| URL: | http://dl.static.iqiyi.com/ppstreamsetup_tuwenfixsetup.exe |
| Full analysis: | https://app.any.run/tasks/51e2e2ee-e243-461d-b468-486389a91bb7 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | August 30, 2019, 12:10:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 2B338B91A24F8D3083BAD185B67DD02B |
| SHA1: | E1E696EE9C93417A1DA28E0A7986FE2668C0EA1D |
| SHA256: | 3984059D8F9894C851FCD99E4B3BDD0A827FFB836125DA92A8C71B4DB88C069E |
| SSDEEP: | 3:N1KaJy4rxWHWQ2SAgA:CaJ5xeW5kA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 296 | "C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyKernel.exe" | C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyKernel.exe | explorer.exe | ||||||||||||
User: admin Company: iQIYI.COM Integrity Level: MEDIUM Description: IQIYI Video Helper Exit code: 0 Version: 15.0.1.680 Modules
| |||||||||||||||
| 1424 | "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="爱奇艺视频播放器组件" dir=in program="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyPlayer.exe" action=allow description="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyPlayer.exe" | C:\Windows\system32\netsh.exe | — | ppstreamsetup_tuwenfixsetup[1].exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe | iexplore.exe | ||||||||||||
User: admin Company: 爱奇艺 Integrity Level: HIGH Description: 爱奇艺 修复程序 Exit code: 0 Version: 6.8.89.6786 Modules
| |||||||||||||||
| 2128 | "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="爱奇艺奇秀客户端" dir=in program="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QYAppPlugin\qixiu\QXClient.exe" action=allow description="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QYAppPlugin\qixiu\QXClient.exe" | C:\Windows\system32\netsh.exe | — | ppstreamsetup_tuwenfixsetup[1].exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2144 | "C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=makeppstat --ppsdat=010110111567167108 | C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe | ppstreamsetup_tuwenfixsetup[1].exe | ||||||||||||
User: admin Company: 爱奇艺 Integrity Level: HIGH Description: 爱奇艺视频辅助程序 Exit code: 0 Version: 6.8.89.6786 Modules
| |||||||||||||||
| 2204 | "C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=parker | C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe | QyKernel.exe | ||||||||||||
User: admin Company: 爱奇艺 Integrity Level: MEDIUM Description: 爱奇艺视频辅助程序 Exit code: 0 Version: 6.8.89.6786 Modules
| |||||||||||||||
| 2328 | "C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QiyiDACL.exe" QiyiUpdate "C:\Program Files\Common Files\IQIYI Video" true | C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QiyiDACL.exe | — | ppstreamsetup_tuwenfixsetup[1].exe | |||||||||||
User: admin Company: 爱奇艺 Integrity Level: HIGH Description: 爱奇艺组件 Exit code: 0 Version: 2.0.0.1 Modules
| |||||||||||||||
| 2376 | "C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=bubble | C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe | — | QyFragment.exe | |||||||||||
User: admin Company: 爱奇艺 Integrity Level: MEDIUM Description: 爱奇艺视频辅助程序 Exit code: 0 Version: 6.8.89.6786 Modules
| |||||||||||||||
| 2752 | \??\C:\Windows\system32\conhost.exe | C:\Windows\system32\conhost.exe | csrss.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {20210393-CB1F-11E9-B86F-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 2 | |||
| (PID) Process: | (3416) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E307080005001E000C000A0010002903 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3416 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 3416 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 3416 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF58ECFD859A7501A0.TMP | — | |
MD5:— | SHA256:— | |||
| 3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LN9SI0ZZ\ppstreamsetup_tuwenfixsetup[1].exe | — | |
MD5:— | SHA256:— | |||
| 3416 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe | — | |
MD5:— | SHA256:— | |||
| 3416 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF8430B6F0ADECB089.TMP | — | |
MD5:— | SHA256:— | |||
| 3416 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{20210393-CB1F-11E9-B86F-5254004A04AF}.dat | — | |
MD5:— | SHA256:— | |||
| 2068 | ppstreamsetup_tuwenfixsetup[1].exe | C:\Users\admin\AppData\Local\Temp\nsyA450.tmp\nsrB99F.tmp | — | |
MD5:— | SHA256:— | |||
| 3908 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:C7803EC52D0C8B048A85C272AB26F722 | SHA256:CF3C1ABE248E31AEEF55772E593C4E842463B6826685D14CF24DBE6BB8CE2F41 | |||
| 2068 | ppstreamsetup_tuwenfixsetup[1].exe | C:\Users\admin\AppData\Local\Temp\nsyA450.tmp\System.dll | executable | |
MD5:DDA1197A2890D6A617346EC1D20A729F | SHA256:2A26DC9CE6683FB702DF403BB6FAE70C4A2D86A39B7FAEA673D5D7A08BA9573E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2068 | ppstreamsetup_tuwenfixsetup[1].exe | GET | 200 | 36.110.209.200:80 | http://dl.static.iqiyi.com/bundled/config_encode.php?type=install&v=6.8.89.6786&w=61&f=fixsetup&lpi=NoPPSPid&new=0&ini=1&lang=1033&isv=0&rn=184307&ss=L&skb=1&home=about:blank | CN | text | 1.14 Kb | suspicious |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | GET | 200 | 36.110.209.200:80 | http://spider.pps.tv/ppstream/config_encode.php?type=install&v=6.8.89.6786&w=61&f=fixsetup&lpi=NoPPSPid&new=0&ini=1&lang=1033&isv=0&rn=394727&ss=L&skb=1&home=about:blank | CN | text | 2.11 Kb | suspicious |
296 | QyKernel.exe | GET | 200 | 111.206.13.61:80 | http://policy.video.iqiyi.com/policy.qtp.qtpconfig.blf | CN | binary | 12.0 Kb | suspicious |
296 | QyKernel.exe | GET | 200 | 101.227.188.198:80 | http://data.video.iqiyi.com/v.f4v | CN | text | 213 b | malicious |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | GET | 200 | 36.110.220.15:80 | http://msg.qy.net/v5/pcclient/cid_recal?&p1=201_11_114&os=6.1&rn=1567167103&mv=&reason=1&cid=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&cid_old=&mac=5254004a04af&lhdd=C4BA-3647&hdd= | CN | — | — | suspicious |
3368 | QiyiService.exe | GET | 200 | 106.38.219.49:80 | http://msg.qy.net/b?t=11&type=70&pf=1&p=11&p1=114&c1=&s1=2&channelid=&nu=&e=&se=&r=&u=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&pu=&rn=00000001567167107&v=6.8.89.6786 | CN | — | — | suspicious |
296 | QyKernel.exe | GET | 200 | 111.206.13.61:80 | http://policy.video.iqiyi.com/policy.mssconfig.pc.json | CN | text | 492 b | suspicious |
3368 | QiyiService.exe | GET | 200 | 36.110.220.15:80 | http://msg.qy.net/v5/pcclient/cid_recal?&p1=201_11_114&os=6.1&rn=1567167107&mv=&reason=4&cid=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&cid_old=&mac=5254004a04af&lhdd=C4BA-3647&hdd= | CN | — | — | suspicious |
296 | QyKernel.exe | GET | 200 | 111.206.13.61:80 | http://policy.video.iqiyi.com/policy.hcdnclient.pc.blf | CN | binary | 4.47 Kb | suspicious |
296 | QyKernel.exe | GET | 200 | 111.206.13.61:80 | http://policy.video.iqiyi.com/YKTaskConfig.blf | CN | binary | 282 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3416 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3908 | iexplore.exe | 36.110.209.200:80 | dl.static.iqiyi.com | IDC, China Telecommunications Corporation | CN | suspicious |
3908 | iexplore.exe | 36.110.209.201:80 | dl.static.iqiyi.com | IDC, China Telecommunications Corporation | CN | malicious |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | 36.110.209.200:80 | dl.static.iqiyi.com | IDC, China Telecommunications Corporation | CN | suspicious |
3368 | QiyiService.exe | 106.38.219.49:80 | msg.qy.net | IDC, China Telecommunications Corporation | CN | malicious |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | 106.38.219.49:443 | msg.qy.net | IDC, China Telecommunications Corporation | CN | malicious |
3368 | QiyiService.exe | 36.110.220.15:80 | msg.qy.net | IDC, China Telecommunications Corporation | CN | malicious |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | 36.110.220.15:80 | msg.qy.net | IDC, China Telecommunications Corporation | CN | malicious |
296 | QyKernel.exe | 39.156.40.6:3478 | — | Guangdong Mobile Communication Co.Ltd. | CN | unknown |
— | — | 120.221.8.196:3478 | — | Shandong Mobile Communication Company Limited | CN | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
dl.static.iqiyi.com |
| unknown |
dns.msftncsi.com |
| shared |
msg.qy.net |
| suspicious |
spider.pps.tv |
| suspicious |
policy.video.iqiyi.com |
| suspicious |
data.video.iqiyi.com |
| malicious |
data.video.qiyi.com |
| suspicious |
hotchat-im.iqiyi.com |
| unknown |
list3.ppstream.com.iqiyi.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3908 | iexplore.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3908 | iexplore.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2068 | ppstreamsetup_tuwenfixsetup[1].exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent (HttpDownload) |
3368 | QiyiService.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent (HttpDownload) |
2204 | QyFragment.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
2204 | QyFragment.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake FireFox Version 2. |
Process | Message |
|---|---|
ppstreamsetup_tuwenfixsetup[1].exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
ppstreamsetup_tuwenfixsetup[1].exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
ppstreamsetup_tuwenfixsetup[1].exe | NVIDIA Api not initialized
|
ppstreamsetup_tuwenfixsetup[1].exe | NVIDIA Api not initialized
|
ppstreamsetup_tuwenfixsetup[1].exe | NVIDIA Api not initialized
|
QiyiService.exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
QiyiService.exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
QyFragment.exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
QyFragment.exe | configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini |
QyFragment.exe | SkOSWindow eglInitialize failed, error code: 12289 |