download:

Baofeng16-9.03.0801.1111.exe

Full analysis: https://app.any.run/tasks/02d29979-2551-4288-9048-5feb823ac6ba
Verdict: Malicious activity
Analysis date: November 13, 2019, 07:27:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

361692856E2EFDFCE88646811CC45BBF

SHA1:

BF98852CF0A8810EFF41C01C7C03510E9529FE70

SHA256:

726D6BA83AE5FEB3598B5A12CB896AF71470DA34503DA5C89F356E55BDD68CCD

SSDEEP:

786432:k8lU0GNDS7C1jl5kgc8Fap0gM5lX0J/Zx495WnvlX:BYDS7APk1gJQhy5WntX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
      • StormPlayer9.exe (PID: 1944)
      • Stormplayer9.exe (PID: 1404)
      • Welcome9.exe (PID: 2928)
      • BaofengPlatform9.exe (PID: 1820)
      • BaofengUpdate9.exe (PID: 2136)
      • StormPlayer9.exe (PID: 1648)
    • Connects to CnC server

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Application was dropped or rewritten from another process

      • StormPlayer9.exe (PID: 1944)
      • Stormplayer9.exe (PID: 1404)
      • Welcome9.exe (PID: 2928)
      • BaofengPlatform9.exe (PID: 1820)
      • StormPlayer9.exe (PID: 1648)
      • BaofengUpdate9.exe (PID: 2136)
    • Changes the autorun value in the registry

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
  • SUSPICIOUS

    • Creates COM task schedule object

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Creates a software uninstall entry

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Changes IE settings (feature browser emulation)

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Creates files in the user directory

      • StormPlayer9.exe (PID: 1944)
      • StormPlayer9.exe (PID: 1648)
      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Reads Internet Cache Settings

      • Welcome9.exe (PID: 2928)
      • BaofengPlatform9.exe (PID: 1820)
    • Modifies the open verb of a shell class

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Searches for installed software

      • BaofengPlatform9.exe (PID: 1820)
    • Reads internet explorer settings

      • Welcome9.exe (PID: 2928)
    • Creates files in the program directory

      • BaofengPlatform9.exe (PID: 1820)
      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
      • BaofengUpdate9.exe (PID: 2136)
      • StormPlayer9.exe (PID: 1648)
      • StormPlayer9.exe (PID: 1944)
    • Executable content was dropped or overwritten

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Baofeng16-9.03.0801.1111.exe (PID: 2396)
    • Manual execution by user

      • StormPlayer9.exe (PID: 1944)
      • StormPlayer9.exe (PID: 1648)
    • Reads the hosts file

      • BaofengPlatform9.exe (PID: 1820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:08:05 09:07:13+02:00
PEType: PE32
LinkerVersion: 10
CodeSize: 712704
InitializedDataSize: 30046208
UninitializedDataSize: -
EntryPoint: 0x92b96
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 9.3.801.1111
ProductVersionNumber: 9.3.801.1111
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: 暴风集团股份有限公司
FileDescription: 暴风影音16安装程序
FileVersion: 9.03.0801.1111
LegalCopyright: Copyright (C) 2007-2019 暴风集团股份有限公司
ProductName: 暴风影音16安装程序
ProductVersion: 9.03.0801.1111

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 05-Aug-2019 07:07:13
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • D:\svnwork\stormplayer\branches\local_9.00.1128.1111\Setup\BF_NewInstall\src\BF_InstallEngine\bin\Release\B5_Install.pdb
CompanyName: 暴风集团股份有限公司
FileDescription: 暴风影音16安装程序
FileVersion: 9.03.0801.1111
LegalCopyright: Copyright (C) 2007-2019 暴风集团股份有限公司
ProductName: 暴风影音16安装程序
ProductVersion: 9.03.0801.1111

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 05-Aug-2019 07:07:13
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000ADF22
0x000AE000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.64852
.rdata
0x000AF000
0x0002A3FC
0x0002A400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.96517
.data
0x000DA000
0x00012B20
0x0000D200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.06746
.rsrc
0x000ED000
0x01C4E5D8
0x01C4E600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.99904
.reloc
0x01D3C000
0x00021AB4
0x00021C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
3.40493

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.21844
856
Latin 1 / Western European
English - United States
RT_MANIFEST
2
4.35388
67624
Latin 1 / Western European
Chinese - PRC
RT_ICON
3
4.74354
16936
Latin 1 / Western European
Chinese - PRC
RT_ICON
4
5.02082
9640
Latin 1 / Western European
Chinese - PRC
RT_ICON
5
5.70736
4264
Latin 1 / Western European
Chinese - PRC
RT_ICON
6
5.87011
2440
Latin 1 / Western European
Chinese - PRC
RT_ICON
7
6.0124
1128
Latin 1 / Western European
Chinese - PRC
RT_ICON
107
2.91902
104
Latin 1 / Western European
Chinese - PRC
RT_GROUP_ICON
136
6.22611
6655
Latin 1 / Western European
Chinese - PRC
RESOURCE_DATA
138
7.99999
29436094
Latin 1 / Western European
Chinese - PRC
RESOURCE_DATA

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
IPHLPAPI.DLL
KERNEL32.dll
MSIMG32.dll
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
SensApi.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start baofeng16-9.03.0801.1111.exe stormplayer9.exe stormplayer9.exe welcome9.exe no specs baofengplatform9.exe stormplayer9.exe baofengupdate9.exe baofeng16-9.03.0801.1111.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1404"C:\Program Files\BaofengVideo\StormPlayer9\Stormplayer9.exe"C:\Program Files\BaofengVideo\StormPlayer9\Stormplayer9.exe
Baofeng16-9.03.0801.1111.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
HIGH
Description:
暴风影音16
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\stormplayer9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1648"C:\Program Files\BaofengVideo\StormPlayer9\StormPlayer9.exe" C:\Program Files\BaofengVideo\StormPlayer9\StormPlayer9.exe
explorer.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音16
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\stormplayer9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1820"C:\Program Files\BaofengVideo\StormPlayer9\BaofengPlatform9.exe" /StartByStormC:\Program Files\BaofengVideo\StormPlayer9\BaofengPlatform9.exe
StormPlayer9.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音平台中心
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\baofengplatform9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\program files\baofengvideo\stormplayer9\crt.dll
c:\windows\system32\version.dll
1944"C:\Program Files\BaofengVideo\StormPlayer9\StormPlayer9.exe" C:\Program Files\BaofengVideo\StormPlayer9\StormPlayer9.exe
explorer.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音16
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\stormplayer9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2136"C:\Program Files\BaofengVideo\StormPlayer9\BaofengUpdate9.exe" /AutoC:\Program Files\BaofengVideo\StormPlayer9\BaofengUpdate9.exe
BaofengPlatform9.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音升级程序
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\baofengupdate9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2396"C:\Users\admin\AppData\Local\Temp\Baofeng16-9.03.0801.1111.exe" C:\Users\admin\AppData\Local\Temp\Baofeng16-9.03.0801.1111.exe
explorer.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
HIGH
Description:
暴风影音16安装程序
Exit code:
0
Version:
9.03.0801.1111
Modules
Images
c:\users\admin\appdata\local\temp\baofeng16-9.03.0801.1111.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2928"C:\Program Files\BaofengVideo\StormPlayer9\Welcome9.exe" /From=C:\Program Files\BaofengVideo\StormPlayer9\Welcome9.exeStormPlayer9.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音基础组件
Exit code:
8
Version:
9.03.0801.1111
Modules
Images
c:\program files\baofengvideo\stormplayer9\welcome9.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3992"C:\Users\admin\AppData\Local\Temp\Baofeng16-9.03.0801.1111.exe" C:\Users\admin\AppData\Local\Temp\Baofeng16-9.03.0801.1111.exeexplorer.exe
User:
admin
Company:
暴风集团股份有限公司
Integrity Level:
MEDIUM
Description:
暴风影音16安装程序
Exit code:
3221226540
Version:
9.03.0801.1111
Modules
Images
c:\users\admin\appdata\local\temp\baofeng16-9.03.0801.1111.exe
c:\systemroot\system32\ntdll.dll
Total events
3 410
Read events
1 311
Write events
2 095
Delete events
4

Modification events

(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BFSetUp9
Operation:writeName:BFSetUpID
Value:
2396
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:asf
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:wm
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:wmp
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:wmv
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:wma
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:ram
Value:
1
(PID) Process:(2396) Baofeng16-9.03.0801.1111.exeKey:HKEY_CURRENT_USER\Software\BaofengVideo\StormPlayer9\FileAssociateList
Operation:writeName:rm
Value:
1
Executable files
368
Suspicious files
35
Text files
65
Unknown types
16

Dropped files

PID
Process
Filename
Type
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\Archive.7z
MD5:
SHA256:
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Local\Temp\BaoFengDefaultBdSetup.xmlxml
MD5:21B3A63C555EBC90020712334D6D021A
SHA256:A3FFFE5D7052CBBAF6C941B55A353F648B6541279B68A1A71D62E70E8583A6D3
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\ApplicationData\Profiles\vod\dsp\parser.swfswf
MD5:43B35BA012EBB032B50C0EA28F81EB25
SHA256:B453E80CE5FB680B59BE13CD7B02B33D12211867F57F0058E6CC4FA93CDF7F02
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\ApplicationData\Profiles\vod\dsp\main.swfswf
MD5:F6BDD8DED84D605FC66D8972AD7C3491
SHA256:06D16EB36AD6F367FC108B2E6B0792A5ACF58F0DB8307CF6632F20444F92E78A
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\ApplicationData\Profiles\vod\flash_common.xmlxml
MD5:9BD53240F896C3D29DE358EB04708B7C
SHA256:8B42B8692CFF1BDAB24659625BEA1DB73641097B9A0FC6BC8E54FB7B79A709FD
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\ApplicationData\Profiles\vod\dsp\Tips.swfswf
MD5:859ED4AB229DAB3C6C7E55215A4E2307
SHA256:9E64F334DFB9CED9BC4221B07BBB781214B865FB0D8B6D33D0DDEAF0CB197F2B
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\exp\images\01.pngimage
MD5:667E94700ACCF7F4D91A32CB5DE0FD15
SHA256:1A7235F3852B33839668803B7F1908A202A5F6815E35E0FCEA5B5D56B4AFC2F8
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\exp\images\02.pngimage
MD5:836B127B24DB1226DA4F77A1F987C190
SHA256:1B3D9AA2E5D52B33949944B99CCAEF86C10AF8BB4321097A37BDCA54761861CB
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\exp\images\02_wel.pngimage
MD5:F81A0C366F1BEAB3879FE616AA2C43A1
SHA256:4589EB467707A7073AFE0AD2BFCACEB1FFEE9FD8349E66AC0F78F93519715F2D
2396Baofeng16-9.03.0801.1111.exeC:\Users\admin\AppData\Roaming\BaofengVideoTemp\exp\images\03.pngimage
MD5:69903B497D081E011D33E635C9758CFB
SHA256:56CBEB53FE660BB792F4303A10E1FE21861E86E124CE467997217C0851BE2573
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
50
DNS requests
34
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2396
Baofeng16-9.03.0801.1111.exe
GET
200
124.243.229.41:80
http://errorcode.logger.baofeng.com/errorcode.html?type=setup&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&ver=9.03.0801.1111&errcode=4006
CN
image
43 b
malicious
2396
Baofeng16-9.03.0801.1111.exe
GET
200
124.243.229.41:80
http://errorcode.logger.baofeng.com/errorcode.html?type=setup&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&ver=9.03.0801.1111&errcode=8002
CN
image
43 b
malicious
2396
Baofeng16-9.03.0801.1111.exe
GET
103.15.200.150:80
http://log.nvwa.baofeng.com/logger.php?category=install&ruid=&clientid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&t=1&veriosn=9.03.0801.1111&bid=2&isnew=1&mac=5254004A04AF
CN
unknown
1944
StormPlayer9.exe
GET
200
124.243.229.42:80
http://active.baofeng.com/active5?pid=2&id=2&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&gid=&t=4&ver=9.03.0801.1111&idate=20191113&installday=0&activeinterval=0&activetotal=1&fixedid=2&channel=&activechannel=&msg={%22os%22:%226.1%22}
CN
image
43 b
malicious
1944
StormPlayer9.exe
GET
200
124.243.229.42:80
http://action.logger.baofeng.com/lefteye_action.html?active=0&close=0&ver=9.03.0801.1111&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&id=731
CN
image
43 b
malicious
1944
StormPlayer9.exe
GET
200
124.243.229.41:80
http://action.logger.baofeng.com/rightear_action.html?active=0&close=0&ver=9.03.0801.1111&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&id=2
CN
image
43 b
malicious
2396
Baofeng16-9.03.0801.1111.exe
GET
200
124.243.229.41:80
http://action.logger.baofeng.com/ninstall_action.html?type=3&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&ver=9.03.0801.1111&start=&mi_over=&end=1&rls=&env=1&bit=1&movie=2
CN
image
43 b
malicious
1944
StormPlayer9.exe
GET
200
124.243.229.41:80
http://action.logger.baofeng.com/3d_action.html?active=0&action=0&ver=9.03.0801.1111&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&id=2
CN
image
43 b
malicious
1820
BaofengPlatform9.exe
GET
200
124.243.229.41:80
http://log.houyi.baofeng.net/logger.php?ltype=popv5&uid={5EE9881A-E12E-21A8-33CD-D66C4C3E178D}&ver=9.03.0801.1111&json={%22position%22:%22confpre%22,%22type%22:%221%22,%22ecode%22:%220%22}
CN
image
43 b
malicious
1820
BaofengPlatform9.exe
GET
200
125.44.162.161:80
http://static.houyi.baofeng.net/config/popyx.xml
CN
xml
75 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2396
Baofeng16-9.03.0801.1111.exe
124.243.229.41:80
action.logger.baofeng.com
China Unicom Beijing Province Network
CN
malicious
2396
Baofeng16-9.03.0801.1111.exe
103.15.200.150:80
log.nvwa.baofeng.com
No.31,Jin-rong Street
CN
unknown
1944
StormPlayer9.exe
124.243.229.41:80
action.logger.baofeng.com
China Unicom Beijing Province Network
CN
malicious
1944
StormPlayer9.exe
124.243.229.42:80
action.logger.baofeng.com
China Unicom Beijing Province Network
CN
malicious
1820
BaofengPlatform9.exe
124.243.229.41:80
action.logger.baofeng.com
China Unicom Beijing Province Network
CN
malicious
1820
BaofengPlatform9.exe
124.243.221.212:80
midinfo.baofeng.com
China Unicom Beijing Province Network
CN
unknown
1820
BaofengPlatform9.exe
125.44.162.161:80
static.houyi.baofeng.net
CHINA UNICOM China169 Backbone
CN
unknown
1820
BaofengPlatform9.exe
42.56.86.187:8000
ncnet.mars.baofeng.net
CHINA UNICOM China169 Backbone
CN
unknown
1820
BaofengPlatform9.exe
110.172.215.192:80
ploy.baofeng.net
China Unicom Beijing Province Network
CN
suspicious
1820
BaofengPlatform9.exe
42.56.86.151:80
ncmsr.mars.baofeng.net
CHINA UNICOM China169 Backbone
CN
suspicious

DNS requests

Domain
IP
Reputation
tuijian.bd.baofeng.com
malicious
action.logger.baofeng.com
  • 124.243.229.41
  • 124.243.229.42
malicious
errorcode.logger.baofeng.com
  • 124.243.229.41
  • 124.243.229.42
malicious
log.nvwa.baofeng.com
  • 103.15.200.150
unknown
active.baofeng.com
  • 124.243.229.42
  • 124.243.229.41
malicious
diag.baofeng.com
unknown
log.houyi.baofeng.net
  • 124.243.229.41
  • 124.243.229.42
malicious
midinfo.baofeng.com
  • 124.243.221.212
malicious
static.houyi.baofeng.net
  • 125.44.162.161
  • 61.156.196.92
  • 61.156.196.89
  • 125.44.162.158
  • 61.156.196.104
  • 61.156.196.101
  • 61.156.196.90
  • 125.44.162.159
  • 61.156.196.87
  • 61.156.196.99
malicious
diag.baofeng.net
unknown

Threats

PID
Process
Class
Message
2396
Baofeng16-9.03.0801.1111.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Baofeng PUA CnC Checkin
2396
Baofeng16-9.03.0801.1111.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Baofeng PUA CnC Checkin
1820
BaofengPlatform9.exe
A Network Trojan was detected
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
1820
BaofengPlatform9.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
1820
BaofengPlatform9.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
1820
BaofengPlatform9.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
1820
BaofengPlatform9.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
1820
BaofengPlatform9.exe
A Network Trojan was detected
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2 ETPRO signatures available at the full report
Process
Message
Baofeng16-9.03.0801.1111.exe
[Begin] _tWinMain
Baofeng16-9.03.0801.1111.exe
[Begin] ????
Baofeng16-9.03.0801.1111.exe
[Begin] CB5_InstallApp::WinMain
Baofeng16-9.03.0801.1111.exe
[Begin] CB5_InstallApp::InitInstance
Baofeng16-9.03.0801.1111.exe
[End] CB5_InstallApp::InitInstance
Baofeng16-9.03.0801.1111.exe
MediaLibrary: Get UninstallString failed
Baofeng16-9.03.0801.1111.exe
[B5_Install] [TID:272] [I] [BFDrv OpenSCManager() ok ! ]
Baofeng16-9.03.0801.1111.exe
[B5_Install] [TID:272] [E] [BFDrv OpenService() Faild 1060 ! ]
Baofeng16-9.03.0801.1111.exe
[B5_Install] [TID:272] [E] [BFDrv CopyFile from C:\Program Files\BaofengVideo\StormPlayer9\BFDrv.sys to C:\Windows\system32\drivers\BFDrv.sys Faild 2 ! ]
StormPlayer9.exe
[OPT] CStormApp::WinMain: 78