| URL: | https://sunlogin.oray.com/download/ |
| Full analysis: | https://app.any.run/tasks/4ef65d0f-21c1-4353-9625-bd08f3a93b94 |
| Verdict: | Malicious activity |
| Analysis date: | September 30, 2021, 07:47:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | CDEF57F20EB1273B5580CBACFE398ABD |
| SHA1: | E3F8A902DCC40A82C1355B47C022860E3EE87386 |
| SHA256: | 07F3D21B9162E4D138D21759C9248B8FDD95811C855182540D5F231026C81865 |
| SSDEEP: | 3:N8d9KMEcLGG8Ln:2qmLGNL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | cmd /c netsh advfirewall firewall add rule name="SunloginClient" dir=in action=allow program="C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" protocol=udp enable=yes profile=private | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 120 | netsh advfirewall firewall add rule name="SunloginDesktopAgent" dir=in action=allow program="C:\Program Files\Oray\SunLogin\SunloginClient\agent\SunloginClient.exe" protocol=udp enable=yes profile=private | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 572 | "C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" --mod=install --cmd=driver_mirror | C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe | SunloginClient_12.0.1.40571.exe | ||||||||||||
User: admin Company: Shanghai Best Oray Information Technology Co., Ltd. Integrity Level: HIGH Description: SunloginClient Exit code: 0 Version: 12.0.1.40571 Modules
| |||||||||||||||
| 580 | cmd /c netsh advfirewall firewall delete rule name="SunloginDesktopAgent" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 656 | "C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" --admin=1 | C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe | SunloginClient.exe | ||||||||||||
User: admin Company: Shanghai Best Oray Information Technology Co., Ltd. Integrity Level: MEDIUM Description: SunloginClient Exit code: 0 Version: 12.0.1.40571 Modules
| |||||||||||||||
| 708 | "C:\Program Files\Oray\SunLogin\SunloginClient\Driver\Mirror\devcon.exe" reinstall "C:\Program Files\Oray\SunLogin\SunloginClient\Driver\Mirror\OrayMir.inf" C50B00D7-AE62-4936-8BC8-20E0B9F0BEFB | C:\Program Files\Oray\SunLogin\SunloginClient\Driver\Mirror\devcon.exe | SunloginClient.exe | ||||||||||||
User: admin Company: Windows (R) Server 2003 DDK provider Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 5.2.3790.1830 built by: WinDDK Modules
| |||||||||||||||
| 824 | "C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" --mod=update --cmd=check | C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe | SunloginClient.exe | ||||||||||||
User: SYSTEM Company: Shanghai Best Oray Information Technology Co., Ltd. Integrity Level: SYSTEM Description: SunloginClient Exit code: 0 Version: 12.0.1.40571 Modules
| |||||||||||||||
| 1340 | cmd /c netsh advfirewall firewall add rule name="SunloginClient" dir=in action=allow program="C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" protocol=tcp enable=yes profile=domain | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1384 | netsh advfirewall firewall add rule name="SunloginClient" dir=in action=allow program="C:\Program Files\Oray\SunLogin\SunloginClient\SunloginClient.exe" protocol=udp enable=yes profile=private | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1740 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\SunloginClient_12.0.1.40571.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\SunloginClient_12.0.1.40571.exe | — | iexplore.exe | |||||||||||
User: admin Company: Shanghai Best Oray Information Technology Co., Ltd. Integrity Level: MEDIUM Description: SunloginClient Exit code: 1 Version: 12.0.1.40571 Modules
| |||||||||||||||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30913999 | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30913999 | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2392) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 2392 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442 | der | |
MD5:— | SHA256:— | |||
| 2392 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442 | binary | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_C39E9DBC666D19C07EEE7CD1E11AF8BE | binary | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\773CFF2C7835D48C4E76FE153DBA9F81_DE868A117854FB5E13D53239776C372A | der | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_C39E9DBC666D19C07EEE7CD1E11AF8BE | der | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\download[1].htm | html | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\773CFF2C7835D48C4E76FE153DBA9F81_40A8C54141774970FA2A3B2AC3918CCD | binary | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\773CFF2C7835D48C4E76FE153DBA9F81_DE868A117854FB5E13D53239776C372A | binary | |
MD5:— | SHA256:— | |||
| 3028 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\773CFF2C7835D48C4E76FE153DBA9F81_40A8C54141774970FA2A3B2AC3918CCD | der | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3028 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEAPY2n2T43%2BdvgqpLgTuB8s%3D | US | der | 471 b | shared |
3028 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEAsjf0QkQYAdL0CSeiItMII%3D | US | der | 471 b | shared |
3028 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDHI53Mm%2BtcnNeVQV%2BQ%3D%3D | US | der | 1.46 Kb | whitelisted |
3028 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDDPT5nWSERQN6vQXtA%3D%3D | US | der | 1.41 Kb | whitelisted |
3028 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsllCLO2YEqFaBOmVKKDvo%3D | US | der | 471 b | whitelisted |
3028 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8EJH | US | der | 1.41 Kb | whitelisted |
3028 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D | US | der | 1.40 Kb | whitelisted |
2392 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
2392 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
2392 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3028 | iexplore.exe | 120.55.52.22:443 | sentry.oray.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3028 | iexplore.exe | 47.110.217.173:443 | sunlogin.oray.com | — | CN | unknown |
3028 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3028 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2392 | iexplore.exe | 204.79.197.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
2392 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2392 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3028 | iexplore.exe | 79.133.177.225:443 | res.orayimg.com | SOT LINE Limited Company | RU | malicious |
3028 | iexplore.exe | 103.235.46.191:443 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
3028 | iexplore.exe | 110.242.68.204:443 | fxgate.baidu.com | CHINA UNICOM China169 Backbone | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
sunlogin.oray.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
status.rapidssl.com |
| shared |
res.orayimg.com |
| malicious |
static.orayimg.com |
| malicious |
cdn.orayimg.com |
| malicious |
hm.baidu.com |
| whitelisted |
Process | Message |
|---|---|
SunloginClient_12.0.1.40571.exe | [2104] 2021-09-30 08:49:40.924 - Info - [dpi] SetDPIAwareness isn't support.
|
SunloginClient_12.0.1.40571.exe | [2104] 2021-09-30 08:49:40.929 = Debug = [select_tracker] run ok
|
SunloginClient_12.0.1.40571.exe | [2104] 2021-09-30 08:49:40.999 = Debug = [select_tracker] run ok
|
SunloginClient_12.0.1.40571.exe | [3856] 2021-09-30 08:49:40.999 = Debug = [thread] set thread name Thread-3856 0458e1e0 / 3856
|
SunloginClient_12.0.1.40571.exe | [3856] 2021-09-30 08:49:41.000 * Error * [SensorsDatas::init_sensors_thread] [sensors] distinct_id is empty create now!
|
SunloginClient_12.0.1.40571.exe | [3856] 2021-09-30 08:49:41.001 - Info - [SensorsDatas::init_sensors_thread] [sensors] init with file: C:/ProgramData/OrayClient/sensors/datas
|
SunloginClient_12.0.1.40571.exe | [2104] 2021-09-30 08:49:41.014 * Error * [CSSLStream] Remove temp(C:\Users\admin\AppData\Local\Temp\u1u4.0) file ok
|
SunloginClient_12.0.1.40571.exe | [2104] 2021-09-30 08:49:41.015 = Debug = [select_tracker] run ok
|
SunloginClient_12.0.1.40571.exe | [3920] 2021-09-30 08:49:41.015 = Debug = [thread] set thread name Thread-3920 0458e0e0 / 3920
|
SunloginClient_12.0.1.40571.exe | [3856] 2021-09-30 08:49:43.782 - Info - [http::call3][1] new call:https://sl-tk.oray.com/track
|