File name:

anyunlock-iphone-password-unlocker-en-setup.exe

Full analysis: https://app.any.run/tasks/86c3ce3c-4628-4eb5-aaca-a92792edc661
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: June 29, 2024, 03:08:10
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

DEE2B414A4F0437D87F37B0CBCBCBC50

SHA1:

BBB3B605E1EBDF1B631BA403D6A82EFE5653A6E0

SHA256:

FD71A9586386F3F1BCF75ED4420B392F9C62DC5D501D8D8542DDFB1B36721C30

SSDEEP:

196608:29MUj5vDX0YBWPlVBZ4hHVGZOM+0tijDx5x2Q:w5vDX0YBWPlf2G8M+xx5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • 7z.exe (PID: 4180)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
    • The process creates files with name similar to system file names

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • 7z.exe (PID: 4180)
    • Reads security settings of Internet Explorer

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Reads the date of Windows installation

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Executable content was dropped or overwritten

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Drops 7-zip archiver for unpacking

      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • The process drops C-runtime libraries

      • 7z.exe (PID: 4180)
    • Drops a system driver (possible attempt to evade defenses)

      • 7z.exe (PID: 4180)
    • Creates a software uninstall entry

      • setup.exe (PID: 1088)
    • Searches for installed software

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Application launched itself

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Checks Windows Trust Settings

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Adds/modifies Windows certificates

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Potential Corporate Privacy Violation

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Process requests binary or script from the Internet

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
  • INFO

    • Checks supported languages

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • identity_helper.exe (PID: 6836)
      • TextInputHost.exe (PID: 6948)
      • identity_helper.exe (PID: 2764)
    • Reads the computer name

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • identity_helper.exe (PID: 6836)
      • TextInputHost.exe (PID: 6948)
      • identity_helper.exe (PID: 2764)
    • Reads CPU info

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
    • Create files in a temporary directory

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Process checks computer location settings

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Creates files or folders in the user directory

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads Environment values

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Disables trace logs

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Creates files in the program directory

      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads the software policy settings

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Dropped object may contain TOR URL's

      • 7z.exe (PID: 4180)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 1088)
      • msedge.exe (PID: 2216)
      • msedge.exe (PID: 4440)
      • msedge.exe (PID: 6588)
    • Application launched itself

      • msedge.exe (PID: 4440)
      • msedge.exe (PID: 2216)
      • msedge.exe (PID: 6588)
    • Manual execution by a user

      • msedge.exe (PID: 2216)
    • Checks proxy server information

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • setup.exe (PID: 1088)
    • Reads product name

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 2216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 26624
InitializedDataSize: 475136
UninitializedDataSize: 16896
EntryPoint: 0x3415
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.1.0.1
ProductVersionNumber: 2.1.0.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: iMobie Inc.
FileDescription: AnyUnlock - iPhone Password Unlocker
FileVersion: 2.1.0.1
InternalName: AnyUnlock - iPhone Password Unlocker-Setup
LegalCopyright: Copyright (C) iMobie Inc. All rights reserved
LegalTrademarks: iMobie Inc. All rights reserved
OriginalFileName: AnyUnlock - iPhone Password Unlocker-Setup
ProductName: AnyUnlock - iPhone Password Unlocker
ProductVersion: 2.1.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
69
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start anyunlock-iphone-password-unlocker-en-setup.exe setup.exe 7z.exe conhost.exe no specs anyunlock - iphone password unlocker.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anyunlock - iphone password unlocker.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anyunlock-iphone-password-unlocker-en-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4668 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
368"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5084 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3472 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exe" ver:2.1.0 gv:2.1.0.1 gs:Official-com lan:en-USC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exe
anyunlock-iphone-password-unlocker-en-setup.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
HIGH
Description:
anyunlock Setup
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nswd8ed.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=36 --mojo-platform-channel-handle=6300 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1384"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4788 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2020"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5268 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://www.imobie.com/anyunlock/thankyou/install-complete.htmC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2292"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2780 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2476"C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.exe" -h tVi0ShKTiriCg9wvuX2R9A==C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.exe
AnyUnlock - iPhone Password Unlocker.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
HIGH
Description:
AnyUnlock - iPhone Password Unlocker
Version:
2.1.0.1
Modules
Images
c:\program files (x86)\imobie\anyunlock - iphone password unlocker\anyunlock - iphone password unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
37 594
Read events
37 375
Write events
211
Delete events
8

Modification events

(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
Executable files
241
Suspicious files
588
Text files
196
Unknown types
10

Dropped files

PID
Process
Filename
Type
1088setup.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.7z
MD5:
SHA256:
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exeexecutable
MD5:023DFCE70301896FB6B2E15ECA718549
SHA256:9140755BADAB25FCCA359FE83F74A4A435EC6136302DDAFB489A90F563AD4157
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\uninstall.exeexecutable
MD5:C2F9D1DEAD92047E1FBC539CEC19DC40
SHA256:8CDD859AC1891C8EBE29FDC3A489554EBBE69AEF9ADDFA9BBEF1ABEE696131CD
41807z.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\res\restore\x64\driver\usbaapl64.infbinary
MD5:2DA3A91B71919D035D8FD17B6B90BBC2
SHA256:EDEA577E694EFCEEC5B26D745FFF8125E9FC8A78CACD7365E77EF35031EBC49B
41807z.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\res\ventoy\ventoy\ventoy.disk.img.xz
MD5:
SHA256:
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\System.dllexecutable
MD5:CA332BB753B0775D5E806E236DDCEC55
SHA256:DF5AE79FA558DC7AF244EC6E53939563B966E7DBD8867E114E928678DBD56E5D
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\CheckProVs.dllexecutable
MD5:62E85098CE43CB3D5C422E49390B7071
SHA256:EE7E26894CBF89C93AE4DF15BDB12CD9A21F5DEACEDFA99A01EEFE8FA52DAEC2
1088setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\7z.exeexecutable
MD5:43141E85E7C36E31B52B22AB94D5E574
SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\nsProcess.dllexecutable
MD5:F0438A894F3A7E01A4AAE8D1B5DD0289
SHA256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11
1088setup.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\setup.icoimage
MD5:B7DEEBBEC0BEF0F946C44FEEA5146A5E
SHA256:C1B054D824D141F9976C45435D9F4C53B639AE1EF29967B419B22E0F8E28CC4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
48
TCP/UDP connections
185
DNS requests
171
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2916
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
2916
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
3848
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
1048
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
2476
AnyUnlock - iPhone Password Unlocker.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
unknown
2476
AnyUnlock - iPhone Password Unlocker.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2916
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
3168
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1132
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
setup.exe
172.217.18.110:443
www.google-analytics.com
GOOGLE
US
whitelisted
2916
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2916
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1088
setup.exe
104.26.12.111:443
imobie-resource.com
CLOUDFLARENET
US
unknown
1088
setup.exe
67.225.249.166:443
dl.imobie.com
LIQUIDWEB
US
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 172.217.18.110
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
imobie-resource.com
  • 104.26.12.111
  • 172.67.68.126
  • 104.26.13.111
unknown
dl.imobie.com
  • 67.225.249.166
unknown
dlde.imobie.com
  • 172.104.130.191
unknown
dljp.imobie.com
  • 172.104.67.70
unknown
self.events.data.microsoft.com
  • 104.46.162.225
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.73
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.64
  • 20.190.159.68
  • 20.190.159.71
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.23
whitelisted

Threats

PID
Process
Class
Message
2476
AnyUnlock - iPhone Password Unlocker.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2476
AnyUnlock - iPhone Password Unlocker.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2476
AnyUnlock - iPhone Password Unlocker.exe
A Network Trojan was detected
ET HUNTING Terse Unencrypted Request for Google - Likely Connectivity Check
2636
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2636
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1 ETPRO signatures available at the full report
Process
Message
setup.exe
GA: {"client_id":"au-Windows","user_id":"26B799FA","user_properties":null,"events":[{"name":"Install_SW","params":{"engagement_time_msec":"1","ea":"Launch App","el":"1","install_productversion":"Official-com","install_trackversion":"2.1.0.1","soft_os_version":"Windows10_64"}}]}
setup.exe
GA: {"client_id":"au-Windows","user_id":"26B799FA","user_properties":null,"events":[{"name":"Install_SW","params":{"engagement_time_msec":"1","ea":"Start Download","el":"https://imobie-resource.com/product/anyunlock-64.7z","install_productversion":"Official-com","install_trackversion":"2.1.0.1","soft_os_version":"Windows10_64"}}]}
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dl.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dlde.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dljp.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
C:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\7z.exe x "C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.7z" -o"C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker" -r -bsp1