| URL: | http://download.huawei.com/edownload/enterprise/download!download.action?contentType=NEWS&contentId=NEWS1000000152&partNo=2001&idPath= |
| Full analysis: | https://app.any.run/tasks/cf724a64-420e-4e90-ba55-30bd49fecc8a |
| Verdict: | Malicious activity |
| Analysis date: | December 05, 2018, 19:14:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 7CA8A81BACDCEB8023432F2FFF5B4C12 |
| SHA1: | D9731EAE8690D23B843C92DF1748EC324A1E6A97 |
| SHA256: | 0A39549A65E5969194327FDA0D9F2A10BE2CDA5B284C43872E2DC1235EB01479 |
| SSDEEP: | 3:N1KaKElcD4EXuPWAaKFBK4nWlukAG3kda2uHh8ReYFVUDMp:Ca5q6W0pnWluJG3kYLYFVHp |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 408 | "C:\Users\admin\Desktop\HedEx Lite\BIN\HedExExtractText.exe" "C:\Users\admin\Desktop\HedEx Lite\bin\hedexbeeskin\finished_menu.html" "C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index/ETText.txt" "C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index/ETAttri.txt" "C:/Users/admin/Desktop/HedEx Lite/BIN/log/system.log" BCC9CCA4-AA6B-4EA7-8AAC-4933BB98046A | C:\Users\admin\Desktop\HedEx Lite\BIN\HedExExtractText.exe | — | VfExtractText.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 456 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "false;false;0fda45dc3f4dfbf1d5c1217f47f22cd0.txt;false;C:\Users\admin\Desktop\HedEx Lite\;1544037413;C:/Users/admin/Desktop/HedEx Lite/BIN/;C:/Users/admin/Desktop/HedEx Lite/bin/appearance/kse.txt;C:/Users/admin/Desktop/HedEx Lite/;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;null" "AddIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 456 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "false;false;2df8ece2b1f29fafaa1fafeb2141d05a.html;false;C:\Users\admin\Desktop\HedEx Lite\;1544037413;C:/Users/admin/Desktop/HedEx Lite/BIN/;C:/Users/admin/Desktop/HedEx Lite/bin/hedexbeeskin/delhdxtasktip.html;C:/Users/admin/Desktop/HedEx Lite/;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;null" "AddIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 612 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 772 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\HedEx_Lite_V200R006C00SPC007_English_forEnterprise.zip" | C:\Program Files\WinRAR\WinRAR.exe | chrome.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 792 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "C:/Users/admin/Desktop/HedEx Lite/bin/hedexbeeskin/commonctrl.html;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;C:/Users/admin/Desktop/HedEx Lite/BIN/" "QueryIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 920 | "C:\Users\admin\Desktop\HedEx Lite\BIN\HedExIndexProcessor.exe" "createnewnavi" "C:\Users\admin\Desktop\HedEx Lite\BIN\resources\1000002\01\index_temp" "C:\Users\admin\Desktop\HedEx Lite\BIN\resources\1000002\01\navi.xml" | C:\Users\admin\Desktop\HedEx Lite\BIN\HedExIndexProcessor.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2005 Modules
| |||||||||||||||
| 956 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "C:/Users/admin/Desktop/HedEx Lite/bin/appearance/SpellCheckIndex.zip;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;C:/Users/admin/Desktop/HedEx Lite/BIN/" "QueryIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 992 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "false;false;925feff05ae1b2bef3e6ae53fc8b75f6.html;false;C:\Users\admin\Desktop\HedEx Lite\;1544037413;C:/Users/admin/Desktop/HedEx Lite/BIN/;C:/Users/admin/Desktop/HedEx Lite/bin/hedexbeeskin/AddTask.html;C:/Users/admin/Desktop/HedEx Lite/;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;null" "AddIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 1004 | "C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe" "C:/Users/admin/Desktop/HedEx Lite/bin/hedexbeeskin/main.html;C:/Users/admin/Desktop/HedEx Lite/BIN/vfresource/1544037413/index;C:/Users/admin/Desktop/HedEx Lite/BIN/" "QueryIndex" | C:\Users\admin\Desktop\HedEx Lite\BIN\VfExtractText.exe | — | HedExHS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2924) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2976-13188510891354875 |
Value: 259 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3516-13180984670829101 |
Value: 0 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 2976-13188510891354875 |
Value: 259 | |||
| (PID) Process: | (2976) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\83f5afba-a556-4815-9882-34b2f247f92e.tmp | — | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\2d4a9104-d308-4750-9be7-666d59d3b0dc.tmp | — | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old~RF246d03.TMP | text | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model | binary | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model~RF246f06.TMP | binary | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
| 2976 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3192 | HedExLite.exe | GET | 200 | 23.0.40.144:80 | http://support.huawei.com/da/da/hedex/online?at=1 | NL | — | — | malicious |
2976 | chrome.exe | GET | 200 | 23.37.61.100:80 | http://download.huawei.com/edownload/enterprise/download!download.action?contentType=NEWS&contentId=NEWS1000000152&partNo=2001&idPath= | NL | compressed | 15.0 Mb | whitelisted |
3192 | HedExLite.exe | GET | 200 | 23.37.61.100:80 | http://download.huawei.com/dl/download.do?actionFlag=download&nid=HDX1000000052&partNo=3001&mid=SUP_HDXLITE | NL | xml | 231 b | whitelisted |
3848 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
3848 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3848 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2976 | chrome.exe | 172.217.21.227:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
2976 | chrome.exe | 23.37.61.100:80 | download.huawei.com | Akamai Technologies, Inc. | NL | whitelisted |
2976 | chrome.exe | 172.217.21.237:443 | accounts.google.com | Google Inc. | US | whitelisted |
2976 | chrome.exe | 172.217.21.238:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
3192 | HedExLite.exe | 23.0.40.144:80 | support.huawei.com | Akamai Technologies, Inc. | NL | whitelisted |
3192 | HedExLite.exe | 23.37.61.100:80 | download.huawei.com | Akamai Technologies, Inc. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
download.huawei.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
accounts.google.com |
| shared |
sb-ssl.google.com |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
support.huawei.com |
| malicious |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2976 | chrome.exe | Web Application Attack | SC WEB_APPLICATION_ATTACK Suspicious Generic - Path Traversal for Windows in Zip archive |
2976 | chrome.exe | Web Application Attack | SC WEB_APPLICATION_ATTACK Suspicious Generic - Path Traversal for Unix in Zip archive |
2976 | chrome.exe | Generic Protocol Command Decode | SURICATA Applayer Wrong direction first Data |