| URL: | www.transocks.com |
| Full analysis: | https://app.any.run/tasks/0edc556d-955d-4a5f-9cd2-5522984911bc |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | January 17, 2026, 13:32:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 8337EEB35222E0E6DB08B2A1C9DB449D |
| SHA1: | A68C54E9636EB4AB3075FFA71DB91CEEB01B7A65 |
| SHA256: | 136A8DD344AF5052B5174696B41B1FA4A4114F9BE6B61BEDF5DD6A1699E4E6E6 |
| SSDEEP: | 3:EMGLK:4LK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1420 | DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\WINDOWS\INF\oem9.inf" "oem9.inf:3beb73aff103cc24:tap0901.ndi:9.0.0.21:tap0901," "4d14a44ff" "000000000000018C" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1700 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=4484,i,17950522401960206339,18186809695375099225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3116 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 3136 | --tundev "tap0901:Ethernet:10.7.0.2:10.7.0.0:255.255.255.0" --netif-ipaddr 10.198.75.60 --netif-netmask 255.255.255.0 --socks-server-addr 127.0.0.1:51089 --getway 192.168.100.2 --ip 192.168.100.6 --index 4 --metric 26 --process "|115CHROME.EXE|53KF.EXE|53KF_V6.1.0.9_SETUP.EXE|91D2.EXE|91D2LOADER.EXE|92NO1.EXE|ABOBOO.EXE|ALIWORKBENCH.EXE|ALIWORKBENCHTASK.EXE|AUTOPOWEROFF.EXE|AVP.EXE|AVPUI.EXE|BAIDU-SI-ASSISTANT.EXE|BAIDUBRIDGE.EXE|BAIDUMUSIC.EXE|BAIDUMUSICSERVICE.EXE|BAIDUNETDISK.EXE|BAIWENIM.EXE|BATTLE.NET.EXE|BILILIVE.EXE|BILILIVE_BROWER.EXE|BUGREPORT.EXE|CBOX.EXE|CBOXSERVICE.EXE|CC.EXE|CCTALK.EXE|CEFRENDER.EXE|CHOICEHELPER.EXE|CHOICELOADER.EXE|CLEAN-CACHE.EXE|CLIENT2.EXE|CLOUDMUSIC.EXE|CLOUDMUSIC_REPORTER.EXE|CRASHREPORT.EXE|CTUPDATE.EXE|D5_VIEW.EXE|DATATRANSFORMEX.EXE|DINGTALK.EXE|DNCONSOLE.EXE|DNMULTIPLAYER.EXE|DNPLAYER.EXE|DOUYULIVE.EXE|DUOMI.EXE|DWIPCPROC.EXE|DWIPCPROC_X64.EXE|DYMIRACASTRPCCLIENT.EXE|DYTOOL.EXE|DZH.EXE|DZH2.EXE|DZH2SJ.EXE|DZHTOOL.EXE|ELSWORD.EXE|EVERNOTE.EXE|EVE_DEALER.EXE|EVE_DEALER_EXECUTOR.EXE|EXTRACTSKIN.EXE|FASTMEETING.EXE|FFMPEG.EXE|FIEWORKS.EXE|FIREWORKS.EXE|FISHINGPLANET.EXE|FLASHPLAYER.EXE|FTNN.EXE|FUTUOPEND.EXE|GACRUNNER.EXE|GAMECL.EXE|GAMECLIENT.EXE|GAMEMON.DES|GDZQ.EXE|HAPP.EXE|HEARTHSTONE.EXE|HEXIN.EXE|HFWEBSVC.EXE|HTTPDOWNEX.EXE|HUYA.EXE|HUYACLIENT.EXE|HWCODECTEST.EXE|IEXPLORER.EXE|IKUACC.EXE|INITWAPI.EXE|INSTALLONLINE_INSIDE.EXE|INSTALLSTAT.EXE|JAVA.EXE|JAVACPL.EXE|JAVAW.EXE|JAVAWS.EXE|JIXIAN.EXE|JX3CLIENT.EXE|JX3CLIENT64.EXE|JZSC.EXE|KADB.EXE|KGDAEMON.EXE|KGSCRSAVER.EXE|KGSERVICE.EXE|KOOK.EXE|KPM_SERVICE.EXE|KSOLAUNCH.EXE|KUAIWAN.EXE|KUGOU.EXE|KUGOU_1.EXE|KWMINISITE.EXE|KWMUSIC.EXE|KWSERVICE.EXE|KWUPDATE.EXE|KWUPDATER.EXE|KWWEBKIT.EXE|L193.EXE|LAUNCH.EXE|LAUNCHER.EXE|LD.EXE|LDCAM.EXE|LDINST.EXE|LDNEWS.EXE|LETVLOADER.EXE|LIVEHIME.EXE|LIVESTART.EXE|MANGOCEF.EXE|MAPLESTORY.EXE|METIN.EXE|MGTV.CLIENT.EXE|MGTV.EXE|MGTVWEBINS.EXE|MIGUAPP.EXE|MIGUVIDEO.EXE|MINIDUMP_STACKWALK.EXE|MSTSC.EXE|MTS.EXE|MY.EXE|MYTRADER_SPQH.EXE|MYTRADER_WH.EXE|MYTRADER_WHSP.EXE|NEMUBOOTER.EXE|NEMUPLAYER.EXE|NETEASEMUSIC.EXE|NEWYOUKU.EXE|NODETOOL.EXE|NOX.EXE|OBS32.EXE|OBS64.EXE|OFDBATCHMAKER.EXE|OUTSIDE.EXE|PATCH.BIN|POTPLAYERMINI.EXE|POTPLAYERMINI64.EXE|PPAP.EXE|PPLIVE.EXE|PPLIVEU.EXE|PRIVACYPROTECTOR.EXE|PUSH-MESSAGE.EXE|QBCLIENT.EXE|QIDIAN.EXE|QIYIDACL.EXE|QIYISERVICE.EXE|QMBROWSER.EXE|QMWEIYUN.EXE|QOWJFXFGVGEGTHFTIIUM.EXE|QQGAME.EXE|QQLIVE.EXE|QQLIVEBROWSER.EXE|QQMUSIC.EXE|QQMUSICAGENT.EXE|QQMUSICDOWNLOADER.EXE|QQMUSICEXTERNAL.EXE|QQMUSICIE.EXE|QQMUSICSERVICE.EXE|QQMUSICSVR.EXE|QYCLIENT.EXE|QYFRAGMENT.EXE|QYKERNEL.EXE|QYPLAYER.EXE|SDOLOGIN.EXE|SDOLPLUGIN.EXE|SHPLAYER.EXE|SHRES.EXE|SNAKELOADER.EXE|SNAKE_PC_WEBVIEW.EXE|SNIPERELITE4_DX12.EXE|SODAMUSIC.EXE|SOHUVA.EXE|START.EXE|STARTDESKTOPPROJECTION32.EXE|STARTDESKTOPPROJECTION64.EXE|STARTDESKTOPPROJECTIONFORXP.EXE|STOCKWAY.EXE|SUWELLREADER.EXE|TDXW.EXE|TDXW7603+.EXE|TESTNAME.EXE|TIANTIAN.EXE|TING_EN.EXE|TTPLAYER.EXE|UPC.EXE|UPDATE.EXE|UPDATER.EXE|UPLAYWEBCORE.EXE|VLC.EXE|VMWARE-VDISKMANAGER.EXE|WBOX.EXE|WBROWSER.EXE|WEBSERVE.EXE|WEGAME.EXE|WELINK.EXE|WESING.EXE|WESINGBSV1.EXE|WESINGUP.EXE|WESINGWEBKIT.EXE|WIM.EXE|WIMBROSWER.EXE|WINDCRASHREPORT.EXE|WINDECIS.EXE|WINDNAVIGATOR.EXE|WINDNET.EXE|WINDRS.EXE|WMAIN.EXE|WPFLAUNCHER.EXE|WPSUPDATE.EXE|WRITEMBOX.EXE|WXWORKLOCAL.EXE|XIAMI.EXE|XIAMIPC.EXE|XIAMIWEB.EXE|XKLIVE.EXE|XLAUNCHERKERNEL.EXE|YODAODICT.EXE|YOUKUCLIENT|YOUKUDESKTOP.EXE|YOUKUMEDIACENTER.EXE|YOUKUNPLAYER.EXE|YTBROWSER.EXE|YY.EXE|YYBROWSER.EXE|YYEXTERNAL.EXE|YYHOST.EXE|YYLAUNCHER.EXE|YYPLATFORM.EXE|YYQLOGIN.EXE|YYRUN.EXE|ZHUAFANLIVE.EXE|" --domain "110zhuangbei.com|116.211.199.18|122.gov.cn|123yun.net|126.net|127.net|135editor.com|163.xdwscache.ourglb0.com|1688.com|23yun.net|3gimg.qq.com|45.32.164.128|5eplay.com|653228.com|71.am|71.cm|71edge.com|7881.com|86faka.cccpan.com|900126.private.mabangerp.com|acfun.cn|acgvideo.com|act.vip.iqiyi.com|adsmind.gdtimg.com|aiplus.cnki.net|alicdn.com|amemv.com|android.bugly.qq.com|android.rqd.qq.com|anime.bilibili.com|api-t.iqiyi.com|api.bilibili.com|api.im.qcloud.com|api.iplay.163.com|api.live.bilibili.com|api.music.163.com|api.ptqy.gqiyu.com|api.sports.qq.com|api.t.iqiyi.com|api.tencentmusic.com|api.vip.iqiyi.com|api.xiaohongshu.com|api.ximalaya.com|apm-misaka.biliaoi.net|apm.music.163.com|apm3.music.163.com|app-measurement.com|app.bilibili.com|app.cctv.com|app.maiduidui.com|app.xiaohongshu.com|apple.com|appsflyer.com|aqqmusic.tc.qq.com|ar.xmcdn.com|asimgs.pplive.cn|auth.iqiyi.com|authserver.ougd.cn|b23.tv|baidu.com|baiducdnct.inter.iqiyi.com|baishixi.com|banana.eotones.net|bangumi.bilibili.com|beacon.qq.com|biliapi.net|bilibili.cn|bilibili.com|biligame.com|bilivideo.com|bimibimi.tv|bjelcme.com|blog.csdn.net|brand.xiaohongshu.com|bsy.tsmusic.kg.qq.com|btrace.play.aiseet.atianqi.com|buka.cn|byted-static.com|bytedance.com|bytedns1.com|bytegecko.com|bytegoofy.com|byteimg.com|byteoversea.com|c-uaa.if.iqiyi.com|c.kdocs.cn|cache.video.iqiyi.com|cache.video.ptqy.gitv.tv|cache.video.qiyi.com|cards.iqiyi.com|careers.pinduoduo.com|ccccltd.cn|ccccnfc.ccccltd.cn|cccpan.com|cctv.com|cdn20.com|cdndata.video.iqiyi.com|cdndm5.com|cffex.com.cn|cgi.kg.qq.com|changdunovel.com|chec.ccccltd.cn|chinanetcenter.com|cht-2-web.lv-show.com|cibntv.net|ckm.iqiyi.com|client.kugou.com|clientlog.music.163.com|cloudplay.iqiyi.com|cm.ipinyou.com|cmts.iqiyi.com|cmvideo.cn|cn.bing.com|cn.manbet165.com|cnc.dm5.com|cnki.net|cntv.cn|codefather.cn|com.wondertek.miguaikan|community.iqiyi.com|conf.voice.qcloud.com|configsvr.msf.3g.qq.com|control-i.iqiyi.com|conviva.com|cooperation.ssports.com|course.ougd.cn|coze.cn|cpta.com.cn|cs-feige.iqiyi.com|csdn.net|da.mgtv.com|data.bilibili.com|data.music.163.com|data.video.iqiyi.com|data.video.ptqy.gitv.tv|data.video.qiyi.com|dataflow.biliapi.com|ddt.wan.com|display.bz.miguvideo.com|dm5.com|dmzj.com|docs.wps.cn|douban.com|douyin.com|douyincdn.com|douyinpic.com|douyinvod.com|dp3.qq.com|dtlive-push.alicdn.com|dtlive.alicdn.com|dtliving.alicdn.com|duokanbox.com|duowan.com|eastmoney.com|edu.wencaischool.net|emoticon-sns.iqiyi.com|epicgames.com|erp321.com|fanqienovel.com|film.qq.com|fotor.com.cn|fqnovelstatic.com|fs.web.kugou.com|futunn.com|g.cdn.163.com|gaoding.com|gateway.kugou.com|gcaptcha4.geetest.com|gcp.gvt2.com|gdrtvu.edu.cn|geetest.com|gitv.tv|globalsign.com|globalsign.net|grpc.biliapi.net|guanyierp.com|h5.kg.qq.com|h5.vod.cmvideo.cn|hanju.com|hbisscm.com|hdlsb.com|hdslb.com|higher.sc.smartedu.m|hiido.com|huya.com|i.vip.iqiyi.com|i0.hdlsb.com|i0.hdslb.com|i2.hdslb.com|iam.pt.ouchn.cn|iamxk.com|id.163.com|iface.iqiyi.com|iface2.iqiyi.com|ifacelog.iqiyi.com|ilive.qq.com|image2.xmcdn.com|img.cmvideo.cn|img1.126.net|img2.126.net|img3.126.net|img4.126.net|imgcache.qq.com|interface.music.163.com|interface3.music.163.com|ios.rqd.qq.com|ip.sb|ip.taobao.com|ip.ws.126.net|ip111.cn|ip111cn.appspot.com|ip138.com|ipapi.co|iqid.iqiyi.com|iqiyi.com|iqiyiedge.net|iqiyipic.com|iqiyizy.com|irobot.qq.com|irs01.com|isure.stream.qqmusic.qq.com|ixigua.com|jiandaoyun.com|jtmu.net|juc.suyoda.cn|junyuxuan.com|k.cnki.net|kaiheila.cn|kaplancitic.com.cn|kbs.sports.qq.com|kcdnvip.com|kdocs.cn|keke1.app|keke11.com|kg.cdn.com|kg.qq.com|kg2.qq.com|kmf.com|kmxibanyayu.com|kns.cnki.net|kuaishou.com|kugou.com|kuwo.cn|kworks.cn|l.qq.com|lbs.map.qq.com|lebo.cn|leetcode.cn|letv.com|license.vod2.myqcloud.com|liho.club|link.bilibili.com|live.bilibili.com|live.cmvideo.cn|live.douyin.com|live.kuaishou.com|live.miguvideo.com|live.qq.com|live.video.iqiyi.com|live.video.sina.com.cn|lives.cmvideo.cn|lkong.net|log.miguvideo.com|log.stat.kugou.com|log.tbs.qq.com|login.cnki.net|login.guanyierp.com|longzhu.cn|longzhu.com|longzhu.tv|lrts.me|m.bilibili.com|m.iqiyi.com|m.iqiyipic.com|m.irs01.com|m.kugou.com|m.miguvideo.com|m.onehome.me|m.v.qq.com|m.ximalaya.com|m10.music.126.net|m7cy.music.126.net|ma.ximalaya.com|mangabz.com|manhua.dmzj.com|matchweb.sports.qq.com|mazu.3g.qq.com|mbdlog.iqiyi.com|mcbbs.net|menhu.pt.ouchn.cn|message.bilibili.com|mgtv.bz.miguvideo.com|miaozhen.com|migu.cn|migucloud.com|miguvideo.com|misfeng.com|mobile.ximalaya.com|mobilecdn.kugou.com|monitor.music.qq.com|monitor.uu.qq.com|moomoo.com|moviebook.com.cn|mp.iqiyi.com|msg.71.am|msg.iqiyi.com|msg.qy.net|msga.cupid.iqiyi.com|msgv6.qy.net|mting.info|music.126.net|music.126.net.wscdns.com|music.163.com|music.douyin.com|music.httpdns.c.163.com|music.migu.cn|nba.qq.com|netease.com|news.l.qq.com|nga.178.com|nl-rcd.iqiyi.com|node.kg.qq.com|obsproject.com|ok.you-dy.com|one.ouchn.cn|onehome.me|ooklaserver.net|open.ximalaya.com|openapi.kugou.com|opportunarch.iqiyi.com|otheve.beacon.qq.com|p-l.play.aiseet.atianqi.com|p.l.qq.com|p1.music.126.net|p2.music.126.net|p3.music.126.net|p4.music.126.net|pact.powerchina.cn|pan.baidu.com|paopao-monitor.iqiyi.com|paopao.iqiyi.com|passport.163.com|passport.bilibili.com|passport.iqiyi.com|pc.ximalaya.com|pcaapi.iqiyi.com|pcs-sdk-server.alibaba.com|pcw-api.iqiyi.com|pdata.video.qiyi.com|pic0.iqiyipic.com|pic2.iqiyipic.com|pinduoduo.com|ping.huatuo.qq.com|pingfore.qq.com|play.lang.live|plu.cn|plures.cn|plures.net|portal.ccccltd.cn|pp.tv|pplive.cn|pplive.com|pplive.com.cn|pplive.net|pplive.net.cn|pps.tv|ppsimg.com|ppsport.com|pptv.com|pptvyun.com|preimage0.iqiyipic.com|puma-api.iqiyi.com|puma-api.ptqy.gitv.tv|qcc.com|qie.tv|qishui.com|qiyi.com|qiyu.iqiyi.com|qlwjedu.com|qqgame.qq.com|qy.net|qy.wangdian.cn|qzs.qq.com|r.qq.com|reading-lq.snssdk.com|reading.snssdk.com|report.tencentmusic.com|roborock.com|s.video.qq.com|s1.hdslb.com|s1.music.126.net|s2.music.126.net|s3.music.126.net|s4.music.126.net|scholar.cnki.net|sci-hub.ren|search.bilibili.com|search.video.iqiyi.com|secure.wostatic.cn|sgmyip.yongtongcentury.com|sina.cn|sina.com.cn|sns-comment.iqiyi.com|sns-paopao.iqiyi.com|sohu.com|sohu.com.cn|speedtest.cn|sports.cctv.com|sports.miguvideo.com|sports.qq.com|sports.sina.com.cn|sports.video.sina.com.cn|sportsts.tc.qq.com|sse.com.cn|ssports.com|st.ougd.cn|static-s.iqiyi.com|static.geetest.com|static.hdslb.com|static.iqiyi.com|steampowered.com|stock.cheesefortune.com|subscription.iqiyi.com|subtitle.iqiyi.com|suning.cn|suning.com|sv-video.play.aiseet.atianqi.com|synacast.com|szmg.qq.com|t7z.cupid.iqiyi.com|tangram.e.qq.com|taobao.com|tbcache.com|ten.sngapm.qq.com|thmyip.yongtongcentury.com|tianpuyue.cn|tianyancha.com|tongxinda.com|trackercdn.kugou.com|tudou.com|tv.cctv.com|tv.iqiyi.com|tv.miguvideo.com|tvguide-pc-client.iqiyi.com|tvguide.if.iqiyi.com|tvibe.cn|tvp.v.qq.com|tx.xmcdn.com|txd.cn|txd.com.cn|tyaqy.m.cn.miaozhen.com|uaa.iqiyi.com|ubi.com|ugcws.video.qq.com|union-game.com|unipay.qq.com|upgrade.miguvideo.com|uxms.gaoding.com|v-3b341007.71edge.com|v-b786400c.71edge.com|v.qq.com|v6z.cupid.iqiyi.com|video.ptqy.gitv.tv|video.qq.com|video.sina.com.cn|videosource.iqiyi.com|videoyi.com|vip.iqiyi.com|vmobile.sports.qq.com|vod.126.net|vod.cmvideo.cn|vod.sports.qq.com|vt.ipinyou.com|wa.qq.com|wangdian.cn|wangzhe88.live|web.push.126.net|webfs.tx.kugou.com|wenku8.com|wenku8.net|wenku8.net/index.php|weread.qq.com|wns.qq.com|wnskg.qq.com|wolai.com|wps.cn|ws.stream.qqmusic.qq.com|wspeed.qq.com|wting.info|wup.browser.qq.com|www.115.com|www.aigei.com|www.bilibili.com|www.futunn.com|www.guanyierp.com|www.iqiyi.com|www.junyuxuan.com|www.le.com|www.tosound.com|www.wenku8.net|wxsnsencsvp.wxs.qq.com|wzapp66.live|wzapp88.com|xhs.cn|xhscdn.com|xhslink.com|xhzhicaoge.com|xiami.com|xiami.net|xiaohongshu.com|xiaohongshu.net|xiazai.ma|ximalaya.com|xinqi.if.iqiyi.com|xmcdn.com|y.qq.com|yangshipin.cn|yaoguo.com|yizhiknow.com|ykimg.com|you-dy.com|youzan.com|yrucd.com|ysp.cctv.cn|yy.com|zhangyu.tv|zhibo.tv|zhibo23.com|zhidao.baidu.com|zhihu.com|zhipin.com|zijieapi.com|" --rejectList "088458.com|0887027.com|090903.com|168cp.app|365-288.com|464kok.com|7308bob.com|7654.cc|783238.com|bet010.com|bt30888.com|cn.167manx.com|epochtimes.com|haoyoutw.com|hga026.com|hga030.com|hga035.com|hga037.com|hga038.com|hga039.com|hga050.com|hscp09.com|kaiyunhk.com|kaiyunsports.net|ky-sport.com|kysports.cc|mos011.com|mos022.com|mos033.com|mos044.com|mos055.com|mos066.com|mos077.com|mos088.com|mos099.com|mos100.com|n0808.com|sandai.net|soundofhope.org|tdrtx.com|tvt386.com|udn.com|vattibj.com|vipky.com|vua9sq.vip|zoty88.com|" --directList "189.cn|9598.net|a-download.youku.com|a.bdydns.com|a.etoote.com|a.ykimg.com|aaid.uyunad.com|aaplimg.com|acs.youku.com|adkwai.com|akadns.net|akamaiedge.com|akamaiedge.net|akamaized.net|aliapp.org|alikunlun.com|aliyuncs.com|amghibt.cn|api.gxyzcwlapp.com|api.kwatzt.com|api.weibo.cn|api.weibo.com|api.youku.com|api.zhihu.com|appcloud.zhihu.com|apple-dns.net|aswxzj.cn|b-api.youku.com|b.bdstatic.com|b.ykimg.com|bb926835.com|bdydns.com|binance.com|bintray.com|blz-contentstack-assets.akamaized.net|blzprofile.akamaized.net|browserkernel.baidu.com|cdn-apple.com|chatnow.mstatik.com|cmbc.com|cmbc.com.cn|cmpassport.com|cnswhr.com|coupang.com|cygames.jp|dp.im.weibo.cn|ecswai.com|f.gm.mob.com|fb.com|feed-image.baidu.com|fengkongcloud.com|fobwifi.com|gifshow.com|graph.facebook.com|gstatic.com|gtimg.cn|gtimg.com|h5.sinaimg.cn|hdns.ksyun.com|hitv.com|hpplay.cn|httpdns.bcelive.com|i.youku.com|id6.me|inkuai.com|instagram.com|ioshost.qtlcdn.com|ip-api.com|ipchaxun.com|ipi.shuzilm.cn|ipip.net|jucaizhan.com|kai621.cc|kolacdn.xyz|kolavpn.win|kolavpn.xyz|ksapisrv.com|ksyuncdn.com|kwaicdn.com|kwaixiaodian.com|kwimgs.com|lespark|login.wechat.com|login.wx.qq.com|m-cloud.zhihu.com|m.weibo.cn|m.youku.com|meta.com|mgtv.com|mmbiz.qpic.cn|mobilecdn.youku.com|mostonegame.com|mp.weixin.qq.com|myqcloud.com|myzhiniu.com|naver.com|od0r3fjlu.bkt.clouddn.com|okex.com|open.weixin.qq.com|openapi.youku.com|opencdntbvideo.jomodns.com|opencdnzhihustatic.jomodns.com|passport.baidu.com|paypay.ne.jp|pbqly.cn|play.youku.com|pstatp.com|pv.sohu.com|qpic.cn|qyh699.cc|qzone.qq.com|res.servicewechat.com|sdkapp.uve.weibo.com|sdkoptedge.chinanetcenter.com|security.wechat.com|servicewechat.com|sfp.safe.baidu.com|short.weixin.qq.com|sinaedge.com|sinaimg.cn|sinajs.cn|smart.lenovo.com.cn|snssdk.com|soulapp.cn|soulchat.cn|ssltieba.jomodns.com|starbucks.co.kr|static.n.shifen.com|static.zhihu.com|steamcommunity.com|support.weixin.qq.com|t13.baidu.com|t14.baidu.com|tb.himg.baidu.com|tenpay.com|tieba-ares.cdn.bcebos.com|tieba.baidu.com|tiebacchunwan.n.shifen.com|torrentsnows.com|toutiao.com|toutiaoimg.com|toutiaostatic.com|toutiaovod.com|tradingview.com|transmoon.xyz|transocks.com.cn|twitch.com|ulogs.umeng.com|umeng.com|ups.youku.com|v.youku.com|v6r.ipip.net|vali-dns.cp31.ott.cibntv.net|vali.cp31.ott.cibntv.net|vzuu.com|wa.me|wappass.baidu.com|waze.com|web.wechatapp.com|web.whatsapp.com|wechat.com|wechat.org|wechatapp.com|weibo.cn|weibo.com|weibocdn.com|weixin.qq.com|weixin.qq.com.cn|weixinconf.qq.com|whatsapp.biz|whatsapp.cc|whatsapp.com|whatsapp.net|whatsappbrand.com|wosms.cn|wostore.cn|ws.acs.youku.com|www.amctheatres.com|wx.qlogo.cn|wx.qq.com|wxs.qq.com|xlznjr.com|xtrader.cm.admaster.com.cn|xunlei.com|ykv-web.youku.com|youku.com|yximgs.com|zcxjf.com|zhimg.com|zhuanlan.zhihu.com|zsinaimg.v.bsgslb.cn|" --smart 0 --udpgw-remote-server-addr 127.0.0.1:51090 --dns 192.168.100.2 --proxydns 119.29.29.29 | C:\Program Files\transocks\tun2socks.exe | transocks.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 3152 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=10 --field-trial-handle=4660,i,17950522401960206339,18186809695375099225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4676 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 3152 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4552 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoABAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=3556,i,17950522401960206339,18186809695375099225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=5788 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 5304 | "C:\Program Files\transocks\transocks-worker.exe" | C:\Program Files\transocks\transocks-worker.exe | — | transocks.exe | |||||||||||
User: admin Company: 成都飞欧比网络科技有限公司 Integrity Level: HIGH Description: 穿梭电脑客户端 Version: 1.0.0.1 Modules
| |||||||||||||||
| 7420 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=3600,i,17950522401960206339,18186809695375099225,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4344 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 7520 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints "www.transocks.com" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 7624 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7ffd6f7dfff8,0x7ffd6f7e0004,0x7ffd6f7e0010 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| (PID) Process: | (9016) tapinstall.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus |
| Operation: | write | Name: | setupapi.dev.log |
Value: 4096 | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tap0901 |
| Operation: | write | Name: | Owners |
Value: oem9.inf | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemRoot%/System32/drivers/tap0901.sys |
| Operation: | write | Name: | Owners |
Value: oem9.inf | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Descriptors\tap0901 |
| Operation: | write | Name: | Configuration |
Value: tap0901.ndi | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Descriptors\tap0901 |
| Operation: | write | Name: | Manufacturer |
Value: %provider% | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Descriptors\tap0901 |
| Operation: | write | Name: | Description |
Value: %devicedescription% | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Configurations\tap0901.ndi |
| Operation: | write | Name: | Service |
Value: tap0901 | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Configurations\tap0901.ndi |
| Operation: | write | Name: | ConfigScope |
Value: 5 | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Configurations\tap0901.ndi\Driver\Ndi |
| Operation: | write | Name: | Service |
Value: tap0901 | |||
| (PID) Process: | (1420) drvinst.exe | Key: | HKEY_LOCAL_MACHINE\DRIVERS\DriverDatabase\DriverPackages\oemvista.inf_amd64_a572b7f20c402d28\Configurations\tap0901.ndi\Driver\Ndi\Interfaces |
| Operation: | write | Name: | UpperRange |
Value: ndis5 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RFfdfd7.TMP | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RFfdfd7.TMP | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RFfdfe7.TMP | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RFfdfd7.TMP | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\LOG.old~RFfdfe7.TMP | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7520 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7772 | chrome.exe | GET | 200 | 142.250.186.174:80 | http://clients2.google.com/time/1/current?cup2key=8:R8axL8xBHdlZmtHjBDhC5fPYtwe_2aQgXzg2QfI0t4c&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 106 b | whitelisted |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/css/common.css?t=20251105 | US | text | 19.3 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/wx2x.png | US | image | 116 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/btn_icon_promote@2x.png | US | image | 2.49 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/css/lib/iconfont.css?t=20250717 | US | text | 4.28 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js | US | text | 1.21 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/pic_logo_transocks@2x.png | US | image | 10.3 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/bg.jpg | US | image | 128 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/icon_study.png | US | image | 3.35 Kb | unknown |
7772 | chrome.exe | GET | 200 | 104.21.28.97:443 | https://www.transocks.com/img/btn_icon_recharge@2x.png | US | image | 4.07 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
6300 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3192 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7772 | chrome.exe | 216.58.212.138:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | whitelisted |
7772 | chrome.exe | 142.250.186.174:80 | clients2.google.com | GOOGLE | US | whitelisted |
7772 | chrome.exe | 64.233.184.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
7772 | chrome.exe | 104.21.28.97:443 | www.transocks.com | CLOUDFLARENET | US | whitelisted |
3412 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
clients2.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
www.transocks.com |
| unknown |
accounts.google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
s95.cnzz.com |
| whitelisted |
www.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7772 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
7772 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
7772 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2292 | svchost.exe | Misc activity | INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com) |
8756 | transocks.exe | Misc activity | ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI) |
2292 | svchost.exe | Misc activity | ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com) |
8756 | transocks.exe | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |
8756 | transocks.exe | Misc activity | SUSPICIOUS [ANY.RUN] Sent Host Name in HTTP POST Body |
8756 | transocks.exe | Attempted Information Leak | HUNTING [ANY.RUN] Windows PC hostname observed in outbound connection |
8756 | transocks.exe | Generic Protocol Command Decode | SURICATA HTTP Request unrecognized authorization method |