File name:

咪咕视频客户端.exe

Full analysis: https://app.any.run/tasks/13e907a1-0d54-48a6-922c-d2f557db4a7f
Verdict: Malicious activity
Analysis date: November 11, 2023, 12:48:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D4718C19110C129913C908A32355AA4D

SHA1:

D33177B2A706799D7E47F2B4FC4BBF77088191AB

SHA256:

359F4BC0B9E16A41C037C79B2344BD8E68FA39E664E2A6345145C2CA2F7FA2AA

SSDEEP:

98304:YgMYgrBVhVvdpy6x/Yng8DWK+NZyp8RiGIr7Nn84aJjgbKMln+Awa7BiqQBQNtOa:VGIrW6drBV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process requests binary or script from the Internet

      • 咪咕视频客户端.exe (PID: 3504)
  • INFO

    • Reads the computer name

      • 咪咕视频客户端.exe (PID: 3504)
      • wmpnscfg.exe (PID: 3408)
    • Create files in a temporary directory

      • 咪咕视频客户端.exe (PID: 3504)
    • Checks supported languages

      • 咪咕视频客户端.exe (PID: 3504)
      • wmpnscfg.exe (PID: 3408)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3408)
      • 咪咕视频客户端.exe (PID: 3504)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1970:02:16 21:07:28+01:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 1691648
InitializedDataSize: 2351104
UninitializedDataSize: -
EntryPoint: 0xa59f8
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2023.8.21.852
ProductVersionNumber: 9.3.0.2451
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Kingsoft Corporation
FileDescription: Kingsoft Security - 安装程序
FileVersion: 2023,07,17,2451
InternalName: KInstallTool
LegalCopyright: Copyright (C) 1998-2023 Kingsoft Corporation
OriginalFileName: -
ProductName: Kingsoft Internet Security
ProductVersion: 9,3,0,2451
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 咪咕视频客户端.exe wmpnscfg.exe no specs 咪咕视频客户端.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3408"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3428"C:\Users\admin\AppData\Local\Temp\咪咕视频客户端.exe" C:\Users\admin\AppData\Local\Temp\咪咕视频客户端.exeexplorer.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
MEDIUM
Description:
Kingsoft Security - 安装程序
Exit code:
3221226540
Version:
2023,07,17,2451
Modules
Images
c:\users\admin\appdata\local\temp\咪咕视频客户端.exe
c:\windows\system32\ntdll.dll
3504"C:\Users\admin\AppData\Local\Temp\咪咕视频客户端.exe" C:\Users\admin\AppData\Local\Temp\咪咕视频客户端.exe
explorer.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 安装程序
Exit code:
0
Version:
2023,07,17,2451
Modules
Images
c:\users\admin\appdata\local\temp\咪咕视频客户端.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
414
Read events
403
Write events
8
Delete events
3

Modification events

(PID) Process:(3504) å’ªå’•视频客户端.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
Operation:writeName:idex
Value:
5d6a2ee9985410960d4438cb9da0a7e0
(PID) Process:(3504) å’ªå’•视频客户端.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
Operation:writeName:idno
Value:
1
(PID) Process:(3408) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{91F7092C-8FBB-4433-A838-B700DF3EF1F2}\{05DCF10E-89D3-41B2-B6F2-D1AFEDEB8911}
Operation:delete keyName:(default)
Value:
(PID) Process:(3408) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{91F7092C-8FBB-4433-A838-B700DF3EF1F2}
Operation:delete keyName:(default)
Value:
(PID) Process:(3408) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60BAD3A4-18E3-4F55-BE83-12D9DF2F157A}
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
0
Text files
22
Unknown types
0

Dropped files

PID
Process
Filename
Type
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\jcqgx.initext
MD5:478B13BDC92E7D49E1E4A9B9C496FE9A
SHA256:7B8DFFD78EB43C4FA4472104DFC03C787196E5E6D852189F0F5BC0DC816E4F79
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\kinst.logtext
MD5:A7FF685208F7500FE6E48050D6D9BF07
SHA256:CC3CFD5D97AA704EA379AA0F7E246FC0ADEC54D1E5ACC9BDE8413E9DC7CA265F
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\soft.icoimage
MD5:F09986091A0DA5D72A57248E12A9AE4E
SHA256:20C293C66182884940954A5EE7A37937B3FBBC90BDB0FCEE714B66BEE2518671
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0317\6001.xmltext
MD5:32DAB5393C08D8A2E417C3F4B2E0A403
SHA256:4AC54965A7795EB6A22EA7F19C9D18D55B7834006B9B34C53F107BE81461FD3A
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0307\6001.xmltext
MD5:A41FE6AD4115C9508AF69013806AF36D
SHA256:C300345EA071E284C7B619544ED1BBD993DA4052307189962A7876AFE042D082
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0317\100.pngimage
MD5:A64D7F2A825F5547182E9E3EE25B4544
SHA256:E78B678846C177786E70E29D5111359D4AFF20D9AC5935FAD2BE87B17D7F9FC9
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0317\110.pngimage
MD5:020AE4ED917D5F84277384CAB39E56B0
SHA256:DC35117220A1A6959FFC2125DBD3A40452F88FFCA94B2A69CCBD9CF58380FDD9
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0317\soft.icoimage
MD5:F09986091A0DA5D72A57248E12A9AE4E
SHA256:20C293C66182884940954A5EE7A37937B3FBBC90BDB0FCEE714B66BEE2518671
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\backup_0307\6000.xmltext
MD5:B1C00F67FE681FFF27F80A020D4D8CD9
SHA256:7C37E942CE92FC48457FC6D484E8ED788DA7B8B23689C0ED4601D26B0F629336
3504咪咕视频客户端.exeC:\Users\admin\AppData\Local\Temp\install_res\6000.xmltext
MD5:9605F14AED72906A40155329EAE6F49B
SHA256:B6C22395227C36B8BBE240CB826B1277A65DC6AAB15A46A0E2D3F96485BFB098
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
21
DNS requests
8
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3504
咪咕视频客户端.exe
HEAD
200
39.91.190.6:80
http://cu003.www.duba.net/duba/tools/dubatools/softmgricon/70007331.png
unknown
unknown
3504
咪咕视频客户端.exe
POST
200
139.9.45.223:80
http://infoc0.duba.net/c/
unknown
binary
43 b
unknown
3504
咪咕视频客户端.exe
POST
200
139.9.46.163:80
http://infoc0.duba.net/c/
unknown
binary
43 b
unknown
3504
咪咕视频客户端.exe
POST
200
139.9.45.223:80
http://infoc0.duba.net/c/
unknown
binary
43 b
unknown
3504
咪咕视频客户端.exe
POST
200
139.9.45.223:80
http://infoc0.duba.net/c/
unknown
binary
43 b
unknown
3504
咪咕视频客户端.exe
GET
200
218.12.76.156:80
http://2398.35go.net/defend/o1/jcqgx.ini
unknown
text
10 b
unknown
3504
咪咕视频客户端.exe
POST
200
139.9.45.223:80
http://infoc0.duba.net/c/
unknown
binary
43 b
unknown
3504
咪咕视频客户端.exe
GET
120.52.95.247:80
http://config.i.duba.net/seminstall/166/691.xml?time=1699706926
unknown
unknown
3504
咪咕视频客户端.exe
GET
200
182.107.80.35:80
http://softmgr.duba.net/softmgr_v2/softdetail/70007331.json?ver=1
unknown
binary
1.51 Kb
unknown
3504
咪咕视频客户端.exe
GET
200
39.91.190.6:80
http://cu003.www.duba.net/duba/tools/dubatools/softmgricon/70007331.png
unknown
image
1.88 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
3504
咪咕视频客户端.exe
218.12.76.156:80
2398.35go.net
CHINA UNICOM China169 Backbone
CN
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3504
咪咕视频客户端.exe
139.9.45.223:80
infoc0.duba.net
Huawei Cloud Service data center
CN
unknown
3504
咪咕视频客户端.exe
182.107.80.35:80
softmgr.duba.net
Chinanet
CN
unknown
3504
咪咕视频客户端.exe
39.91.190.6:80
cu003.www.duba.net
CHINA UNICOM China169 Backbone
CN
unknown
3504
咪咕视频客户端.exe
114.132.191.224:443
softmgr-softsem-srv.jinshanapi.com
Shenzhen Tencent Computer Systems Company Limited
CN
unknown
3504
咪咕视频客户端.exe
139.9.46.163:80
infoc0.duba.net
Huawei Cloud Service data center
CN
unknown

DNS requests

Domain
IP
Reputation
2398.35go.net
  • 218.12.76.156
  • 120.52.95.245
  • 120.52.95.247
  • 218.12.76.158
whitelisted
infoc0.duba.net
  • 139.9.45.223
  • 139.9.46.163
  • 124.71.209.131
  • 139.9.36.171
  • 139.9.39.206
  • 139.9.43.15
whitelisted
softmgr.duba.net
  • 182.107.80.35
  • 150.138.110.35
  • 150.138.188.35
  • 171.214.23.35
  • 171.214.24.35
  • 175.4.51.35
  • 180.97.64.35
  • 182.84.110.35
  • 182.106.158.35
  • 125.74.110.35
unknown
cu003.www.duba.net
  • 39.91.190.6
  • 116.162.19.1
  • 118.112.233.1
  • 111.227.116.1
  • 175.6.49.1
  • 1.194.250.6
  • 1.193.210.6
  • 183.61.243.1
  • 221.195.206.1
unknown
softmgr-softsem-srv.jinshanapi.com
  • 114.132.191.224
unknown
config.i.duba.net
  • 120.52.95.245
  • 120.52.95.247
  • 218.12.76.158
  • 218.12.76.156
whitelisted

Threats

PID
Process
Class
Message
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
3504
咪咕视频客户端.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
No debug info