File name:

Todesk远程桌面_1037_425eb.exe

Full analysis: https://app.any.run/tasks/cde29169-df18-4830-9455-e4a8f7c40c4a
Verdict: Malicious activity
Threats:

First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.

Analysis date: June 13, 2025, 08:55:02
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
xor-url
generic
greyware
stealer
pecompact
emmenhtal
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

0493252310C104FBC2CE86C1854FBD4F

SHA1:

AC559AEF70D8CC5EE6606846FA176B41AB29E5CD

SHA256:

256C34DD2E94CBFCED6D841158F249E4247F3EEE23F23964CEC47649825C7ACE

SSDEEP:

24576:aIZKh8uILxXS8LksJWqp1j/uh0NKkGB+f:aIZKh8uILxXS8LksAqpluh0NKz+f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • XORed URL has been found (YARA)

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • 360Tray.exe (PID: 5124)
    • GENERIC has been found (auto)

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Changes the autorun value in the registry

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Actions looks like stealing of personal data

      • csrss.exe (PID: 608)
      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • regsvr32.exe (PID: 2276)
    • Executing a file with an untrusted certificate

      • 360SecLogonHelper.exe (PID: 1068)
      • AdvUtils.exe (PID: 6176)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SoftupNotify.exe (PID: 1164)
      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • 360Tray.exe (PID: 5124)
    • EMMENHTAL has been detected (YARA)

      • 360Tray.exe (PID: 5124)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • 360Tray.exe (PID: 5124)
    • Reads security settings of Internet Explorer

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Process requests binary or script from the Internet

      • explorer.exe (PID: 4772)
      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • 360Tray.exe (PID: 5124)
    • Potential Corporate Privacy Violation

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • explorer.exe (PID: 4772)
    • The process verifies whether the antivirus software is installed

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • csrss.exe (PID: 608)
      • explorer.exe (PID: 4772)
      • regsvr32.exe (PID: 2276)
    • Executable content was dropped or overwritten

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • EaInstHelper64.exe (PID: 1700)
      • 360Tray.exe (PID: 5124)
    • Write to the desktop.ini file (may be used to cloak folders)

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Drops a system driver (possible attempt to evade defenses)

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • EaInstHelper64.exe (PID: 1700)
      • 360Tray.exe (PID: 5124)
    • Adds/modifies Windows certificates

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Creates a software uninstall entry

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Creates files in the driver directory

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Zapya greyware has been detected

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Drops 7-zip archiver for unpacking

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Creates/Modifies COM task schedule object

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • regsvr32.exe (PID: 2276)
    • Executes as Windows Service

      • ZhuDongFangYu.exe (PID: 5368)
    • Creates or modifies Windows services

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • There is functionality for communication over UDP network (YARA)

      • 360Tray.exe (PID: 5124)
  • INFO

    • Checks supported languages

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • zoolsiVmYvKdS26.exe (PID: 6940)
    • Creates files or folders in the user directory

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • explorer.exe (PID: 4772)
    • Reads the computer name

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • zoolsiVmYvKdS26.exe (PID: 6940)
    • Checks proxy server information

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • explorer.exe (PID: 4772)
      • slui.exe (PID: 1352)
    • Create files in a temporary directory

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • explorer.exe (PID: 4772)
    • Reads the machine GUID from the registry

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4772)
    • The sample compiled with chinese language support

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
      • explorer.exe (PID: 4772)
      • EaInstHelper64.exe (PID: 1700)
      • 360Tray.exe (PID: 5124)
    • Launching a file from a Registry key

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • The sample compiled with english language support

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Creates files in the program directory

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Reads the software policy settings

      • slui.exe (PID: 1352)
    • Reads Environment values

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • Process checks computer location settings

      • Todesk远程桌面_1037_425eb.exe (PID: 6268)
    • PECompact has been detected (YARA)

      • 360Tray.exe (PID: 5124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:23 04:07:36+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 781824
InitializedDataSize: 243200
UninitializedDataSize: -
EntryPoint: 0x5e1d3
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.1091
ProductVersionNumber: 2.0.0.1091
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Unknown (0004)
CharacterSet: Unicode
CompanyName: 360.cn
FileDescription: InstallSoft.exe
FileVersion: 2, 0, 0, 1091
InternalName: InstSoft.exe
LegalCopyright: (C) 360.cn All Rights Reserved.
OriginalFileName: InstallSoft.exe
ProductVersion: 2, 0, 0, 1091
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
169
Monitored processes
26
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start #XOR-URL todesk远程桌面_1037_425eb.exe explorer.exe slui.exe zoolsivmyvkds26.exe regsvr32.exe 360seclogonhelper.exe popwndtracker.exe no specs eainsthelper.exe no specs eainsthelper64.exe zhudongfangyu.exe no specs powersaver.exe no specs 360cleanhelper.exe no specs #XOR-URL 360tray.exe softupnotify.exe no specs zhudongfangyu.exe no specs zhudongfangyu.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs advutils.exe no specs wscreg.exe no specs 360enthelper.exe no specs csrss.exe todesk远程桌面_1037_425eb.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
608%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Version:
10.0.19041.1 (WinBuild.160101.0800)
1068"C:\Program Files (x86)\360\360Safe\Utils\360seclogon\360SecLogonHelper.exe" C:\Program Files (x86)\360\360Safe\Utils\360SecLogon\360SecLogonHelper.exe
Todesk远程桌面_1037_425eb.exe
User:
admin
Integrity Level:
HIGH
Description:
360安全卫士 系统安全登录辅助模块
Exit code:
0
Version:
1, 0, 0, 1037
Modules
Images
c:\program files (x86)\360\360safe\utils\360seclogon\360seclogonhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1164"C:\Program Files (x86)\360\360Safe\SoftMgr\SoftupNotify.exe" /installC:\Program Files (x86)\360\360Safe\SoftMgr\SoftupNotify.exeTodesk远程桌面_1037_425eb.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360软件管家
Exit code:
0
Version:
16, 0, 0, 1050
Modules
Images
c:\program files (x86)\360\360safe\softmgr\softupnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1192"C:\Program Files (x86)\360\360Safe\safemon\WscReg.exe" /installC:\Program Files (x86)\360\360Safe\safemon\WscReg.exe360Tray.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360安全卫士 安全中心接口
Exit code:
0
Version:
10, 0, 0, 8120
Modules
Images
c:\program files (x86)\360\360safe\safemon\wscreg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1352C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1604"C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exe" C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exeexplorer.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
InstallSoft.exe
Exit code:
3221226540
Version:
2, 0, 0, 1091
Modules
Images
c:\users\admin\appdata\local\temp\todesk远程桌面_1037_425eb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1700"C:\Program Files (x86)\360\360Safe\softmgr\EaInstHelper64.exe" /InstallC:\Program Files (x86)\360\360Safe\SoftMgr\EaInstHelper64.exe
Todesk远程桌面_1037_425eb.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360安全卫士 安全防护模块
Exit code:
0
Version:
1, 0, 0, 1055
Modules
Images
c:\program files (x86)\360\360safe\softmgr\eainsthelper64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2276"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\360\360Safe\Utils\shell360ext64.dll"C:\Windows\System32\regsvr32.exe
Todesk远程桌面_1037_425eb.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2460"C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe" /StartC:\Program Files (x86)\360\360Safe\deepscan\ZhuDongFangYu.exeTodesk远程桌面_1037_425eb.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360主动防御服务模块
Exit code:
0
Version:
3, 2, 2, 3105
Modules
Images
c:\program files (x86)\360\360safe\deepscan\zhudongfangyu.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2952"C:\Program Files (x86)\360\360Safe\Utils\PowerSaver.exe" /flightsigning /HImmuC:\Program Files (x86)\360\360Safe\Utils\PowerSaver.exeTodesk远程桌面_1037_425eb.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360安全卫士卸载清理模块
Exit code:
0
Version:
11.0.0.1111
Modules
Images
c:\program files (x86)\360\360safe\utils\powersaver.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
46 368
Read events
36 976
Write events
3 852
Delete events
5 540

Modification events

(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
Operation:writeName:C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exe
Value:
1
(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup
Operation:writeName:mid
Value:
80342cb959da2233832ae840f019ccba8b56b331eb673be97c52113eab1cd1bc
(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup
Operation:writeName:m2
Value:
fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec
(PID) Process:(4772) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000000000000000000
(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6268) Todesk远程桌面_1037_425eb.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4772) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000080272
Operation:writeName:VirtualDesktop
Value:
10000000303044563096AFED4A643448A750FA41CFC7F708
(PID) Process:(4772) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010012000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000001200000000000000640065006200740076006900730069006F006E002E006A00700067003E002000200000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000001100000000000000610062006C00650077006F0075006C0064002E006A00700067003E00200020000000120000000000000061006E0079006F006E0065006C006100770073002E007200740066003E0020002000000014000000000000006C006F0077006500720061006900720070006F00720074002E007200740066003E0020002000000014000000000000006D0069006C00690074006100720079007400680061006E002E007200740066003E00200020000000130000000000000070006C0061006300650073006C006100620065006C002E006A00700067003E00200020000000180000000000000070006F007300740065006400660075006E006300740069006F006E0061006C002E007200740066003E0020002000000015000000000000007200650061006C006C0079006A0061006E0075006100720079002E006A00700067003E002000200000001B0000000000000073007000720069006E0067006F007200670061006E0069007A006100740069006F006E0073002E007200740066003E00200020000000120000000000000073007400610074007500730073006B0069006E002E007200740066003E002000200000001600000000000000740065007300740069006E0067006D0069007300730069006F006E002E007200740066003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001200000000000000000000000000000000000000803F0000004008000000803F000040400900000000000000404003000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A0401100000000000000803F01000000000000000040020000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700
(PID) Process:(4772) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
Executable files
949
Suspicious files
750
Text files
1 330
Unknown types
1

Dropped files

PID
Process
Filename
Type
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{76F1CE13-99F8-4bb2-9A1B-8FA0F8930334}.tmpbinary
MD5:B91AFD7111C9A4BFAA3D8EAC4C1716EF
SHA256:889CF88E593853F9C1C9B03C1A7755FE1BB23EFEC5435E46D61BABEB90A45035
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{4DA6A021-C317-434b-9E6B-459895BCD2E9}.tmpbinary
MD5:4DFF4F9A9DF081717CE8DA72D66FC8A4
SHA256:CB18D3200C00638796991B86135A58333D8C8886A4570696424993C4FB740520
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{F4D4350B-05C8-4232-A299-0BA129809A17}.tmpbinary
MD5:DE00B506A1563E0F9E033DE377E3B766
SHA256:B0178F61D4F469686C6583C4AFB2430AC9412D8D0A529FD8ED3ECC7A2B15D996
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{E914E039-09F8-4c13-BFD9-D33578A1D1E0}\jPiJtFoQrRrSiIfV.tmpbinary
MD5:A17BCBC593F10CB4161A46F99DD7040E
SHA256:41D1CE91A34763818F4CC30567A6E4428A519EC4F64907DE444165F3C6AE6D79
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{427E951F-12B7-466c-9F0E-711AFF6A1B6D}.tmpbinary
MD5:A873F14CCBE7DF387C611EBDCC568869
SHA256:366D30DA335741331A09788AAFDE8CB8A6E580C66B65BA05C2BAFA0E3ED927AA
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{F54D9B3F-3E9D-4ca7-AC7F-01BC0D65A747}.tmpbinary
MD5:A80D572499AFB75D2032DEBA88F43A5C
SHA256:AF7F759B455628C54EE142848F77D9E161AEFBA5E5E91A04245FB21A828B2C4E
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{4527C245-80F9-4702-BAD2-DA18F1D59284}.tmpbinary
MD5:2C3372C2A4112E15A994E003F891C2D3
SHA256:BA07E7E6284B9B4C60FA109DDB71AADF400F0383E3E62238F61E3AE21A6893FF
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\wXmApGnQlWlFlAmE\360ini.dllexecutable
MD5:F47309E65852FB80D3D4FF473DACC4AC
SHA256:BF185055A6C074A784FAFDD78982EAF54A4BFA807FA604F9AD096EBC5685B863
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\360ini[1].cabcompressed
MD5:4612DE1425D198498C77B958E354FC37
SHA256:D90F56FD779BE952DDFF327A0134251D5F9C0D4039D233CF82529AA0BE6BA03F
6268Todesk远程桌面_1037_425eb.exeC:\Users\admin\AppData\Local\Temp\{17ECB454-C214-4bfc-84F9-5743E0C5A60E}\xTxKnAjFaYhAzCxO.tmpbinary
MD5:746AB6BF6608096EDD52FD836968E34B
SHA256:FBE43F0C7CC3371FAC78E9F4E5DA8799C022D85D66D46C8374639AC25DA7DBF5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
164
TCP/UDP connections
198
DNS requests
50
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
138.113.20.168:80
http://sfdl.360safe.com/gf/360ini.cab
unknown
whitelisted
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
HEAD
200
138.113.20.168:80
http://sfdl.360safe.com/gf/360ini.cab
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/safe/instcomp.htm?soft=2023040419&status=1&pid=319385&mid=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=700&r=0&d=99990001
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=705&r=0&d=99990001
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=3000&r=0&d=0
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=3001&r=0&d=0
unknown
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
GET
200
101.198.2.147:80
http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=1200&r=0&d=319385
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2228
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
101.198.193.210:443
baoku.360.cn
Beijing Qihu Technology Company Limited
CN
whitelisted
4
System
192.168.100.255:138
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
101.198.2.147:80
s.360.cn
IDC, China Telecommunications Corporation
CN
whitelisted
6268
Todesk远程桌面_1037_425eb.exe
138.113.20.168:80
sfdl.360safe.com
QUANTILNETWORKS
US
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
baoku.360.cn
  • 101.198.193.210
whitelisted
s.360.cn
  • 101.198.2.147
  • 180.163.251.231
  • 180.163.251.230
  • 171.8.167.89
  • 171.8.167.90
whitelisted
sfdl.360safe.com
  • 138.113.20.168
  • 168.235.193.153
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
grow.safe.360.cn
  • 180.163.247.35
  • 101.198.3.25
whitelisted
inf.safe.360.cn
  • 180.163.237.185
whitelisted
dl.360safe.com
  • 104.192.108.20
  • 104.192.108.21
  • 104.192.108.17
whitelisted

Threats

PID
Process
Class
Message
4772
explorer.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
4772
explorer.exe
Misc activity
ET INFO Packed Executable Download
6268
Todesk远程桌面_1037_425eb.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
6268
Todesk远程桌面_1037_425eb.exe
Misc activity
ET INFO Packed Executable Download
No debug info