File name:

anyunlock-iphone-password-unlocker-en-setup.exe

Full analysis: https://app.any.run/tasks/86c3ce3c-4628-4eb5-aaca-a92792edc661
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: June 29, 2024, 03:08:10
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

DEE2B414A4F0437D87F37B0CBCBCBC50

SHA1:

BBB3B605E1EBDF1B631BA403D6A82EFE5653A6E0

SHA256:

FD71A9586386F3F1BCF75ED4420B392F9C62DC5D501D8D8542DDFB1B36721C30

SSDEEP:

196608:29MUj5vDX0YBWPlVBZ4hHVGZOM+0tijDx5x2Q:w5vDX0YBWPlf2G8M+xx5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
    • Process drops legitimate windows executable

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • 7z.exe (PID: 4180)
    • Reads security settings of Internet Explorer

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • The process creates files with name similar to system file names

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • 7z.exe (PID: 4180)
    • Reads the date of Windows installation

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Executable content was dropped or overwritten

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Drops 7-zip archiver for unpacking

      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • The process drops C-runtime libraries

      • 7z.exe (PID: 4180)
    • Searches for installed software

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Drops a system driver (possible attempt to evade defenses)

      • 7z.exe (PID: 4180)
    • Creates a software uninstall entry

      • setup.exe (PID: 1088)
    • Application launched itself

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Checks Windows Trust Settings

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Adds/modifies Windows certificates

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Potential Corporate Privacy Violation

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Process requests binary or script from the Internet

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
  • INFO

    • Checks supported languages

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • TextInputHost.exe (PID: 6948)
      • identity_helper.exe (PID: 2764)
      • identity_helper.exe (PID: 6836)
    • Reads CPU info

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
    • Create files in a temporary directory

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads the computer name

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • identity_helper.exe (PID: 2764)
      • identity_helper.exe (PID: 6836)
      • TextInputHost.exe (PID: 6948)
    • Process checks computer location settings

      • anyunlock-iphone-password-unlocker-en-setup.exe (PID: 5076)
      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Disables trace logs

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Checks proxy server information

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Creates files or folders in the user directory

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads the software policy settings

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Reads Environment values

      • setup.exe (PID: 1088)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 3932)
    • Creates files in the program directory

      • setup.exe (PID: 1088)
      • 7z.exe (PID: 4180)
      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Dropped object may contain TOR URL's

      • 7z.exe (PID: 4180)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 1088)
      • msedge.exe (PID: 4440)
      • msedge.exe (PID: 2216)
      • msedge.exe (PID: 6588)
    • Application launched itself

      • msedge.exe (PID: 4440)
      • msedge.exe (PID: 2216)
      • msedge.exe (PID: 6588)
    • Manual execution by a user

      • msedge.exe (PID: 2216)
    • Reads product name

      • AnyUnlock - iPhone Password Unlocker.exe (PID: 2476)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 2216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 26624
InitializedDataSize: 475136
UninitializedDataSize: 16896
EntryPoint: 0x3415
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.1.0.1
ProductVersionNumber: 2.1.0.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: iMobie Inc.
FileDescription: AnyUnlock - iPhone Password Unlocker
FileVersion: 2.1.0.1
InternalName: AnyUnlock - iPhone Password Unlocker-Setup
LegalCopyright: Copyright (C) iMobie Inc. All rights reserved
LegalTrademarks: iMobie Inc. All rights reserved
OriginalFileName: AnyUnlock - iPhone Password Unlocker-Setup
ProductName: AnyUnlock - iPhone Password Unlocker
ProductVersion: 2.1.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
69
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start anyunlock-iphone-password-unlocker-en-setup.exe setup.exe 7z.exe conhost.exe no specs anyunlock - iphone password unlocker.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anyunlock - iphone password unlocker.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs anyunlock-iphone-password-unlocker-en-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4668 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
368"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5084 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1064"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3472 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exe" ver:2.1.0 gv:2.1.0.1 gs:Official-com lan:en-USC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exe
anyunlock-iphone-password-unlocker-en-setup.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
HIGH
Description:
anyunlock Setup
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nswd8ed.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1188"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=36 --mojo-platform-channel-handle=6300 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1384"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4788 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2020"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5268 --field-trial-handle=2384,i,9330388047030248920,5315220578275270532,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2216"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://www.imobie.com/anyunlock/thankyou/install-complete.htmC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2292"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2780 --field-trial-handle=2268,i,15479476008301087895,7990465796532254443,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2476"C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.exe" -h tVi0ShKTiriCg9wvuX2R9A==C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.exe
AnyUnlock - iPhone Password Unlocker.exe
User:
admin
Company:
iMobie Inc.
Integrity Level:
HIGH
Description:
AnyUnlock - iPhone Password Unlocker
Version:
2.1.0.1
Modules
Images
c:\program files (x86)\imobie\anyunlock - iphone password unlocker\anyunlock - iphone password unlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
37 594
Read events
37 375
Write events
211
Delete events
8

Modification events

(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5076) anyunlock-iphone-password-unlocker-en-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1088) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\setup_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
Executable files
241
Suspicious files
588
Text files
196
Unknown types
10

Dropped files

PID
Process
Filename
Type
1088setup.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.7z
MD5:
SHA256:
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\nsProcess.dllexecutable
MD5:F0438A894F3A7E01A4AAE8D1B5DD0289
SHA256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11
1088setup.exeC:\Users\admin\AppData\Roaming\iMobie\InstallLog\log-2024.txttext
MD5:8ADEA078B2C10764CD42E10007B24441
SHA256:327B8F679A95727A3FCE0F8A22361917CF11874E60F063666A7220D00DB79B71
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\uninstall.exeexecutable
MD5:C2F9D1DEAD92047E1FBC539CEC19DC40
SHA256:8CDD859AC1891C8EBE29FDC3A489554EBBE69AEF9ADDFA9BBEF1ABEE696131CD
41807z.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\res\ventoy\ventoy\ventoy.disk.img.xz
MD5:
SHA256:
1088setup.exeC:\Users\admin\AppData\Local\Temp\iMobie\Update\Config.Plistxml
MD5:B46FA32F92C1274B19E8043EDDAE394E
SHA256:F704CF125430C32B7DDB0C983CDFE4CAA59FE643D2996D168AD6FD87CDAF15D3
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\setup.exeexecutable
MD5:023DFCE70301896FB6B2E15ECA718549
SHA256:9140755BADAB25FCCA359FE83F74A4A435EC6136302DDAFB489A90F563AD4157
41807z.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\config\devices.plistxml
MD5:09DF055F79EDFB0DCC322DBC8E30742F
SHA256:5628F9900FF77EBAAAA020ADF47819499DECC37348B5EA8DE5E363D5DB627EAE
41807z.exeC:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\res\restore\x64\driver\USBAAPL64.CATcat
MD5:26EEE7AF8AA1EF8C1BD7C9327C602844
SHA256:946B0A8150213D6A4DD3AEF6248EBB923F8167C84C7FF1B10137E5030EC8BF30
5076anyunlock-iphone-password-unlocker-en-setup.exeC:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\dotNetFx45_Full_setup.exeexecutable
MD5:9E8253F0A993E53B4809DBD74B335227
SHA256:E434828818F81E6E1F5955E84CAEC08662BD154A80B24A71A2EDA530D8B2F66A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
48
TCP/UDP connections
185
DNS requests
171
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2916
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
unknown
2916
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
unknown
640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
unknown
640
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
unknown
1048
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
3848
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
2476
AnyUnlock - iPhone Password Unlocker.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHgDGEJFcIpBz28BuO60qVQ%3D
unknown
binary
1.40 Kb
unknown
2476
AnyUnlock - iPhone Password Unlocker.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
binary
1.41 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2916
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
3168
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1132
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
setup.exe
172.217.18.110:443
www.google-analytics.com
GOOGLE
US
whitelisted
2916
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2916
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1088
setup.exe
104.26.12.111:443
imobie-resource.com
CLOUDFLARENET
US
unknown
1088
setup.exe
67.225.249.166:443
dl.imobie.com
LIQUIDWEB
US
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 172.217.18.110
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
imobie-resource.com
  • 104.26.12.111
  • 172.67.68.126
  • 104.26.13.111
unknown
dl.imobie.com
  • 67.225.249.166
unknown
dlde.imobie.com
  • 172.104.130.191
unknown
dljp.imobie.com
  • 172.104.67.70
unknown
self.events.data.microsoft.com
  • 104.46.162.225
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.73
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.64
  • 20.190.159.68
  • 20.190.159.71
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.23
whitelisted

Threats

PID
Process
Class
Message
2476
AnyUnlock - iPhone Password Unlocker.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2476
AnyUnlock - iPhone Password Unlocker.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2476
AnyUnlock - iPhone Password Unlocker.exe
A Network Trojan was detected
ET HUNTING Terse Unencrypted Request for Google - Likely Connectivity Check
2636
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2636
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
1 ETPRO signatures available at the full report
Process
Message
setup.exe
GA: {"client_id":"au-Windows","user_id":"26B799FA","user_properties":null,"events":[{"name":"Install_SW","params":{"engagement_time_msec":"1","ea":"Launch App","el":"1","install_productversion":"Official-com","install_trackversion":"2.1.0.1","soft_os_version":"Windows10_64"}}]}
setup.exe
GA: {"client_id":"au-Windows","user_id":"26B799FA","user_properties":null,"events":[{"name":"Install_SW","params":{"engagement_time_msec":"1","ea":"Start Download","el":"https://imobie-resource.com/product/anyunlock-64.7z","install_productversion":"Official-com","install_trackversion":"2.1.0.1","soft_os_version":"Windows10_64"}}]}
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dl.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dlde.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
get length from <https://dljp.imobie.com/anyunlock.7z> failed: The remote server returned an error: (404) Not Found.
setup.exe
setup.exe Information: 0 :
setup.exe
C:\Users\admin\AppData\Local\Temp\nswD8ED.tmp\7z.exe x "C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker\AnyUnlock - iPhone Password Unlocker.7z" -o"C:\Program Files (x86)\iMobie\AnyUnlock - iPhone Password Unlocker" -r -bsp1