File name:

FLiNG_Trainer_c18_b2174305.exe

Full analysis: https://app.any.run/tasks/43cb3abc-d9ec-4bbf-92d9-a26d2e5de478
Verdict: Malicious activity
Analysis date: August 20, 2024, 08:49:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
vmprotect
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

8A2DC89841D6446317ECAAB55C854BFF

SHA1:

9852E4EF42DA54EA8F399946EEFDC20DF14299D3

SHA256:

324CF60DACF248B91CDA9793B5EBA4FA3CE312FDAF99A20D721F515231B0357E

SSDEEP:

98304:wT1xqWV2JyOkr54SnQ9YpW/Dco4HIEk0c7kiYCD2lpXX/kXoZO0Trf9ulBw9ZVQx:iYE8R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs injected code in another process

      • syspin.exe (PID: 6324)
    • Application was injected by another process

      • explorer.exe (PID: 4552)
    • Registers / Runs the DLL via REGSVR32.EXE

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Searches for installed software

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 2904)
    • Uses TASKKILL.EXE to kill process

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Creates a software uninstall entry

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Process drops legitimate windows executable

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Reads the date of Windows installation

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • The process drops C-runtime libraries

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Reads security settings of Internet Explorer

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Application launched itself

      • FLiNGTrainer.exe (PID: 6884)
    • Drops the executable file immediately after the start

      • FLiNGTrainer.exe (PID: 6884)
      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Executable content was dropped or overwritten

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
  • INFO

    • Checks supported languages

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • syspin.exe (PID: 6324)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 5144)
      • FLiNGTrainer.exe (PID: 2904)
      • FLiNGTrainer.exe (PID: 1372)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4552)
    • Create files in a temporary directory

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
    • Creates files in the program directory

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
    • Reads the computer name

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 5144)
    • Process checks computer location settings

      • FLiNG_Trainer_c18_b2174305.exe (PID: 6612)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 2904)
    • Reads Microsoft Office registry keys

      • explorer.exe (PID: 4552)
    • Checks proxy server information

      • FLiNGTrainer.exe (PID: 6884)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 4552)
      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 5144)
      • FLiNGTrainer.exe (PID: 2904)
    • VMProtect protector has been detected

      • FLiNGTrainer.exe (PID: 6884)
      • FLiNGTrainer.exe (PID: 4064)
      • FLiNGTrainer.exe (PID: 1372)
      • FLiNGTrainer.exe (PID: 5144)
    • Reads the software policy settings

      • FLiNGTrainer.exe (PID: 6884)
    • Reads the machine GUID from the registry

      • FLiNGTrainer.exe (PID: 6884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:12:11 07:12:34+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 263680
UninitializedDataSize: 8192
EntryPoint: 0x30de
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.83
ProductVersionNumber: 2.0.0.83
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Latin1
CompanyName: Hefei Kunbo Information Technology Co., Ltd.
FileDescription: FLiNGTrainer
FileVersion: 2.0.0.83
LegalCopyright: Copyright 2024 Hefei Kunbo Information Technology Co., Ltd. All rights reserved.
LegalTrademarks: FLiNGTrainer
ProductName: FLiNGTrainer
ProductVersion: 2.0.0.83
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
15
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start fling_trainer_c18_b2174305.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs syspin.exe no specs conhost.exe no specs regsvr32.exe no specs THREAT flingtrainer.exe THREAT flingtrainer.exe no specs THREAT flingtrainer.exe no specs THREAT flingtrainer.exe flingtrainer.exe no specs explorer.exe fling_trainer_c18_b2174305.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1372"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --ignore-urlfetcher-cert-requests=true --no-sandbox --ignore-certificate-errors=true --ignore-certificate-errors=true --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=2260 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
2904"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --first-renderer-process --no-sandbox --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --remote-debugging-port=33229 --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2600 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exeFLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
4064"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=gpu-process --no-sandbox --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=1672 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
4552C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\aepic.dll
c:\windows\system32\oleaut32.dll
5144"C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --ignore-urlfetcher-cert-requests=true --no-sandbox --ignore-certificate-errors=true --ignore-certificate-errors=true --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --log-file="C:\Program Files (x86)\FLiNGTrainer\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1748,i,4606536205926055991,3874564749120256988,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe
FLiNGTrainer.exe
User:
admin
Integrity Level:
HIGH
Description:
风灵月影修改器
Version:
2.0.0.83
Modules
Images
c:\program files (x86)\flingtrainer\flingtrainer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
6304regsvr32 /s "C:\Program Files (x86)\FLiNGTrainer\ContextMenuDemo_x64.dll"C:\Windows\SysWOW64\regsvr32.exeFLiNG_Trainer_c18_b2174305.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6324"C:\Program Files (x86)\FLiNGTrainer\syspin.exe" "C:\Program Files (x86)\FLiNGTrainer\FLiNGTrainer.exe" 5386C:\Program Files (x86)\FLiNGTrainer\syspin.exeFLiNG_Trainer_c18_b2174305.exe
User:
admin
Company:
Thunder Network
Integrity Level:
HIGH
Description:
SysPin
Exit code:
0
Version:
1.0.0.2
Modules
Images
c:\program files (x86)\flingtrainer\syspin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6344\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesyspin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6564"C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe" C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exeexplorer.exe
User:
admin
Company:
Hefei Kunbo Information Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
FLiNGTrainer
Exit code:
3221226540
Version:
2.0.0.83
Modules
Images
c:\users\admin\appdata\local\temp\fling_trainer_c18_b2174305.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6612"C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe" C:\Users\admin\AppData\Local\Temp\FLiNG_Trainer_c18_b2174305.exe
explorer.exe
User:
admin
Company:
Hefei Kunbo Information Technology Co., Ltd.
Integrity Level:
HIGH
Description:
FLiNGTrainer
Exit code:
0
Version:
2.0.0.83
Modules
Images
c:\users\admin\appdata\local\temp\fling_trainer_c18_b2174305.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
20 024
Read events
19 906
Write events
113
Delete events
5

Modification events

(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000000000000000000
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000050388
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(6612) FLiNG_Trainer_c18_b2174305.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FLiNGTrainer
Operation:writeName:cid
Value:
18
(PID) Process:(6612) FLiNG_Trainer_c18_b2174305.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FLiNGTrainer
Operation:writeName:bid
Value:
2174305
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search
Operation:writeName:TraySearchBoxVisible
Value:
1
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010012000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C0000001500000000000000630061007400650067006F007200790061006C00620075006D002E006A00700067003E002000200000001300000000000000630075007200720065006E0074006C007900630064002E007200740066003E002000200000000F0000000000000063007500740062006C00750065002E007200740066003E00200020000000130000000000000065006900740068006500720077006F0072006C0064002E0070006E0067003E002000200000001100000000000000670072006F007700740068006E00650074002E007200740066003E0020002000000012000000000000006D006F00760069006500730077006F0072006B002E007200740066003E0020002000000013000000000000006F006600660069006300690061006C00620069006E002E007200740066003E002000200000001300000000000000730074007500660066007200610074006800650072002E0070006E0067003E002000200000001600000000000000740068006F00750067006800650063006F006E006F006D00690063002E0070006E0067003E0020002000000013000000000000007A006F006E00650070006C00610079006500720073002E007200740066003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001200000000000000000000000000000000000000803F0000004008000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A0401100000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
CF58C46600000000
(PID) Process:(4552) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(4552) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0400000000000000030000000E0000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
Executable files
73
Suspicious files
252
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
6612FLiNG_Trainer_c18_b2174305.exeC:\Program Files (x86)\FLiNGTrainer\package.7z
MD5:
SHA256:
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\icudtl.dat
MD5:
SHA256:
4552explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\nsvE9A2.tmp\BgWorker.dllexecutable
MD5:33EC04738007E665059CF40BC0F0C22B
SHA256:50F735AB8F3473423E6873D628150BBC0777BE7B4F6405247CDDF22BB00FB6BE
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\ar.pakbinary
MD5:421ED78CF9BAC81BE79530E1D8A06921
SHA256:8B5EC1F2210062CD26D1A15CBB903578A327A42530B75A9519C0D085D135DF4F
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\nsvE9A2.tmp\nsExec.dllexecutable
MD5:2FD10D2F8AE885CC7E34FF21703AEF6C
SHA256:E0959B690F25160D590CFD7E2467BB9CE7E9D959663E7E203F502DCE5246507D
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\chrome_100_percent.pakbinary
MD5:535B4F1F57A3625D912467F0A7E1650B
SHA256:2E0983144A46898FA34F82AB6629E963F82F776B22374C9628C14EFC4AA07FC9
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\el.pakbinary
MD5:1D92699092785523CCA96518676629D2
SHA256:6F2D867103D0D4A516892AE7792344AF7B1A83C81475C88538C5BDD184C5FA55
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\am.pakpgc
MD5:8415BD85D951F7F18280107B505A8B30
SHA256:FA0FD4D62876E89EC360D5FADD5C44797060C791FE791F777D1F6AFC6DC9D199
6612FLiNG_Trainer_c18_b2174305.exeC:\Users\admin\AppData\Local\Temp\package\locales\bg.pakbinary
MD5:5BBF21D6017687BD1D0E4C1488BD2AA0
SHA256:6A89C2011887BD70876062B394A8C13553D6751D0C0D6B82EC8D13ABB7F14F57
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
74
DNS requests
32
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2384
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2468
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6476
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3992
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4760
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4760
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6612
FLiNG_Trainer_c18_b2174305.exe
180.163.146.89:443
dl.fucnm.com
China Telecom Group
CN
unknown
6612
FLiNG_Trainer_c18_b2174305.exe
180.163.146.83:443
file.fucnm.com
China Telecom Group
CN
unknown
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2384
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
dl.fucnm.com
  • 180.163.146.89
unknown
file.fucnm.com
  • 180.163.146.83
unknown
login.live.com
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.73
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted

Threats

No threats detected
Process
Message
FLiNG_Trainer_c18_b2174305.exe
Õý³£´´½¨³ÌÐò×é¿ì½Ý·½Ê½
FLiNG_Trainer_c18_b2174305.exe
FLiNG_Trainer_c18_b2174305.exe
°²×°Íê³É
FLiNG_Trainer_c18_b2174305.exe
FLiNGTrainer.exe
[0820/085348.585:WARNING:account_consistency_mode_manager.cc(70)] Desktop Identity Consistency cannot be enabled as no OAuth client ID and client secret have been configured.