File name:

ianygo.exe

Full analysis: https://app.any.run/tasks/ecff22e9-0faf-4c44-8765-8683b349985e
Verdict: Malicious activity
Analysis date: December 06, 2023, 16:22:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

BC63ACC81F990D55B420730BCA103470

SHA1:

E38E336EA77A502798912C6B658406370B7EEB3A

SHA256:

DA89E6C063B327CD9F791FBD89C4487E1DBD3A5E065D12F54E7BBA6E4DB0A0C3

SSDEEP:

98304:BXuHPx1C6PGczmSLf1zrBKzYMjZtNWBrgNFd1Lr6Z4xt7RxN6JujMFvZm9nIUcyS:mb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • ianygo.exe (PID: 1560)
    • Drops the executable file immediately after the start

      • ianygo_net_4.0.12.exe (PID: 3524)
      • ianygo_net_4.0.12.tmp (PID: 3484)
  • SUSPICIOUS

    • Reads the Internet Settings

      • ianygo.exe (PID: 1560)
      • ianygo_net_4.0.12.tmp (PID: 3484)
    • Reads security settings of Internet Explorer

      • ianygo.exe (PID: 1560)
    • Reads settings of System Certificates

      • ianygo.exe (PID: 1560)
    • Checks Windows Trust Settings

      • ianygo.exe (PID: 1560)
    • Checks for external IP

      • ianygo.exe (PID: 1560)
    • Reads the Windows owner or organization settings

      • ianygo_net_4.0.12.tmp (PID: 3484)
    • Starts CMD.EXE for commands execution

      • ianygo_net_4.0.12.tmp (PID: 3484)
    • Get information on the list of running processes

      • ianygo_net_4.0.12.tmp (PID: 3484)
      • cmd.exe (PID: 3164)
      • cmd.exe (PID: 3152)
    • Drops 7-zip archiver for unpacking

      • ianygo_net_4.0.12.tmp (PID: 3484)
    • Process drops legitimate windows executable

      • ianygo_net_4.0.12.tmp (PID: 3484)
    • The process drops C-runtime libraries

      • ianygo_net_4.0.12.tmp (PID: 3484)
    • Drops a system driver (possible attempt to evade defenses)

      • ianygo_net_4.0.12.tmp (PID: 3484)
  • INFO

    • Checks supported languages

      • ianygo.exe (PID: 1560)
      • wmpnscfg.exe (PID: 3208)
      • ianygo_net_4.0.12.tmp (PID: 3484)
      • wmpnscfg.exe (PID: 2408)
      • ianygo_net_4.0.12.exe (PID: 3524)
    • Reads the computer name

      • ianygo.exe (PID: 1560)
      • wmpnscfg.exe (PID: 3208)
      • ianygo_net_4.0.12.tmp (PID: 3484)
      • wmpnscfg.exe (PID: 2408)
    • Checks proxy server information

      • ianygo.exe (PID: 1560)
    • Reads Environment values

      • ianygo.exe (PID: 1560)
    • Reads the machine GUID from the registry

      • ianygo.exe (PID: 1560)
    • Creates files or folders in the user directory

      • ianygo.exe (PID: 1560)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3208)
      • wmpnscfg.exe (PID: 2408)
    • Create files in a temporary directory

      • ianygo.exe (PID: 1560)
      • ianygo_net_4.0.12.tmp (PID: 3484)
      • ianygo_net_4.0.12.exe (PID: 3524)
    • Creates files in the program directory

      • ianygo_net_4.0.12.tmp (PID: 3484)
      • ianygo.exe (PID: 1560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:19 10:15:38+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1765376
InitializedDataSize: 217088
UninitializedDataSize: 2187264
EntryPoint: 0x3c4fc0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Tenorshare Co., Ltd.
FileDescription: Tenorshare iAnyGo
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 Tenorshare Co.,Ltd.
ProductName: 20231019161502
ProductVersion: 2.7.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
12
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ianygo.exe wmpnscfg.exe no specs ianygo_net_4.0.12.exe no specs ianygo_net_4.0.12.tmp no specs cmd.exe no specs tasklist.exe no specs find.exe no specs cmd.exe no specs tasklist.exe no specs find.exe no specs wmpnscfg.exe no specs ianygo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120find /c /i "adb.exe" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1560"C:\Users\admin\AppData\Local\Temp\ianygo.exe" C:\Users\admin\AppData\Local\Temp\ianygo.exe
explorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
HIGH
Description:
Tenorshare iAnyGo
Exit code:
0
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\ianygo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2068tasklist /nhC:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Users\admin\AppData\Local\Temp\ianygo.exe" C:\Users\admin\AppData\Local\Temp\ianygo.exeexplorer.exe
User:
admin
Company:
Tenorshare Co., Ltd.
Integrity Level:
MEDIUM
Description:
Tenorshare iAnyGo
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\ianygo.exe
c:\windows\system32\ntdll.dll
2792tasklist /nhC:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3152"C:\Windows\system32\cmd.exe" /c tasklist /nh|find /c /i "InstallAndDriver.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\System32\cmd.exeianygo_net_4.0.12.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3164"C:\Windows\system32\cmd.exe" /c tasklist /nh|find /c /i "adb.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\System32\cmd.exeianygo_net_4.0.12.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3208"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3240find /c /i "InstallAndDriver.exe" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
7 145
Read events
7 113
Write events
32
Delete events
0

Modification events

(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1560) ianygo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1560) ianygo.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3484) ianygo_net_4.0.12.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
661
Suspicious files
350
Text files
1 379
Unknown types
2

Dropped files

PID
Process
Filename
Type
1560ianygo.exeC:\Users\admin\AppData\Local\Temp\ianygo_net\ianygo_net_4.0.12.exe
MD5:
SHA256:
1560ianygo.exeC:\Users\admin\AppData\Local\Temp\ianygo_net\ianygo_net_4.0.12.exe.xmltext
MD5:4584ACF3A2CAE17AA0F37F05A96297C8
SHA256:92BEDA38C2A183BBA62863A2F346CCB5E308317A94C014A91132AFD83E5BF8CF
1560ianygo.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\9RNX1R97.txttext
MD5:A9A6123CD14CF8871F3F9E51070CEB53
SHA256:BBBD00E8F148441EB991179D2AA5E6020760B3C87C87467DDC32B8D28019D123
1560ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:672FD2EB15BC81C2CA7FFB2E60C56FCC
SHA256:932D44DAD67582EA1D1FB0F7D04399BAD8494E0C958EFE88601AE8AE595BF4FC
1560ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:F36732A4D7F37D882FEF5E84E865446A
SHA256:88C2C77B3C1854CDCAA203AD61BD426CFEE0095961251BCD1FE8754C6971F6E4
3524ianygo_net_4.0.12.exeC:\Users\admin\AppData\Local\Temp\is-DHPMP.tmp\ianygo_net_4.0.12.tmpexecutable
MD5:9A4302A39FC63B2C950BD96FF3C1730C
SHA256:61E3B052E7E1E21F8B5CD899C05507FE9946E9A403DAB6FBA59330D45746C8AB
3484ianygo_net_4.0.12.tmpC:\Program Files\Tenorshare\Tenorshare iAnyGo\unins000.exeexecutable
MD5:9A4302A39FC63B2C950BD96FF3C1730C
SHA256:61E3B052E7E1E21F8B5CD899C05507FE9946E9A403DAB6FBA59330D45746C8AB
3484ianygo_net_4.0.12.tmpC:\Program Files\Tenorshare\Tenorshare iAnyGo\is-BSHDV.tmpexecutable
MD5:9A4302A39FC63B2C950BD96FF3C1730C
SHA256:61E3B052E7E1E21F8B5CD899C05507FE9946E9A403DAB6FBA59330D45746C8AB
1560ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3E3E9689537B6B136ECF210088069D55_EF6C9357BB54DDB629FD2D79F1594F95binary
MD5:D079F627AE374A0568472739CE8A4D53
SHA256:3ED1B98B2571626B00A400262C8A024A0D1A88465E736F2D5E759446F73F0CA3
1560ianygo.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3E3E9689537B6B136ECF210088069D55_EF6C9357BB54DDB629FD2D79F1594F95binary
MD5:D686156E014FBDF73E118295E7FAD670
SHA256:79B91059C7ED2CDB5D46178704315DBD36EF2C5BB596CC754F83AF3CBFC7757F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
37
TCP/UDP connections
197
DNS requests
7
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1560
ianygo.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
1560
ianygo.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d7bbe5ad0097b02e
unknown
compressed
4.66 Kb
unknown
1560
ianygo.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
155 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
1560
ianygo.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
1560
ianygo.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1560
ianygo.exe
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
1560
ianygo.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1560
ianygo.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1560
ianygo.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1560
ianygo.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
1560
ianygo.exe
142.250.185.142:443
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
ip-api.com
  • 208.95.112.1
shared
www.google-analytics.com
  • 142.250.185.142
whitelisted
download.tenorshare.net
  • 104.18.10.138
  • 104.18.11.138
whitelisted

Threats

PID
Process
Class
Message
1560
ianygo.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1560
ianygo.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1560
ianygo.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1560
ianygo.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
1560
ianygo.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tensorshare Google Analytics Checkin
2 ETPRO signatures available at the full report
No debug info