File name:

859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe

Full analysis: https://app.any.run/tasks/606d204a-dc20-4984-a958-f1b60889f894
Verdict: Malicious activity
Analysis date: March 10, 2024, 14:53:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3B688B75649EF910EABC215D7264D72F

SHA1:

3C4F54BD45B8C75DFAE67A57FD685FA7FD43FB50

SHA256:

859A1E537099AF06C48D9ACBFA1870698FB2412A8B5D3FE37E9B6AB363F931DA

SSDEEP:

49152:lrJMtrkzsKwKP2naH1SPQyS0Sf5+DndcWdkNBSLtmF/og8RQlr:lrJMCzsKwlaV9yS0Sf5aqN4s/KQlr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Scans artifacts that could help determine the target

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Reads Microsoft Outlook installation path

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Reads Internet Explorer settings

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Process requests binary or script from the Internet

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Checks Windows Trust Settings

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
  • INFO

    • Checks supported languages

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
      • identity_helper.exe (PID: 7544)
    • Reads the computer name

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
      • identity_helper.exe (PID: 7544)
    • Checks proxy server information

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
      • BackgroundTransferHost.exe (PID: 3540)
      • slui.exe (PID: 7012)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 5488)
      • BackgroundTransferHost.exe (PID: 3540)
      • BackgroundTransferHost.exe (PID: 6528)
      • BackgroundTransferHost.exe (PID: 6432)
      • BackgroundTransferHost.exe (PID: 6952)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 3540)
      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 3540)
      • slui.exe (PID: 7012)
      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Reads Microsoft Office registry keys

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
      • msedge.exe (PID: 6804)
    • Process checks Internet Explorer phishing filters

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Reads the machine GUID from the registry

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Create files in a temporary directory

      • 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe (PID: 6988)
    • Application launched itself

      • msedge.exe (PID: 6804)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:08:28 14:59:07+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 593920
InitializedDataSize: 528384
UninitializedDataSize: -
EntryPoint: 0x6c59c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 1.0.0.0
FileDescription: 尐迷顺
ProductName: 西普大陆尐迷顺
ProductVersion: 1.0.0.0
CompanyName: 尐迷顺
LegalCopyright: 尐迷顺
Comments: 尐迷顺
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
173
Monitored processes
38
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1784"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1980 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2560"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=5952 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3984 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3192"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2340 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3340"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2548 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3540"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.746 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4256"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.95 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.66 --initial-client-data=0x2e0,0x2e4,0x2e8,0x2dc,0x2f4,0x7ffd9e725fd8,0x7ffd9e725fe4,0x7ffd9e725ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4968"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3436 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
5488"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.746 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
6176"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --mojo-platform-channel-handle=3868 --field-trial-handle=1996,i,12906463927965720970,12965209204256459400,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.66
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.66\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
18 352
Read events
18 242
Write events
107
Delete events
3

Modification events

(PID) Process:(6988) 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6988) 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6988) 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6988) 859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5488) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5488) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5488) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3540) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3540) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3540) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
2
Suspicious files
112
Text files
62
Unknown types
86

Dropped files

PID
Process
Filename
Type
3540BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\AC\BackgroundTransferApi\123ef075-51e5-4332-a91b-6d15614f1c2d.down_data
MD5:
SHA256:
3540BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\AC\BackgroundTransferApi\123ef075-51e5-4332-a91b-6d15614f1c2d.fba2101b-4e4f-40c4-a14b-2158a0348bbc.down_metabinary
MD5:00A25D7AD7ED7C857F17AFFD6324CFF3
SHA256:62F444CACCD1E1FC0F5716F2B16EB73C4327CE80061B05CE786AAB9CF2A60630
3540BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Ader
MD5:A88028032B2F21C56D1EBCF81CD72FEE
SHA256:DEB77E66751B5330F93CC98E697E473EC8BEEB9C19743582C7D0FFC68D3C2D79
6988859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\base_iframe[1].csstext
MD5:D663B502FE1230D02E173C096A83BFCD
SHA256:ADF8155B0BFC5B1C0AFB03D7A0FD67B1769BE15CB86426F49B7AAF563A4A6AD4
3540BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\AC\BackgroundTransferApi\4b38e2b4-a325-493f-8851-52966ab2d0e3.fba2101b-4e4f-40c4-a14b-2158a0348bbc.down_metabinary
MD5:00A25D7AD7ED7C857F17AFFD6324CFF3
SHA256:62F444CACCD1E1FC0F5716F2B16EB73C4327CE80061B05CE786AAB9CF2A60630
6988859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\myindex[1].htmhtml
MD5:395C97BE4030CD7462C35A707814FEA7
SHA256:61B057599CC7A463DA71621385A7C52997EEAD4225484A238C30F58EA15DD674
6988859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\ucenter_iframe[1].jstext
MD5:9F5926C7D8E1DD1217AF899878EDD83C
SHA256:06B9AE7B13B609208284F30A082D7EFD988C31E4970FCCAEDC520458E090D103
3540BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:E8E1100100A654B599EEF5133CC183C3
SHA256:DB5A13AE820D4724329EEA9816E95B2E0C0838D32448EC96578148E65249E997
6988859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DA3B6E45325D5FFF28CF6BAD6065C907_2B8CDDC1665ED16B271C2FC718FB86D0der
MD5:99D8585E2F0AB8706D80458A14F10238
SHA256:399F37F365C1732B4687DAC289F3AD6470C98607700A277581BA4475AC7153A0
6988859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DA3B6E45325D5FFF28CF6BAD6065C907_2B8CDDC1665ED16B271C2FC718FB86D0binary
MD5:8291BAAFA30C8D3ADB355B73143D8BDF
SHA256:006A45BDBEBAFFDDFD0550358EA13CC93E15829A390C27A4304562C66803BB79
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
78
DNS requests
62
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6692
svchost.exe
POST
302
23.211.9.234:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
104.193.88.126:80
http://hi.baidu.com/qysvylaiegasuwe/item/9b4dc359f94fe4a409be17a4
unknown
unknown
3540
BackgroundTransferHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
43.152.44.160:80
http://xpdl999.aiwan4399.com/myindex.html
unknown
html
3.29 Kb
unknown
6692
svchost.exe
POST
302
23.211.9.234:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
43.152.44.160:80
http://xpdl999.aiwan4399.com/js/swfobject.js
unknown
text
3.85 Kb
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
43.152.44.160:80
http://xpdl999.aiwan4399.com/comm/flash_check/flashopen_cpp.js?v=20230301
unknown
text
1.26 Kb
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
163.171.128.161:80
http://ptlogin.3304399.net/resource/ucenter_iframe.js?v=2012
unknown
text
2.34 Kb
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
163.171.128.161:80
http://ptlogin.3304399.net/resource/css/init.css
unknown
text
1022 b
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
GET
200
163.171.128.161:80
http://ptlogin.3304399.net/resource/css/base_iframe.css
unknown
text
537 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3624
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
whitelisted
3308
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
892
svchost.exe
20.190.159.0:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6876
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
104.193.88.126:80
hi.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
US
unknown
4
System
192.168.100.255:137
whitelisted
892
svchost.exe
20.190.159.68:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6808
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4432
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
hi.baidu.com
  • 104.193.88.126
  • 104.193.88.125
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
www.bing.com
  • 2.19.120.21
  • 2.19.120.29
  • 23.59.234.48
  • 23.59.234.15
  • 23.59.234.26
  • 23.59.234.41
  • 204.79.197.200
  • 13.107.21.200
whitelisted
go.microsoft.com
  • 23.211.9.234
  • 23.210.17.178
whitelisted
dmd.metaservices.microsoft.com
  • 138.91.171.81
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
xpdl999.aiwan4399.com
  • 43.152.44.160
  • 43.152.26.142
  • 43.152.26.58
  • 43.152.26.154
  • 43.152.26.104
  • 43.152.26.151
  • 43.152.26.197
  • 43.152.26.221
unknown

Threats

PID
Process
Class
Message
6988
859a1e537099af06c48d9acbfa1870698fb2412a8b5d3fe37e9b6ab363f931da.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
No debug info