File name:

FLiNG_Trainer_c18_b2174305.exe

Full analysis: https://app.any.run/tasks/43cb3abc-d9ec-4bbf-92d9-a26d2e5de478
Verdict: Malicious activity
Analysis date: August 20, 2024, 08:49:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
vmprotect
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

8A2DC89841D6446317ECAAB55C854BFF

SHA1:

9852E4EF42DA54EA8F399946EEFDC20DF14299D3

SHA256:

324CF60DACF248B91CDA9793B5EBA4FA3CE312FDAF99A20D721F515231B0357E

SSDEEP:

98304:wT1xqWV2JyOkr54SnQ9YpW/Dco4HIEk0c7kiYCD2lpXX/kXoZO0Trf9ulBw9ZVQx:iYE8R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs injected code in another process

      • syspin.exe (PID: 6324)
    • Application was injected by another process

      • explorer.exe (PID: 4552)
    • Registers / Runs the DLL via REGSVR32.EXE

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Drops the executable file immediately after the start

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • The process creates files with name similar to system file names

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Searches for installed software

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 2904)
    • Process drops legitimate windows executable

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Reads security settings of Internet Explorer

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Creates a software uninstall entry

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • The process drops C-runtime libraries

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Uses TASKKILL.EXE to kill process

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Reads the date of Windows installation

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Application launched itself

      • FLiNGTrainer.exe (PID: 6884)
  • INFO

    • Checks supported languages

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • syspin.exe (PID: 6324)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 2904)
      • FLiNGTrainer.exe (PID: 1372)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 5144)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4552)
    • Create files in a temporary directory

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
    • Reads the computer name

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 5144)
    • Creates files in the program directory

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
    • Process checks computer location settings

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 2904)
      • FLiNGTrainer.exe (PID: 6884)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 4552)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 2904)
      • FLiNGTrainer.exe (PID: 5144)
    • Checks proxy server information

      • FLiNGTrainer.exe (PID: 6884)
    • Reads Microsoft Office registry keys

      • explorer.exe (PID: 4552)
    • VMProtect protector has been detected

      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 5144)
      • FLiNGTrainer.exe (PID: 1372)
    • Reads the software policy settings

      • FLiNGTrainer.exe (PID: 6884)
    • Reads the machine GUID from the registry

      • FLiNGTrainer.exe (PID: 6884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:12:11 07:12:34+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 263680
UninitializedDataSize: 8192
EntryPoint: 0x30de
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.83
ProductVersionNumber: 2.0.0.83
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Latin1
CompanyName: Hefei Kunbo Information Technology Co., Ltd.
FileDescription: FLiNGTrainer
FileVersion: 2.0.0.83
LegalCopyright: Copyright 2024 Hefei Kunbo Information Technology Co., Ltd. All rights reserved.
LegalTrademarks: FLiNGTrainer
ProductName: FLiNGTrainer
ProductVersion: 2.0.0.83
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
15
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start fling_trainer_c18_b2174305.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs syspin.exe no specs conhost.exe no specs regsvr32.exe no specs THREAT flingtrainer.exe THREAT flingtrainer.exe no specs THREAT flingtrainer.exe no specs THREAT flingtrainer.exe flingtrainer.exe no specs explorer.exe fling_trainer_c18_b2174305.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1372"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --ignore-urlfetcher-cert-requests=true --no-sandbox --ignore-certificate-errors=true --ignore-certificate-errors=true --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=2260 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
2904"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --first-renderer-process --no-sandbox --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --remote-debugging-port=33229 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2600 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exeFLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
4064"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=gpu-process --no-sandbox --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=1672 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
4552C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\aepic.dll
c:\windows\system32\oleaut32.dll
5144"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --ignore-urlfetcher-cert-requests=true --no-sandbox --ignore-certificate-errors=true --ignore-certificate-errors=true --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
6304regsvr32 /s "C:\Program Files (x86)\FLiNGTrainer\ContextMenuDemo_x64.dll"C:\Windows\SysWOW64\regsvr32.exeFLiNG_Trainer_c18_b2174305.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6324"C:\Program Files (x86)\FLiNGTrainer\syspin.exe" "C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" 5386C:\Program Files (x86)\FLiNGTrainer\syspin.exeFLiNG_Trainer_c18_b2174305.exe
User:
admin
Company:
Thunder Network
Integrity Level:
HIGH
Description:
SysPin
Exit code:
0
Version:
1.0.0.2
Modules
Images
c:\program files (x86)\flingtrainer\syspin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6344\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesyspin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6564"C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe" C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exeexplorer.exe
User:
admin
Company:
Hefei Kunbo Information Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
FLiNGTrainer
Exit code:
3221226540
Version:
2.0.0.83
Modules
Images
c:\users\admin\appdata\local\temp\fling_trainer_c18_b2174305.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6612"C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe" C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe
explorer.exe
User:
admin
Company:
Hefei Kunbo Information Technology Co., Ltd.
Integrity Level:
HIGH
Description:
FLiNGTrainer
Exit code:
0
Version:
2.0.0.83
Modules
Images
c:\users\admin\appdata\local\temp\fling_trainer_c18_b2174305.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
20 024
Read events
19 906
Write events
113
Delete events
5

Modification events

(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000000000000000000
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000050388
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(6612) FLiNG_Trainer_c18_b2174305.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FLiNGTrainer
Operation:writeName:cid
Value:
18
(PID) Process:(6612) FLiNG_Trainer_c18_b2174305.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FLiNGTrainer
Operation:writeName:bid
Value:
2174305
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search
Operation:writeName:TraySearchBoxVisible
Value:
1
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010012000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C0000001500000000000000630061007400650067006F007200790061006C00620075006D002E006A00700067003E002000200000001300000000000000630075007200720065006E0074006C007900630064002E007200740066003E002000200000000F0000000000000063007500740062006C00750065002E007200740066003E00200020000000130000000000000065006900740068006500720077006F0072006C0064002E0070006E0067003E002000200000001100000000000000670072006F007700740068006E00650074002E007200740066003E0020002000000012000000000000006D006F00760069006500730077006F0072006B002E007200740066003E0020002000000013000000000000006F006600660069006300690061006C00620069006E002E007200740066003E002000200000001300000000000000730074007500660066007200610074006800650072002E0070006E0067003E002000200000001600000000000000740068006F00750067006800650063006F006E006F006D00690063002E0070006E0067003E0020002000000013000000000000007A006F006E00650070006C00610079006500720073002E007200740066003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001200000000000000000000000000000000000000803F0000004008000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A0401100000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
CF58C46600000000
(PID) Process:(4552) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(4552) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0400000000000000030000000E0000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
Executable files
73
Suspicious files
252
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
6612FLiNG_Trainer_c18_b2174305.exeC:\Program Files (x86)\FLiNGTrainer\package.7z
MD5:
SHA256:
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\icudtl.dat
MD5:
SHA256:
4552explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\nsvE9A2.tmp\nsExec.dllexecutable
MD5:2FD10D2F8AE885CC7E34FF21703AEF6C
SHA256:E0959B690F25160D590CFD7E2467BB9CE7E9D959663E7E203F502DCE5246507D
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\de.pakbinary
MD5:C7786FA864E194DE40BC157CB2F672E6
SHA256:513AB338AF45C715F08A946C3CC1A36BB9574C4C02071938192BF075AC71E8F9
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\nsvE9A2.tmp\nsInstall.dllexecutable
MD5:B0226B0A6420641A1AD20BD264EF0773
SHA256:77B9DE16E105274D91379597DDED837027A669D244138D7CA08274D89CF5FE43
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\chrome_200_percent.pakbinary
MD5:B702A944A665241D2DCDFDAB69EA32C3
SHA256:BF547EF8687B1E965D68455F8B8B1B0E6F2C2452188A3967FBC54BFBD44C8E07
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\en-GB.pakbinary
MD5:BC3D7D36026ECC916E385B293F17EB08
SHA256:F4268EDD9E2D6D4E34FCEB0D855AE9BD4DD67713760398FB6F5F771D367B55A5
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\cs.pakbinary
MD5:1913AC7ECED40BE423F1DC51E09E256A
SHA256:D905C5C03EE7C59FA0415C55E3D212E6C81EF423234F4946B104837CC027CE20
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\am.pakpgc
MD5:8415BD85D951F7F18280107B505A8B30
SHA256:FA0FD4D62876E89EC360D5FADD5C44797060C791FE791F777D1F6AFC6DC9D199
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
74
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2384
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6476
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2468
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3992
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4760
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4760
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6612
FLiNG_Trainer_c18_b2174305.exe
180.163.146.89:443
dl.fucnm.com
China Telecom Group
CN
unknown
6612
FLiNG_Trainer_c18_b2174305.exe
180.163.146.83:443
file.fucnm.com
China Telecom Group
CN
unknown
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2384
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
dl.fucnm.com
  • 180.163.146.89
unknown
file.fucnm.com
  • 180.163.146.83
unknown
login.live.com
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.73
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted

Threats

No threats detected
Process
Message
FLiNG_Trainer_c18_b2174305.exe
Õý³£´´½¨³ÌÐò×é¿ì½Ý·½Ê½
FLiNG_Trainer_c18_b2174305.exe
FLiNG_Trainer_c18_b2174305.exe
°²×°Íê³É
FLiNG_Trainer_c18_b2174305.exe
FLiNGTrainer.exe
[0820/085348.585:WARNING:account_consistency_mode_manager.cc(70)] Desktop Identity Consistency cannot be enabled as no OAuth client ID and client secret have been configured.