File name:

lonelyscreen-win-installer.exe

Full analysis: https://app.any.run/tasks/ebac8d75-665f-4980-8f9f-681f5b5479be
Verdict: Malicious activity
Analysis date: April 30, 2024, 13:28:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

64DA00119C76C6E1D75F059FFC4A772D

SHA1:

EBAEBFF7DB60430CAD107D4EFC45654D43F98075

SHA256:

039004B76A1BC5AC020958256BDCF97F1464398C13B0BE2E0D0078F1AEE8B3A7

SSDEEP:

12288:AS3yBV888888888888W88888888888pKfXGU69eTutORzK/AA9i6Zub02O9HtFbl:/3yLKfXG6wZ/D9kqtZaTq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • lonelyscreen-win-installer.exe (PID: 4000)
      • lonelyscreen-win-installer.exe (PID: 748)
      • lonelyscreen-win-installer.tmp (PID: 1064)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • lonelyscreen-win-installer.exe (PID: 748)
      • lonelyscreen-win-installer.exe (PID: 4000)
      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Process drops legitimate windows executable

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Reads the Windows owner or organization settings

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Reads the Internet Settings

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Reads security settings of Internet Explorer

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Checks Windows Trust Settings

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Adds/modifies Windows certificates

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Reads settings of System Certificates

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Process requests binary or script from the Internet

      • lonelyscreen-win-installer.tmp (PID: 1064)
  • INFO

    • Reads the computer name

      • lonelyscreen-win-installer.tmp (PID: 4016)
      • lonelyscreen-win-installer.tmp (PID: 1064)
      • wmpnscfg.exe (PID: 1628)
    • Checks supported languages

      • lonelyscreen-win-installer.tmp (PID: 4016)
      • lonelyscreen-win-installer.exe (PID: 4000)
      • lonelyscreen-win-installer.tmp (PID: 1064)
      • lonelyscreen-win-installer.exe (PID: 748)
      • wmpnscfg.exe (PID: 1628)
    • Create files in a temporary directory

      • lonelyscreen-win-installer.exe (PID: 4000)
      • lonelyscreen-win-installer.exe (PID: 748)
      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Checks proxy server information

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1628)
    • Reads the software policy settings

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Creates files or folders in the user directory

      • lonelyscreen-win-installer.tmp (PID: 1064)
    • Reads the machine GUID from the registry

      • lonelyscreen-win-installer.tmp (PID: 1064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (45.2)
.dll | Win32 Dynamic Link Library (generic) (20.9)
.exe | Win32 Executable (generic) (14.3)
.exe | Win16/32 Executable Delphi generic (6.6)
.exe | Generic Win/DOS Executable (6.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:09 08:48:22+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 60416
InitializedDataSize: 52736
UninitializedDataSize: -
EntryPoint: 0xf3bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: IMTIGER Technologies Inc.
FileDescription: lonelyscreen.com
FileVersion:
LegalCopyright: (c) IMTIGER Technologies Inc.
ProductName: LonelyScreen AirPlay Receiver
ProductVersion: 1.2
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start lonelyscreen-win-installer.exe lonelyscreen-win-installer.tmp no specs lonelyscreen-win-installer.exe lonelyscreen-win-installer.tmp wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
748"C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe
lonelyscreen-win-installer.tmp
User:
admin
Company:
IMTIGER Technologies Inc.
Integrity Level:
HIGH
Description:
lonelyscreen.com
Version:
Modules
Images
c:\users\admin\appdata\local\temp\lonelyscreen-win-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1064"C:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmp" /SL5="$2013A,164153,114176,C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" /SPAWNWND=$20130 /NOTIFYWND=$30136 C:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmp
lonelyscreen-win-installer.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-43ogh.tmp\lonelyscreen-win-installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1628"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4000"C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe
explorer.exe
User:
admin
Company:
IMTIGER Technologies Inc.
Integrity Level:
MEDIUM
Description:
lonelyscreen.com
Version:
Modules
Images
c:\users\admin\appdata\local\temp\lonelyscreen-win-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4016"C:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmp" /SL5="$30136,164153,114176,C:\Users\admin\AppData\Local\Temp\lonelyscreen-win-installer.exe" C:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmplonelyscreen-win-installer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ptjdc.tmp\lonelyscreen-win-installer.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
7 828
Read events
7 775
Write events
42
Delete events
11

Modification events

(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
2804000014CB9E58029BDA01
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
4F5D21794D91D76DB0D77E2B0A1FD01355C7024931F316CD7D09EDC32E333065
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1064) lonelyscreen-win-installer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
6
Suspicious files
3
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
748lonelyscreen-win-installer.exeC:\Users\admin\AppData\Local\Temp\is-43OGH.tmp\lonelyscreen-win-installer.tmpexecutable
MD5:F120C361B527A9D090782300AA8F1CE5
SHA256:9209A83AC4B0127081327B6E03960E2A4325DBB31F0BBA2B56DFB785583F9825
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:822467B728B7A66B081C91795373789A
SHA256:AF2343382B88335EEA72251AD84949E244FF54B6995063E24459A7216E9576B9
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:FB9569C9170575768DCFD9DFB15CDF19
SHA256:B483A7992E5C6BD43537E5889512D4C0CC23D01AE10CD6283694C404C33E37E3
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:6966035405B2AE1BCE082B185A6C4B65
SHA256:B4788DF9AB8732BD13487BBAA90904DDCF551972CB74FA35BC22B54824A525BC
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DD3BA095E5AF215985404F0FFC83A409der
MD5:80CFA4B7FD8AB0E3804C155FC8B5C262
SHA256:A1FB7CC2E6CF7785FBEAA0602638E6B372BE4F6824B82E45B8E9203C684FF83C
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\bonjour.msiexecutable
MD5:E14A6762E68472C648EA0EEA0EBE01A0
SHA256:34B0AF1165F531847B509D3D47F22BB87F3EED93344521986105350BCCC2CBED
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DD3BA095E5AF215985404F0FFC83A409binary
MD5:AD517CF0D82E574B9C6CBBCCD7AEDE45
SHA256:C7ED2EB1CBAC97B818AA5E997599763EA66531AD51133D4A179E4C2A00A3B6FB
4000lonelyscreen-win-installer.exeC:\Users\admin\AppData\Local\Temp\is-PTJDC.tmp\lonelyscreen-win-installer.tmpexecutable
MD5:F120C361B527A9D090782300AA8F1CE5
SHA256:9209A83AC4B0127081327B6E03960E2A4325DBB31F0BBA2B56DFB785583F9825
1064lonelyscreen-win-installer.tmpC:\Users\admin\AppData\Local\Temp\is-0JMSH.tmp\isxdl.dllexecutable
MD5:16881920CBE9DDB46C3EF29EE405A857
SHA256:59ABE5F46020CB56E1079DF8DC1145B2033E4B1459AE3D92F637064A6B618BC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1064
lonelyscreen-win-installer.tmp
HEAD
301
50.116.44.52:80
http://www.lonelyscreen.com/files/bonjour32.msi
unknown
unknown
1064
lonelyscreen-win-installer.tmp
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?173dfc45889b84bc
unknown
unknown
1064
lonelyscreen-win-installer.tmp
GET
200
23.203.141.24:80
http://x1.c.lencr.org/
unknown
unknown
1064
lonelyscreen-win-installer.tmp
GET
200
92.123.106.9:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQLFi%2FyMlHNhBWstbz2x40bLQ%3D%3D
unknown
unknown
1064
lonelyscreen-win-installer.tmp
GET
301
50.116.44.52:80
http://www.lonelyscreen.com/files/bonjour32.msi
unknown
unknown
1064
lonelyscreen-win-installer.tmp
HEAD
301
50.116.44.52:80
http://www.lonelyscreen.com/files/lonelyscreen-setup.exe
unknown
unknown
1064
lonelyscreen-win-installer.tmp
GET
301
50.116.44.52:80
http://www.lonelyscreen.com/files/lonelyscreen-setup.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1064
lonelyscreen-win-installer.tmp
50.116.44.52:80
www.lonelyscreen.com
Linode, LLC
US
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1064
lonelyscreen-win-installer.tmp
50.116.44.52:443
www.lonelyscreen.com
Linode, LLC
US
unknown
1064
lonelyscreen-win-installer.tmp
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1064
lonelyscreen-win-installer.tmp
23.203.141.24:80
x1.c.lencr.org
AKAMAI-AS
ZA
unknown
1064
lonelyscreen-win-installer.tmp
92.123.106.9:80
r3.o.lencr.org
TELECOM ITALIA SPARKLE S.p.A.
IT
unknown

DNS requests

Domain
IP
Reputation
www.lonelyscreen.com
  • 50.116.44.52
unknown
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
x1.c.lencr.org
  • 23.203.141.24
whitelisted
r3.o.lencr.org
  • 92.123.106.9
  • 92.123.106.42
  • 92.123.106.88
  • 92.123.106.16
  • 92.123.106.51
shared

Threats

No threats detected
No debug info