download:

baidunetdisk_6.1.0.exe

Full analysis: https://app.any.run/tasks/b47bc22f-2282-49c5-a62f-773b0b07d4d5
Verdict: Malicious activity
Analysis date: July 25, 2018, 03:44:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7370BA7DDFF34DE0C20551FF23E029F0

SHA1:

E0E1E731A2592533C7B740BB089365E5383ED5DF

SHA256:

3939E0AA283C1F2AC9BB24771766267D89A1B39CE9CB2DD19C71695195B81278

SSDEEP:

786432:6QJLVFqODLpU4Sq2Iv+wMey0rmlMge+BkvP/SGFbj:6QJrJUp7i+XeFCl9e+BkvP/z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • baidunetdisk_6.1.0.exe (PID: 1944)
      • BaiduNetdisk.exe (PID: 1716)
      • BaiduNetdisk.exe (PID: 3008)
      • YunDetectService.exe (PID: 3460)
      • YunUtilityService.exe (PID: 3144)
      • regsvr32.exe (PID: 3092)
      • BaiduNetdiskHost.exe (PID: 2876)
      • regsvr32.exe (PID: 2108)
      • YunDetectService.exe (PID: 3272)
    • Application was dropped or rewritten from another process

      • BaiduNetdisk.exe (PID: 3008)
      • BaiduNetdisk.exe (PID: 1716)
      • BaiduNetdiskHost.exe (PID: 2876)
      • YunUtilityService.exe (PID: 3144)
      • AutoUpdate.exe (PID: 3692)
      • YunDetectService.exe (PID: 3460)
      • YunDetectService.exe (PID: 3272)
    • Registers / Runs the DLL via REGSVR32.EXE

      • baidunetdisk_6.1.0.exe (PID: 1944)
    • Changes the autorun value in the registry

      • BaiduNetdisk.exe (PID: 3008)
  • SUSPICIOUS

    • Creates files in the user directory

      • BaiduNetdisk.exe (PID: 3008)
      • YunDetectService.exe (PID: 3272)
      • BaiduNetdisk.exe (PID: 1716)
      • AutoUpdate.exe (PID: 3692)
      • baidunetdisk_6.1.0.exe (PID: 1944)
    • Modifies the open verb of a shell class

      • BaiduNetdisk.exe (PID: 3008)
      • YunDetectService.exe (PID: 3460)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 2108)
      • regsvr32.exe (PID: 3092)
    • Executable content was dropped or overwritten

      • baidunetdisk_6.1.0.exe (PID: 1944)
      • BaiduNetdisk.exe (PID: 1716)
    • Creates a software uninstall entry

      • baidunetdisk_6.1.0.exe (PID: 1944)
    • Reads Internet Cache Settings

      • BaiduNetdisk.exe (PID: 1716)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • baidunetdisk_6.1.0.exe (PID: 1944)
      • AutoUpdate.exe (PID: 3692)
    • Dropped object may contain URL's

      • BaiduNetdisk.exe (PID: 1716)
      • AutoUpdate.exe (PID: 3692)
      • baidunetdisk_6.1.0.exe (PID: 1944)
    • Reads settings of System Certificates

      • AutoUpdate.exe (PID: 3692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 20:19:59+01:00
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 24-Feb-2012 19:19:59
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 24-Feb-2012 19:19:59
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006F10
0x00007000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.49788
.rdata
0x00008000
0x00002A92
0x00002C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.39389
.data
0x0000B000
0x00067EBC
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.47278
.ndata
0x00073000
0x000E1000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00154000
0x0005AF90
0x0005B000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.80149
.reloc
0x001AF000
0x00000F8A
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
4.41359

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.21698
968
UNKNOWN
English - United States
RT_MANIFEST
2
5.80323
67624
UNKNOWN
English - United States
RT_ICON
3
5.94822
16936
UNKNOWN
English - United States
RT_ICON
4
6.14
9640
UNKNOWN
English - United States
RT_ICON
5
6.20708
4264
UNKNOWN
English - United States
RT_ICON
6
6.66261
1128
UNKNOWN
English - United States
RT_ICON
103
2.55883
90
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.68733
494
UNKNOWN
English - United States
RT_DIALOG
106
2.86626
228
UNKNOWN
English - United States
RT_DIALOG
111
2.9304
218
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
VERSION.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start baidunetdisk_6.1.0.exe baidunetdisk.exe regsvr32.exe no specs regsvr32.exe no specs yunutilityservice.exe no specs yundetectservice.exe no specs baidunetdisk.exe yundetectservice.exe baidunetdiskhost.exe no specs autoupdate.exe baidunetdisk_6.1.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1716C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe
baidunetdisk_6.1.0.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BaiduNetdisk
Exit code:
0
Version:
6.1.0.10
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\baidunetdisk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\updateagent.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1944"C:\Users\admin\AppData\Local\Temp\baidunetdisk_6.1.0.exe" C:\Users\admin\AppData\Local\Temp\baidunetdisk_6.1.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\users\admin\appdata\local\temp\baidunetdisk_6.1.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2108"C:\Windows\system32\regsvr32.exe" "/s" "C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\npYunWebDetect.dll"C:\Windows\system32\regsvr32.exebaidunetdisk_6.1.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2492"C:\Users\admin\AppData\Local\Temp\baidunetdisk_6.1.0.exe" C:\Users\admin\AppData\Local\Temp\baidunetdisk_6.1.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\baidunetdisk_6.1.0.exe
c:\systemroot\system32\ntdll.dll
2876"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdiskHost.exe" -PluginId 3 -PluginPath "C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\module\CyberPlayer\CyberPlayer.dll" -ChannelName baidunetdisk.1716.0.1643855412\125791561 -QuitEventName BAIDU_NETDISK_VIDEO_PLAY_SDK_0A0EDEC8-5A3D-4BDB-9D84-71DC841F0563 -BaiduId "" -IP "192.168.100.52" -PcGuid "BDIMXV2-O_E9653340B6614321AA2226F461089627-C_0-D_4d51303030302031202020202020202020202020-M_5254004AAD11-V_C4BA3647" -Version "6.1.0.10" -DiskApiHttps 0 -StatisticHttps 0 -ReportCrash 1C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdiskHost.exeBaiduNetdisk.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BaiduNetdiskHost
Exit code:
0
Version:
6.1.0.10
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\baidunetdiskhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\bull140u.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\minosagent.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\msvcp140.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\vcruntime140.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\api-ms-win-crt-runtime-l1-1-0.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\ucrtbase.dll
3008"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe" -install "createdetectstartup" -install "btassociation" -install "createshortcut" "0" -install "createstartup"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe
baidunetdisk_6.1.0.exe
User:
admin
Integrity Level:
HIGH
Description:
BaiduNetdisk
Exit code:
1
Version:
6.1.0.10
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\baidunetdisk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\baidu\baidunetdisk\updateagent.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3092"C:\Windows\system32\regsvr32.exe" "/s" "C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunShellExt.dll"C:\Windows\system32\regsvr32.exebaidunetdisk_6.1.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3144"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunUtilityService.exe" --uninstallC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunUtilityService.exebaidunetdisk_6.1.0.exe
User:
admin
Integrity Level:
HIGH
Description:
YunUtilityService
Exit code:
5
Version:
6.1.0.10
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\yunutilityservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3272C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe
baidunetdisk_6.1.0.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\yundetectservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3460"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe" regC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exebaidunetdisk_6.1.0.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\baidu\baidunetdisk\yundetectservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 701
Read events
1 286
Write events
398
Delete events
17

Modification events

(PID) Process:(1944) baidunetdisk_6.1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1944) baidunetdisk_6.1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(1944) baidunetdisk_6.1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:Favorites
Value:
007C01000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016001401320085050000454B864A2000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00520000001D00EFBE02004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000001C000000007601000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000E013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00740000001D00EFBE02007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000001C000000007801000014001F80C827341F105C1042AA032EE45287D6685200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B004200610072000000160010013200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C004C0000001D00EFBE02004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000001C000000005201000014001F80C827341F105C1042AA032EE45287D6685200310000000000F04C6F3A11005461736B426172003C0008000400EFBE454B864AF04C6F3A2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200FB060000F04C6F3A20004F50455241317E312E4C4E4B0000540008000400EFBEF04C6F3AF04C6F3A2A0000006AB900000000020000000000000000000000000000004F007000650072006100310032002E0031003500200031003700340038002E006C006E006B0000001C007A0000001D00EFBE02007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004F0070006500720061005C006F0070006500720061002E0065007800650000001C00000000EE00000014001F80C827341F105C1042AA032EE45287D6685200310000000000F04CAE3B11005461736B426172003C0008000400EFBE454B864AF04CAE3B2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600860032005D080000F04CE23A2000474F4F474C457E312E4C4E4B0000500008000400EFBEF04CAE3BF04CAE3B2A0000001040000000000D00000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C001A0000001D00EFBE02004300680072006F006D00650000001C000000005201000014001F80C827341F105C1042AA032EE45287D6685200310000000000F94CE11D11005461736B426172003C0008000400EFBE454B864AF94CE11D2A000000603E00000000040000000000000000000000000000005400610073006B0042006100720000001600EA003200C5030000F94CE11D2000434242317E312E4C4E4B00003E0008000400EFBEF94CE11DF94CE11D2A000000AFF100000000010000000000000000000000000000007E76A65E517FD8762E006C006E006B0000001A00920000001D00EFBE020043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C00620061006900640075005C00420061006900640075004E00650074006400690073006B005C00420061006900640075004E00650074006400690073006B002E0065007800650000001A000000FF
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:FavoritesChanges
Value:
9
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
Operation:writeName:FavoritesVersion
Value:
2
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:BaiduYunGuanjia
Value:
"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdisk.exe" AutoRun
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:BaiduYunDetect
Value:
"C:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunDetectService.exe"
(PID) Process:(3008) BaiduNetdisk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BaiduYunGuanjia.torrent
Operation:writeName:
Value:
百度网盘BT种子文件
Executable files
82
Suspicious files
20
Text files
21
Unknown types
10

Dropped files

PID
Process
Filename
Type
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Local\Temp\nshB96D.tmp\VersionInfo.xmlxml
MD5:E7D4D428228761BEC871123BCD7367E7
SHA256:6A74FB11BA609965B418F8E180CAE9C4D7BEA5E9B811F25B82247880411B896C
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\Bull140U.dllexecutable
MD5:C8E52D096C555CCD4925FE08CEEB47E4
SHA256:CBE136833469DCC9F6CFEC3031AA88EBCBC33F5C4875E3F60AEC3C6CC4EFE9A3
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Local\Temp\nshB96D.tmp\NsisInstallUI.dllexecutable
MD5:D571CAE06354C13EAC801C19E00D77CB
SHA256:67EF978EC1A6A312333FCDB724C17502E76CE58651B509FF19C91A9591BEF2B5
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\kernel.dllexecutable
MD5:2A4AA18493AE3624DB38C4AEAE8A8B2C
SHA256:3A303B4575902373FE0F7AD692371467CC7C5CE4D5BB59BA26F3DB21A9CE4771
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\kernelUpdate.exeexecutable
MD5:DD5D8B40669AA3CAB2263FB80BCB8BC1
SHA256:EC33814F4222D52723A2BC0E067E81222DEFA0464CC2BA7090CAC8EBB07DFC20
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\channelpcsdk.dllexecutable
MD5:DF363298FD4377FBC5463DD2D54A92C9
SHA256:A645A94F2AC346CE42A5026866B4C9CBD557C2A1305DC0D253410BA020F2851F
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\BaiduNetdiskHost.exeexecutable
MD5:3C520EC6EFE9B6F50859FB0531B79B38
SHA256:ACED1CCC9E8A5DAA6A7F92B3A015402A5C9656D51640EFF896C01BC86BA9A624
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunLogic.dllexecutable
MD5:4F3FC5D8A8B1DF6B66FAA5A7C7C90A11
SHA256:447E4DF5E1D56F4F3576A595647780C7B9C078EFDC251FDD8C2D5CA620FAD974
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\YunSub.dllexecutable
MD5:29F03D73F4E45CA15689CA35337EBFBC
SHA256:5FF9AC3E090A95115985EEC36C9A4A767DFAC6CEFC9622847AD5981D934721A7
1944baidunetdisk_6.1.0.exeC:\Users\admin\AppData\Roaming\baidu\BaiduNetdisk\VersionInfobinary
MD5:F8EA8DCF7C5CA0EDC2C4F1A8DD014305
SHA256:69884A0A33E99B2A1CE74D7BF41C75B857DFEE5A64AFF2AF31D64579B7956CFB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
29
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1716
BaiduNetdisk.exe
POST
200
180.149.133.176:80
http://bj.t.bcsp2p.baidu.com:80/cms/config?method=query&cfg=version_control
CN
text
115 b
whitelisted
1716
BaiduNetdisk.exe
POST
200
58.217.200.62:80
http://nj.t.bcsp2p.baidu.com/seed
CN
binary
96 b
whitelisted
1716
BaiduNetdisk.exe
GET
200
111.206.37.70:80
http://pan.baidu.com/res/static/thirdparty/connect.jpg?t=1532490485
CN
text
2 b
whitelisted
1716
BaiduNetdisk.exe
POST
200
58.217.200.62:80
http://nj.t.bcsp2p.baidu.com/router
CN
binary
320 b
whitelisted
1716
BaiduNetdisk.exe
POST
502
123.125.114.235:80
http://update.pan.baidu.com/statistics?clienttype=8&devuid=BDIMXV2%2DO%5FE9653340B6614321AA2226F461089627%2DC%5F0%2DD%5F4d51303030302031202020202020202020202020%2DM%5F5254004AAD11%2DV%5FC4BA3647&channel=00000000000000000000000000000000&version=6.1.0.10&ver=1&id=15324904277FBA02DF459142399F6325BDC9843A39&vip=0
CN
html
166 b
whitelisted
1716
BaiduNetdisk.exe
POST
200
58.217.200.62:80
http://nj.t.bcsp2p.baidu.com/router
CN
binary
80 b
whitelisted
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFE%2FuXQ4cLc0QEGNMJMGmf8%3D
NL
der
1.71 Kb
whitelisted
1716
BaiduNetdisk.exe
POST
502
123.125.114.235:80
http://update.pan.baidu.com/statistics?clienttype=8&devuid=BDIMXV2%2DO%5FE9653340B6614321AA2226F461089627%2DC%5F0%2DD%5F4d51303030302031202020202020202020202020%2DM%5F5254004AAD11%2DV%5FC4BA3647&channel=00000000000000000000000000000000&version=6.1.0.10&ver=1&id=15324904277FBA02DF459142399F6325BDC9843A39&vip=0
CN
html
166 b
whitelisted
GET
200
23.37.43.27:80
http://ss.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTRsWSLjJ8N0Wujis0rUBfV%2Bc%2FAZAQUX2DPYZBV34RDFIpgKrL1evRDGO8CEEYL7cxsaPsAZ%2FCYDbhNv4I%3D
NL
der
1.57 Kb
whitelisted
GET
200
23.37.43.27:80
http://ss.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTRsWSLjJ8N0Wujis0rUBfV%2Bc%2FAZAQUX2DPYZBV34RDFIpgKrL1evRDGO8CEG6PrCxmmU8tZDNcJoriZ80%3D
NL
der
1.57 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1716
BaiduNetdisk.exe
8.253.145.121:80
www.download.windowsupdate.com
Level 3 Communications, Inc.
US
unknown
1716
BaiduNetdisk.exe
123.125.114.235:443
update.pan.baidu.com
China Unicom Beijing Province Network
CN
unknown
1716
BaiduNetdisk.exe
59.38.112.31:443
gss0.bdstatic.com
CHINANET Guangdong province network
CN
unknown
106.38.242.172:8840
IDC, China Telecommunications Corporation
CN
unknown
1716
BaiduNetdisk.exe
123.125.114.235:80
update.pan.baidu.com
China Unicom Beijing Province Network
CN
unknown
1716
BaiduNetdisk.exe
180.97.33.12:8829
nj.h.bcsp2p.baidu.com
No.31,Jin-rong Street
CN
unknown
1716
BaiduNetdisk.exe
58.217.200.62:80
nj.t.bcsp2p.baidu.com
No.31,Jin-rong Street
CN
unknown
1716
BaiduNetdisk.exe
111.206.37.70:443
pan.baidu.com
China Unicom Beijing Province Network
CN
suspicious
106.38.242.171:8841
IDC, China Telecommunications Corporation
CN
unknown
23.37.43.27:80
ocsp.verisign.com
Akamai Technologies, Inc.
NL
whitelisted

DNS requests

Domain
IP
Reputation
pan.baidu.com
  • 111.206.37.70
whitelisted
socket.pan.baidu.com
  • 202.108.23.113
whitelisted
bj.t.bcsp2p.baidu.com
  • 180.149.133.176
whitelisted
www.download.windowsupdate.com
  • 8.253.145.121
  • 8.248.97.254
  • 67.26.83.254
  • 8.253.145.105
  • 8.248.109.254
whitelisted
nj.h.bcsp2p.baidu.com
  • 180.97.33.12
whitelisted
nj.t.bcsp2p.baidu.com
  • 58.217.200.62
whitelisted
update.pan.baidu.com
  • 123.125.114.235
whitelisted
gss0.bdstatic.com
  • 59.38.112.31
whitelisted
ocsp.verisign.com
  • 23.37.43.27
whitelisted
s2.symcb.com
  • 23.37.43.27
whitelisted

Threats

No threats detected
No debug info