| File name: | imyfone-fixppo-9.0.3-crack-with-registration-code-2024_archive.torrent |
| Full analysis: | https://app.any.run/tasks/e4e9f86f-5e4a-4cff-ab2d-5e426bd676ac |
| Verdict: | Malicious activity |
| Analysis date: | March 11, 2025, 08:52:38 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-bittorrent |
| File info: | BitTorrent file |
| MD5: | AB54D744A1CD31F41EC00E1922DB4CD0 |
| SHA1: | E422F59A7AD56614BA22537358657488BA05AC00 |
| SHA256: | 456CDA19A3E92D07701933A621F4FE320759442D3B5BE041BE77797913348589 |
| SSDEEP: | 48:H2Cx/6OEBlf5PQwY7Kpw1kJxECpUx77/u67Ib7KrwDL:rx/6OaPQwYEskJxE1x77u67Ib+kL |
| .torrent | | | Torrent (trackerless) (57.6) |
|---|---|---|
| .torrent | | | Torrent (42.3) |
| Announce: | http://bt1.archive.org:6969/announce |
|---|---|
| AnnounceList1: | http://bt1.archive.org:6969/announce |
| AnnounceList2: | http://bt2.archive.org:6969/announce |
| Comment: | (Binary data 774 bytes, use -b option to extract) |
| Creator: | ia_make_torrent |
| CreateDate: | 2025:01:30 01:40:54+00:00 |
| Collections1: | org.archive.imyfone-fixppo-9.0.3-crack-with-registration-code-2024 |
| Crc32_1: | f0784e1f |
| File1Length: | 9.5 kB |
| Md5_1: | 86fba220810b1265f84a0ae3b4c9c7b0 |
| Mtime1: | 1712420337 |
| File1Path: | __ia_thumb.jpg |
| Sha1: | 56b0fdcdcabd347ff3e1ac551d621a120b745089 |
| Crc32_2: | b3f44bbf |
| File2Length: | 5.4 kB |
| Md5_2: | 32e5a4995cfad8aa4f83b884fde5d366 |
| Mtime2: | 1712420307 |
| File2Path: | download-2024-01-20T224411.723.jpg |
| Sha2: | e4faa46562af460762ba5f24ea6a192dedc162c7 |
| Crc32_3: | 483ff9e4 |
| File3Length: | 8.0 kB |
| Md5_3: | 33e0cfb0092907c3efe67700e871d117 |
| Mtime3: | 1712420363 |
| File3Path: | download-2024-01-20T224411.723_thumb.jpg |
| Sha3: | bc953c51b0b5d57599a73794c7843b3d6de87072 |
| Crc32_4: | 4ffcc753 |
| File4Length: | 37 kB |
| Md5_4: | fa94dc8cc861fdc427159d18faf5a4c2 |
| Mtime4: | 1712420334 |
| File4Path: | imyfone-fixppo-9.0.3-crack-with-registration-code-2024_meta.sqlite |
| Sha4: | af08db746796a6471a5140a3a3f9977ac832998a |
| Crc32_5: | e3dd85ba |
| File5Length: | 5.2 kB |
| Md5_5: | d2b3051711a09de9e19c293bb3604daa |
| Mtime5: | 1738134398 |
| File5Path: | imyfone-fixppo-9.0.3-crack-with-registration-code-2024_meta.xml |
| Sha5: | 842389f8b34ce2d31f3343b98f41410bf9485f6e |
| Name: | imyfone-fixppo-9.0.3-crack-with-registration-code-2024 |
| PieceLength: | 524288 |
| Pieces: | (Binary data 20 bytes, use -b option to extract) |
| Locale: | en |
| Title: | imyfone-fixppo-9.0.3-crack-with-registration-code-2024 |
| URLList1: | https://archive.org/download/ |
| URLList2: | http://ia600308.us.archive.org/1/items/ |
| URLList3: | http://ia800308.us.archive.org/1/items/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 728 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Downloads\KeyForgeX.zip" C:\Users\admin\Downloads\KeyForgeX\ | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5372 -childID 5 -isForBrowser -prefsHandle 5300 -prefMapHandle 5308 -prefsLen 31870 -prefMapSize 244679 -jsInitHandle 1460 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {43be8ade-f5e8-48be-adf1-77744a0d14ee} 8016 "\\.\pipe\gecko-crash-server-pipe.8016" 1d32f30ba10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1056 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1900 -parentBuildID 20240213221259 -prefsHandle 1828 -prefMapHandle 1816 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ef0759f-b7b7-4ded-a09b-93d9c96ba155} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264f10f1510 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 1676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5988 -childID 11 -isForBrowser -prefsHandle 6268 -prefMapHandle 6272 -prefsLen 31366 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {eb5a6f18-e2e5-4f85-8216-3bbcb74fe2d0} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fc58fd90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2140 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2140 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5552 -childID 25 -isForBrowser -prefsHandle 5784 -prefMapHandle 5780 -prefsLen 32150 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ce8a483-12b7-4036-b4c0-ce3e3c96455a} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fc8a7d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2852 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3268 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3676 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5680 -childID 10 -isForBrowser -prefsHandle 6176 -prefMapHandle 6140 -prefsLen 31366 -prefMapSize 244583 -jsInitHandle 1392 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c80120d3-ed3c-4289-97f9-419806179a9d} 6644 "\\.\pipe\gecko-crash-server-pipe.6644" 264fb8fd150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6644) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (6644) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | DisplayName |
Value: qBittorrent | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\qBittorrent\uninst.exe" | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Program Files\qBittorrent\qbittorrent.exe",0 | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | Publisher |
Value: The qBittorrent project | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | URLInfoAbout |
Value: https://www.qbittorrent.org | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | DisplayVersion |
Value: 5.0.4 | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (9616) qbittorrent_5.0.4_x64_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\qBittorrent |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6644 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.bin | binary | |
MD5:76AF3298C8A0225EFC7A19C2F24711D0 | SHA256:EFBE7E99EF243668CDF6D6C4740DD9D514A25631451AFDB7094BB4817B3944F4 | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:C95DDC2B1A525D1A243E4C294DA2F326 | SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363 | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-wal | binary | |
MD5:2A7E73B56803EAD4BBB84B4E6D90B0D6 | SHA256:4B9EFAACD5E66B6EA659FEA204B2F0EF7B69451F8A075B7D08BC40BE950C6479 | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6644 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6644 | firefox.exe | POST | 200 | 142.250.186.163:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 142.250.186.163:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 142.250.186.163:80 | http://o.pki.goog/s/wr3/UTA | unknown | — | — | whitelisted |
6644 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 23.32.238.82:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 23.32.238.82:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 142.250.186.163:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 184.24.77.48:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6644 | firefox.exe | POST | 200 | 142.250.186.163:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6644 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6644 | firefox.exe | 34.117.188.166:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
6644 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
example.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6644 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6644 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6644 | firefox.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7720 | qbittorrent.exe | Misc activity | INFO [ANY.RUN] P2P BitTorrent Protocol |