URL: | http://dl.tenorshare.net/iCareFonetrial_ts_en.exe |
Full analysis: | https://app.any.run/tasks/1d4aef77-935c-4735-84d3-770779d5138d |
Verdict: | Malicious activity |
Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
Analysis date: | February 28, 2019, 04:00:54 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MD5: | 6BDAD3459B1114B40AD4FF1B13167C8F |
SHA1: | 757BD12F059CA14C7E1208AFFF3E1A8A69314E0A |
SHA256: | F11CDA6840D5479E46560DE00F90F84272F2D90038F3140848EC90F9337D804F |
SSDEEP: | 3:N1KaJaxLLznEXGTR6uL4A:CaJwL7BLN |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2956 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3204 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2956 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
2772 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe | — | iexplore.exe |
User: admin Company: Tenorshare, Inc. Integrity Level: MEDIUM Description: Tenorshare iCareFone Setup Exit code: 3221226540 Version: | ||||
3776 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe | iexplore.exe | |
User: admin Company: Tenorshare, Inc. Integrity Level: HIGH Description: Tenorshare iCareFone Setup Exit code: 0 Version: | ||||
2964 | "C:\Users\admin\AppData\Local\Temp\is-0PGFG.tmp\iCareFonetrial_ts_en[1].tmp" /SL5="$5018C,85535845,289280,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe" | C:\Users\admin\AppData\Local\Temp\is-0PGFG.tmp\iCareFonetrial_ts_en[1].tmp | iCareFonetrial_ts_en[1].exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
3816 | "C:\Program Files\Tenorshare iCareFone\NetFrameCheck.exe" | C:\Program Files\Tenorshare iCareFone\NetFrameCheck.exe | — | iCareFonetrial_ts_en[1].tmp |
User: admin Company: Tenorshare Co.Ltd Integrity Level: HIGH Description: Tenorshare iCarefone Exit code: 0 Version: 2.0.0.0 | ||||
2832 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | iCareFonetrial_ts_en[1].tmp | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
2924 | "C:\Program Files\Tenorshare iCareFone\Tenorshare iCareFone.exe" | C:\Program Files\Tenorshare iCareFone\Tenorshare iCareFone.exe | NetFrameCheck.exe | |
User: admin Company: Tenorshare Integrity Level: HIGH Description: iCareFone Version: 5.3.2.8 | ||||
1712 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2832 CREDAT:79873 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
1856 | "C:\Program Files\Tenorshare iCareFone\7z\7z.exe" x "C:\Users\admin\AppData\Local\Temp\iTunes.exe" -y -o"C:\Users\admin\AppData\Local\Temp\iTunes" | C:\Program Files\Tenorshare iCareFone\7z\7z.exe | Tenorshare iCareFone.exe | |
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Console Exit code: 0 Version: 18.05 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2956 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
2956 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
2956 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFD27972D57E9BD8B3.TMP | — | |
MD5:— | SHA256:— | |||
3204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\iCareFonetrial_ts_en[1].exe | — | |
MD5:— | SHA256:— | |||
2956 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\iCareFonetrial_ts_en[1].exe | — | |
MD5:— | SHA256:— | |||
2956 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF4E4CFAA4699CD2D3.TMP | — | |
MD5:— | SHA256:— | |||
2956 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{7AAF589D-3B0D-11E9-BEEC-5254004A04AF}.dat | — | |
MD5:— | SHA256:— | |||
2964 | iCareFonetrial_ts_en[1].tmp | C:\Program Files\Tenorshare iCareFone\is-7U396.tmp | — | |
MD5:— | SHA256:— | |||
2964 | iCareFonetrial_ts_en[1].tmp | C:\Program Files\Tenorshare iCareFone\is-M3E1M.tmp | — | |
MD5:— | SHA256:— | |||
2964 | iCareFonetrial_ts_en[1].tmp | C:\Program Files\Tenorshare iCareFone\is-4TMJB.tmp | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3204 | iexplore.exe | GET | — | 2.16.186.51:80 | http://dl.tenorshare.net/iCareFonetrial_ts_en.exe | unknown | — | — | whitelisted |
2956 | iexplore.exe | GET | 200 | 13.107.21.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2956 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3204 | iexplore.exe | 2.16.186.81:80 | dl.tenorshare.net | Akamai International B.V. | — | whitelisted |
3204 | iexplore.exe | 2.16.186.51:80 | dl.tenorshare.net | Akamai International B.V. | — | whitelisted |
2956 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
www.bing.com |
| whitelisted |
dl.tenorshare.net |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
3204 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2964 | iCareFonetrial_ts_en[1].tmp | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
2964 | iCareFonetrial_ts_en[1].tmp | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
2964 | iCareFonetrial_ts_en[1].tmp | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2964 | iCareFonetrial_ts_en[1].tmp | Misc activity | ADWARE [PTsecurity] Adware.AdAnti |
2924 | Tenorshare iCareFone.exe | Generic Protocol Command Decode | SURICATA STREAM excessive retransmissions |
2924 | Tenorshare iCareFone.exe | Generic Protocol Command Decode | SURICATA STREAM excessive retransmissions |
Process | Message |
---|---|
Tenorshare iCareFone.exe | 2019-2-28 4:2:23 Tenorshare iCareFone<3116>:: MainViewModel : iTunes Component Check. Unerected
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:23 Tenorshare iCareFone<3632>:: TSPackageManagerImpl::OnHandle : Download File = C:\Users\admin\AppData\Local\Temp\iTunes.exe
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:23 Tenorshare iCareFone<3632>:: iTunesService : Dwonload Started.
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:39 Tenorshare iCareFone<3632>:: TSPackageManagerImpl::OnHandle Download C:\Users\admin\AppData\Local\Temp\iTunes.exe Result = 0
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:39 Tenorshare iCareFone<3632>:: iTunesService : Dwonload Completed. Package = C:\Users\admin\AppData\Local\Temp\iTunes.exe
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:39 Tenorshare iCareFone<3632>:: iTunesService : Dwonload Ended.
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:39 Tenorshare iCareFone<2624>:: TSPackageManagerImpl::Install Command = "C:\Program Files\Tenorshare iCareFone\7z\7z.exe" x "C:\Users\admin\AppData\Local\Temp\iTunes.exe" -y -o"C:\Users\admin\AppData\Local\Temp\iTunes"
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:42 Tenorshare iCareFone<2624>:: iTunesService : Install Started.
|
Tenorshare iCareFone.exe | 2019-2-28 4:2:42 Tenorshare iCareFone<2624>:: TSPackageManagerImpl::Install ExtractDir = C:\Users\admin\AppData\Local\Temp\iTunes
|
Tenorshare iCareFone.exe | 2019-2-28 4:3:7 Tenorshare iCareFone<2624>:: iTunesService : Install Completed. Index = 0, Package = C:\Users\admin\AppData\Local\Temp\iTunes\AppleApplicationSupport.msi
|