File name:

360驱动大师纯净版2.0.0.2000.exe

Full analysis: https://app.any.run/tasks/b0cb13ee-97de-42ea-9231-78e6175a4828
Verdict: Malicious activity
Analysis date: July 09, 2024, 12:12:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

6BB504BCBC9E9A44A2404966CF8B0C10

SHA1:

156F3E26200E7CE936DB6583A9E8D2500A31527F

SHA256:

5ACB8AEFFDE1A8CFCE6C3CA2FA1FE711AF4AAA8AD84449CE46FF08A3E6DDE7AF

SSDEEP:

98304:iDoOmvdZ0qMyhlU+YdgKDRB7ri53wvrVBDoMHdXMjo5tjCHKvTXlF0p/Z++8lLoe:SCKKiOTTcKuoRCFoC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • 360DrvMgr.exe (PID: 5220)
    • Drops the executable file immediately after the start

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Reads security settings of Internet Explorer

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360DrvMgr.exe (PID: 5220)
    • Checks Windows Trust Settings

      • 360DrvMgr.exe (PID: 5220)
    • Process drops legitimate windows executable

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Application launched itself

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Reads Microsoft Outlook installation path

      • 360DrvMgr.exe (PID: 5220)
    • The process verifies whether the antivirus software is installed

      • 360DrvMgr.exe (PID: 5220)
    • Reads Internet Explorer settings

      • 360DrvMgr.exe (PID: 5220)
    • Reads the date of Windows installation

      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
    • Executable content was dropped or overwritten

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
  • INFO

    • Creates files or folders in the user directory

      • 360DrvMgr.exe (PID: 5220)
    • Reads the machine GUID from the registry

      • 360DrvMgr.exe (PID: 5220)
    • Reads the software policy settings

      • 360DrvMgr.exe (PID: 5220)
    • Process checks computer location settings

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
    • Reads the computer name

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360DrvMgr.exe (PID: 5220)
    • Checks supported languages

      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Checks proxy server information

      • 360DrvMgr.exe (PID: 5220)
    • UPX packer has been detected

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
    • Process checks Internet Explorer phishing filters

      • 360DrvMgr.exe (PID: 5220)
    • Reads Environment values

      • 360DrvMgr.exe (PID: 5220)
    • Manual execution by a user

      • Taskmgr.exe (PID: 5004)
      • Taskmgr.exe (PID: 6652)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 6652)
    • Create files in a temporary directory

      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:30 08:49:49+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 53248
InitializedDataSize: 274432
UninitializedDataSize: 344064
EntryPoint: 0x60ee0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.2000
ProductVersionNumber: 2.0.0.2000
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: 360.cn
FileDescription: 驱动大师主程序
FileVersion: 2.0.0.2000
InternalName: 360DrvMgr.exe
LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
OriginalFileName: 360DrvMgr.exe
ProductName: 驱动大师
ProductVersion: 2.0.0.2000
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT 360驱动大师纯净版2.0.0.2000.exe THREAT 360驱动大师纯净版2.0.0.2000.exe no specs 360drvmgr.exe taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe" -sfxwaitall:0 "360DrvMgr\360DrvMgr.exe" C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe
360驱动大师纯净版2.0.0.2000.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\360驱动大师纯净版2.0.0.2000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2784"C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe" C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe
explorer.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\360驱动大师纯净版2.0.0.2000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5004"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
5220"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exe
360驱动大师纯净版2.0.0.2000.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\360drvmgr\360drvmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6652"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
Total events
24 214
Read events
24 190
Write events
23
Delete events
1

Modification events

(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\LiveUpdate360
Operation:writeName:IsLowPC
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
25
Suspicious files
13
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360Base.dllexecutable
MD5:A73CF0457DF35FAB74EF3393D2766667
SHA256:DF411EBC1B4A652A3822DE0CEBD5A48151ABB3DD99C8C3D15F858401B27243FD
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exeexecutable
MD5:D57C5DC032F2AD8EF18D07410F54772B
SHA256:CDC9F01C71FC1A5814760824ED73F5E4CCA103D8418AE946ECF1F68CB800A8F5
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360LibDrvmgr.datbinary
MD5:558127B5BAA12EE8AF3BFAEE9ABE2579
SHA256:FBD649E49EBEA36794D40716314BD4121B0F1EE5C0EC75F7C325345633F0A03D
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\7za.dllexecutable
MD5:34F4329522A2B16D1BC9AD4AB58D9FC1
SHA256:FC07200668D45A640BBD5F6997851E31A20941FCB661F8E09469899BECEBDF8A
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360net.dllexecutable
MD5:2BCA9E782840C8214DBC3EF6EE64404C
SHA256:1320CE2BF517978D3C65CF9CB8390318F3EA1896EF10A66B53A1832792341C62
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\cacert.dattext
MD5:E10C92A310813373102FE1B5AC4CA476
SHA256:2F8436D3568FA6BBA1BEBF367DB6F50E1A0C4E0C38544A268EB5E01B30191776
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\ComputerZ1.dllexecutable
MD5:6DBF812D5B61F30A21DDCCAEC30B4452
SHA256:197C529ACFF08FBC13B11010D95C270E50DDD867F783CFEC598C5F831F847033
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\ComputerZService.exeexecutable
MD5:4CC0DCA3267469362678CF23133937E2
SHA256:48428B09F1900C7AA4B3E74661325E9FF93963D32B202FD0E60DECA8A672772F
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360P2SP.dllexecutable
MD5:75AE5114927B0200EA73E016211AE572
SHA256:8E38AEB187EDD59329007FE10D2B509E5566256E993A127902D57BAC66B17346
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\ComputerZ5.dllexecutable
MD5:D8308AA7CC08C3A56C9187029DB56702
SHA256:850BB1419AB0C93D524284A6C9C15DB69A1E5328E9F84F06BB27BA5EFB8A65B8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
84
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3680
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5220
360DrvMgr.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
unknown
5220
360DrvMgr.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAXebB5tyzTfmGmu3BV%2FByU%3D
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=7&e=5&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&o=10.0.19045&p=64&ver=&rpid=&pid=&dm=1
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=0&e=1&in=1&o=10.0.19045&p=64&i=1661339444&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&ver=&rpid=&pid=&f=0&g=0&dm=1
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=7&e=12&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&o=10.0.19045&p=64&ver=&rpid=&pid=&dm=1&i=7
unknown
unknown
4092
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
7156
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
7156
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
5220
360DrvMgr.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQDVbiRslO1jq7FG78GWtk%2Bw
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4392
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
2272
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1060
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
unknown
3680
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3040
OfficeClickToRun.exe
52.111.227.11:443
nexusrules.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3680
svchost.exe
192.229.221.95:80
EDGECAST
US
whitelisted
5220
360DrvMgr.exe
192.229.221.95:80
EDGECAST
US
whitelisted
5220
360DrvMgr.exe
104.192.110.254:80
conf.wsm.360.cn
Beijing Qihu Technology Company Limited
US
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.35.238.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.136
  • 20.190.160.20
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.71
whitelisted
conf.wsm.360.cn
  • 104.192.110.254
unknown
arc.msn.com
  • 20.24.249.45
  • 20.103.156.88
whitelisted
res.qhsetup.com
  • 1.192.137.108
  • 180.163.237.138
  • 106.39.219.55
unknown
dm.weishi.360.cn
  • 106.63.103.7
unknown
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info