File name:

anytrans-ios-en-setup.exe

Full analysis: https://app.any.run/tasks/ca4ae840-eb5f-4305-80ca-ebaa81905fe4
Verdict: Malicious activity
Analysis date: November 25, 2023, 20:36:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

01587438ECE97192DB51ECE4CEB1141A

SHA1:

3640C2D0918D21FF60C5531D9DEEBBA3E9518031

SHA256:

36F3E07B3EDD4A130CBEE92AD92C9F73850C1F8E9D19B0C66E60466FEC4C9542

SSDEEP:

98304:BcNFHYPDMZBsTNyKuu7RU4hv7+Jvi6Hk3QTaVs+JIoxwBuAvV0VuRv2TB0kyMDUG:g23RnGMeBOZv2YYABD/T

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • anytrans-ios-en-setup.exe (PID: 2720)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Reads settings of System Certificates

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Reads security settings of Internet Explorer

      • anytrans-ios-en-setup.exe (PID: 2720)
    • The process creates files with name similar to system file names

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Checks Windows Trust Settings

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Reads the Internet Settings

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Starts CMD.EXE for commands execution

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Process drops legitimate windows executable

      • anytrans-ios-en-setup.exe (PID: 2720)
  • INFO

    • Create files in a temporary directory

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Reads the computer name

      • anytrans-ios-en-setup.exe (PID: 2720)
      • wmpnscfg.exe (PID: 1952)
      • wmpnscfg.exe (PID: 2400)
    • Checks supported languages

      • anytrans-ios-en-setup.exe (PID: 2720)
      • wmpnscfg.exe (PID: 2400)
      • wmpnscfg.exe (PID: 1952)
    • Reads CPU info

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2400)
      • wmpnscfg.exe (PID: 1952)
    • Checks proxy server information

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 1952)
      • wmpnscfg.exe (PID: 2400)
      • anytrans-ios-en-setup.exe (PID: 2720)
    • Creates files in the program directory

      • anytrans-ios-en-setup.exe (PID: 2720)
    • Creates files or folders in the user directory

      • anytrans-ios-en-setup.exe (PID: 2720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 14:19:38+02:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 26624
InitializedDataSize: 475136
UninitializedDataSize: 16896
EntryPoint: 0x3415
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 8.8.4.4
ProductVersionNumber: 8.8.4.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: iMobie Inc.
FileDescription: AnyTrans
FileVersion: 8.8.4.4
InternalName: ${Name}
LegalCopyright: Copyright (C) iMobie Inc. All rights reserved
LegalTrademarks: iMobie Inc. All rights reserved
ProductName: AnyTrans
ProductVersion: 8.8.4.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start anytrans-ios-en-setup.exe cmd.exe no specs wmpnscfg.exe no specs cmd.exe no specs wmpnscfg.exe no specs anytrans-ios-en-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564"C:\Users\admin\AppData\Local\Temp\anytrans-ios-en-setup.exe" C:\Users\admin\AppData\Local\Temp\anytrans-ios-en-setup.exeexplorer.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
MEDIUM
Description:
AnyTrans
Exit code:
3221226540
Version:
8.8.4.4
Modules
Images
c:\users\admin\appdata\local\temp\anytrans-ios-en-setup.exe
c:\windows\system32\ntdll.dll
1952"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2400"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2720"C:\Users\admin\AppData\Local\Temp\anytrans-ios-en-setup.exe" C:\Users\admin\AppData\Local\Temp\anytrans-ios-en-setup.exe
explorer.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
HIGH
Description:
AnyTrans
Exit code:
0
Version:
8.8.4.4
Modules
Images
c:\users\admin\appdata\local\temp\anytrans-ios-en-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2808"C:\Windows\System32\cmd.exe" /c "curl -X POST -H "Content-Type: application/json" -d "{\"client_id\":\"ati-Windows\",\"user_id\":\"C4BA3647\",\"events\":[{\"name\":\"Install_SW\",\"params\":{\"engagement_time_msec\":\"1\",\"ea\":\"Start Download\",\"el\":\"1\",\"install_productversion\":\"Official-com\",\"install_trackversion\":\"8.8.4.4\",\"soft_os_version\":\"Windows_32\"}}]}" "https://www.google-analytics.com/mp/collect?measurement_id=G-TGM4BTG393&api_secret=-b-I9VfrR4muDLllouukmA""C:\Windows\System32\cmd.exeanytrans-ios-en-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2972"C:\Windows\System32\cmd.exe" /c "curl -X POST -H "Content-Type: application/json" -d "{\"client_id\":\"ati-Windows\",\"user_id\":\"C4BA3647\",\"events\":[{\"name\":\"Install_SW\",\"params\":{\"engagement_time_msec\":\"1\",\"ea\":\"Launch App\",\"el\":\"1\",\"install_productversion\":\"Official-com\",\"install_trackversion\":\"8.8.4.4\",\"soft_os_version\":\"Windows_32\"}}]}" "https://www.google-analytics.com/mp/collect?measurement_id=G-TGM4BTG393&api_secret=-b-I9VfrR4muDLllouukmA""C:\Windows\System32\cmd.exeanytrans-ios-en-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
6 973
Read events
6 941
Write events
24
Delete events
8

Modification events

(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2720) anytrans-ios-en-setup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2400) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{195B97A8-DD24-4646-BA5B-D525A56615AE}\{ECEF9665-5F63-44A8-B44C-1414A043AE26}
Operation:delete keyName:(default)
Value:
(PID) Process:(2400) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{195B97A8-DD24-4646-BA5B-D525A56615AE}
Operation:delete keyName:(default)
Value:
(PID) Process:(2400) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{A402D8BB-33D3-4BE7-ACC9-31786AEA107F}
Operation:delete keyName:(default)
Value:
Executable files
7
Suspicious files
10
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\ico.icoimage
MD5:308BE2C54862EAC75D05B70D5561AB27
SHA256:84FB71C271A13C36353B124616DBAB92EF2CAED8ED88BE87714C802184945FF2
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\System.dllexecutable
MD5:CA332BB753B0775D5E806E236DDCEC55
SHA256:DF5AE79FA558DC7AF244EC6E53939563B966E7DBD8867E114E928678DBD56E5D
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\Setup.icoimage
MD5:308BE2C54862EAC75D05B70D5561AB27
SHA256:84FB71C271A13C36353B124616DBAB92EF2CAED8ED88BE87714C802184945FF2
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\Help.icoimage
MD5:308BE2C54862EAC75D05B70D5561AB27
SHA256:84FB71C271A13C36353B124616DBAB92EF2CAED8ED88BE87714C802184945FF2
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\track_Official-com.txttext
MD5:FA52EC95F4829013CDFD7EC9B8B1E533
SHA256:8BDD7A58EFB7679D680D94E1A5067699D4B06161700335E05FC20268E53C75B2
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\GoogleTracingLib.dllexecutable
MD5:624A9F37DA45B426653A6AE687220138
SHA256:AE29CE5E517FA86FC0DBC67C816CB39D568F5C34C9662654D44BFFCE2B3F1F7F
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\nsDui.dllexecutable
MD5:58446FF940213FC25AF42DB726EB351A
SHA256:37CE09533032AB354210C938311C7189403AF5CAAB98C3828011E58AC5C23AAC
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\Local\Temp\nsvE116.tmp\dotNetFx45_Full_setup.exeexecutable
MD5:9E8253F0A993E53B4809DBD74B335227
SHA256:E434828818F81E6E1F5955E84CAEC08662BD154A80B24A71A2EDA530D8B2F66A
2720anytrans-ios-en-setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:0C711B513FB12E7327E151314BD3815E
SHA256:D6286A209FDCD514BCF434ADA83D9E57571EB15A7A64505CC00B864458BF8A46
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
10
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2720
anytrans-ios-en-setup.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d002453401c7afa5
unknown
compressed
4.66 Kb
unknown
2720
anytrans-ios-en-setup.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2720
anytrans-ios-en-setup.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2720
anytrans-ios-en-setup.exe
GET
200
216.58.212.131:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
unknown
binary
472 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?60b2f43ad8cf70d9
unknown
unknown
2720
anytrans-ios-en-setup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5d0f3f151fb92950
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2720
anytrans-ios-en-setup.exe
142.250.186.78:443
www.google-analytics.com
GOOGLE
US
whitelisted
2720
anytrans-ios-en-setup.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2720
anytrans-ios-en-setup.exe
216.58.212.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2720
anytrans-ios-en-setup.exe
104.26.12.111:443
imobie-resource.com
CLOUDFLARENET
US
unknown
2720
anytrans-ios-en-setup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.186.78
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 216.58.212.131
whitelisted
imobie-resource.com
  • 104.26.12.111
  • 104.26.13.111
  • 172.67.68.126
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info