| File name: | iris-mini-0.4.1-installer.exe |
| Full analysis: | https://app.any.run/tasks/cd0eaff9-83f5-4ee3-a802-ba6a8b8923c9 |
| Verdict: | Malicious activity |
| Analysis date: | June 02, 2024, 20:21:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 45E49B8CB6773D286F9D6854B9B4EDDB |
| SHA1: | D7986C156A565290BB5D0E51CDC85E117C0D8B91 |
| SHA256: | A98328B86D1532D23487D898EE15E67065F3B27AAC35861F7C1B4D3C9E284C4A |
| SSDEEP: | 98304:X6QiT8rks/L1tmMYetrxiJxnFCZXHeXqnrsQf9FIw8Ggmz6bb/8rtL+wrSsnBNxo:dxxWMlWwHk2pjBX9e |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 22:24:41+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25600 |
| InitializedDataSize: | 162816 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x320c |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 524 | "C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\gamma_ramp.reg" | C:\Windows\regedit.exe | iris-mini-dynamic.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 928 | "C:\Users\admin\AppData\Local\Iris mini\iris-mini-dynamic.exe" | C:\Users\admin\AppData\Local\Iris mini\iris-mini-dynamic.exe | iris-mini-0.4.1-installer.exe | ||||||||||||
User: admin Company: IrisTech Integrity Level: MEDIUM Description: Iris mini - Software for eye protection Version: 1.0.0.0 Modules
| |||||||||||||||
| 1488 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1588 | "C:\Users\admin\AppData\Local\Iris mini\iris-mini-dynamic.exe" | C:\Users\admin\AppData\Local\Iris mini\iris-mini-dynamic.exe | — | explorer.exe | |||||||||||
User: admin Company: IrisTech Integrity Level: MEDIUM Description: Iris mini - Software for eye protection Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\AppData\Local\Temp\iris-mini-0.4.1-installer.exe" | C:\Users\admin\AppData\Local\Temp\iris-mini-0.4.1-installer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\ns543E.tmp" taskkill /F /IM iris-mini-dynamic.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\ns543E.tmp | — | iris-mini-0.4.1-installer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 128 Modules
| |||||||||||||||
| 4024 | taskkill /F /IM iris-mini-dynamic.exe | C:\Windows\System32\taskkill.exe | — | ns543E.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | DisplayName |
Value: Iris mini - Software for eye protection | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\Iris mini\uninstall.exe" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Users\admin\AppData\Local\Iris mini\uninstall.exe" /S | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | InstallLocation |
Value: "C:\Users\admin\AppData\Local\Iris mini" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Local\Iris mini\logo.ico" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | Publisher |
Value: "IrisTech" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | HelpLink |
Value: "http://iristech.co/" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | URLUpdateInfo |
Value: "http://iristech.co/" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | URLInfoAbout |
Value: "http://iristech.co/" | |||
| (PID) Process: | (3968) iris-mini-0.4.1-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\IrisTech Iris mini |
| Operation: | write | Name: | DisplayVersion |
Value: "0.4.1" | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\modern-header.bmp | image | |
MD5:940C56737BF9BB69CE7A31C623D4E87A | SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Iris mini\Qt5Network.dll | executable | |
MD5:C6E586373EF7F9118AC7C0CDFEF12971 | SHA256:CB3B77A492825DAB30413389A3E45E343E729ACF26B40E649651C2F898155500 | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\System.dll | executable | |
MD5:FBE295E5A1ACFBD0A6271898F885FE6A | SHA256:A1390A78533C47E55CC364E97AF431117126D04A7FAED49390210EA3E89DD0E1 | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\nsDialogs.dll | executable | |
MD5:AB101F38562C8545A641E95172C354B4 | SHA256:3CDF3E24C87666ED5C582B8B028C01EE6AC16D5A9B8D8D684AE67605376786EA | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Iris mini\Qt5Core.dll | executable | |
MD5:00BB6AC5601DE561CD2D9AD3ADF5A214 | SHA256:246FBA0F175EA8146C8FD3C17C278BA279224320FA97F56B73E6545C46A2067F | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\nsExec.dll | executable | |
MD5:50BA20CAD29399E2DB9FA75A1324BD1D | SHA256:E7B145ABC7C519E6BD91DC06B7B83D1E73735AC1AC37D30A7889840A6EED38FC | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Iris mini\Qt5Widgets.dll | executable | |
MD5:2FF65EB0669728E99448CEE07497E1FE | SHA256:10A13E22D67D95146247D06C1FCDE3DECF8AA77AC0D9BC6BE0D311B1E59DAE6E | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Temp\nsz3674.tmp\ns543E.tmp | executable | |
MD5:50BA20CAD29399E2DB9FA75A1324BD1D | SHA256:E7B145ABC7C519E6BD91DC06B7B83D1E73735AC1AC37D30A7889840A6EED38FC | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Iris mini\iris-mini-dynamic.exe | executable | |
MD5:308488CDB5A7853F2883A905161DD292 | SHA256:9B0CBAC56F288043AE4DD001B6E29845C513A62C0EDBD468CFC65483FFE9BA3D | |||
| 3968 | iris-mini-0.4.1-installer.exe | C:\Users\admin\AppData\Local\Iris mini\SSLeay32.dll | executable | |
MD5:F50E5955E71034B57D33850877E970C0 | SHA256:BF49DC783FFC58C81461DF85B1672998219A05FFF8C4AE9BD3051AD7B753E3E2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
928 | iris-mini-dynamic.exe | GET | 302 | 185.123.188.60:80 | http://iristech.co/custom-code/ip-to-location/ | unknown | — | — | unknown |
— | — | POST | 200 | 142.250.185.174:80 | http://www.google-analytics.com/collect | unknown | — | — | unknown |
928 | iris-mini-dynamic.exe | GET | 200 | 185.123.188.60:80 | http://iristech.co/custom-code/iris_mini_license.php?activation_code=&machine_fingerprint=4667614486:3300537927:0:770:v3&version=0.4.1 | unknown | — | — | unknown |
928 | iris-mini-dynamic.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
928 | iris-mini-dynamic.exe | 142.250.185.174:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
928 | iris-mini-dynamic.exe | 185.123.188.60:80 | iristech.co | SuperHosting.BG Ltd. | BG | unknown |
928 | iris-mini-dynamic.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
iristech.co |
| whitelisted |
www.google-analytics.com |
| whitelisted |
ip-api.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
928 | iris-mini-dynamic.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
Process | Message |
|---|---|
iris-mini-dynamic.exe | QObject::startTimer: Timers cannot have negative intervals
|
iris-mini-dynamic.exe | "4667614486:3300537927:0:770:v3"
|
iris-mini-dynamic.exe | Keyboard connected
|
iris-mini-dynamic.exe | 0x877f8
|
iris-mini-dynamic.exe | No such code. There is no such activation code
|