| URL: | https://download.cnet.com/aiseesoft-iphone-unlocker/3000-18501_4-78440716.html |
| Full analysis: | https://app.any.run/tasks/d48b3cba-760b-4212-8fe5-a67b88af96c9 |
| Verdict: | Malicious activity |
| Analysis date: | January 31, 2024, 14:14:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 29EF3E7881E746F645A60E9542E97EAA |
| SHA1: | 10DC23F7CCC3DD4BE28A5A0DDE0707F86A47576F |
| SHA256: | D0AC0F4818304D7D93F38A0CB9B038BB2376DC0330D77E799F843BDD546C0442 |
| SSDEEP: | 3:N8SElbKPDiQLJcSsjuu6Jn:2SKmPDieJcKln |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0x120,0x661df598,0x661df5a8,0x661df5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 332 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3592 --field-trial-handle=1308,i,8499325519402025560,16068470956155681984,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 448 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2220 --field-trial-handle=1308,i,8499325519402025560,16068470956155681984,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe" D {'"client_id'":'"7769C1F0-C02C-4702-9E2D-2B8E7D654A32'",'"events'":{'"name'":'"oi_startforminstall_first'",'"params'":{'"app_id'":'"161'",'"app_name'":'"Aiseesoft iPhone Unlocker'",'"app_version'":'"2.0.12'",'"evt_category'":'"downloadbehavior'",'"session_id'":'"1706710472'"}}} | C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe | iphone-unlocker.tmp | ||||||||||||
User: admin Company: Aiseesoft Integrity Level: HIGH Description: Aiseesoft iPhone Unlocker Exit code: 0 Version: 2.0.36.4337 Modules
| |||||||||||||||
| 880 | "C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe" --access_after_install_counting_url | C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe | iphone-unlocker-x86.tmp | ||||||||||||
User: admin Company: Aiseesoft Integrity Level: HIGH Description: Aiseesoft iPhone Unlocker Exit code: 0 Version: 2.0.36.4337 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe" --register | C:\Program Files\Aiseesoft Studio\Aiseesoft iPhone Unlocker\Aiseesoft iPhone Unlocker.exe | iphone-unlocker-x86.tmp | ||||||||||||
User: admin Company: Aiseesoft Integrity Level: HIGH Description: Aiseesoft iPhone Unlocker Exit code: 0 Version: 2.0.36.4337 Modules
| |||||||||||||||
| 1020 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2228 --field-trial-handle=1308,i,8499325519402025560,16068470956155681984,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1196 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3120 --field-trial-handle=1120,i,8294478174803881049,14522054667884919903,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1232 | "C:\Users\admin\AppData\Local\Temp\is-M6C9O.tmp\iphone-unlocker.tmp" /SL5="$8023A,1555477,314880,C:\Users\admin\Downloads\iphone-unlocker.exe" | C:\Users\admin\AppData\Local\Temp\is-M6C9O.tmp\iphone-unlocker.tmp | iphone-unlocker.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1264 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "https://download.cnet.com/aiseesoft-iphone-unlocker/3000-18501_4-78440716.html" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (1264) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF163443.TMP | — | |
MD5:— | SHA256:— | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\319a1973-ee1e-407c-ba2d-d1f68a1eadb2.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:9F941EA08DBDCA2EB3CFA1DBBBA6F5DC | SHA256:127F71DF0D2AD895D4F293E62284D85971AE047CA15F90B87BF6335898B0B655 | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:AD0DB8476493577A67FA94A162B646C4 | SHA256:304FB5B4FD83D4A9FF1EF4CF20232A1783169C148297BFE37ED24A1D22A74F2B | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF163c13.TMP | — | |
MD5:— | SHA256:— | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Variations | binary | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
| 1264 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old~RF164f4d.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
488 | lsass.exe | GET | 304 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c | unknown | — | — | unknown |
488 | lsass.exe | GET | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
488 | lsass.exe | GET | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
488 | lsass.exe | GET | 200 | 142.250.185.227:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEE80yiW5Mf2wCipGbb3nZn0%3D | unknown | binary | 471 b | unknown |
1080 | svchost.exe | GET | 200 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c503292d7802e201 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2868 | chrome.exe | 108.177.119.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
1264 | chrome.exe | 239.255.255.250:1900 | — | — | — | unknown |
2868 | chrome.exe | 199.232.194.154:443 | download.cnet.com | FASTLY | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2868 | chrome.exe | 142.250.185.226:443 | securepubads.g.doubleclick.net | GOOGLE | US | unknown |
2868 | chrome.exe | 151.101.194.154:443 | at.adtech.redventures.io | FASTLY | US | unknown |
2868 | chrome.exe | 142.250.181.232:443 | www.googletagmanager.com | GOOGLE | US | unknown |
2868 | chrome.exe | 104.18.130.236:443 | cdn.cookielaw.org | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
download.cnet.com |
| whitelisted |
at.adtech.redventures.io |
| unknown |
securepubads.g.doubleclick.net |
| whitelisted |
cdn.cookielaw.org |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
cdn.cohesionapps.com |
| whitelisted |
ingest.make.rvapps.io |
| unknown |
geolocation.onetrust.com |
| whitelisted |
cdn.confiant-integrations.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2868 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
Process | Message |
|---|---|
Aiseesoft iPhone Unlocker.exe | MAIN_Font use font "Tahoma"
|
Aiseesoft iPhone Unlocker.exe | MAIN_Font use font "Tahoma"
|
Aiseesoft iPhone Unlocker.exe | MAIN version "2.0.36"
|
Aiseesoft iPhone Unlocker.exe | MAIN version "2.0.36"
|
Aiseesoft iPhone Unlocker.exe | QPixmap::scaled: Pixmap is a null pixmap
|
Aiseesoft iPhone Unlocker.exe | ASL checking for logging parameters in environment variable "Aiseesoft iPhone Unlocker.exe.log"
|
Aiseesoft iPhone Unlocker.exe | ASL checking for logging parameters in environment variable "asl.log"
|
Aiseesoft iPhone Unlocker.exe | ASL logging to file "C:\Users\admin\AppData\Roaming\Apple Computer\Logs\asl.141618_31Jan24.log"
|
Aiseesoft iPhone Unlocker.exe | [(unknown facility) Aiseesoft iPhone Unlocker.exe] _MobileDeviceLibraryInitRoutine (thread 1544): MobileDevice.framework version: 1533.100.57.100.2
|
Aiseesoft iPhone Unlocker.exe | [(unknown facility) Aiseesoft iPhone Unlocker.exe] AMDeviceNotificationSubscribeWithOptions (thread 1544): Failed to subscribe for mux notifications: 0xe8000063 (kAMDMuxCreateListenerError)
|