File name:

CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe

Full analysis: https://app.any.run/tasks/536db3cf-8e03-4470-8b66-fd2e638dea97
Verdict: Malicious activity
Analysis date: November 22, 2024, 04:54:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

2A786DCC065EC9624C18C73B820B9E25

SHA1:

60502A63C96B963CD03E4A9B68AC7392CA75E56C

SHA256:

F9F0D1E156845333E9115F58353E8BF7F26267BF5863A3B8541FA685B0135B68

SSDEEP:

98304:QtXACmWZ7qwor0HhRC4JVeXlDNJ5b+MNkLZMQe93HUR7FpPjshl8fZUneoRxcgYO:yRZBQbCoEcxKkbssgK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 6996)
      • WaveEditorPortable.exe (PID: 7116)
    • The process drops C-runtime libraries

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 6996)
    • Process drops legitimate windows executable

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 6996)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • WaveEditorPortable.exe (PID: 7116)
    • Drops 7-zip archiver for unpacking

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
  • INFO

    • Reads the computer name

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
    • Checks supported languages

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
    • Manual execution by a user

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 6996)
      • WaveEditorPortable.exe (PID: 7068)
      • WaveEditorPortable.exe (PID: 7116)
    • Create files in a temporary directory

      • CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe (PID: 3792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:04:30 12:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 168960
InitializedDataSize: 119808
UninitializedDataSize: -
EntryPoint: 0x2769c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 18.5.0.0
ProductVersionNumber: 18.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 18.05
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFileName: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 18.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cyberlink.waveeditor.2.1.9913.0-rsload.net-.exe textinputhost.exe no specs rundll32.exe no specs cyberlink.waveeditor.2.1.9913.0-rsload.net-.exe waveeditorportable.exe no specs waveeditorportable.exe waveeditor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3792"C:\Users\admin\AppData\Local\Temp\CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe" C:\Users\admin\AppData\Local\Temp\CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z SFX
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\cyberlink.waveeditor.2.1.9913.0-rsload.net-.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4976"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
6712C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6996"C:\Users\admin\AppData\Local\Temp\CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe" C:\Users\admin\AppData\Local\Temp\CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z SFX
Exit code:
0
Version:
18.05
Modules
Images
c:\users\admin\appdata\local\temp\cyberlink.waveeditor.2.1.9913.0-rsload.net-.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\oleaut32.dll
c:\windows\syswow64\msvcp_win.dll
7068"C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\WaveEditorPortable.exe" C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\WaveEditorPortable.exeexplorer.exe
User:
admin
Company:
cwer.ws/portable
Integrity Level:
MEDIUM
Description:
CyberLink WaveEditor 2 Portable
Exit code:
3221226540
Version:
2018.05.24.0
Modules
Images
c:\users\admin\appdata\local\temp\a\cyberlink waveeditor 2\waveeditorportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7116"C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\WaveEditorPortable.exe" C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\WaveEditorPortable.exe
explorer.exe
User:
admin
Company:
cwer.ws/portable
Integrity Level:
HIGH
Description:
CyberLink WaveEditor 2 Portable
Exit code:
0
Version:
2018.05.24.0
Modules
Images
c:\users\admin\appdata\local\temp\a\cyberlink waveeditor 2\waveeditorportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7148"C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor\WaveEditor.exe"C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor\WaveEditor.exeWaveEditorPortable.exe
User:
admin
Company:
Cyberlink
Integrity Level:
HIGH
Description:
Cyberlink WaveEditor
Exit code:
3222601730
Version:
2.1.9529.0
Modules
Images
c:\users\admin\appdata\local\temp\a\cyberlink waveeditor 2\app\waveeditor\waveeditor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
840
Read events
742
Write events
45
Delete events
53

Modification events

(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WaveEditor.exe
Operation:writeName:Path
Value:
C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor\
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor\WaveEditor.exe
Value:
RUNASADMIN
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor\WaveEditor.exe
Value:
RUNASADMIN
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0
Operation:writeName:InstallPath
Value:
C:\Users\admin\AppData\Local\Temp\a\CyberLink WaveEditor 2\App\WaveEditor
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0
Operation:writeName:UserName
Value:
Portable by punsh
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0\BuildInfo
Operation:writeName:SR_No
Value:
P2G180309-07
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0\BuildInfo
Operation:writeName:Setup
Value:
-
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0\BuildInfo
Operation:writeName:Branch
Value:
Generic
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0\BuildInfo
Operation:writeName:AutoSK
Value:
svn:23602
(PID) Process:(7116) WaveEditorPortable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Cyberlink\WaveEditor\2.0\BuildInfo
Operation:writeName:EULA
Value:
131120a_wUnicode
Executable files
182
Suspicious files
9
Text files
723
Unknown types
4

Dropped files

PID
Process
Filename
Type
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\ClAuRsmpl.axexecutable
MD5:274E3D61F67B42182A1BC7DF06BBC8A4
SHA256:541DEFC3719122139CEE71E08CD5D4AFF2AAF07CB5709AD0BEB0B4FB94E5C1A7
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\APReg.urlurl
MD5:493D9E483311E26A5A0502EE7F7828BF
SHA256:AE045BA8EEE9A9FD78AD6A67EDA308390E73FD72B639170CFF468218E97C23B5
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\CLAud.axexecutable
MD5:1A1446EF4D0A72AC3DCBCE42254BC60A
SHA256:D94B86FFC0FFA6178570CAF9E3E009EB138607C393A79F6C1D53F6400C175540
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\clauts.axexecutable
MD5:3CD9968555840DC9678E0110888017F5
SHA256:CCFCF247EF92F7CE85804F1BF48A393391B017D1E1B836599359940925402BAE
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\CLAuNRWrapper.axexecutable
MD5:48B58EDF4DD5BAC6FC33358B0BCD3D91
SHA256:8847AF07D8C073C5FFD838232A1600A8CDD17465709CBDB93C19537DD0550F42
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\clm4muxer.axexecutable
MD5:EAD84BD5AD7B61C4D3EF731A78A11E81
SHA256:DC0EB8BEA33FF856732B6C4057F891D2A63DE5F511DB703418081951A3DAB79D
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\CLChSplitter.axexecutable
MD5:34F709BE6041C19FD01576E2B49DEE18
SHA256:F5C0E5C87B255A2AA2E47214736A63400900B9C9085C1475A1D8444CD7C9F5BB
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\CLAudEnc.axexecutable
MD5:8B72D52C7645B0122A1FDE994FC58EEB
SHA256:337A0FE587F6A85A0CBCAD83A90A62B4AE23980C49828AE87CEC19EB5D349C70
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\Eula\lic_Cht.txttext
MD5:7AF18F35D23C54FD129934419BCFF03F
SHA256:2A943332745667FFA851E1CE19C2232AF3F9BCD60D4F0C216DEE0E9BD2B41A7E
3792CyberLink.WaveEditor.2.1.9913.0-rsload.net-.exeC:\Users\admin\AppData\Local\Temp\CyberLink WaveEditor 2\App\WaveEditor\Eula\lic_Esp.txttext
MD5:2BD0BD38D8487A661AE7C37CE1D77337
SHA256:08D31C8C700037908E63E5D7BBBD0A89587D89BE56E7A72D8DFF9DD1786B9E2D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
46
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4932
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4932
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
772
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6576
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5996
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4932
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4932
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4932
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4932
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.130
  • 92.123.104.59
  • 92.123.104.28
  • 92.123.104.32
  • 92.123.104.34
  • 92.123.104.33
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.68
  • 40.126.32.138
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.133
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
r.bing.com
  • 92.123.104.34
  • 92.123.104.32
  • 92.123.104.33
  • 92.123.104.28
  • 92.123.104.59
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
No debug info