| URL: | http://wps.cn |
| Full analysis: | https://app.any.run/tasks/5ed8f5b9-397e-4210-b60a-126e7e46ba8a |
| Verdict: | Malicious activity |
| Analysis date: | August 24, 2019, 03:42:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | C4E2B25B54EFF70084B92C82015C5B05 |
| SHA1: | 6B3B4F7395BD8AF68A455B347E1573A79A2B8608 |
| SHA256: | 71DCF41806978A11D088CF63976A3918F4C7EB5ECD982EB41DD82D4AB38538AA |
| SSDEEP: | 3:N1KJVHL:Cf |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,16172058548017808399,7041611739319893982,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6961036308974361384 --mojo-platform-channel-handle=4408 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 276 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 308 | "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\ksomisc.exe" -Assopowerpnt | C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\ksomisc.exe | W.P.S.8980.12012.2019.exe | ||||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Office Module Exit code: 0 Version: 11,1,0,8980 Modules
| |||||||||||||||
| 320 | "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe" /krecentfile /init /From=Qing | C:\Users\admin\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe | — | wps.exe | |||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Office Exit code: 0 Version: 11,1,0,8980 Modules
| |||||||||||||||
| 552 | "C:\Windows\system32\regsvr32.exe" /s /n /i:contextmenu "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\qingnse.dll" | C:\Windows\system32\regsvr32.exe | — | ksomisc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 776 | "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\ksomisc.exe" -register | C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\ksomisc.exe | W.P.S.8980.12012.2019.exe | ||||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Office Module Exit code: 0 Version: 11,1,0,8980 Modules
| |||||||||||||||
| 852 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,16172058548017808399,7041611739319893982,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=2617946441672326904 --mojo-platform-channel-handle=4104 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 924 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,16172058548017808399,7041611739319893982,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=1914981184956930751 --mojo-platform-channel-handle=4200 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 996 | "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\wps.exe" Run "C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\addons\ktaskschdtool\ktaskschdtool.dll" /task=wpsexternal /createtask | C:\Users\admin\AppData\Local\Kingsoft\WPS Office\11.1.0.8980\office6\wps.exe | — | ksomisc.exe | |||||||||||
User: admin Company: Zhuhai Kingsoft Office Software Co.,Ltd Integrity Level: MEDIUM Description: WPS Office Exit code: 0 Version: 11,1,0,8980 Modules
| |||||||||||||||
| (PID) Process: | (3480) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 3436-13211091775714000 |
Value: 259 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (3436) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 1512-13197841398593750 |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\32510823-422e-4ad1-a0b1-656016044daa.tmp | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF169dbb.TMP | text | |
MD5:454106CCF080F3E3795C229FC73350D4 | SHA256:9974DC611BE9E20BDFA7B8D939CB913AD23859DEA5F52EBB8D10CEAD9AB5B4FA | |||
| 852 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:12B7DAAEAC62822D64B1DC9CF00A1959 | SHA256:D0B7F56E9304F87E9F14ABF6C9D4349A9778C2FA788DA8B62B5D31C286CA87A1 | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 | — | |
MD5:— | SHA256:— | |||
| 3436 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:70F27BB5FF84782E8065F81EE64E6008 | SHA256:FD5DD0C6F1056C6EE6C2D29BD31653ABB589E7D528957942E65B3972B7ECB4E9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2008 | ksomisc.exe | GET | — | 120.92.88.213:80 | http://dyn.wps.cn/wpsv6internet/infos.ads?q=9oYzCdlnJuSHrKNEQ0H7wAUx7Rj4M3amvzA4KEy4jKa5uaOudbGeDz8ZxQfnSkz6d7ZDXYnH69zHcY3GROry3lfqaxAfeLhmJ3ETj48AmszW9x0 | CN | — | — | suspicious |
3020 | chrome.exe | GET | 301 | 120.92.124.199:80 | http://wps.cn/ | CN | html | 169 b | whitelisted |
3020 | chrome.exe | GET | 301 | 120.92.124.198:80 | http://www.wps.cn/ | CN | html | 169 b | whitelisted |
3020 | chrome.exe | GET | — | 173.194.164.121:80 | http://r3---sn-4g5e6nl7.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=82.102.26.200&mm=28&mn=sn-4g5e6nl7&ms=nvh&mt=1566618253&mv=m&mvi=2&pl=25&shardbypass=yes | US | — | — | whitelisted |
2508 | wps.exe | POST | — | 120.92.33.171:80 | http://120.92.33.171/httpdns/v1 | CN | — | — | suspicious |
2508 | wps.exe | POST | — | 120.92.33.171:80 | http://120.92.33.171/httpdns/v1 | CN | — | — | suspicious |
2508 | wps.exe | GET | — | 140.210.77.190:80 | http://qing.wps.cn/update?type=switch&wpsver=11.1.0.8980&channel=12012.00002019&qingver=11.1.0.8980&language=zh_CN | CN | — | — | suspicious |
2508 | wps.exe | GET | — | 10.83.236.159:80 | http://int.dpool.sina.com.cn/iplookup/iplookup.php?format=js | unknown | — | — | malicious |
2508 | wps.exe | GET | — | 10.83.236.159:80 | http://int.dpool.sina.com.cn/iplookup/iplookup.php?format=js | unknown | — | — | malicious |
276 | explorer.exe | GET | 200 | 125.74.3.121:80 | http://switch.pcfg.cache.wpscdn.cn/wps_assets/cfg/ad/switch/nse_live | CN | binary | 1 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3020 | chrome.exe | 120.92.124.199:80 | wps.cn | Beijing Kingsoft Cloud Internet Technology Co., Ltd | CN | unknown |
3020 | chrome.exe | 172.217.18.163:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3020 | chrome.exe | 216.58.206.13:443 | accounts.google.com | Google Inc. | US | whitelisted |
3020 | chrome.exe | 120.92.124.198:80 | www.wps.cn | Beijing Kingsoft Cloud Internet Technology Co., Ltd | CN | unknown |
3020 | chrome.exe | 120.92.124.198:443 | www.wps.cn | Beijing Kingsoft Cloud Internet Technology Co., Ltd | CN | unknown |
3020 | chrome.exe | 140.210.77.190:443 | account.wps.cn | China Unicom Beijing Province Network | CN | unknown |
3020 | chrome.exe | 60.221.17.1:443 | js1.epy.wpscdn.cn | CHINA UNICOM China169 Backbone | CN | unknown |
3020 | chrome.exe | 106.122.251.241:443 | js2.epy.wpscdn.cn | Fuzhou | CN | suspicious |
3020 | chrome.exe | 222.85.26.209:443 | c.cnzz.com | No.31,Jin-rong Street | CN | unknown |
3020 | chrome.exe | 203.119.206.95:443 | q17.cnzz.com | — | CN | malicious |
Domain | IP | Reputation |
|---|---|---|
wps.cn |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.wps.cn |
| unknown |
qn.cache.wpscdn.cn |
| malicious |
js1.epy.wpscdn.cn |
| suspicious |
js2.epy.wpscdn.cn |
| malicious |
account.wps.cn |
| unknown |
c.cnzz.com |
| whitelisted |
w.cnzz.com |
| unknown |
Process | Message |
|---|---|
W.P.S.8980.12012.2019.exe | [kscreen] isElide:0 switchRec:0 switchRecElide:1 |
W.P.S.8980.12012.2019.exe | [kscreen] now screensaver is |
W.P.S.8980.12012.2019.exe | unregister dll path:qingshellext.dll
|
W.P.S.8980.12012.2019.exe | unregister dll path:qingshellext.dll
|
W.P.S.8980.12012.2019.exe | unInstall qingshellex success!
|
ksomisc.exe | 2019/08/24 04:45:26 I ksomisc 00000e98:00000e8c [wWinMain][ksomisc begin] cmdline:-setlng zh_CN FL:T:\rc_v11_per_new_20190806\Coding\support\ksomisc\ksomisc.cpp(465)
|
ksomisc.exe | 2019/08/24 04:45:26 I ksomisc 00000bb4:00000b0c [wWinMain][ksomisc begin] cmdline:-setservers FL:T:\rc_v11_per_new_20190806\Coding\support\ksomisc\ksomisc.cpp(465)
|
ksomisc.exe | 2019/08/24 04:45:26 I ksomisc 00000308:000003d0 [wWinMain][ksomisc begin] cmdline:-register FL:T:\rc_v11_per_new_20190806\Coding\support\ksomisc\ksomisc.cpp(465)
|
ksomisc.exe | 2019/08/24 04:45:41 I ksomisc 00000f78:00000888 [wWinMain][ksomisc begin] cmdline:-regmtfont FL:T:\rc_v11_per_new_20190806\Coding\support\ksomisc\ksomisc.cpp(465)
|
ksomisc.exe | 2019/08/24 04:45:41 I ksomisc 00000d2c:00000d68 [wWinMain][ksomisc begin] cmdline:-setappcap FL:T:\rc_v11_per_new_20190806\Coding\support\ksomisc\ksomisc.cpp(465)
|