File name:

tenorshare-ianygo-2-7-11-0.exe

Full analysis: https://app.any.run/tasks/5bde0f61-a53a-40e0-be21-b9e2f3785e7f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: August 17, 2024, 01:51:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
upx
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

CE6445BF4679954AEDCDF508C2247D40

SHA1:

D709EB5D452816248A34B4070A6CF13152D29BD8

SHA256:

07FB293A4DDD301CAE0D21BF2DEE4829F9416BA34CB57E4E65A5EDB4B8BA0FD9

SSDEEP:

49152:41OOKgkBsWP5UXpv4k6rKRIoPDPOGF9MzM1qEKnQC8cDuIGgFXTw:41ZNKe54k6aIoPDP/fMzS7KnQBc8gFX0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Reads security settings of Internet Explorer

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Checks Windows Trust Settings

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Potential Corporate Privacy Violation

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Checks for external IP

      • svchost.exe (PID: 2256)
      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Access to an unwanted program domain was detected

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
  • INFO

    • Reads the computer name

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Checks supported languages

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Reads Environment values

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Checks proxy server information

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Reads the machine GUID from the registry

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Creates files or folders in the user directory

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Reads the software policy settings

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Create files in a temporary directory

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • Creates files in the program directory

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
    • UPX packer has been detected

      • tenorshare-ianygo-2-7-11-0.exe (PID: 6784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:06 08:01:32+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1765376
InitializedDataSize: 217088
UninitializedDataSize: 2187264
EntryPoint: 0x3c4f70
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Tenorshare Co., Ltd.
FileDescription: Tenorshare iAnyGo
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 Tenorshare Co.,Ltd.
ProductName: 20230606160107
ProductVersion: 2.7.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
125
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT tenorshare-ianygo-2-7-11-0.exe svchost.exe tenorshare-ianygo-2-7-11-0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
6680"C:\Users\admin\Desktop\tenorshare-ianygo-2-7-11-0.exe" C:\Users\admin\Desktop\tenorshare-ianygo-2-7-11-0.exeexplorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
MEDIUM
Description:
Tenorshare iAnyGo
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\desktop\tenorshare-ianygo-2-7-11-0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6784"C:\Users\admin\Desktop\tenorshare-ianygo-2-7-11-0.exe" C:\Users\admin\Desktop\tenorshare-ianygo-2-7-11-0.exe
explorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
HIGH
Description:
Tenorshare iAnyGo
Version:
2.7.11.0
Modules
Images
c:\users\admin\desktop\tenorshare-ianygo-2-7-11-0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
1 361
Read events
1 350
Write events
11
Delete events
0

Modification events

(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
028EF156-85E5-4A6C-88A7-491F51DF1375
(PID) Process:(6784) tenorshare-ianygo-2-7-11-0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
Executable files
0
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6784tenorshare-ianygo-2-7-11-0.exeC:\Users\admin\AppData\Local\Temp\ianygo_ts\ianygo_ts_4.3.2.exe.xmltext
MD5:2B6671CBFD1C9F256FBA386092CB417F
SHA256:0B5CC062D7AA0484C395DF0E53A804C442ECB53C5B3A920869005DC2B4775616
6784tenorshare-ianygo-2-7-11-0.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:8305F98BF2C5194E8B7DD125D68BF7DF
SHA256:7CD0306237EF5B8FF7369F6A0A04DB1CF025FD6F8EA26736DAD17E670B5CD505
6784tenorshare-ianygo-2-7-11-0.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cder
MD5:79C6FBAF1162B58B5B88B4FA23521788
SHA256:4654AF8C6F3641E5A79F96314DA23AE630F57E7DB359DD97E60F997AC5136EA6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
128
DNS requests
20
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
6784
tenorshare-ianygo-2-7-11-0.exe
GET
301
104.17.192.141:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
whitelisted
6784
tenorshare-ianygo-2-7-11-0.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
6784
tenorshare-ianygo-2-7-11-0.exe
POST
200
142.250.185.110:80
http://www.google-analytics.com/collect
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
568
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3984
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5336
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
unknown
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3812
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3812
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.182
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.71
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.0
whitelisted
www.tenorshare.com
  • 104.17.192.141
  • 104.17.207.155
whitelisted
th.bing.com
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.130
whitelisted
ip-api.com
  • 208.95.112.1
shared
www.google-analytics.com
  • 142.250.185.110
whitelisted

Threats

PID
Process
Class
Message
6784
tenorshare-ianygo-2-7-11-0.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
6784
tenorshare-ianygo-2-7-11-0.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
6784
tenorshare-ianygo-2-7-11-0.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2256
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
6784
tenorshare-ianygo-2-7-11-0.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tenorshare Google Analytics Checkin
2 ETPRO signatures available at the full report
No debug info