File name:

ianygo.exe

Full analysis: https://app.any.run/tasks/6bc0761a-a676-43d1-93fa-68d9d7d06017
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 24, 2025, 10:00:57
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
adware
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

0ABF7A6DE998DC274E9113633771A0BD

SHA1:

DDD3F3033068C2FCD72F9C4C02DFAD4583399051

SHA256:

3119AB64E976FEF2420DA45282D122B328F2A3BB896D1FC401F6DF74EF9845AA

SSDEEP:

98304:jXuHPx1C6PGczmSLf1zrBKzYMjZtNWBrgNFd1Lr6Z42tHAKoQg9Vn/ctJmGu0ake:pN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • ianygo.exe (PID: 7316)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ianygo.exe (PID: 7316)
    • Checks for external IP

      • svchost.exe (PID: 2196)
      • ianygo.exe (PID: 7316)
    • Potential Corporate Privacy Violation

      • ianygo.exe (PID: 7316)
    • Access to an unwanted program domain was detected

      • ianygo.exe (PID: 7316)
  • INFO

    • Checks supported languages

      • ianygo.exe (PID: 7316)
    • Reads the machine GUID from the registry

      • ianygo.exe (PID: 7316)
    • Reads the software policy settings

      • ianygo.exe (PID: 7316)
    • The sample compiled with english language support

      • ianygo.exe (PID: 7316)
    • Reads the computer name

      • ianygo.exe (PID: 7316)
    • Creates files or folders in the user directory

      • ianygo.exe (PID: 7316)
    • Checks proxy server information

      • ianygo.exe (PID: 7316)
    • Create files in a temporary directory

      • ianygo.exe (PID: 7316)
    • UPX packer has been detected

      • ianygo.exe (PID: 7316)
    • Creates files in the program directory

      • ianygo.exe (PID: 7316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:06 08:00:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1765376
InitializedDataSize: 217088
UninitializedDataSize: 2187264
EntryPoint: 0x3c4fe0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Tenorshare Co., Ltd.
FileDescription: Tenorshare iAnyGo
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 Tenorshare Co.,Ltd.
ProductName: 20230606160015
ProductVersion: 2.7.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ianygo.exe svchost.exe sppextcomobj.exe no specs slui.exe no specs ianygo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
7216"C:\Users\admin\Downloads\ianygo.exe" C:\Users\admin\Downloads\ianygo.exeexplorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
MEDIUM
Description:
Tenorshare iAnyGo
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\downloads\ianygo.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7316"C:\Users\admin\Downloads\ianygo.exe" C:\Users\admin\Downloads\ianygo.exe
explorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
HIGH
Description:
Tenorshare iAnyGo
Version:
2.7.11.0
Modules
Images
c:\users\admin\downloads\ianygo.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7512C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7544"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 169
Read events
1 166
Write events
3
Delete events
0

Modification events

(PID) Process:(7316) ianygo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(7316) ianygo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:guid
Value:
AB8B2069-8E13-4A87-8CDF-9E6E318D560B
(PID) Process:(7316) ianygo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
Operation:writeName:user_id
Value:
1001
Executable files
0
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7316ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:ED539EFE616B4E10B93E3F6901147EDA
SHA256:B102F6A0FDDD7B39632688146E59524E1697885E5ABBE948DF74FC36350F4FB3
7316ianygo.exeC:\Users\admin\AppData\Local\Temp\ianygo_net\ianygo_net_4.8.1.exe.xmltext
MD5:3D9F1ED630E38A1D9479C1F54F83971A
SHA256:14AD1FB2E50BD6CE9C116937FD85E325AB5F363CE5FC1EADC98980B1C2F0A488
7316ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:014D0A8FE9767A8F05570FB4D6EBDB6D
SHA256:9C5F1684F802CD826EC74748F58104D2A5B4647418B5595AF395A9A82522FF85
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
123
DNS requests
19
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7316
ianygo.exe
POST
200
142.250.184.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
GET
200
2.16.164.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7316
ianygo.exe
GET
301
104.18.25.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
whitelisted
7316
ianygo.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
whitelisted
7316
ianygo.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
whitelisted
7316
ianygo.exe
POST
200
142.250.184.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
7316
ianygo.exe
POST
200
142.250.184.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
7316
ianygo.exe
POST
200
142.250.184.238:80
http://www.google-analytics.com/collect
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.164.25:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7316
ianygo.exe
104.18.25.249:80
www.tenorshare.com
CLOUDFLARENET
whitelisted
7316
ianygo.exe
104.18.25.249:443
www.tenorshare.com
CLOUDFLARENET
whitelisted
7316
ianygo.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.25
  • 2.16.164.131
  • 2.16.164.120
  • 2.16.164.91
  • 2.16.164.9
  • 2.16.164.27
  • 2.16.164.26
  • 2.16.164.17
  • 2.16.164.32
whitelisted
login.live.com
  • 40.126.32.138
  • 20.190.160.66
  • 20.190.160.17
  • 40.126.32.133
  • 20.190.160.64
  • 20.190.160.132
  • 40.126.32.68
  • 20.190.160.2
  • 20.190.159.131
  • 40.126.31.69
  • 40.126.31.71
  • 40.126.31.129
  • 20.190.159.75
  • 40.126.31.3
  • 40.126.31.73
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
www.tenorshare.com
  • 104.18.25.249
  • 104.18.24.249
whitelisted
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
ip-api.com
  • 208.95.112.1
whitelisted
www.google-analytics.com
  • 142.250.184.238
whitelisted

Threats

PID
Process
Class
Message
7316
ianygo.exe
Potential Corporate Privacy Violation
ET INFO Unsupported/Fake Windows NT Version 5.0
2196
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
2196
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
7316
ianygo.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7316
ianygo.exe
Potential Corporate Privacy Violation
ET INFO Unsupported/Fake Windows NT Version 5.0
7316
ianygo.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tenorshare Google Analytics Checkin
No debug info