4A0A3D42C8CD6D612BA5ECC71E46E9890DD4E7BEB72C4722BB442B87C6105F91
2356FreemakeVideoConverterFull.tmpC:\Program Files\Freemake\Freemake Video Converter\Uninstall\is-E4S60.tmp
MD5:
SHA256:
2924iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{FC57049E-01EE-11E9-834A-5254004A04AF}.datbinary
MD5:A50D50F0FC891C1DAFBABBD20B8C98B5
SHA256:2CCF2B29F5BC209537771F9E17FC1994CCED6DC7FA5201EE2A456ABD35F261F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
8
DNS requests
5
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3188
iexplore.exe
GET
200
94.31.29.3:80
http://download.freemake.net/products/B70A0A377487710FFFBB3F839DAEA921/FreemakeVideoConverterSetup.exe
GB
executable
987 Kb
whitelisted
3736
FreemakeVideoConverterSetup[1].tmp
GET
200
34.192.103.139:80
http://geoip.freemake.com/geoip.php
US
text
2 b
suspicious
3736
FreemakeVideoConverterSetup[1].tmp
HEAD
200
94.31.29.3:80
http://download.freemake.net/products/D695334FE0739EC1E3A7804F1EFFEB61/FreemakeVideoConverterFull.exe
GB
whitelisted
3736
FreemakeVideoConverterSetup[1].tmp
GET
200
34.192.103.139:80
http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoConverter&language=es&version=4.1.10.137[MAIN]&exit_step=START_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=0&statistics=1&country=CH&guid={DC66FECE-E321-4BC0-9A02-261C75EEDFBB}&errorcode=0&adv=0
US
suspicious
3736
FreemakeVideoConverterSetup[1].tmp
GET
200
18.233.92.157:80
http://releases.freemake.com/api/v1/products/fvc/installers/offline?segment=main&version=4.1.10.137
US
text
103 b
unknown
3736
FreemakeVideoConverterSetup[1].tmp
GET
200
94.31.29.3:80
http://download.freemake.net/products/D695334FE0739EC1E3A7804F1EFFEB61/FreemakeVideoConverterFull.exe
GB
executable
38.4 Mb
whitelisted
3736
FreemakeVideoConverterSetup[1].tmp
GET
200
34.192.103.139:80
http://installreport.freemake.com/installation/installation_stat.php?id=FreemakeVideoConverter&language=es&version=4.1.10.137[MAIN]&exit_step=FINISH_ONLINE&is_net_before=1&is_net_after=0&install_type=Full&is_toolbar_checked=0&statistics=1&country=CH&guid={DC66FECE-E321-4BC0-9A02-261C75EEDFBB}&errorcode=0&adv=0
US
suspicious
2356
FreemakeVideoConverterFull.tmp
GET
200
34.192.103.139:80
http://geoip.freemake.com/geoip.php
US
text
2 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2924
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3188
iexplore.exe
94.31.29.3:80
download.freemake.net
netDNA
GB
malicious
3736
FreemakeVideoConverterSetup[1].tmp
34.192.103.139:80
geoip.freemake.com
Amazon.com, Inc.
US
suspicious
3736
FreemakeVideoConverterSetup[1].tmp
18.233.92.157:80
releases.freemake.com
US
unknown
3736
FreemakeVideoConverterSetup[1].tmp
94.31.29.3:80
download.freemake.net
netDNA
GB
malicious
2356
FreemakeVideoConverterFull.tmp
34.192.103.139:80
geoip.freemake.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
download.freemake.net
  • 94.31.29.3
whitelisted
geoip.freemake.com
  • 34.192.103.139
unknown
installreport.freemake.com
  • 34.192.103.139
suspicious
releases.freemake.com
  • 18.233.92.157
  • 18.235.150.239
unknown

Threats

PID
Process
Class
Message
3188
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3188
iexplore.exe
Misc activity
ET INFO EXE - Served Attached HTTP
3736
FreemakeVideoConverterSetup[1].tmp
A Network Trojan was detected
SC TROJAN_DOWNLOADER Possible threat - .exe downloading with HEAD option
3736
FreemakeVideoConverterSetup[1].tmp
Misc activity
ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent
3736
FreemakeVideoConverterSetup[1].tmp
Misc activity
ADWARE [PTsecurity] PUP.Win32/Freemake.A UserAgent
3736
FreemakeVideoConverterSetup[1].tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3736
FreemakeVideoConverterSetup[1].tmp
Misc activity
ET INFO EXE - Served Attached HTTP
3736
FreemakeVideoConverterSetup[1].tmp
unknown
SURICATA TCPv4 invalid checksum
3736
FreemakeVideoConverterSetup[1].tmp
unknown
SURICATA TCPv4 invalid checksum
No debug info