| File name: | åªåè§é¢å®¢æ·ç«¯.exe |
| Full analysis: | https://app.any.run/tasks/13e907a1-0d54-48a6-922c-d2f557db4a7f |
| Verdict: | Malicious activity |
| Analysis date: | November 11, 2023, 12:48:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D4718C19110C129913C908A32355AA4D |
| SHA1: | D33177B2A706799D7E47F2B4FC4BBF77088191AB |
| SHA256: | 359F4BC0B9E16A41C037C79B2344BD8E68FA39E664E2A6345145C2CA2F7FA2AA |
| SSDEEP: | 98304:YgMYgrBVhVvdpy6x/Yng8DWK+NZyp8RiGIr7Nn84aJjgbKMln+Awa7BiqQBQNtOa:VGIrW6drBV |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1970:02:16 21:07:28+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 1691648 |
| InitializedDataSize: | 2351104 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa59f8 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2023.8.21.852 |
| ProductVersionNumber: | 9.3.0.2451 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Kingsoft Corporation |
| FileDescription: | Kingsoft Security - 安装程序 |
| FileVersion: | 2023,07,17,2451 |
| InternalName: | KInstallTool |
| LegalCopyright: | Copyright (C) 1998-2023 Kingsoft Corporation |
| OriginalFileName: | - |
| ProductName: | Kingsoft Internet Security |
| ProductVersion: | 9,3,0,2451 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3408 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3428 | "C:\Users\admin\AppData\Local\Temp\åªåè§é¢å®¢æ·ç«¯.exe" | C:\Users\admin\AppData\Local\Temp\åªåè§é¢å®¢æ·ç«¯.exe | — | explorer.exe | |||||||||||
User: admin Company: Kingsoft Corporation Integrity Level: MEDIUM Description: Kingsoft Security - 安装程序 Exit code: 3221226540 Version: 2023,07,17,2451 Modules
| |||||||||||||||
| 3504 | "C:\Users\admin\AppData\Local\Temp\åªåè§é¢å®¢æ·ç«¯.exe" | C:\Users\admin\AppData\Local\Temp\åªåè§é¢å®¢æ·ç«¯.exe | explorer.exe | ||||||||||||
User: admin Company: Kingsoft Corporation Integrity Level: HIGH Description: Kingsoft Security - 安装程序 Exit code: 0 Version: 2023,07,17,2451 Modules
| |||||||||||||||
| (PID) Process: | (3504) åªåè§é¢å®¢æ·ç«¯.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5} |
| Operation: | write | Name: | idex |
Value: 5d6a2ee9985410960d4438cb9da0a7e0 | |||
| (PID) Process: | (3504) åªåè§é¢å®¢æ·ç«¯.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5} |
| Operation: | write | Name: | idno |
Value: 1 | |||
| (PID) Process: | (3408) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{91F7092C-8FBB-4433-A838-B700DF3EF1F2}\{05DCF10E-89D3-41B2-B6F2-D1AFEDEB8911} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3408) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{91F7092C-8FBB-4433-A838-B700DF3EF1F2} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3408) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60BAD3A4-18E3-4F55-BE83-12D9DF2F157A} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\jcqgx.ini | text | |
MD5:478B13BDC92E7D49E1E4A9B9C496FE9A | SHA256:7B8DFFD78EB43C4FA4472104DFC03C787196E5E6D852189F0F5BC0DC816E4F79 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\kinst.log | text | |
MD5:A7FF685208F7500FE6E48050D6D9BF07 | SHA256:CC3CFD5D97AA704EA379AA0F7E246FC0ADEC54D1E5ACC9BDE8413E9DC7CA265F | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\soft.ico | image | |
MD5:F09986091A0DA5D72A57248E12A9AE4E | SHA256:20C293C66182884940954A5EE7A37937B3FBBC90BDB0FCEE714B66BEE2518671 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0317\6001.xml | text | |
MD5:32DAB5393C08D8A2E417C3F4B2E0A403 | SHA256:4AC54965A7795EB6A22EA7F19C9D18D55B7834006B9B34C53F107BE81461FD3A | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0307\6001.xml | text | |
MD5:A41FE6AD4115C9508AF69013806AF36D | SHA256:C300345EA071E284C7B619544ED1BBD993DA4052307189962A7876AFE042D082 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0317\100.png | image | |
MD5:A64D7F2A825F5547182E9E3EE25B4544 | SHA256:E78B678846C177786E70E29D5111359D4AFF20D9AC5935FAD2BE87B17D7F9FC9 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0317\110.png | image | |
MD5:020AE4ED917D5F84277384CAB39E56B0 | SHA256:DC35117220A1A6959FFC2125DBD3A40452F88FFCA94B2A69CCBD9CF58380FDD9 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0317\soft.ico | image | |
MD5:F09986091A0DA5D72A57248E12A9AE4E | SHA256:20C293C66182884940954A5EE7A37937B3FBBC90BDB0FCEE714B66BEE2518671 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\backup_0307\6000.xml | text | |
MD5:B1C00F67FE681FFF27F80A020D4D8CD9 | SHA256:7C37E942CE92FC48457FC6D484E8ED788DA7B8B23689C0ED4601D26B0F629336 | |||
| 3504 | åªåè§é¢å®¢æ·ç«¯.exe | C:\Users\admin\AppData\Local\Temp\install_res\6000.xml | text | |
MD5:9605F14AED72906A40155329EAE6F49B | SHA256:B6C22395227C36B8BBE240CB826B1277A65DC6AAB15A46A0E2D3F96485BFB098 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3504 | åªåè§é¢å®¢æ·ç«¯.exe | HEAD | 200 | 39.91.190.6:80 | http://cu003.www.duba.net/duba/tools/dubatools/softmgricon/70007331.png | unknown | — | — | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | POST | 200 | 139.9.45.223:80 | http://infoc0.duba.net/c/ | unknown | binary | 43 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | POST | 200 | 139.9.46.163:80 | http://infoc0.duba.net/c/ | unknown | binary | 43 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | POST | 200 | 139.9.45.223:80 | http://infoc0.duba.net/c/ | unknown | binary | 43 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | POST | 200 | 139.9.45.223:80 | http://infoc0.duba.net/c/ | unknown | binary | 43 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | GET | 200 | 218.12.76.156:80 | http://2398.35go.net/defend/o1/jcqgx.ini | unknown | text | 10 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | POST | 200 | 139.9.45.223:80 | http://infoc0.duba.net/c/ | unknown | binary | 43 b | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | GET | — | 120.52.95.247:80 | http://config.i.duba.net/seminstall/166/691.xml?time=1699706926 | unknown | — | — | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | GET | 200 | 182.107.80.35:80 | http://softmgr.duba.net/softmgr_v2/softdetail/70007331.json?ver=1 | unknown | binary | 1.51 Kb | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | GET | 200 | 39.91.190.6:80 | http://cu003.www.duba.net/duba/tools/dubatools/softmgricon/70007331.png | unknown | image | 1.88 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 218.12.76.156:80 | 2398.35go.net | CHINA UNICOM China169 Backbone | CN | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 139.9.45.223:80 | infoc0.duba.net | Huawei Cloud Service data center | CN | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 182.107.80.35:80 | softmgr.duba.net | Chinanet | CN | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 39.91.190.6:80 | cu003.www.duba.net | CHINA UNICOM China169 Backbone | CN | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 114.132.191.224:443 | softmgr-softsem-srv.jinshanapi.com | Shenzhen Tencent Computer Systems Company Limited | CN | unknown |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | 139.9.46.163:80 | infoc0.duba.net | Huawei Cloud Service data center | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
2398.35go.net |
| whitelisted |
infoc0.duba.net |
| whitelisted |
softmgr.duba.net |
| unknown |
cu003.www.duba.net |
| unknown |
softmgr-softsem-srv.jinshanapi.com |
| unknown |
config.i.duba.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3504 | åªåè§é¢å®¢æ·ç«¯.exe | Potentially Bad Traffic | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |