instatime.exe

InstaTime

The executable instatime.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘InstaTime’. While running, it connects to the Internet address edge-star-mini-shv-01-syd2.facebook.com on port 443.
Publisher:
InstaTime  (signed and verified)

MD5:
5d5656570a920ee5ed94bb19fe6ed0e7

SHA-1:
f22aee9c42f54cae3c162bca000b21e42562d711

SHA-256:
27a0e04eeae51bb2e58b41770a2dd13b65cb07fdf4517b7d8c1a683eb7f1077e

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/26/2024 11:33:49 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.1.15

File size:
47.2 MB (49,533,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\instatime\instatime.exe

Digital Signature
Signed by:

Authority:
InstaTime

Valid from:
6/1/2015 10:40:01 PM

Valid to:
5/29/2025 10:40:01 PM

Subject:
E=softninjas@gmail.com, CN=InstaTime, O=InstaTime, S=Some-State, C=US

Issuer:
E=softninjas@gmail.com, CN=InstaTime, O=InstaTime, S=Some-State, C=US

Serial number:
00E63C0FE02346D411

File PE Metadata
Compilation timestamp:
2/20/2016 3:43:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:kuK9C64r1c7VQZgnUrurLpbH05yL5dsuUQq6+4UYOkdOXQvhSk/:5wC64r1c6ZgnUSrLpbUAdBUQq6/BLrss

Entry address:
0x1C9A031

Entry point:
E8, 5A, 3A, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 55, 0C, A1, 20, A8, EC, 02, F7, D2, 8B, 4D, 08, 23, D0, 23, 4D, 0C, 0B, D1, 89, 15, 20, A8, EC, 02, 5D, C3, E8, 09, 21, 00, 00, 85, C0, 74, 08, 6A, 16, E8, CC, 21, 00, 00, 59, F6, 05, 20, A8, EC, 02, 02, 74, 21, 6A, 17, E8, D9, 20, 60, 00, 85, C0, 74, 05, 6A, 07, 59, CD, 29, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, A9, F8, FF, FF, 83, C4, 0C, 6A, 03, E8, 16, FC, FF, FF, CC, 55, 8B, EC, 8D, 45, 18, 50, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75...
 
[+]

Code size:
34.9 MB (36,634,112 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
InstaTime

Command:
C:\users\{user}\appdata\roaming\instatime\instatime.exe su


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to e2.ycpi.vip.lob.yahoo.com  (87.248.114.12:443)

TCP (HTTP SSL):
Connects to edge-star-mini-shv-01-cdg2.facebook.com  (179.60.192.36:443)

TCP (HTTP SSL):
Connects to rtr3.l7.search.vip.ir2.yahoo.com  (217.12.15.96:443)

TCP (HTTP SSL):
Connects to a23-213-140-88.deploy.static.akamaitechnologies.com  (23.213.140.88:443)

TCP (HTTP SSL):
Connects to xx-fbcdn-shv-01-cdg2.fbcdn.net  (179.60.192.7:443)

TCP (HTTP):
Connects to server-54-230-187-41.cdg51.r.cloudfront.net  (54.230.187.41:80)

TCP (HTTP):
Connects to server-54-230-187-108.cdg51.r.cloudfront.net  (54.230.187.108:80)

TCP (HTTP):
Connects to hotelamur.ru  (62.109.15.15:80)

TCP (HTTP SSL):
Connects to edge-star-shv-01-cdg2.facebook.com  (179.60.192.3:443)

TCP (HTTP SSL):
Connects to ec2-52-57-191-92.eu-central-1.compute.amazonaws.com  (52.57.191.92:443)

TCP (HTTP SSL):
Connects to ec2-204-236-239-173.compute-1.amazonaws.com  (204.236.239.173:443)

TCP (HTTP SSL):
Connects to e1.ycpi.vip.lob.yahoo.com  (87.248.114.11:443)

TCP (HTTP):
Connects to a88-221-113-144.deploy.akamaitechnologies.com  (88.221.113.144:80)

TCP (HTTP):
Connects to a88-221-112-43.deploy.akamaitechnologies.com  (88.221.112.43:80)

TCP (HTTP):
Connects to a104-85-41-231.deploy.static.akamaitechnologies.com  (104.85.41.231:80)

TCP (HTTP SSL):
Connects to a104-85-23-121.deploy.static.akamaitechnologies.com  (104.85.23.121:443)

TCP (HTTP):
Connects to 7.8.211.130.bc.googleusercontent.com  (130.211.8.7:80)

TCP (HTTP):
Connects to 38.22.211.130.bc.googleusercontent.com  (130.211.22.38:80)

TCP (HTTP SSL):
Connects to 221.105.199.104.bc.googleusercontent.com  (104.199.105.221:443)

TCP (HTTP SSL):
Connects to 207.140.251.23.bc.googleusercontent.com  (23.251.140.207:443)

Remove instatime.exe - Powered by Reason Core Security