URL:

http://down.360safe.com/instmobilemgr.exe

Full analysis: https://app.any.run/tasks/d3dce1de-8e22-4c80-b931-e953296d37b0
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: August 02, 2019, 13:18:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
adware
Indicators:
MD5:

0B458923AD6500BB722EFEE36D532D1D

SHA1:

677787CFA19EE65B19FF1C0A0C9C61B4D31C6837

SHA256:

BECF110CE127B3940A993791DCA2D8417B0F0FBCBFC125F16FEB2BF73D43B6C6

SSDEEP:

3:N1KaKluLqy3KCbAdAn:CaAyVAC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • instmobilemgr.exe (PID: 2532)
      • instmobilemgr.exe (PID: 1296)
      • 360mobilemgr.exe (PID: 3060)
      • 360mobiledevice.exe (PID: 3664)
      • 360MobileLink.exe (PID: 1128)
      • 360MobileMgr.exe (PID: 3568)
      • 360mobiledevice.exe (PID: 1928)
      • 360MobileMgr.exe (PID: 692)
      • 360MobileMgr.exe (PID: 3796)
    • Loads dropped or rewritten executable

      • instmobilemgr.exe (PID: 2532)
      • 360MobileLink.exe (PID: 1128)
      • 360mobilemgr.exe (PID: 3060)
      • 360MobileMgr.exe (PID: 3568)
      • 360MobileMgr.exe (PID: 692)
      • 360MobileMgr.exe (PID: 3796)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 404)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 404)
      • iexplore.exe (PID: 3932)
      • instmobilemgr.exe (PID: 2532)
      • 360mobilemgr.exe (PID: 3060)
    • Creates files in the program directory

      • 360mobilemgr.exe (PID: 3060)
      • instmobilemgr.exe (PID: 2532)
      • 360MobileLink.exe (PID: 1128)
    • Reads internet explorer settings

      • instmobilemgr.exe (PID: 2532)
    • Reads Internet Cache Settings

      • 360mobilemgr.exe (PID: 3060)
      • 360MobileLink.exe (PID: 1128)
      • 360MobileMgr.exe (PID: 692)
    • Low-level read access rights to disk partition

      • 360mobilemgr.exe (PID: 3060)
    • Creates files in the user directory

      • 360mobilemgr.exe (PID: 3060)
      • 360MobileLink.exe (PID: 1128)
      • 360MobileMgr.exe (PID: 692)
    • Creates a software uninstall entry

      • 360mobilemgr.exe (PID: 3060)
    • Modifies the open verb of a shell class

      • 360mobilemgr.exe (PID: 3060)
    • Executed as Windows Service

      • 360mobiledevice.exe (PID: 1928)
    • Reads the BIOS version

      • 360mobilemgr.exe (PID: 3060)
    • Application launched itself

      • 360mobilemgr.exe (PID: 3060)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 404)
      • iexplore.exe (PID: 3932)
    • Application launched itself

      • iexplore.exe (PID: 3932)
    • Changes internet zones settings

      • iexplore.exe (PID: 3932)
    • Dropped object may contain Bitcoin addresses

      • 360MobileMgr.exe (PID: 692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start iexplore.exe iexplore.exe instmobilemgr.exe no specs instmobilemgr.exe 360mobilemgr.exe 360mobilelink.exe 360mobiledevice.exe no specs 360mobiledevice.exe no specs 360mobilemgr.exe no specs 360mobilemgr.exe 360mobilemgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
404"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3932 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
692360MobileMgr.exe -child 874 12 210C:\Program Files\360\360Safe\mobilemgr\360MobileMgr.exe
360mobilemgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手
Exit code:
0
Version:
3, 0, 0, 1120
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobilemgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1128"C:\Program Files\360\360Safe\mobilemgr\360MobileLink.exe" /ref=installerC:\Program Files\360\360Safe\mobilemgr\360MobileLink.exe
360mobilemgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手 手机连接模块
Exit code:
0
Version:
1, 0, 0, 1900
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobilelink.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1296"C:\Users\admin\Downloads\instmobilemgr.exe" C:\Users\admin\Downloads\instmobilemgr.exeiexplore.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360手机助手 安装程序
Exit code:
3221226540
Version:
3, 0, 0, 1121
Modules
Images
c:\users\admin\downloads\instmobilemgr.exe
c:\systemroot\system32\ntdll.dll
1928"c:\program files\360\360safe\mobilemgr\360mobiledevice.exe"c:\program files\360\360safe\mobilemgr\360mobiledevice.exeservices.exe
User:
SYSTEM
Company:
360.cn
Integrity Level:
SYSTEM
Description:
360手机助手 手机识别服务模块
Exit code:
0
Version:
1, 0, 0, 1030
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobiledevice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2532"C:\Users\admin\Downloads\instmobilemgr.exe" C:\Users\admin\Downloads\instmobilemgr.exe
iexplore.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手 安装程序
Exit code:
0
Version:
3, 0, 0, 1121
Modules
Images
c:\users\admin\downloads\instmobilemgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3060"c:\program files\360\360safe\mobilemgr\360mobilemgr.exe" /ref=installerc:\program files\360\360safe\mobilemgr\360mobilemgr.exe
instmobilemgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手
Exit code:
0
Version:
3, 0, 0, 1120
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobilemgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3568"C:\program files\360\360safe\mobilemgr\360MobileMgr.exe" /ref=installerC:\program files\360\360safe\mobilemgr\360MobileMgr.exeinstmobilemgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手
Exit code:
0
Version:
3, 0, 0, 1120
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobilemgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3664"c:\program files\360\360safe\mobilemgr\360mobiledevice.exe" -ic:\program files\360\360safe\mobilemgr\360mobiledevice.exeinstmobilemgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手 手机识别服务模块
Exit code:
0
Version:
1, 0, 0, 1030
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobiledevice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3796"c:\program files\360\360safe\mobilemgr\360MobileMgr.exe" -flwnd -checkc:\program files\360\360safe\mobilemgr\360MobileMgr.exe360mobiledevice.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360手机助手
Exit code:
0
Version:
3, 0, 0, 1120
Modules
Images
c:\program files\360\360safe\mobilemgr\360mobilemgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 857
Read events
1 291
Write events
561
Delete events
5

Modification events

(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{056E6AF7-B528-11E9-9885-5254004A04AF}
Value:
0
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(3932) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070800050002000D0012001F005C03
Executable files
50
Suspicious files
11
Text files
554
Unknown types
21

Dropped files

PID
Process
Filename
Type
3932iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF4018353F4EAFCB4E.TMP
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBCAD67AD3492266C.TMP
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{056E6AF7-B528-11E9-9885-5254004A04AF}.dat
MD5:
SHA256:
404iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{056E6AF8-B528-11E9-9885-5254004A04AF}.datbinary
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019080220190803\index.datdat
MD5:
SHA256:
2532instmobilemgr.exeC:\Users\admin\AppData\Local\Temp\3619796\setup.xmlxml
MD5:
SHA256:
404iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019080220190803\index.datdat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
308
TCP/UDP connections
152
DNS requests
50
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3060
360mobilemgr.exe
GET
180.163.242.246:80
http://intf1.zsall.mobilem.360.cn/intf/cloudControl?version=3.0.0.1120
CN
unknown
3060
360mobilemgr.exe
GET
104.192.108.19:80
http://shouji.360tpcdn.com/161012/ebeb8ce2c9caacdb497db8defd194b49/360emu.dll
US
malicious
3060
360mobilemgr.exe
GET
104.192.108.19:80
http://shouji.360tpcdn.com/161012/ebeb8ce2c9caacdb497db8defd194b49/360emu.dll
US
malicious
3060
360mobilemgr.exe
GET
200
106.120.164.179:80
http://softm.360safe.com/mobi.html?type=open&action=MainApp&ref=installer&status=nophone&fromvirus=1&appver=3.0.0.1120&uid=1&pid=h_home&m=cfe1ce9b8f5123cc37f394accff90c49&clientchannel=100000&sys=2&i=&freq=0
CN
unknown
3060
360mobilemgr.exe
GET
104.192.108.19:80
http://shouji.360tpcdn.com/161012/ebeb8ce2c9caacdb497db8defd194b49/360emu.dll
US
malicious
3060
360mobilemgr.exe
GET
104.192.108.20:80
http://shouji.360tpcdn.com/161012/ebeb8ce2c9caacdb497db8defd194b49/360emu.dll
US
malicious
3060
360mobilemgr.exe
GET
200
171.13.14.66:80
http://s.360.cn/zhushou/pmobi.html?ver=3.0.0.1120&mode=0&safever=10.1.0.2002&t=02141901&random=18467&action=MainApp&ref=installer&fromvirus=1&appver=3.0.0.1120&m=cfe1ce9b8f5123cc37f394accff90c49&clientchannel=100000
CN
whitelisted
3060
360mobilemgr.exe
GET
200
163.171.128.148:80
http://intf.zsall.mobilem.360.cn/html/data/dywplugin.json?t=080214&appver=3.0.0.1120
US
text
257 b
malicious
3060
360mobilemgr.exe
GET
200
180.163.242.246:80
http://intf1.zsall.mobilem.360.cn/index/hot?t=1564751940
CN
text
1.29 Kb
unknown
3060
360mobilemgr.exe
GET
206
104.192.108.20:80
http://shouji.360tpcdn.com/161012/ebeb8ce2c9caacdb497db8defd194b49/360emu.dll
US
binary
1.09 Mb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
404
iexplore.exe
104.192.108.18:80
down.360safe.com
Beijing Qihu Technology Company Limited
US
suspicious
3932
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3060
360mobilemgr.exe
163.171.128.148:80
intf.zsall.mobilem.360.cn
US
malicious
3060
360mobilemgr.exe
1.192.137.108:80
res.qhcdn.com
No.31,Jin-rong Street
CN
malicious
3060
360mobilemgr.exe
180.163.242.246:80
intf1.zsall.mobilem.360.cn
China Telecom (Group)
CN
unknown
3060
360mobilemgr.exe
171.13.14.66:80
s.360.cn
No.31,Jin-rong Street
CN
suspicious
3060
360mobilemgr.exe
180.163.237.138:80
res.qhcdn.com
China Telecom (Group)
CN
suspicious
3060
360mobilemgr.exe
104.192.108.19:80
shouji.360tpcdn.com
Beijing Qihu Technology Company Limited
US
suspicious
3060
360mobilemgr.exe
104.192.108.20:80
shouji.360tpcdn.com
Beijing Qihu Technology Company Limited
US
malicious
3060
360mobilemgr.exe
13.225.84.62:80
p6.qhimg.com
US
suspicious

DNS requests

Domain
IP
Reputation
down.360safe.com
  • 104.192.108.18
  • 104.192.108.21
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
intf.zsall.mobilem.360.cn
  • 163.171.128.148
malicious
res.qhcdn.com
  • 1.192.137.108
  • 180.163.237.138
malicious
intf1.zsall.mobilem.360.cn
  • 180.163.242.246
unknown
res.qhupdate.com
  • 180.163.237.138
  • 36.110.213.38
  • 1.192.137.108
malicious
softm.360safe.com
  • 106.120.164.179
  • 180.97.63.236
unknown
s.360.cn
  • 171.13.14.66
  • 180.97.63.237
  • 171.8.167.90
  • 180.163.251.231
  • 180.163.251.230
whitelisted
shouji.360tpcdn.com
  • 104.192.108.20
  • 104.192.108.19
malicious
agd.p.360.cn
  • 119.188.66.33
whitelisted

Threats

PID
Process
Class
Message
404
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3060
360mobilemgr.exe
Misc activity
SUSPICIOUS [PTsecurity] Cmd.Powershell.Download HTTP UserAgent (Win7)
3060
360mobilemgr.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3060
360mobilemgr.exe
Misc activity
ADWARE [PTsecurity] Win32/Yiwanzhushou.A
3060
360mobilemgr.exe
Misc activity
ADWARE [PTsecurity] Win32/Yiwanzhushou.A
3060
360mobilemgr.exe
Misc activity
ADWARE [PTsecurity] Win32/Yiwanzhushou.A
1128
360MobileLink.exe
Misc activity
SUSPICIOUS [PTsecurity] Cmd.Powershell.Download HTTP UserAgent (Win7)
1128
360MobileLink.exe
Generic Protocol Command Decode
SURICATA HTTP missing Host header
3060
360mobilemgr.exe
Misc activity
ADWARE [PTsecurity] Win32/Yiwanzhushou.A
No debug info