| File name: | 点击此处安装语言包.exe |
| Full analysis: | https://app.any.run/tasks/f015aabf-c919-4424-953f-387a13e9dcb1 |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2024, 09:11:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B870E407C73E0E67598A2BD52BE901D3 |
| SHA1: | EAC8FE722AB0B8AE08A6A246B2CDED4368B65EEF |
| SHA256: | 5AD6A353F211050D91B196DBC85958629888BFA4DB8828A2F7B941B90655CAF7 |
| SSDEEP: | 49152:zlu5dF7/u+xLysh1FYShjSdkwOunK0YHw0hRWQiLrmyN+:z4tDu+LVYM+37nK0YQ0viPmZ |
| .exe | | | Win64 Executable (generic) (49.4) |
|---|---|---|
| .scr | | | Windows screen saver (23.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (11.7) |
| .exe | | | Win32 Executable (generic) (8) |
| .exe | | | Generic Win/DOS Executable (3.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:10:15 07:41:44+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 548864 |
| InitializedDataSize: | 315392 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xec2c6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6388 | "C:\Users\admin\AppData\Local\Temp\点击此处安装语言包.exe" | C:\Users\admin\AppData\Local\Temp\点击此处安装语言包.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6580 | C:\Users\Public\Videos\VSTelem\msdot\msdot.exe | C:\Users\Public\Videos\VSTelem\msdot\msdot.exe | 点击此处安装语言包.exe | ||||||||||||
User: admin Company: CyberLink Corp. Integrity Level: MEDIUM Description: PowerDVD Language Application Version: 1.00.3413 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6580 | msdot.exe | C:\ProgramData\Lexicon\Setting.dt | — | |
MD5:— | SHA256:— | |||
| 6388 | 点击此处安装语言包.exe | C:\Users\Public\Videos\VSTelem\msdot\Update.log | binary | |
MD5:7E651E861E25E68820D109B1F2618D79 | SHA256:E7B0140998A55EAC72263FD9D41452851475EF99FEA74E201DFB76A963E25B80 | |||
| 6388 | 点击此处安装语言包.exe | C:\Users\Public\Videos\VSTelem\msdot\Language.dll | executable | |
MD5:3DC8268E939EA269474B319E6AD64066 | SHA256:0E807EEA09CFB000D965D3F32AC4DFBA6FA9A480BF6289FFD3C7576DDDFDBB5A | |||
| 6388 | 点击此处安装语言包.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SYSTEM_START.lnk | lnk | |
MD5:6A5697D2DF94F2D08A61C943BAFBE6A9 | SHA256:3BC6BBFFBD5EFB514D9073C1320941C96CED3938E94301C3ABC6315B3FAE000D | |||
| 6388 | 点击此处安装语言包.exe | C:\Users\Public\Videos\VSTelem\msdot\msdot.exe | executable | |
MD5:86810E2D993F7327EB5B25B5D17D21C1 | SHA256:63636CEC408ACBBC4D04C01F9EFDBE4B9B08FA0C4390EC8729B9FF0C8BE9D246 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6388 | 点击此处安装语言包.exe | GET | — | 148.113.164.76:8080 | http://qincc.vip:8080/navi/D41D8CD98F00B204 | unknown | — | — | suspicious |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2204 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2204 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6768 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6816 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
5240 | RUXIMICS.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4100 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6388 | 点击此处安装语言包.exe | 148.113.164.76:8080 | — | OVH SAS | CA | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4100 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6580 | msdot.exe | 148.113.152.19:9266 | sk.2x5.xyz | OVH SAS | CA | unknown |
5336 | SearchApp.exe | 2.23.209.187:443 | www.bing.com | Akamai International B.V. | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
s.2x5.xyz |
| malicious |
settings-win.data.microsoft.com |
| whitelisted |
sk.2x5.xyz |
| unknown |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6388 | 点击此处安装语言包.exe | Potentially Bad Traffic | PAYLOAD [ANY.RUN] XORed Windows executable has been loaded |