File name:

360hb4.0.276.0__weiruan__ (1).exe

Full analysis: https://app.any.run/tasks/89483781-dc19-46c1-a2ac-1b801b474bbe
Verdict: Malicious activity
Analysis date: October 22, 2024, 07:18:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-html
arch-scr
arch-exec
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7D56EAEF1FA70AF9DD0B10F298D9AD3A

SHA1:

CF5B60F53926411BCE9F6B4D53CB23F8981AC08A

SHA256:

08D6B1EA34A3F3CB8E8DEF63CAB00A5C20E545026C6692B12334E69F7538B406

SSDEEP:

98304:t0R/qWahEIkGfjTt0Pf3VnIkFMMwOkDOUBvc9/20zpEGal2G/XVMmoNygrs31DNi:oOvkm+IfUQaUhRtVHsd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • 360huabaosetup.exe (PID: 6612)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
      • 360huabaosetup.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
      • 360se15.0.1376.0.exe (PID: 1204)
      • setup.exe (PID: 4548)
      • 360huabaosetup.exe (PID: 6612)
      • 360huabao.exe (PID: 6436)
      • 360huabao.exe (PID: 6936)
    • The process verifies whether the antivirus software is installed

      • 360huabaosetup.exe (PID: 6612)
    • Searches for installed software

      • 360huabaosetup.exe (PID: 6612)
    • Creates a software uninstall entry

      • 360huabaosetup.exe (PID: 6612)
    • Checks Windows Trust Settings

      • 360huabaosetup.exe (PID: 6612)
    • Process drops legitimate windows executable

      • setup.exe (PID: 4548)
    • The process drops C-runtime libraries

      • setup.exe (PID: 4548)
    • Application launched itself

      • 360huabao.exe (PID: 6436)
  • INFO

    • Create files in a temporary directory

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
    • The process uses the downloaded file

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
    • Reads the computer name

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
      • 360huabaosetup.exe (PID: 6612)
    • Checks supported languages

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
      • 360huabaosetup.exe (PID: 6612)
    • Process checks computer location settings

      • 360hb4.0.276.0__weiruan__ (1).exe (PID: 5284)
    • Checks proxy server information

      • 360huabaosetup.exe (PID: 6612)
    • Creates files or folders in the user directory

      • 360huabaosetup.exe (PID: 6612)
    • Reads the machine GUID from the registry

      • 360huabaosetup.exe (PID: 6612)
    • Reads the software policy settings

      • 360huabaosetup.exe (PID: 6612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:21 09:02:22+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 97280
InitializedDataSize: 8558592
UninitializedDataSize: -
EntryPoint: 0x8544
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 4.0.276.0
ProductVersionNumber: 4.0.276.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileDescription: 360壁纸 服务组件
FileVersion: 4.0.276.0
LegalCopyright: Copyright (C) 2021
ProductName: 360壁纸 服务组件
ProductVersion: 4.0.276.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
17
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 360hb4.0.276.0__weiruan__ (1).exe 360huabaosetup.exe sppextcomobj.exe no specs slui.exe slui.exe 360se15.0.1376.0.exe setup.exe 360huabao.exe 360huabao.exe 360huabao.exe no specs 360huabao.exe 360huabao.exe no specs 360huabao.exe no specs 360huabao.exe no specs 360huabaosetup.exe 360secore.exe 360huabao.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1204C:\Users\admin\AppData\Local\Temp\360se15.0.1376.0.exe --secore-install --secore-forsdk --silent-installC:\Users\admin\AppData\Local\Temp\360se15.0.1376.0.exe
360huabaosetup.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360安全浏览器
Exit code:
0
Version:
15.0.1376.0
Modules
Images
c:\users\admin\appdata\local\temp\360se15.0.1376.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1432"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" --type=gpu-process --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\360huabao\\user_data\\chromeshellmain" --main-ver=15.0.1376.0 --mainprocess-ver=15.0.1376.0 --gpu-preferences=WAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --use-gl=disabled --mojo-platform-channel-handle=2968 --field-trial-handle=2736,i,4046529691598077520,11598470162461425572,262144 --disable-features=HardwareMediaKeyHandling /prefetch:2C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe360huabao.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Version:
4.0.276.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3156C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4516"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\360huabao\\user_data\\chromeshellmain" --main-ver=15.0.1376.0 --mainprocess-ver=15.0.1376.0 --no-sandbox --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4456 --field-trial-handle=2736,i,4046529691598077520,11598470162461425572,262144 --disable-features=HardwareMediaKeyHandling /prefetch:1C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe360huabao.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Version:
4.0.276.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4548"C:\Users\admin\AppData\Local\Temp\CR_7CEBA.tmp\setup.exe" --exe-path="C:\Users\admin\AppData\Local\Temp\360se15.0.1376.0.exe" --secore-install --secore-forsdk --silent-installC:\Users\admin\AppData\Local\Temp\CR_7CEBA.tmp\setup.exe
360se15.0.1376.0.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360安全浏览器
Exit code:
0
Version:
15.0.1376.0
Modules
Images
c:\users\admin\appdata\local\temp\cr_7ceba.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5196"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\360huabao\\user_data\\chromeshellmain" --main-ver=15.0.1376.0 --mainprocess-ver=15.0.1376.0 --mojo-platform-channel-handle=4692 --field-trial-handle=2736,i,4046529691598077520,11598470162461425572,262144 --disable-features=HardwareMediaKeyHandling /prefetch:8C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe360huabao.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Exit code:
0
Version:
4.0.276.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5284"C:\Users\admin\AppData\Local\Temp\360hb4.0.276.0__weiruan__ (1).exe" C:\Users\admin\AppData\Local\Temp\360hb4.0.276.0__weiruan__ (1).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸 服务组件
Exit code:
0
Version:
4.0.276.0
Modules
Images
c:\users\admin\appdata\local\temp\360hb4.0.276.0__weiruan__ (1).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5980"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\360huabao\\user_data\\chromeshellmain" --main-ver=15.0.1376.0 --mainprocess-ver=15.0.1376.0 --mojo-platform-channel-handle=3160 --field-trial-handle=2736,i,4046529691598077520,11598470162461425572,262144 --disable-features=HardwareMediaKeyHandling /prefetch:8C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe360huabao.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Version:
4.0.276.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6000C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6132"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
10 227
Read events
9 989
Write events
231
Delete events
7

Modification events

(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\360\360huabao
Operation:writeName:Version
Value:
4.0.276.0
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\360\360huabao
Operation:writeName:hbinstalltime
Value:
1729581512
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\360\360huabao
Operation:writeName:InstallType
Value:
2
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\360\360huabao
Operation:writeName:alivetime
Value:
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\fbd30ee5-8150-549e-9aed-fd9d4443\07
Operation:writeName:inst_time
Value:
C851176700000000
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\fbd30ee5-8150-549e-9aed-fd9d4443\07
Operation:writeName:inst_times
Value:
1
(PID) Process:(6612) 360huabaosetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\360\360huabao\Update\ClientState\{aa167145-da48-4de7-bbab-fa13134c7af1}
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Roaming\360huabao\4.0.276.0\360huabaosetup.exe /uninstall:byuser
Executable files
75
Suspicious files
181
Text files
189
Unknown types
0

Dropped files

PID
Process
Filename
Type
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\360huabao.exeexecutable
MD5:FC29CAAFA88BF7A0D1081B45A7DB856D
SHA256:F9512E39717B1ACA3F701FBC66AB3B21C8599536037547ED279157F44CCF733C
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\baseutil.dllexecutable
MD5:297F8E05D26092FEB32FBE3D7CC8A0A0
SHA256:A737E962E77C3F08B25621B959E4C3AFD4E401504FDF53C17EBF6704829A69E9
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\wallpaper_video.zipcompressed
MD5:DFB429F2B1B44010C452D3923B5A453A
SHA256:A60E3FEEEDBD7C4E9353151660C6BCE24FA086496284B13A71C5E404A3742BBD
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\HuabaoUtil.dllexecutable
MD5:6047A8CA8F66EA228136213DDAB14E24
SHA256:096C3C1E3C903DB3AD57982532C8AD36933A0AE8739003BE72091150930FCB77
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\360huabao_uninstall.zipcompressed
MD5:7B646D769438C52F67508E510B4A7712
SHA256:391ABDBAA83A13B2BF7C77CEEE2FD4375EEA2C44ECDE0921FACBFA91C6F9788F
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\360Huabao_shell.zipcompressed
MD5:F398923F7C7D4C13568082224707DF8C
SHA256:BD9EC733C3371A7FCACC1E831EBF017B736E6FC5625845F611B61F77E2E353A8
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\360base.dllexecutable
MD5:A73CF0457DF35FAB74EF3393D2766667
SHA256:DF411EBC1B4A652A3822DE0CEBD5A48151ABB3DD99C8C3D15F858401B27243FD
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\360Huabao_chat.zipcompressed
MD5:E57B9B3CBAC00D1241E9AF739BAF9304
SHA256:FCD7B6EFB04A381C8C5C1A0B4CCD3E0247ACA6B118EFAAAC496A86BADEC1F175
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\360huabaosetup.exeexecutable
MD5:FD3162B9C1BD31C14851D3BAF1055A90
SHA256:7FAE64292D2C11B04A990140AB7B12F5A37EB74998C16A174EC13339783893B8
5284360hb4.0.276.0__weiruan__ (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.276.0\wallpaper_exception.zipcompressed
MD5:9FE2BC0205B508D569644C4CE51197C3
SHA256:AE551CA9105E2D78277C5CE7231435423AABAE6D3D49A2CE4B0876AFAF9C6F5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
224
DNS requests
107
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6612
360huabaosetup.exe
GET
200
171.13.14.66:80
http://s.360.cn/360huabao/inst.htm?ver=4.0.276.0&pid=weiruan&type=install&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=&ccsrc=&ss=0&os=4&w64=1&sf=0&wb=0&im=1&ach=0_0_0
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6612
360huabaosetup.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6612
360huabaosetup.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQDVbiRslO1jq7FG78GWtk%2Bw
unknown
whitelisted
4144
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1252
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6612
360huabaosetup.exe
180.163.246.72:443
dd.browser.360.cn
China Telecom Group
CN
whitelisted
4360
SearchApp.exe
2.23.209.142:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4700
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4700
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted
dd.browser.360.cn
  • 180.163.246.72
  • 101.198.2.228
whitelisted
www.bing.com
  • 2.23.209.142
  • 2.23.209.140
  • 2.23.209.131
  • 2.23.209.135
  • 2.23.209.130
  • 2.23.209.191
  • 2.23.209.141
  • 2.23.209.132
  • 2.23.209.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.71
  • 40.126.31.73
whitelisted
th.bing.com
  • 2.23.209.177
  • 2.23.209.180
  • 2.23.209.182
  • 2.23.209.175
  • 2.23.209.176
  • 2.23.209.181
  • 2.23.209.179
  • 2.23.209.178
  • 2.23.209.173
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
s.360.cn
  • 171.13.14.66
  • 180.163.251.231
  • 171.8.167.89
  • 101.198.2.147
  • 180.163.251.230
  • 171.8.167.90
whitelisted
sedl.360safe.com
  • 123.6.52.227
  • 123.53.183.217
  • 1.194.173.167
  • 36.99.118.136
  • 120.226.35.19
  • 61.168.167.221
  • 111.6.38.225
  • 113.56.145.157
  • 113.219.164.152
  • 36.158.188.228
whitelisted

Threats

No threats detected
Process
Message
360huabao.exe
C:\Windows\web\wallpaper\Windows\img0.jpg