File name:

imyfone-musicai_setup-com_filme.exe

Full analysis: https://app.any.run/tasks/6618d62d-37ed-4128-8d35-1db874d213f5
Verdict: Malicious activity
Analysis date: December 13, 2023, 13:14:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

20D7A777C406A7C28FDFCAE6A1240035

SHA1:

9648033660D59438D562EBC4968F7F8572F8ADBF

SHA256:

CA6E18EE466DEA03B9CCB4DEA671848D0158653EE01F327F940CFB168202C820

SSDEEP:

98304:sCVxaPINI8FQ5A/ZaEsBAUNXNg1mRQs8Ednfw5vs1t1wDhhCY2BI9qxgeIGB2Ka7:SPrJxmBL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • imyfone-download.exe (PID: 3140)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Process requests binary or script from the Internet

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Reads the Internet Settings

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
  • INFO

    • Creates files in the program directory

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Checks supported languages

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
      • wmpnscfg.exe (PID: 2668)
      • imyfone-download.tmp (PID: 3080)
      • imyfone-download.exe (PID: 3140)
    • Reads Environment values

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Reads the computer name

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
      • wmpnscfg.exe (PID: 2668)
    • Reads product name

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Checks proxy server information

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Create files in a temporary directory

      • imyfone-download.exe (PID: 3140)
    • Reads the machine GUID from the registry

      • imyfone-musicai_setup-com_filme.exe (PID: 2600)
    • Application launched itself

      • msedge.exe (PID: 3880)
      • msedge.exe (PID: 3116)
    • Manual execution by a user

      • msedge.exe (PID: 3116)
      • wmpnscfg.exe (PID: 2668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:29 03:45:29+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 755712
InitializedDataSize: 2132480
UninitializedDataSize: -
EntryPoint: 0x7f85f
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.9.1
ProductVersionNumber: 4.0.9.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: imyfone-musicai_setup-com_filme.exe
FileVersion: 4.0.9.1
LegalCopyright: Copyright (C) 2023 iMyFone. All rights reserved.
ProductName: iMyFone MusicAI
ProductVersion: 4.0.9.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start imyfone-musicai_setup-com_filme.exe wmpnscfg.exe no specs imyfone-download.exe no specs imyfone-download.tmp no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs imyfone-musicai_setup-com_filme.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1004"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1276"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2600"C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe" C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
imyfone-musicai_setup-com_filme.exe
Exit code:
0
Version:
4.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\imyfone-musicai_setup-com_filme.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2608"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1448 --field-trial-handle=1332,i,1863997486342929838,13105397102220820303,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2668"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3048"C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe" C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
imyfone-musicai_setup-com_filme.exe
Exit code:
3221226540
Version:
4.0.9.1
Modules
Images
c:\users\admin\appdata\local\temp\imyfone-musicai_setup-com_filme.exe
c:\windows\system32\ntdll.dll
3080"C:\Users\admin\AppData\Local\Temp\is-N7C9R.tmp\imyfone-download.tmp" /SL5="$1201B8,77648084,178176,C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\imyfone-download.exe" /verysilent /imyfone_down /wait_run /path="C:\Program Files\" /progress="C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\temp.progress"C:\Users\admin\AppData\Local\Temp\is-N7C9R.tmp\imyfone-download.tmpimyfone-download.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-n7c9r.tmp\imyfone-download.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3092"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1284 --field-trial-handle=1332,i,1863997486342929838,13105397102220820303,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3116"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://apipdm.imyfone.club/producturl?key=installed&pid=200191&lang=english&custom=com_filmeC:\Program Files\Microsoft\Edge\Application\msedge.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3140 /verysilent /imyfone_down /wait_run /path="C:\Program Files\" /progress="C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\temp.progress"C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\imyfone-download.exeimyfone-musicai_setup-com_filme.exe
User:
admin
Company:
Shenzhen iMyFone Technology Co., Ltd.
Integrity Level:
HIGH
Description:
iMyFoneMusicAI
Exit code:
1
Version:
1.0.5.7
Modules
Images
c:\program files\imyfone_down\imyfone-musicai_setup-com_filme\imyfone-download.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
3 983
Read events
3 948
Write events
35
Delete events
0

Modification events

(PID) Process:(2600) imyfone-musicai_setup-com_filme.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2600) imyfone-musicai_setup-com_filme.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2600) imyfone-musicai_setup-com_filme.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3880) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
(PID) Process:(3880) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
8A1A1F2B695E2F00
Executable files
1
Suspicious files
13
Text files
94
Unknown types
0

Dropped files

PID
Process
Filename
Type
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_2.pngimage
MD5:EB696A134C451F6914D566D500197AFB
SHA256:D4EFB9AA08A8DB04BBE905B9E7809A70423F63DCF1B0837617222C210C02BC95
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Chinese\pr_1.pngimage
MD5:5EB9E5184F27FB3A7A096667FB1A7E0D
SHA256:FE20553CF05EF46280733D1CED2EDA9C256121AA82003207E147D2DAFA825538
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Chinese\install_tips.pngimage
MD5:8BB3F391E48650FEC52393E27BB81002
SHA256:390F5972D3E6F8616E0DF23167BF9A15549C123576DAAEEF6AA2DCDBD66B04D9
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_3.pngimage
MD5:5A478ACD2BDEB37D47CC7A2BDA1AF324
SHA256:40D2D29E54F259876FDAA8D35F9623445FDC20DBCE2839F8629E8E40A352C34C
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_1.pngimage
MD5:6D61C01A1474CA8FCDD518C6779E6780
SHA256:B3C2C8F752586805EBD42F63CFD5A0C1D562EA8E86A9C7CA92C0A847A0F5E76A
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\pr_2.pngimage
MD5:C5BB9F2BE96ECF3B2FEF583E2A9E0430
SHA256:3E403E30C7132DC3F668D08215A44F59B8964D3356F962B6338DC20FA3E5CD33
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\install_tips.pngimage
MD5:B4867DB2AEF969A09A3646BD362D964D
SHA256:274F789B6CEDDEC49C715737969862AAA6BC572665AE7F10A380D3C74774BB5F
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\UrlInfo.initext
MD5:3FBD576D5698A3C2A078203B4E3E46BE
SHA256:DF12F4D9552CA8CAA61A213709CB467CFBC707EF8B789A91412CFA2EFB2CFD77
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Chinese\pr_2.pngimage
MD5:C1F41900E00F0E47A1DE8798F7C804E9
SHA256:54D5880EED83F9B5AC48CF9FD2F2F281E70B6E3FB4776740471428BCC2EFC25A
2600imyfone-musicai_setup-com_filme.exeC:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Chinese\pr_3.pngimage
MD5:8C57525D0B2875F09D5D3EE29C86F0BE
SHA256:0F2FB0DDE4227A311FA8BA3563F6C1E4009236391BA65733D1DD4F5A722738D2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
24
DNS requests
2
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2600
imyfone-musicai_setup-com_filme.exe
HEAD
200
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
HEAD
200
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
GET
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
GET
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
GET
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
GET
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
2600
imyfone-musicai_setup-com_filme.exe
GET
65.9.66.119:80
http://download.imyfone.com/imyfone/musicai-for-win.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2600
imyfone-musicai_setup-com_filme.exe
216.58.212.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
2600
imyfone-musicai_setup-com_filme.exe
65.9.66.119:443
download.imyfone.com
AMAZON-02
US
unknown
2600
imyfone-musicai_setup-com_filme.exe
65.9.66.119:80
download.imyfone.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
download.imyfone.com
  • 65.9.66.119
  • 65.9.66.97
  • 65.9.66.61
  • 65.9.66.89
whitelisted
www.google-analytics.com
  • 216.58.212.174
whitelisted

Threats

PID
Process
Class
Message
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2600
imyfone-musicai_setup-com_filme.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2600
imyfone-musicai_setup-com_filme.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
imyfone-musicai_setup-com_filme.exe
[4] 62558124 ~ 78197655,length = 15639532
imyfone-musicai_setup-com_filme.exe
[0] 0 ~ 15639530,length = 15639531
imyfone-musicai_setup-com_filme.exe
[1] 15639531 ~ 31279061,length = 15639531
imyfone-musicai_setup-com_filme.exe
[3] 46918593 ~ 62558123,length = 15639531
imyfone-musicai_setup-com_filme.exe
[2] 31279062 ~ 46918592,length = 15639531