| File name: | imyfone-musicai_setup-com_filme.exe |
| Full analysis: | https://app.any.run/tasks/6618d62d-37ed-4128-8d35-1db874d213f5 |
| Verdict: | Malicious activity |
| Analysis date: | December 13, 2023, 13:14:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 20D7A777C406A7C28FDFCAE6A1240035 |
| SHA1: | 9648033660D59438D562EBC4968F7F8572F8ADBF |
| SHA256: | CA6E18EE466DEA03B9CCB4DEA671848D0158653EE01F327F940CFB168202C820 |
| SSDEEP: | 98304:sCVxaPINI8FQ5A/ZaEsBAUNXNg1mRQs8Ednfw5vs1t1wDhhCY2BI9qxgeIGB2Ka7:SPrJxmBL |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:08:29 03:45:29+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 755712 |
| InitializedDataSize: | 2132480 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x7f85f |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.0.9.1 |
| ProductVersionNumber: | 4.0.9.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | imyfone-musicai_setup-com_filme.exe |
| FileVersion: | 4.0.9.1 |
| LegalCopyright: | Copyright (C) 2023 iMyFone. All rights reserved. |
| ProductName: | iMyFone MusicAI |
| ProductVersion: | 4.0.9.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1004 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1276 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2600 | "C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe" | C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: imyfone-musicai_setup-com_filme.exe Exit code: 0 Version: 4.0.9.1 Modules
| |||||||||||||||
| 2608 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1448 --field-trial-handle=1332,i,1863997486342929838,13105397102220820303,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2668 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3048 | "C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe" | C:\Users\admin\AppData\Local\Temp\imyfone-musicai_setup-com_filme.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: imyfone-musicai_setup-com_filme.exe Exit code: 3221226540 Version: 4.0.9.1 Modules
| |||||||||||||||
| 3080 | "C:\Users\admin\AppData\Local\Temp\is-N7C9R.tmp\imyfone-download.tmp" /SL5="$1201B8,77648084,178176,C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\imyfone-download.exe" /verysilent /imyfone_down /wait_run /path="C:\Program Files\" /progress="C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\temp.progress" | C:\Users\admin\AppData\Local\Temp\is-N7C9R.tmp\imyfone-download.tmp | — | imyfone-download.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3092 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1284 --field-trial-handle=1332,i,1863997486342929838,13105397102220820303,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 3116 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://apipdm.imyfone.club/producturl?key=installed&pid=200191&lang=english&custom=com_filme | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 3140 | /verysilent /imyfone_down /wait_run /path="C:\Program Files\" /progress="C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\temp.progress" | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\imyfone-download.exe | — | imyfone-musicai_setup-com_filme.exe | |||||||||||
User: admin Company: Shenzhen iMyFone Technology Co., Ltd. Integrity Level: HIGH Description: iMyFoneMusicAI Exit code: 1 Version: 1.0.5.7 Modules
| |||||||||||||||
| (PID) Process: | (2600) imyfone-musicai_setup-com_filme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2600) imyfone-musicai_setup-com_filme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2600) imyfone-musicai_setup-com_filme.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (3880) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: 8A1A1F2B695E2F00 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_2.png | image | |
MD5:EB696A134C451F6914D566D500197AFB | SHA256:D4EFB9AA08A8DB04BBE905B9E7809A70423F63DCF1B0837617222C210C02BC95 | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\pr_2.png | image | |
MD5:C5BB9F2BE96ECF3B2FEF583E2A9E0430 | SHA256:3E403E30C7132DC3F668D08215A44F59B8964D3356F962B6338DC20FA3E5CD33 | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_3.png | image | |
MD5:5A478ACD2BDEB37D47CC7A2BDA1AF324 | SHA256:40D2D29E54F259876FDAA8D35F9623445FDC20DBCE2839F8629E8E40A352C34C | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\text.ini | text | |
MD5:18F0A45B8FEE05F2AD547D483ACF16A6 | SHA256:BC4A609A31234A066B449B780B9E0EB2F0B29AA08651191E5DAD98378FCB148C | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\install_tips.png | image | |
MD5:B4867DB2AEF969A09A3646BD362D964D | SHA256:274F789B6CEDDEC49C715737969862AAA6BC572665AE7F10A380D3C74774BB5F | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\pr_3.png | image | |
MD5:F114E71FEB44D6364B6C8D3996229E1C | SHA256:0E200045E707D27391021AC14C59ACB9D658239D966D357EA0659BAC4EA9F5EB | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\pr_1.png | image | |
MD5:6D61C01A1474CA8FCDD518C6779E6780 | SHA256:B3C2C8F752586805EBD42F63CFD5A0C1D562EA8E86A9C7CA92C0A847A0F5E76A | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\install_tips.png | image | |
MD5:6C876AF71AA0C199B1056CDBAA5421EA | SHA256:38D8B1B774A05ED6EE7149508E500CADD0325E81E18CE4E8B306094C69DDE90F | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\Arabic\UrlInfo.ini | text | |
MD5:C1179DEB2B1DC3DE7C40E9BE35FDF43E | SHA256:6DA7A43BA7DF6C325B30059044B5A684D65C2944A872C674315E9A17B1D8263B | |||
| 2600 | imyfone-musicai_setup-com_filme.exe | C:\Program Files\imyfone_down\imyfone-musicai_setup-com_filme\language\ChineseTW\pr_1.png | image | |
MD5:744D6209E1D024064F9849ADA1B1F451 | SHA256:B74507AC584D77C4B24E16CA730BE8D9830F912100000FED83B3EE7D320DD937 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2600 | imyfone-musicai_setup-com_filme.exe | HEAD | 200 | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | HEAD | 200 | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | GET | — | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | GET | — | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | GET | — | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | GET | — | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | GET | — | 65.9.66.119:80 | http://download.imyfone.com/imyfone/musicai-for-win.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | 216.58.212.174:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
2600 | imyfone-musicai_setup-com_filme.exe | 65.9.66.119:443 | download.imyfone.com | AMAZON-02 | US | unknown |
2600 | imyfone-musicai_setup-com_filme.exe | 65.9.66.119:80 | download.imyfone.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
download.imyfone.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2600 | imyfone-musicai_setup-com_filme.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2600 | imyfone-musicai_setup-com_filme.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
imyfone-musicai_setup-com_filme.exe | [4] 62558124 ~ 78197655,length = 15639532
|
imyfone-musicai_setup-com_filme.exe | [0] 0 ~ 15639530,length = 15639531
|
imyfone-musicai_setup-com_filme.exe | [1] 15639531 ~ 31279061,length = 15639531
|
imyfone-musicai_setup-com_filme.exe | [3] 46918593 ~ 62558123,length = 15639531
|
imyfone-musicai_setup-com_filme.exe | [2] 31279062 ~ 46918592,length = 15639531
|