| File name: | LineInst.exe |
| Full analysis: | https://app.any.run/tasks/67e54087-dc15-4b4c-807b-3c7140104e4c |
| Verdict: | Malicious activity |
| Analysis date: | February 26, 2025, 09:10:28 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 4AD2FC6FFF2E693478EADC6793F76924 |
| SHA1: | 6E1EB754887CFF120037E8225350347D74F44C33 |
| SHA256: | 324C952A13CDC0BC8C40FFF971F51C91E5D58F968D1E18873594DF8576DA5A63 |
| SSDEEP: | 12288:0wRStxtNkUyVdGlWwwA4sQ3y0bJUoIC927VPIhmm4r9nzz+:0cSftnyVdqUy0F2VPIhmm4rZz+ |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:12:04 07:24:08+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.34 |
| CodeSize: | 459264 |
| InitializedDataSize: | 555008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x47c71 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.21 |
| ProductVersionNumber: | 1.0.0.21 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | LY Corporation |
| FileDescription: | LineInstaller |
| FileVersion: | 1.0.0.21 |
| InternalName: | LineInstaller |
| LegalCopyright: | (c) LY Corp. All Rights Reserved |
| OriginalFileName: | LineInstaller.exe |
| ProductName: | LineInstaller |
| ProductVersion: | 1.0.0.21 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | "C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LINE.exe" run -t 1169875 | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LINE.exe | LineLauncher.exe | ||||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LINE Exit code: 9 Version: 9.6.1.3529 Modules
| |||||||||||||||
| 1188 | "C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LineAppMgr.exe" -afterinstall | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LineAppMgr.exe | — | LineInst_1123546.exe | |||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LINE Exit code: 0 Version: 8.4.0.3014 Modules
| |||||||||||||||
| 2692 | "C:\Users\admin\AppData\Local\Temp\LineInst.exe" | C:\Users\admin\AppData\Local\Temp\LineInst.exe | explorer.exe | ||||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LineInstaller Exit code: 0 Version: 1.0.0.21 Modules
| |||||||||||||||
| 3100 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3396 | "C:\Users\admin\AppData\Local\LINE\bin\current\LINE.exe" run --updated 9.6.1.3529 -t 1180859 | C:\Users\admin\AppData\Local\LINE\bin\current\LINE.exe | LineLauncher.exe | ||||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LINE Version: 9.6.1.3529 Modules
| |||||||||||||||
| 4620 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4756 | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\crashpad_handler.exe --no-rate-limit --database=C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\.sentry-native --metrics-dir=C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\.sentry-native --url=https://ly.my.sentry.io:443/api/70/minidump/?sentry_client=sentry.native/0.7.10&sentry_key=4e37bced79943210cde3fceb0b7612c8 --attachment=C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\.sentry-native\7855f73b-417f-4288-d064-376976b448da.run\__sentry-event --attachment=C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\.sentry-native\7855f73b-417f-4288-d064-376976b448da.run\__sentry-breadcrumb1 --attachment=C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\.sentry-native\7855f73b-417f-4288-d064-376976b448da.run\__sentry-breadcrumb2 --initial-client-data=0x66c,0x670,0x674,0x668,0x678,0x7ffc89a41868,0x7ffc89a41880,0x7ffc89a41898 | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\crashpad_handler.exe | — | LINE.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 4944 | C:\Users\admin\AppData\Local\Temp\\LineInst_1123546.exe /M | C:\Users\admin\AppData\Local\Temp\LineInst_1123546.exe | LineInst.exe | ||||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LINE Exit code: 0 Version: 9.6.1.3529 Modules
| |||||||||||||||
| 5036 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6416 | "C:\Users\admin\AppData\Local\LINE\bin\LineLauncher.exe" --updated 9.6.1.3529 | C:\Users\admin\AppData\Local\LINE\bin\LineLauncher.exe | — | LineUpdater.exe | |||||||||||
User: admin Company: LY Corporation Integrity Level: MEDIUM Description: LINE Exit code: 0 Version: 1.0.0.23 Modules
| |||||||||||||||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | write | Name: | SlientProgress |
Value: 20 | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | write | Name: | Inatall Language |
Value: 1033 | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | delete value | Name: | RunOnce |
Value: | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Naver\LINE |
| Operation: | write | Name: | InstallType |
Value: N | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | write | Name: | SlientProgress |
Value: 40 | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | write | Name: | locale |
Value: en-US | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LINE Corporation\LINE |
| Operation: | write | Name: | localeMig |
Value: Y | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 114 | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LINE |
| Operation: | write | Name: | DisplayName |
Value: LINE | |||
| (PID) Process: | (4944) LineInst_1123546.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LINE |
| Operation: | write | Name: | UninstallString |
Value: C:\Users\admin\AppData\Local\LINE\bin\LineUnInst.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2692 | LineInst.exe | C:\Users\admin\AppData\Local\Temp\LineInst_1123546.exe | — | |
MD5:— | SHA256:— | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\Temp\nsn6F53.tmp\System.dll | executable | |
MD5:192639861E3DC2DC5C08BB8F8C7260D5 | SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LineAppMgr.exe | executable | |
MD5:7C3E2F5D849BEC9AD37160A4326994E0 | SHA256:B380702C367A1FAF7EEA8D9E3D18E335C5D26ABE2CCDAEB27C09AACAA4A284B1 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\Temp\nsn6F53.tmp\UserInfo.dll | executable | |
MD5:F8B6DD1F9620BE4EF2AD1E81FB6B79FA | SHA256:A921CC9CC4AF332BE96186D60D2539CB413DFA44CFD73E85687F9338505FF85E | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LINE.exe | executable | |
MD5:660EB040872925D0941F5E476DDFC7F3 | SHA256:D507838037D0736754ED26B154A99639F666F19EF026937832B0167981BB1FFD | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LineDiag.exe | executable | |
MD5:EB41C21F2DF228D371162C111385F69B | SHA256:4B08E89075BBD5473E7D033A30D8F2195D817133DBB10B57FCC42BA1C5DA6625 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\LineUnInst.exe | executable | |
MD5:1F00D2FD05DBD7B73BBA8734FF28C792 | SHA256:D7BE46BFCD3C7859CD153C05EEE5B6A7CA5E6D7562B708F455AFCE0CEE98A769 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\Qt6Gui.dll | executable | |
MD5:E9BB450EF0C382123A085FF02CE61CC3 | SHA256:C6DCDA8C35EECDCBBA24676CBB6A55E5F348E119D8E72F338DC149B26D1BACE7 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\Qt6Core.dll | executable | |
MD5:DDADF53A2C4A91A90A590E545396CEBA | SHA256:6F1EFCABB3E6482E1ACCB9C6A4701F2A2740DCEAF72054B34471DEA3E6B51389 | |||
| 4944 | LineInst_1123546.exe | C:\Users\admin\AppData\Local\LINE\bin\9.6.1.3529\Qt6Qml.dll | executable | |
MD5:CA4EC92FEC6A0FDF8F75FB54A63B2305 | SHA256:3DA09589E764EA05ECB6B2C29B4FDC8681B5FEB05F605F364C013E1425B2DEFC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5964 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5964 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1116 | LINE.exe | GET | 200 | 151.101.66.133:80 | http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D | unknown | — | — | whitelisted |
1116 | LINE.exe | GET | 200 | 151.101.66.133:80 | http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D | unknown | — | — | whitelisted |
1116 | LINE.exe | GET | 200 | 151.101.66.133:80 | http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDF%2FdpZVP2y8Ase%2FVyA%3D%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.159.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4892 | backgroundTaskHost.exe | 2.16.204.158:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
6708 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2692 | LineInst.exe | 18.66.142.97:443 | desktop.line-scdn.net | AMAZON-02 | US | whitelisted |
1168 | backgroundTaskHost.exe | 20.223.36.55:443 | fd.api.iris.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6572 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
www.bing.com |
| whitelisted |
desktop.line-scdn.net |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |