File name:

360驱动大师纯净版2.0.0.2000.exe

Full analysis: https://app.any.run/tasks/b0cb13ee-97de-42ea-9231-78e6175a4828
Verdict: Malicious activity
Analysis date: July 09, 2024, 12:12:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

6BB504BCBC9E9A44A2404966CF8B0C10

SHA1:

156F3E26200E7CE936DB6583A9E8D2500A31527F

SHA256:

5ACB8AEFFDE1A8CFCE6C3CA2FA1FE711AF4AAA8AD84449CE46FF08A3E6DDE7AF

SSDEEP:

98304:iDoOmvdZ0qMyhlU+YdgKDRB7ri53wvrVBDoMHdXMjo5tjCHKvTXlF0p/Z++8lLoe:SCKKiOTTcKuoRCFoC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • 360DrvMgr.exe (PID: 5220)
    • Drops the executable file immediately after the start

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Application launched itself

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Executable content was dropped or overwritten

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Reads security settings of Internet Explorer

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360DrvMgr.exe (PID: 5220)
    • Drops 7-zip archiver for unpacking

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Checks Windows Trust Settings

      • 360DrvMgr.exe (PID: 5220)
    • Reads Microsoft Outlook installation path

      • 360DrvMgr.exe (PID: 5220)
    • Reads Internet Explorer settings

      • 360DrvMgr.exe (PID: 5220)
    • Reads the date of Windows installation

      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
    • The process verifies whether the antivirus software is installed

      • 360DrvMgr.exe (PID: 5220)
  • INFO

    • Checks supported languages

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Creates files or folders in the user directory

      • 360DrvMgr.exe (PID: 5220)
    • Reads the machine GUID from the registry

      • 360DrvMgr.exe (PID: 5220)
    • Checks proxy server information

      • 360DrvMgr.exe (PID: 5220)
    • Reads the software policy settings

      • 360DrvMgr.exe (PID: 5220)
    • UPX packer has been detected

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
    • Process checks Internet Explorer phishing filters

      • 360DrvMgr.exe (PID: 5220)
    • Reads Environment values

      • 360DrvMgr.exe (PID: 5220)
    • Create files in a temporary directory

      • 360DrvMgr.exe (PID: 5220)
      • 360驱动大师纯净版2.0.0.2000.exe (PID: 2784)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 6652)
    • Manual execution by a user

      • Taskmgr.exe (PID: 5004)
      • Taskmgr.exe (PID: 6652)
    • Reads the computer name

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
      • 360DrvMgr.exe (PID: 5220)
    • Process checks computer location settings

      • 360驱动大师纯净版2.0.0.2000.exe (PID: 916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:30 08:49:49+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 53248
InitializedDataSize: 274432
UninitializedDataSize: 344064
EntryPoint: 0x60ee0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.2000
ProductVersionNumber: 2.0.0.2000
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: 360.cn
FileDescription: 驱动大师主程序
FileVersion: 2.0.0.2000
InternalName: 360DrvMgr.exe
LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
OriginalFileName: 360DrvMgr.exe
ProductName: 驱动大师
ProductVersion: 2.0.0.2000
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT 360驱动大师纯净版2.0.0.2000.exe THREAT 360驱动大师纯净版2.0.0.2000.exe no specs 360drvmgr.exe taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe" -sfxwaitall:0 "360DrvMgr\360DrvMgr.exe" C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe
360驱动大师纯净版2.0.0.2000.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\360驱动大师纯净版2.0.0.2000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2784"C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe" C:\Users\admin\AppData\Local\Temp\360驱动大师纯净版2.0.0.2000.exe
explorer.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\360驱动大师纯净版2.0.0.2000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5004"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
5220"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exe
360驱动大师纯净版2.0.0.2000.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
驱动大师主程序
Version:
2.0.0.2000
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\360drvmgr\360drvmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6652"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
Total events
24 214
Read events
24 190
Write events
23
Delete events
1

Modification events

(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(916) 360驱动大师纯净版2.0.0.2000.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\LiveUpdate360
Operation:writeName:IsLowPC
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5220) 360DrvMgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
25
Suspicious files
13
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\atiags32.dllexecutable
MD5:A1F7D080D2A00A9DDCA9A469C29663C0
SHA256:81B7E8A1C0073F6B7C4188216A94E5AB6420844E1ACB122D93FAB4C6BC14EEBE
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360Base.dllexecutable
MD5:A73CF0457DF35FAB74EF3393D2766667
SHA256:DF411EBC1B4A652A3822DE0CEBD5A48151ABB3DD99C8C3D15F858401B27243FD
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\ComputerZ5.dllexecutable
MD5:D8308AA7CC08C3A56C9187029DB56702
SHA256:850BB1419AB0C93D524284A6C9C15DB69A1E5328E9F84F06BB27BA5EFB8A65B8
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\cacert.dattext
MD5:E10C92A310813373102FE1B5AC4CA476
SHA256:2F8436D3568FA6BBA1BEBF367DB6F50E1A0C4E0C38544A268EB5E01B30191776
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360P2SP.dllexecutable
MD5:75AE5114927B0200EA73E016211AE572
SHA256:8E38AEB187EDD59329007FE10D2B509E5566256E993A127902D57BAC66B17346
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360NetBase.dllexecutable
MD5:14C6B4BBD31F6FD13530BC941CC71D1A
SHA256:401D8529A84F1D80A439BE8CD4E869202162458E5AFB5E5BAC97C4859BFE8EB5
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\config\defaultskin\defaultskin.uicompressed
MD5:0CC06E728803D0CDEEDDA92E04313E6C
SHA256:3FB6414E92BE15821C674A6E72295E75747E9734C827AC14E85479D4720F2B33
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360net.dllexecutable
MD5:2BCA9E782840C8214DBC3EF6EE64404C
SHA256:1320CE2BF517978D3C65CF9CB8390318F3EA1896EF10A66B53A1832792341C62
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\config\config.xmlxml
MD5:583E167BA709FEC11044409C6B09D04F
SHA256:EA5F4FAF853767718BEEF85023FCD9E13CCA2127EBB3C17331903779DB2916A0
2784360驱动大师纯净版2.0.0.2000.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\360DrvMgr\360DrvMgr.exeexecutable
MD5:D57C5DC032F2AD8EF18D07410F54772B
SHA256:CDC9F01C71FC1A5814760824ED73F5E4CCA103D8418AE946ECF1F68CB800A8F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
84
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5220
360DrvMgr.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=0&e=1&in=1&o=10.0.19045&p=64&i=1661339444&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&ver=&rpid=&pid=&f=0&g=0&dm=1
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=7&e=12&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&o=10.0.19045&p=64&ver=&rpid=&pid=&dm=1&i=7
unknown
unknown
4092
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
5220
360DrvMgr.exe
POST
200
104.192.110.254:80
http://conf.wsm.360.cn/client/query2?m=c3375a2e510ecaee01a0a4820a727e6e&t=1905562&s=qingli_cleansoft
unknown
unknown
2180
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
5220
360DrvMgr.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQDVbiRslO1jq7FG78GWtk%2Bw
unknown
unknown
5220
360DrvMgr.exe
GET
106.63.24.37:80
http://crl.crlocsp.cn/WoTrusDVServerCA_2.crl
unknown
unknown
5220
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=7&e=501&mid=c3375a2e510ecaee01a0a4820a727e6e&m2=eeeeeeee77e256d0cc4755a6dd1f6ad7651f60d32b83&o=10.0.19045&p=64&ver=&rpid=&pid=&dm=1&d=1
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4392
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
2272
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1060
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
unknown
3680
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3040
OfficeClickToRun.exe
52.111.227.11:443
nexusrules.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3680
svchost.exe
192.229.221.95:80
EDGECAST
US
whitelisted
5220
360DrvMgr.exe
192.229.221.95:80
EDGECAST
US
whitelisted
5220
360DrvMgr.exe
104.192.110.254:80
conf.wsm.360.cn
Beijing Qihu Technology Company Limited
US
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.35.238.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.136
  • 20.190.160.20
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.71
whitelisted
conf.wsm.360.cn
  • 104.192.110.254
unknown
arc.msn.com
  • 20.24.249.45
  • 20.103.156.88
whitelisted
res.qhsetup.com
  • 1.192.137.108
  • 180.163.237.138
  • 106.39.219.55
unknown
dm.weishi.360.cn
  • 106.63.103.7
unknown
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info