| File name: | IDMan.exe |
| Full analysis: | https://app.any.run/tasks/108e5aac-09c7-46c8-92de-0561363317fa |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | October 07, 2021, 19:44:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7E0607830FCFA47D4F96A893334C6405 |
| SHA1: | B61E7B96340C8044C1458AFD0C0381A8307FB6E6 |
| SHA256: | DAA93B4D1A9281D05FFC991BB86433D5AFD17857D2EE8CD4E67775CD636012DA |
| SSDEEP: | 98304:/ph5LoBUHDHuIN0P4lr18frP3wbzWFimaI7dlZAq:/R8UHDDNWgbzWFimaI7dl |
| .exe | | | InstallShield setup (18.4) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (13.3) |
| .exe | | | Win64 Executable (generic) (11.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (2.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:07:17 07:17:28+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 2443264 |
| InitializedDataSize: | 3287040 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x208dfc |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.39.2.2 |
| ProductVersionNumber: | 6.39.2.2 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | http://www.internetdownloadmanager.com |
| CompanyName: | Tonec Inc. |
| FileDescription: | Internet Download Manager (IDM) |
| FileVersion: | 6, 39, 2, 2 |
| InternalName: | Internet Download Manager |
| LegalCopyright: | Tonec FZE, Copyright © 1999 - 2021 |
| LegalTrademarks: | Internet Download Manager |
| OriginalFileName: | IDMan.exe |
| ProductName: | Internet Download Manager (IDM) |
| ProductVersion: | 6, 39, 2, 2 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 17-Jul-2021 05:17:28 |
| Detected languages: |
|
| Debug artifacts: |
|
| Comments: | http://www.internetdownloadmanager.com |
| CompanyName: | Tonec Inc. |
| FileDescription: | Internet Download Manager (IDM) |
| FileVersion: | 6, 39, 2, 2 |
| InternalName: | Internet Download Manager |
| LegalCopyright: | Tonec FZE, Copyright © 1999 - 2021 |
| LegalTrademarks: | Internet Download Manager |
| OriginalFilename: | IDMan.exe |
| ProductName: | Internet Download Manager (IDM) |
| ProductVersion: | 6, 39, 2, 2 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 17-Jul-2021 05:17:28 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0025477C | 0x00254800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59412 |
.rdata | 0x00256000 | 0x000B8906 | 0x000B8A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.8694 |
.data | 0x0030F000 | 0x00010FBC | 0x00008000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.60185 |
.rsrc | 0x00320000 | 0x00224BC0 | 0x00224C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.45492 |
.reloc | 0x00545000 | 0x00034084 | 0x00034200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.18266 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.30925 | 1633 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 5.47275 | 4264 | UNKNOWN | English - United States | RT_ICON |
3 | 5.90283 | 1128 | UNKNOWN | English - United States | RT_ICON |
4 | 6.73358 | 2216 | UNKNOWN | English - United States | RT_ICON |
5 | 6.23219 | 4264 | UNKNOWN | English - United States | RT_ICON |
6 | 6.15891 | 2216 | UNKNOWN | English - United States | RT_ICON |
7 | 3.13238 | 338 | UNKNOWN | English - United States | RT_STRING |
8 | 1.0333 | 44 | UNKNOWN | English - United States | RT_STRING |
9 | 4.68664 | 4264 | UNKNOWN | English - United States | RT_ICON |
10 | 6.28402 | 2216 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
GDI32.dll |
KERNEL32.dll |
SHLWAPI.dll |
USER32.dll |
WS2_32.dll (delay-loaded) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1048,14774496759062719614,14214145412005656972,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1056 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 188 | AB2EF g93Xcv53d5 | C:\Users\admin\AppData\Local\Temp\ytmp\AB2EF.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 188 | "NSudo86x.exe" -Wait -U:T -P:E -UseCurrentConsole REG DELETE "HKU\.DEFAULT\Software\Classes\Wow6432Node\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f | C:\Users\admin\AppData\Local\Temp\ytmp\NSudo86x.exe | — | cmd.exe | |||||||||||
User: admin Company: M2-Team Integrity Level: HIGH Description: NSudo for Windows Exit code: 0 Version: 6.2.1812.31 Modules
| |||||||||||||||
| 188 | REG DELETE "HKCU\Software\Wow6432Node\DownloadManager" /f | C:\Windows\system32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 368 | "C:\Program Files\Internet Download Manager\IEMonitor.exe" | C:\Program Files\Internet Download Manager\IEMonitor.exe | — | IDMan.exe | |||||||||||
User: admin Company: Tonec Inc. Integrity Level: MEDIUM Description: Internet Download Manager agent for click monitoring in IE-based browsers Exit code: 1 Version: 6, 37, 8, 1 Modules
| |||||||||||||||
| 368 | FART -c -i "idm.tmp" "68dd140000" "6a00909090" | C:\Users\admin\AppData\Local\Temp\ytmp\fart.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 368 | 7za e files.tmp -pidm@idm420 -aoa "NSudo86x.exe" | C:\Users\admin\AppData\Local\Temp\ytmp\7za.exe | cmd.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 368 | REG DELETE "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f | C:\Windows\system32\REG.exe | NSudo86x.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 368 | REG DELETE "HKLM\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f | C:\Windows\system32\REG.exe | NSudo86x.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 368 | "NSudo86x.exe" -Wait -U:T -P:E -UseCurrentConsole REG DELETE "HKLM\Software\Wow6432Node\Internet Download Manager" /f | C:\Users\admin\AppData\Local\Temp\ytmp\NSudo86x.exe | — | cmd.exe | |||||||||||
User: admin Company: M2-Team Integrity Level: HIGH Description: NSudo for Windows Exit code: 0 Version: 6.2.1812.31 Modules
| |||||||||||||||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE |
| Operation: | write | Name: | name |
Value: Internet Explorer | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\IEXPLORE |
| Operation: | write | Name: | int |
Value: 1 | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\msedge |
| Operation: | write | Name: | name |
Value: Microsoft Edge | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\msedge |
| Operation: | write | Name: | int |
Value: 1 | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox |
| Operation: | write | Name: | name |
Value: Mozilla Firefox | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\Firefox |
| Operation: | write | Name: | int |
Value: 1 | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome |
| Operation: | write | Name: | name |
Value: Google Chrome | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\chrome |
| Operation: | write | Name: | int |
Value: 1 | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA |
| Operation: | write | Name: | name |
Value: Opera | |||
| (PID) Process: | (3836) IDMan.exe | Key: | HKEY_CURRENT_USER\Software\DownloadManager\IDMBI\OPERA |
| Operation: | write | Name: | int |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-615F4E19-CD4.pma | — | |
MD5:— | SHA256:— | |||
| 1708 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\index | binary | |
MD5:— | SHA256:— | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\bcb9dd7d-e6db-4374-b3e5-eea8b1e20a9f.tmp | text | |
MD5:— | SHA256:— | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:5BD3C311F2136A7A88D3E197E55CF902 | SHA256:FA331915E1797E59979A3E4BCC2BD0D3DEAA039B94D4DB992BE251FD02A224B9 | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6a0aac4b-dcdf-4b7c-8ab9-d787497bb634.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:8FF312A95D60ED89857FEB720D80D4E1 | SHA256:946A57FAFDD28C3164D5AB8AB4971B21BD5EC5BFFF7554DBF832CB58CC37700B | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:7721CDA9F5B73CE8A135471EB53B4E0E | SHA256:DD730C576766A46FFC84E682123248ECE1FF1887EC0ACAB22A5CE93A450F4500 | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF9792b.TMP | text | |
MD5:936EB7280DA791E6DD28EF3A9B46D39C | SHA256:CBAF2AFD831B32F6D1C12337EE5D2F090D6AE1F4DCB40B08BEF49BF52AD9721F | |||
| 1708 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 | vxd | |
MD5:CF89D16BB9107C631DAABF0C0EE58EFB | SHA256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E | |||
| 3284 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF9791c.TMP | text | |
MD5:64AD8ED3E666540337BA541C549F72F7 | SHA256:BECBDB08B5B37D203A85F2E974407334053BB1D2270F0B3C9A4DB963896F2206 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
852 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/YGkwa4MXjfWSuERyWQYP_A_4/aapLKTSZ439A-0g3nqJr3Q | US | — | — | whitelisted |
1708 | chrome.exe | GET | 200 | 23.32.238.201:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?535e11789f3a9d9c | US | compressed | 59.7 Kb | whitelisted |
852 | svchost.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvODZmQUFYS2VOaGowdjdSeVBvWFBSTDIxdw/1.0.0.9_llkgjffcdpffmhiakmfcdcblohccpfmo.crx | US | crx | 2.81 Kb | whitelisted |
852 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adys6mm2sd23z36ns7e4hcs4hrqq_1.3.36.111/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.111_win_ac5lwr5427en7czu7myxmee6c7xq.crx3 | US | ini | 20.9 Kb | whitelisted |
852 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/mdmguwvzgrqfqo2pe6jth7ue6y_45/khaoiebndkojlmppeemjhbpbandiljpe_45_win_adcs3xk2sovipzzwrg2uk2acjzwq.crx3 | US | binary | 419 Kb | whitelisted |
852 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adys6mm2sd23z36ns7e4hcs4hrqq_1.3.36.111/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.111_win_ac5lwr5427en7czu7myxmee6c7xq.crx3 | US | binary | 5.63 Kb | whitelisted |
852 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adys6mm2sd23z36ns7e4hcs4hrqq_1.3.36.111/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.111_win_ac5lwr5427en7czu7myxmee6c7xq.crx3 | US | binary | 43.4 Kb | whitelisted |
852 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvODNjQUFXN0xyYnNNZ1UyTjZEQjNiZzhuQQ/4.10.2209.0_oimompecagnajdejgnnjijobebaeigek.crx | US | crx | 5.45 Kb | whitelisted |
852 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adys6mm2sd23z36ns7e4hcs4hrqq_1.3.36.111/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.111_win_ac5lwr5427en7czu7myxmee6c7xq.crx3 | US | binary | 178 Kb | whitelisted |
852 | svchost.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/mdmguwvzgrqfqo2pe6jth7ue6y_45/khaoiebndkojlmppeemjhbpbandiljpe_45_win_adcs3xk2sovipzzwrg2uk2acjzwq.crx3 | US | crx | 5.45 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | Microsoft Corporation | GB | whitelisted |
1708 | chrome.exe | 216.58.212.163:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 142.250.185.196:443 | www.google.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 142.250.186.110:443 | clients2.google.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 172.217.16.131:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 142.250.186.42:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 142.250.184.227:443 | www.gstatic.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 142.250.184.206:443 | encrypted-tbn0.gstatic.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 216.58.212.174:443 | apis.google.com | Google Inc. | US | whitelisted |
1708 | chrome.exe | 172.217.23.99:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clients2.google.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2996 | IDMan.exe | Potential Corporate Privacy Violation | ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted |