URL:

http://dl.static.iqiyi.com/ppstreamsetup_tuwenfixsetup.exe

Full analysis: https://app.any.run/tasks/51e2e2ee-e243-461d-b468-486389a91bb7
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: August 30, 2019, 12:10:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

2B338B91A24F8D3083BAD185B67DD02B

SHA1:

E1E696EE9C93417A1DA28E0A7986FE2668C0EA1D

SHA256:

3984059D8F9894C851FCD99E4B3BDD0A827FFB836125DA92A8C71B4DB88C069E

SSDEEP:

3:N1KaJy4rxWHWQ2SAgA:CaJ5xeW5kA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
      • QiyiDACL.exe (PID: 2328)
      • QiyiDACL.exe (PID: 2980)
      • QiyiService.exe (PID: 2992)
      • QyKernel.exe (PID: 296)
      • QyFragment.exe (PID: 2144)
      • QiyiService.exe (PID: 3368)
      • QyFragment.exe (PID: 2204)
      • explorer.exe (PID: 276)
      • DllHost.exe (PID: 3960)
      • conhost.exe (PID: 2752)
      • QyFragment.exe (PID: 2376)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3908)
    • Adds new firewall rule via NETSH.EXE

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Changes the autorun value in the registry

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Application was dropped or rewritten from another process

      • QiyiDACL.exe (PID: 2328)
      • QiyiDACL.exe (PID: 2980)
      • QiyiService.exe (PID: 2992)
      • QyFragment.exe (PID: 2204)
      • QiyiService.exe (PID: 3368)
      • QyFragment.exe (PID: 2376)
      • QyFragment.exe (PID: 2144)
      • QyKernel.exe (PID: 296)
  • SUSPICIOUS

    • Starts Internet Explorer

      • explorer.exe (PID: 276)
    • Creates files in the Windows directory

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Reads Environment values

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Creates files in the user directory

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
      • QyFragment.exe (PID: 2144)
      • QyFragment.exe (PID: 2204)
      • QyFragment.exe (PID: 2376)
    • Modifies the open verb of a shell class

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Uses NETSH.EXE for network configuration

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Executed as Windows Service

      • QiyiService.exe (PID: 3368)
    • Changes IE settings (feature browser emulation)

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Executable content was dropped or overwritten

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Creates a software uninstall entry

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Creates files in the program directory

      • QyFragment.exe (PID: 2204)
      • QiyiService.exe (PID: 3368)
      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Application launched itself

      • QyFragment.exe (PID: 2204)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3416)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3908)
      • iexplore.exe (PID: 3416)
    • Changes internet zones settings

      • iexplore.exe (PID: 3416)
    • Dropped object may contain Bitcoin addresses

      • ppstreamsetup_tuwenfixsetup[1].exe (PID: 2068)
    • Manual execution by user

      • QyKernel.exe (PID: 296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
69
Monitored processes
22
Malicious processes
11
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe ppstreamsetup_tuwenfixsetup[1].exe no specs ppstreamsetup_tuwenfixsetup[1].exe qiyidacl.exe no specs qiyidacl.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs qiyiservice.exe no specs qiyiservice.exe qyfragment.exe qykernel.exe qyfragment.exe qyfragment.exe no specs explorer.exe Thumbnail Cache Out of Proc Server tracert.exe no specs conhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
276C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
296"C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyKernel.exe" C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyKernel.exe
explorer.exe
User:
admin
Company:
iQIYI.COM
Integrity Level:
MEDIUM
Description:
IQIYI Video Helper
Exit code:
0
Version:
15.0.1.680
Modules
Images
c:\program files\iqiyi video\lstyle\6.8.89.6786\qykernel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1424"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="爱奇艺视频播放器组件" dir=in program="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyPlayer.exe" action=allow description="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyPlayer.exe"C:\Windows\system32\netsh.exeppstreamsetup_tuwenfixsetup[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2068"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe
iexplore.exe
User:
admin
Company:
爱奇艺
Integrity Level:
HIGH
Description:
爱奇艺 修复程序
Exit code:
0
Version:
6.8.89.6786
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\lh043oam\ppstreamsetup_tuwenfixsetup[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2128"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="爱奇艺奇秀客户端" dir=in program="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QYAppPlugin\qixiu\QXClient.exe" action=allow description="C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QYAppPlugin\qixiu\QXClient.exe"C:\Windows\system32\netsh.exeppstreamsetup_tuwenfixsetup[1].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2144"C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=makeppstat --ppsdat=010110111567167108C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe
ppstreamsetup_tuwenfixsetup[1].exe
User:
admin
Company:
爱奇艺
Integrity Level:
HIGH
Description:
爱奇艺视频辅助程序
Exit code:
0
Version:
6.8.89.6786
Modules
Images
c:\program files\iqiyi video\lstyle\6.8.89.6786\qyfragment.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\quilib.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\gbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winmm.dll
2204"C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=parkerC:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe
QyKernel.exe
User:
admin
Company:
爱奇艺
Integrity Level:
MEDIUM
Description:
爱奇艺视频辅助程序
Exit code:
0
Version:
6.8.89.6786
Modules
Images
c:\program files\iqiyi video\lstyle\6.8.89.6786\qyfragment.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\quilib.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\gbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winmm.dll
2328"C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QiyiDACL.exe" QiyiUpdate "C:\Program Files\Common Files\IQIYI Video" trueC:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QiyiDACL.exeppstreamsetup_tuwenfixsetup[1].exe
User:
admin
Company:
爱奇艺
Integrity Level:
HIGH
Description:
爱奇艺组件
Exit code:
0
Version:
2.0.0.1
Modules
Images
c:\program files\iqiyi video\lstyle\6.8.89.6786\qiyidacl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2376"C:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exe" --runmode=bubbleC:\Program Files\IQIYI Video\LStyle\6.8.89.6786\QyFragment.exeQyFragment.exe
User:
admin
Company:
爱奇艺
Integrity Level:
MEDIUM
Description:
爱奇艺视频辅助程序
Exit code:
0
Version:
6.8.89.6786
Modules
Images
c:\program files\iqiyi video\lstyle\6.8.89.6786\qyfragment.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\quilib.dll
c:\program files\iqiyi video\lstyle\6.8.89.6786\gbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winmm.dll
2752\??\C:\Windows\system32\conhost.exeC:\Windows\system32\conhost.exe
csrss.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\conhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
3 448
Read events
2 950
Write events
488
Delete events
10

Modification events

(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{20210393-CB1F-11E9-B86F-5254004A04AF}
Value:
0
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(3416) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307080005001E000C000A0010002903
Executable files
140
Suspicious files
15
Text files
2 967
Unknown types
20

Dropped files

PID
Process
Filename
Type
3416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3416iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF58ECFD859A7501A0.TMP
MD5:
SHA256:
3908iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LN9SI0ZZ\ppstreamsetup_tuwenfixsetup[1].exe
MD5:
SHA256:
3416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ppstreamsetup_tuwenfixsetup[1].exe
MD5:
SHA256:
3416iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF8430B6F0ADECB089.TMP
MD5:
SHA256:
3416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{20210393-CB1F-11E9-B86F-5254004A04AF}.dat
MD5:
SHA256:
2068ppstreamsetup_tuwenfixsetup[1].exeC:\Users\admin\AppData\Local\Temp\nsyA450.tmp\nsrB99F.tmp
MD5:
SHA256:
3908iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:C7803EC52D0C8B048A85C272AB26F722
SHA256:CF3C1ABE248E31AEEF55772E593C4E842463B6826685D14CF24DBE6BB8CE2F41
2068ppstreamsetup_tuwenfixsetup[1].exeC:\Users\admin\AppData\Local\Temp\nsyA450.tmp\System.dllexecutable
MD5:DDA1197A2890D6A617346EC1D20A729F
SHA256:2A26DC9CE6683FB702DF403BB6FAE70C4A2D86A39B7FAEA673D5D7A08BA9573E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
118
DNS requests
53
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2068
ppstreamsetup_tuwenfixsetup[1].exe
GET
200
36.110.209.200:80
http://dl.static.iqiyi.com/bundled/config_encode.php?type=install&v=6.8.89.6786&w=61&f=fixsetup&lpi=NoPPSPid&new=0&ini=1&lang=1033&isv=0&rn=184307&ss=L&skb=1&home=about:blank
CN
text
1.14 Kb
suspicious
2068
ppstreamsetup_tuwenfixsetup[1].exe
GET
200
36.110.209.200:80
http://spider.pps.tv/ppstream/config_encode.php?type=install&v=6.8.89.6786&w=61&f=fixsetup&lpi=NoPPSPid&new=0&ini=1&lang=1033&isv=0&rn=394727&ss=L&skb=1&home=about:blank
CN
text
2.11 Kb
suspicious
296
QyKernel.exe
GET
200
111.206.13.61:80
http://policy.video.iqiyi.com/policy.qtp.qtpconfig.blf
CN
binary
12.0 Kb
suspicious
296
QyKernel.exe
GET
200
101.227.188.198:80
http://data.video.iqiyi.com/v.f4v
CN
text
213 b
malicious
2068
ppstreamsetup_tuwenfixsetup[1].exe
GET
200
36.110.220.15:80
http://msg.qy.net/v5/pcclient/cid_recal?&p1=201_11_114&os=6.1&rn=1567167103&mv=&reason=1&cid=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&cid_old=&mac=5254004a04af&lhdd=C4BA-3647&hdd=
CN
suspicious
3368
QiyiService.exe
GET
200
106.38.219.49:80
http://msg.qy.net/b?t=11&type=70&pf=1&p=11&p1=114&c1=&s1=2&channelid=&nu=&e=&se=&r=&u=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&pu=&rn=00000001567167107&v=6.8.89.6786
CN
suspicious
296
QyKernel.exe
GET
200
111.206.13.61:80
http://policy.video.iqiyi.com/policy.mssconfig.pc.json
CN
text
492 b
suspicious
3368
QiyiService.exe
GET
200
36.110.220.15:80
http://msg.qy.net/v5/pcclient/cid_recal?&p1=201_11_114&os=6.1&rn=1567167107&mv=&reason=4&cid=kjkaasqev4hcunfcsmvbdwkglhnzyk4m&cid_old=&mac=5254004a04af&lhdd=C4BA-3647&hdd=
CN
suspicious
296
QyKernel.exe
GET
200
111.206.13.61:80
http://policy.video.iqiyi.com/policy.hcdnclient.pc.blf
CN
binary
4.47 Kb
suspicious
296
QyKernel.exe
GET
200
111.206.13.61:80
http://policy.video.iqiyi.com/YKTaskConfig.blf
CN
binary
282 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3416
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3908
iexplore.exe
36.110.209.200:80
dl.static.iqiyi.com
IDC, China Telecommunications Corporation
CN
suspicious
3908
iexplore.exe
36.110.209.201:80
dl.static.iqiyi.com
IDC, China Telecommunications Corporation
CN
malicious
2068
ppstreamsetup_tuwenfixsetup[1].exe
36.110.209.200:80
dl.static.iqiyi.com
IDC, China Telecommunications Corporation
CN
suspicious
3368
QiyiService.exe
106.38.219.49:80
msg.qy.net
IDC, China Telecommunications Corporation
CN
malicious
2068
ppstreamsetup_tuwenfixsetup[1].exe
106.38.219.49:443
msg.qy.net
IDC, China Telecommunications Corporation
CN
malicious
3368
QiyiService.exe
36.110.220.15:80
msg.qy.net
IDC, China Telecommunications Corporation
CN
malicious
2068
ppstreamsetup_tuwenfixsetup[1].exe
36.110.220.15:80
msg.qy.net
IDC, China Telecommunications Corporation
CN
malicious
296
QyKernel.exe
39.156.40.6:3478
Guangdong Mobile Communication Co.Ltd.
CN
unknown
120.221.8.196:3478
Shandong Mobile Communication Company Limited
CN
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dl.static.iqiyi.com
  • 36.110.209.201
  • 36.110.209.200
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
msg.qy.net
  • 106.38.219.49
  • 36.110.220.15
suspicious
spider.pps.tv
  • 36.110.209.200
  • 36.110.209.201
suspicious
policy.video.iqiyi.com
  • 111.206.13.61
  • 111.206.13.62
  • 111.206.13.63
  • 111.206.13.64
  • 111.206.13.65
  • 111.206.13.66
suspicious
data.video.iqiyi.com
  • 101.227.188.198
  • 101.227.188.199
  • 101.227.200.133
  • 101.227.200.142
  • 101.227.200.143
  • 101.227.200.146
  • 101.227.200.147
  • 101.227.200.148
  • 101.227.200.149
  • 101.227.200.150
  • 101.227.200.156
  • 101.227.200.157
malicious
data.video.qiyi.com
  • 101.227.188.198
  • 101.227.188.199
  • 101.227.200.133
  • 101.227.200.142
  • 101.227.200.143
  • 101.227.200.146
  • 101.227.200.147
  • 101.227.200.148
  • 101.227.200.149
  • 101.227.200.150
  • 101.227.200.156
  • 101.227.200.157
suspicious
hotchat-im.iqiyi.com
  • 49.7.32.94
unknown
list3.ppstream.com.iqiyi.com
  • 36.110.209.200
  • 36.110.209.201
unknown

Threats

PID
Process
Class
Message
3908
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3908
iexplore.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2068
ppstreamsetup_tuwenfixsetup[1].exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (HttpDownload)
3368
QiyiService.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (HttpDownload)
2204
QyFragment.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake FireFox Version 2.
2204
QyFragment.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake FireFox Version 2.
Process
Message
ppstreamsetup_tuwenfixsetup[1].exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
ppstreamsetup_tuwenfixsetup[1].exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
ppstreamsetup_tuwenfixsetup[1].exe
NVIDIA Api not initialized
ppstreamsetup_tuwenfixsetup[1].exe
NVIDIA Api not initialized
ppstreamsetup_tuwenfixsetup[1].exe
NVIDIA Api not initialized
QiyiService.exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
QiyiService.exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
QyFragment.exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
QyFragment.exe
configFileName:C:\Users\Public\QiYi\QiyiHCDN\Config\psnetwork.ini
QyFragment.exe
SkOSWindow eglInitialize failed, error code: 12289