| File name: | iFlyDownInstall_v10.10.29.exe |
| Full analysis: | https://app.any.run/tasks/8589cabb-5c9e-4a00-84e2-ab3f5cafa0a0 |
| Verdict: | Malicious activity |
| Analysis date: | July 31, 2024, 09:42:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 483574DDC6B3DE00CDDA3CF54A7C8FE0 |
| SHA1: | 7AA490EA4FA9B778887D70905BD19F67B438B740 |
| SHA256: | 1043F12E03B59B6A9E5D7894658FEF43FE469A79595800AE151E850F319FAFE2 |
| SSDEEP: | 49152:E54DAufXBXqB7zXCBmkjT+JtqynAO6ZCmSxbv0kFgQ0Qh1lhUqgE903gkmASRzWz:E54D9XBa5XCBmHtqyAO6smSlvMQ0QrTQ |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:11:22 09:54:59+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 28672 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x3a0b |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.10.29.0 |
| ProductVersionNumber: | 10.10.29.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | iFly Co. |
| FileDescription: | iFlyDown |
| FileVersion: | 10.10.29.0 |
| InternalName: | iFlyDown.exe |
| LegalCopyright: | iFly Co. Copyright(c)2024 |
| ProductName: | iFlyDown |
| ProductVersion: | 10.10.29.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6444 | "C:\Users\admin\AppData\Local\Temp\iFlyDownInstall_v10.10.29.exe" | C:\Users\admin\AppData\Local\Temp\iFlyDownInstall_v10.10.29.exe | — | explorer.exe | |||||||||||
User: admin Company: iFly Co. Integrity Level: MEDIUM Description: iFlyDown Exit code: 3221226540 Version: 10.10.29.0 Modules
| |||||||||||||||
| 6528 | "C:\Users\admin\AppData\Local\Temp\iFlyDownInstall_v10.10.29.exe" | C:\Users\admin\AppData\Local\Temp\iFlyDownInstall_v10.10.29.exe | explorer.exe | ||||||||||||
User: admin Company: iFly Co. Integrity Level: HIGH Description: iFlyDown Version: 10.10.29.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\licence_1033.rtf | text | |
MD5:92248382C7137D9BED6DDCAFC72D7E15 | SHA256:94D17DD4F5F1B87523C0CEFF1EC5182B206FA4B678AB24161C680CD1032C9ADB | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\logo.ico | image | |
MD5:3697FC83423BC493861DE4074110733B | SHA256:9D081B9E2A1F5DD21B96A2DB5263725B9B17AD281CC87374649FC94C1E97012D | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\licence_2052.rtf | text | |
MD5:2F9BE4592F28B531B7464762FE3A95B4 | SHA256:7DC2D01197D1364CE61EBF240F822E1590F793F89DA258E28449D69F3E761A16 | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\StdUtils.dll | executable | |
MD5:C6A6E03F77C313B267498515488C5740 | SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Program Files\iFlyDown\app.7z | compressed | |
MD5:5BE53F2CED23E8A3995AFC2EE8DD6E37 | SHA256:EC31018DCBAD91A8032B79B056BFE51D8F968675A7E6C0A8030A9975A7C3EB79 | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\skin.zip | compressed | |
MD5:71D60AFE9716E1D990BD00B9CD5A949E | SHA256:B9095B86BCD26BAAC6EA1E09ED3E4D81A75FC0B85EDF93BC330C313E064B352A | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\nsNiuniuSkin.dll | executable | |
MD5:1E88AFB7FE5B58D09D8A1B631E442538 | SHA256:21A9A74FD631030981CDCA42AB580F5AA030068AB80C183B73E99BEA2D4F7708 | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Program Files\iFlyDown\config.ini | text | |
MD5:BC866849D4E208C2521BA06B9E0094CE | SHA256:08FA88374B6DD03EF4EA86A103A057367FFE9E6D7E57328ED269AB5772695D3A | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\System.dll | executable | |
MD5:E38D8FF9F749EE1B141A122FEC7280E0 | SHA256:00F7604D4F36A728C7759F4D9CF3E30C9728C503557AAC49BBCD55CFC3E4FCB4 | |||
| 6528 | iFlyDownInstall_v10.10.29.exe | C:\Users\admin\AppData\Local\Temp\nst5262.tmp\BgWorker.dll | executable | |
MD5:33EC04738007E665059CF40BC0F0C22B | SHA256:50F735AB8F3473423E6873D628150BBC0777BE7B4F6405247CDDF22BB00FB6BE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6932 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5484 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7004 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4088 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
840 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
6528 | iFlyDownInstall_v10.10.29.exe | 188.114.96.3:443 | apk.iflydown.com | CLOUDFLARENET | NL | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4088 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5336 | SearchApp.exe | 104.126.37.168:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
apk.iflydown.com |
| unknown |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
Process | Message |
|---|---|
iFlyDownInstall_v10.10.29.exe | Window, size, 560,350
|
iFlyDownInstall_v10.10.29.exe | Window, sizebox, 0,0,0,0
|
iFlyDownInstall_v10.10.29.exe | Window, roundcorner, 3,3
|
iFlyDownInstall_v10.10.29.exe | Window, caption, 0,0,0,560
|
iFlyDownInstall_v10.10.29.exe | Window, showshadow, true
|
iFlyDownInstall_v10.10.29.exe | Window, shadowimage, images/shadow.png
|
iFlyDownInstall_v10.10.29.exe | Window, shadowsize, 14
|
iFlyDownInstall_v10.10.29.exe | Window, shadowcorner, 14,14,14,14
|
iFlyDownInstall_v10.10.29.exe | ControlUI, padding, 240,95,0,0
|
iFlyDownInstall_v10.10.29.exe | ControlUI, width, 80
|