File name:

360.exe

Full analysis: https://app.any.run/tasks/0dea4b9e-f8a6-4afa-9f94-2262968b4aa9
Verdict: Malicious activity
Analysis date: July 07, 2024, 19:31:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

942BA029A58E5F9735B8D76E1B9546A6

SHA1:

F2791CFA10FF6D6D62059550A478206F8E7A2D5E

SHA256:

47C8D6AD0FAF8DF228858C38B368F93AFEE51D415F4664E04FA8690544EDDA60

SSDEEP:

98304:CAxpzDT6HICqRcbp30cxxHuXwcTu3KRkxe+WrFVeBDtP78Q6lCGRkex:CMD2HlzxHFcTuaRkxe+WJVehmQ4CGRBx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 360.exe (PID: 6188)
    • Actions looks like stealing of personal data

      • Taskmgr.exe (PID: 1660)
      • 360.exe (PID: 6188)
    • Changes the autorun value in the registry

      • reg.exe (PID: 5288)
    • Application was injected by another process

      • sihost.exe (PID: 4156)
      • svchost.exe (PID: 4184)
      • svchost.exe (PID: 4228)
      • explorer.exe (PID: 4612)
      • RuntimeBroker.exe (PID: 5088)
      • svchost.exe (PID: 4824)
      • RuntimeBroker.exe (PID: 5256)
      • dllhost.exe (PID: 5352)
      • UserOOBEBroker.exe (PID: 844)
      • dllhost.exe (PID: 6096)
      • svchost.exe (PID: 3644)
      • RuntimeBroker.exe (PID: 6920)
      • RuntimeBroker.exe (PID: 6744)
      • MusNotificationUx.exe (PID: 2028)
      • RuntimeBroker.exe (PID: 5796)
      • ApplicationFrameHost.exe (PID: 1028)
      • RuntimeBroker.exe (PID: 6704)
      • MusNotifyIcon.exe (PID: 3692)
    • Runs injected code in another process

      • dialer.exe (PID: 640)
  • SUSPICIOUS

    • Uses REG/REGEDIT.EXE to modify registry

      • 360.exe (PID: 6188)
    • Executable content was dropped or overwritten

      • 360.exe (PID: 6188)
    • Starts itself from another location

      • 360.exe (PID: 6188)
  • INFO

    • Reads security settings of Internet Explorer

      • RuntimeBroker.exe (PID: 6744)
      • explorer.exe (PID: 4612)
      • Taskmgr.exe (PID: 1660)
    • Manual execution by a user

      • 360.exe (PID: 3692)
      • Taskmgr.exe (PID: 1660)
      • Taskmgr.exe (PID: 2832)
    • Checks supported languages

      • 360.exe (PID: 6188)
      • 360.exe (PID: 3692)
      • 360tray.exe (PID: 884)
    • Creates files or folders in the user directory

      • 360.exe (PID: 6188)
    • Creates files in the program directory

      • MusNotificationUx.exe (PID: 2028)
      • MusNotifyIcon.exe (PID: 3692)
    • Reads the time zone

      • MusNotificationUx.exe (PID: 2028)
      • MusNotifyIcon.exe (PID: 3692)
    • Create files in a temporary directory

      • RuntimeBroker.exe (PID: 6704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:04:10 23:00:36+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 25600
InitializedDataSize: 7436800
UninitializedDataSize: -
EntryPoint: 0x1140
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 12.0.0.1851
ProductVersionNumber: 12.0.0.1851
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: 360安全卫士
FileTitle: 360Tray.exe
FileDescription: 360安全卫士 安全防护中心模块
FileVersion: 12,0,0,1851
LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
LegalTrademark: 360安全卫士 安全防护中心模块
ProductName: 360.cn
ProductVersion: 12,0,0,1851
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
28
Malicious processes
4
Suspicious processes
18

Behavior graph

Click at the process to see the details
start 360.exe runtimebroker.exe runtimebroker.exe runtimebroker.exe 360.exe taskmgr.exe no specs taskmgr.exe dialer.exe no specs reg.exe conhost.exe no specs 360tray.exe no specs musnotificationux.exe sppextcomobj.exe no specs slui.exe no specs musnotifyicon.exe useroobebroker.exe applicationframehost.exe svchost.exe sihost.exe svchost.exe svchost.exe explorer.exe svchost.exe runtimebroker.exe runtimebroker.exe dllhost.exe runtimebroker.exe dllhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
640C:\WINDOWS\system32\dialer.exeC:\Windows\System32\dialer.exe360.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Phone Dialer
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dialer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
844C:\Windows\System32\oobe\UserOOBEBroker.exe -EmbeddingC:\Windows\System32\oobe\UserOOBEBroker.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
User OOBE Broker
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\oobe\useroobebroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
884"C:\Users\admin\AppData\Roaming\360\360tray.exe"C:\Users\admin\AppData\Roaming\360\360tray.exe360.exe
User:
admin
Company:
360安全卫士
Integrity Level:
MEDIUM
Description:
360安全卫士 安全防护中心模块
Exit code:
0
Version:
12,0,0,1851
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\roaming\360\360tray.exe
c:\windows\system32\ntdll.dll
1028C:\WINDOWS\system32\ApplicationFrameHost.exe -EmbeddingC:\Windows\System32\ApplicationFrameHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Application Frame Host
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\applicationframehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\win32u.dll
1660"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2028%systemroot%\system32\MusNotificationUx.exe ClearActiveNotificationsC:\Windows\System32\MusNotificationUx.exe
MusNotification.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MusNotificationUx.exe
Exit code:
0
Version:
10.0.19041.3693 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\musnotificationux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcp_win.dll
2832"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
3644C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroupC:\Windows\System32\svchost.exe
services.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3692"C:\Users\admin\Desktop\360.exe" C:\Users\admin\Desktop\360.exe
explorer.exe
User:
admin
Company:
360安全卫士
Integrity Level:
HIGH
Description:
360安全卫士 安全防护中心模块
Exit code:
0
Version:
12,0,0,1851
Modules
Images
c:\users\admin\desktop\360.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
3692%systemroot%\system32\MusNotifyIcon.exe NotifyTrayIcon 13C:\Windows\System32\MusNotifyIcon.exe
MusNotification.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MusNotifyIcon.exe
Exit code:
2149884437
Version:
10.0.19041.3693 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\musnotifyicon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
39 366
Read events
39 327
Write events
38
Delete events
1

Modification events

(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010016000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C00000011000000000000006100670065006E0074006D0069006E0064002E007200740066003E00200020000000150000000000000061006E0079007400680069006E0067006200750069006C0074002E006A00700067003E0020002000000017000000000000006300680069006E00650073006500660065006100740075007200650064002E007200740066003E00200020000000160000000000000063006F006D006D0075006E00690074007900770068006500720065002E0070006E0067003E002000200000001100000000000000670072006F00770074006800630075006D002E007200740066003E0020002000000012000000000000006F007600650072006D0061006B0069006E0067002E007200740066003E002000200000001000000000000000700061006700650068006100720064002E007200740066003E00200020000000160000000000000070006100720074006E0065007200730073006500610073006F006E002E0070006E0067003E00200020000000130000000000000072006F006F00740073007400750064006900650073002E007200740066003E00200020000000130000000000000073006F007500720063006500730076006F00740065002E007200740066003E002000200000001100000000000000740068006500730065006C006900660065002E0070006E0067003E002000200000001900000000000000770061007300680069006E00670074006F006E00720065006C0061007400650064002E0070006E0067003E00200020000000130000000000000079006F007500740068006100670065006E00630079002E006A00700067003E002000200000000B000000000000003300360030002E006500780065003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001600000000000000000000000000000000000000803F0000004008000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A040110000004040000000001200000040400000803F130000004040000000401400000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F070000004040000040401500
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
0FED8A6600000000
(PID) Process:(4156) sihost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Search_cw5n1h2txyewy
Operation:writeName:WasEverActivated
Value:
1
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A7803901000062B06A59D2B415429F74E9109B0A815348010000
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search
Operation:writeName:TraySearchBoxVisible
Value:
1
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search
Operation:writeName:TraySearchBoxVisibleOnAnyMonitor
Value:
1
(PID) Process:(1660) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:delete valueName:Preferences
Value:
(PID) Process:(4612) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060258
Operation:writeName:VirtualDesktop
Value:
1000000030304456249F86704CD0354CAF53943DFF6B26B6
(PID) Process:(1660) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AADFD7F67F0000000000000000000000000000EA0000001E0000008990000000000000FF00000001015002000000000D0000000000000098AADFD7F67F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AADFD7F67F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AADFD7F67F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AADFD7F67F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000ABDFD7F67F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028ABDFD7F67F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050ABDFD7F67F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AADFD7F67F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070ABDFD7F67F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088ABDFD7F67F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8ABDFD7F67F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8ABDFD7F67F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0ABDFD7F67F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010ACDFD7F67F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AADFD7F67F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AADFD7F67F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AADFD7F67F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040ACDFD7F67F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068ACDFD7F67F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090ACDFD7F67F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8ACDFD7F67F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8ACDFD7F67F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8ACDFD7F67F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028ABDFD7F67F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AADFD7F67F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020ADDFD7F67F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040ADDFD7F67F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068ADDFD7F67F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AADFD7F67F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050ABDFD7F67F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AADFD7F67F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070ABDFD7F67F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088ABDFD7F67F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8ABDFD7F67F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8ABDFD7F67F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AADFD7F67F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088ADDFD7F67F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8ADDFD7F67F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0ADDFD7F67F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AEDFD7F67F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AEDFD7F67F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AEDFD7F67F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AEDFD7F67F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000
Executable files
1
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4612explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
5352dllhost.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\V01.chkbinary
MD5:3890B5B92B625A13279C90A57416264F
SHA256:682FFA5727D0AA334B32FD1C725855D1FB68D86D21680B9F32834AECF61C2395
6704RuntimeBroker.exeC:\Users\admin\AppData\Local\Temp\StructuredQuery.logtext
MD5:120EAEB5EAC441402AFEF17E2624DE5D
SHA256:4746791E5F4C5CC0A6C74EE27F8D0CE7C65CF48E80A9B33A0C15F6A8C638C8DB
1660Taskmgr.exeC:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.locktext
MD5:F49655F856ACB8884CC0ACE29216F511
SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA
6188360.exeC:\Users\admin\AppData\Roaming\360\360tray.exeexecutable
MD5:942BA029A58E5F9735B8D76E1B9546A6
SHA256:47C8D6AD0FAF8DF228858C38B368F93AFEE51D415F4664E04FA8690544EDDA60
3692MusNotifyIcon.exeC:\ProgramData\USOShared\Logs\User\NotifyIcon.c47f00bf-7e12-4e42-853f-39431d01e04a.1.etlbinary
MD5:CFC5DAE8144B4322B930BCDCD9F6B5CD
SHA256:FF284FA165C559396F685953139F4D041C1B073A011CA54BF6D14F0485B0AE23
2028MusNotificationUx.exeC:\ProgramData\USOShared\Logs\User\NotificationUx.d777f7ba-1c97-41a6-910e-cbe80878ee36.1.etletl
MD5:617045BA89F4D79126902CD8B6AE60DB
SHA256:BE2FC7A1E63A77E02C3CA099FC55CD20CAFEDD8AAAE17BF81F9BCADCA7939252
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
48
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6412
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
4004
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5680
svchost.exe
GET
200
23.48.23.181:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
5680
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
6324
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5680
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1764
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1776
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4004
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4004
svchost.exe
192.229.221.95:80
EDGECAST
US
whitelisted
1060
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
unknown
3040
OfficeClickToRun.exe
52.111.236.22:443
nexusrules.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5680
svchost.exe
23.48.23.181:80
crl.microsoft.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.138
  • 40.126.32.74
  • 40.126.32.68
  • 40.126.32.76
  • 40.126.32.133
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
crl.microsoft.com
  • 23.48.23.181
  • 23.48.23.177
  • 23.48.23.174
  • 23.48.23.179
  • 23.48.23.188
  • 23.48.23.190
  • 23.48.23.176
  • 23.48.23.185
  • 23.48.23.178
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info