| File name: | lonelyscreen-win-installer.exe |
| Full analysis: | https://app.any.run/tasks/ebac8d75-665f-4980-8f9f-681f5b5479be |
| Verdict: | Malicious activity |
| Analysis date: | April 30, 2024, 13:28:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 64DA00119C76C6E1D75F059FFC4A772D |
| SHA1: | EBAEBFF7DB60430CAD107D4EFC45654D43F98075 |
| SHA256: | 039004B76A1BC5AC020958256BDCF97F1464398C13B0BE2E0D0078F1AEE8B3A7 |
| SSDEEP: | 12288:AS3yBV888888888888W88888888888pKfXGU69eTutORzK/AA9i6Zub02O9HtFbl:/3yLKfXG6wZ/D9kqtZaTq |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:10:09 08:48:22+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 60416 |
| InitializedDataSize: | 52736 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xf3bc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | IMTIGER Technologies Inc. |
| FileDescription: | lonelyscreen.com |
| FileVersion: | |
| LegalCopyright: | (c) IMTIGER Technologies Inc. |
| ProductName: | LonelyScreen AirPlay Receiver |
| ProductVersion: | 1.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 748 | "C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 | C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe | lonelyscreen-win-installer.tmp | ||||||||||||
User: admin Company: IMTIGER Technologies Inc. Integrity Level: HIGH Description: lonelyscreen.com Version: Modules
| |||||||||||||||
| 1064 | "C:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmp" /SL5="$2013A,164153,114176,C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 | C:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmp | lonelyscreen-win-installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1628 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" | C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe | explorer.exe | ||||||||||||
User: admin Company: IMTIGER Technologies Inc. Integrity Level: MEDIUM Description: lonelyscreen.com Version: Modules
| |||||||||||||||
| 4016 | "C:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmp" /SL5="$30136,164153,114176,C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" | C:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmp | — | lonelyscreen-win-installer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 2804000014CB9E58029BDA01 | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 4F5D21794D91D76DB0D77E2B0A1FD01355C7024931F316CD7D09EDC32E333065 | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1064) lonelyscreen-win-installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 748 | lonelyscreen-win-installer.exe | C:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmp | executable | |
MD5:F120C361B527A9D090782300AA8F1CE5 | SHA256:9209A83AC4B0127081327B6E03960E2A4325DBB31F0BBA2B56DFB785583F9825 | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:822467B728B7A66B081C91795373789A | SHA256:AF2343382B88335EEA72251AD84949E244FF54B6995063E24459A7216E9576B9 | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:FB9569C9170575768DCFD9DFB15CDF19 | SHA256:B483A7992E5C6BD43537E5889512D4C0CC23D01AE10CD6283694C404C33E37E3 | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:6966035405B2AE1BCE082B185A6C4B65 | SHA256:B4788DF9AB8732BD13487BBAA90904DDCF551972CB74FA35BC22B54824A525BC | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DD3BA095E5AF215985404F0FFC83A409 | der | |
MD5:80CFA4B7FD8AB0E3804C155FC8B5C262 | SHA256:A1FB7CC2E6CF7785FBEAA0602638E6B372BE4F6824B82E45B8E9203C684FF83C | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\bonjour.msi | executable | |
MD5:E14A6762E68472C648EA0EEA0EBE01A0 | SHA256:34B0AF1165F531847B509D3D47F22BB87F3EED93344521986105350BCCC2CBED | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DD3BA095E5AF215985404F0FFC83A409 | binary | |
MD5:AD517CF0D82E574B9C6CBBCCD7AEDE45 | SHA256:C7ED2EB1CBAC97B818AA5E997599763EA66531AD51133D4A179E4C2A00A3B6FB | |||
| 4000 | lonelyscreen-win-installer.exe | C:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmp | executable | |
MD5:F120C361B527A9D090782300AA8F1CE5 | SHA256:9209A83AC4B0127081327B6E03960E2A4325DBB31F0BBA2B56DFB785583F9825 | |||
| 1064 | lonelyscreen-win-installer.tmp | C:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\isxdl.dll | executable | |
MD5:16881920CBE9DDB46C3EF29EE405A857 | SHA256:59ABE5F46020CB56E1079DF8DC1145B2033E4B1459AE3D92F637064A6B618BC1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1064 | lonelyscreen-win-installer.tmp | HEAD | 301 | 50.116.44.52:80 | http://www.lonelyscreen.com/files/bonjour32.msi | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | GET | 304 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?173dfc45889b84bc | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | GET | 200 | 23.203.141.24:80 | http://x1.c.lencr.org/ | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | GET | 200 | 92.123.106.9:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQLFi%2FyMlHNhBWstbz2x40bLQ%3D%3D | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | GET | 301 | 50.116.44.52:80 | http://www.lonelyscreen.com/files/bonjour32.msi | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | HEAD | 301 | 50.116.44.52:80 | http://www.lonelyscreen.com/files/lonelyscreen-setup.exe | unknown | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | GET | 301 | 50.116.44.52:80 | http://www.lonelyscreen.com/files/lonelyscreen-setup.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1064 | lonelyscreen-win-installer.tmp | 50.116.44.52:80 | www.lonelyscreen.com | Linode, LLC | US | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1064 | lonelyscreen-win-installer.tmp | 50.116.44.52:443 | www.lonelyscreen.com | Linode, LLC | US | unknown |
1064 | lonelyscreen-win-installer.tmp | 199.232.214.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
1064 | lonelyscreen-win-installer.tmp | 23.203.141.24:80 | x1.c.lencr.org | AKAMAI-AS | ZA | unknown |
1064 | lonelyscreen-win-installer.tmp | 92.123.106.9:80 | r3.o.lencr.org | TELECOM ITALIA SPARKLE S.p.A. | IT | unknown |
Domain | IP | Reputation |
|---|---|---|
www.lonelyscreen.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |