| File name: | UUAbroad-1.0.3.exe |
| Full analysis: | https://app.any.run/tasks/fa9ea3dd-c29a-47c1-a0f7-48db2d4a0b6b |
| Verdict: | Malicious activity |
| Analysis date: | April 30, 2020, 11:44:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1D70DC74B9CE6C57CBE348B8F2933E1B |
| SHA1: | 9688E6EC848D5F8640C4C0A9675D36B1D3887F35 |
| SHA256: | 9270ED4D6CD9557EB586885EECF749000ACA4F82EEF54A98DDE70F617A76C555 |
| SSDEEP: | 196608:j60XuL+OBED8/0lPdFntKP69f0hOJjB5/85w3B/cokuM7f7QUn3:j6u4+OBEI0lPdyP69f02FdOwhM4Un3 |
| .exe | | | InstallShield setup (21.9) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (14.1) |
| .exe | | | Win32 Executable (generic) (2.3) |
| .exe | | | Generic Win/DOS Executable (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:12:18 07:35:13+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 354304 |
| InitializedDataSize: | 9269248 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x41eda |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.0.92 |
| ProductVersionNumber: | 1.1.0.92 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Unknown (0009) |
| CharacterSet: | Unicode |
| CompanyName: | NetEase (Hangzhou) Network Co., Ltd. |
| FileDescription: | NetEase UU Game Booster |
| FileVersion: | 1.1.0.92 |
| InternalName: | install.exe |
| LegalCopyright: | Copyright 1997-2016 NetEase |
| OriginalFileName: | install.exe |
| PrivateBuild: | 93616d2cf08ce7a654020e61e0af86f11303bde9 |
| ProductName: | NetEase UU Game Booster |
| ProductVersion: | 1.1.0.92 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 18-Dec-2019 06:35:13 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | NetEase (Hangzhou) Network Co., Ltd. |
| FileDescription: | NetEase UU Game Booster |
| FileVersion: | 1.1.0.92 |
| InternalName: | install.exe |
| LegalCopyright: | Copyright 1997-2016 NetEase |
| OriginalFilename: | install.exe |
| PrivateBuild: | 93616d2cf08ce7a654020e61e0af86f11303bde9 |
| ProductName: | NetEase UU Game Booster |
| ProductVersion: | 1.1.0.92 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 18-Dec-2019 06:35:13 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00056622 | 0x00056800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56506 |
.rdata | 0x00058000 | 0x00017D6C | 0x00017E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21108 |
.data | 0x00070000 | 0x00005BA0 | 0x00003600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.08596 |
.rsrc | 0x00076000 | 0x008AF03C | 0x008AF200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96797 |
.reloc | 0x00926000 | 0x0000C874 | 0x0000CA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.89777 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.26126 | 1145 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.99329 | 2440 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
3 | 5.75026 | 4264 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
4 | 5.46707 | 9640 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
5 | 5.41665 | 16936 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
6 | 5.19349 | 38056 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
7 | 1.80331 | 60 | Latin 1 / Western European | Chinese - PRC | RT_STRING |
8 | 7.98596 | 48324 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
9 | 2.89005 | 744 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
10 | 2.54353 | 296 | Latin 1 / Western European | Chinese - PRC | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
MSIMG32.dll |
OLEAUT32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 576 | "C:\Program Files\Netease\UUGameBooster\uu_temp\7za.exe" x "C:\Program Files\Netease\UUGameBooster\uu_temp\uu.zip" -o"C:\Program Files\Netease\UUGameBooster\" -aoa | C:\Program Files\Netease\UUGameBooster\uu_temp\7za.exe | UUAbroad-1.0.3.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 9.35 beta Modules
| |||||||||||||||
| 884 | cmd.exe /c rd /s /q "C:\Program Files\Netease\UUGameBooster\uu_temp\" | C:\Windows\system32\cmd.exe | — | UUAbroad-1.0.3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2356 | C:\Program Files\Netease\UUGameBooster\uu_ball.exe /main_form_wnd 721200 /show_flag 0 /pos_x -1 /pos_y -1 | C:\Program Files\Netease\UUGameBooster\uu_ball.exe | uu.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\AppData\Local\Temp\UUAbroad-1.0.3.exe" | C:\Users\admin\AppData\Local\Temp\UUAbroad-1.0.3.exe | — | explorer.exe | |||||||||||
User: admin Company: NetEase (Hangzhou) Network Co., Ltd. Integrity Level: MEDIUM Description: NetEase UU Game Booster Exit code: 3221226540 Version: 1.1.0.92 Modules
| |||||||||||||||
| 3352 | "C:\Users\admin\AppData\Local\Temp\UUAbroad-1.0.3.exe" | C:\Users\admin\AppData\Local\Temp\UUAbroad-1.0.3.exe | explorer.exe | ||||||||||||
User: admin Company: NetEase (Hangzhou) Network Co., Ltd. Integrity Level: HIGH Description: NetEase UU Game Booster Exit code: 0 Version: 1.1.0.92 Modules
| |||||||||||||||
| 3460 | "C:\Program Files\Netease\UUGameBooster\uu.exe" /install_shortcut 1 /install_autorun 0 | C:\Program Files\Netease\UUGameBooster\uu.exe | UUAbroad-1.0.3.exe | ||||||||||||
User: admin Company: NetEase (Hangzhou) Network Co., Ltd. Integrity Level: HIGH Description: NetEase UU Game Booster Exit code: 0 Version: 1.1.0.92 Modules
| |||||||||||||||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | DisplayName |
Value: NetEase UU Booster | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | InstallDir |
Value: C:\Program Files\Netease\UUGameBooster\ | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\Netease\UUGameBooster\uninstall.exe | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | Publisher |
Value: NetEase | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | DisplayVersion |
Value: 1.1.0.92 | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NeteaseGaccOverSea |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Netease\UUGameBooster\uu.exe | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION |
| Operation: | write | Name: | UU.exe |
Value: 11000 | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Channel\NeteaseGaccOverSea |
| Operation: | write | Name: | ChannelName |
Value: abroad | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3352) UUAbroad-1.0.3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2 |
| Operation: | write | Name: | FavoritesResolve |
Value: CD0200004C0000000114020000000000C000000000000046830080002000000012DB96E6E41ED60112DB96E6E41ED601A6E3DCE5E41ED601280400000000000001000000000000000000000000000000780114001F80C827341F105C1042AA032EE45287D66858003100000000009E50BB5D100053544152544D7E310000400008000400EFBE9E50BB5D9E50BB5D2A000000DFCB0000000018000000000000000000000000000000530074006100720074004D0065006E007500000018000A013200280400009E50BA5D20004E45544541537E312E4C4E4B00005A0008000400EFBE9E50BB5D9E50BB5D2A0000000DCC00000000170000000000000000000000000000004E00650074004500610073006500200055005500200042006F006F0073007400650072002E006C006E006B0000001C00940000001D00EFBE02007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004E006500740065006100730065005C0055005500470061006D00650042006F006F0073007400650072005C00750075002E0065007800650000001C000000A30000001C000000010000001C0000002D00000000000000A200000011000000030000004736BAC41000000000433A5C55736572735C61646D696E5C417070446174615C526F616D696E675C4D6963726F736F66745C496E7465726E6574204578706C6F7265725C517569636B204C61756E63685C557365722050696E6E65645C53746172744D656E755C4E65744561736520555520426F6F737465722E6C6E6B000060000000030000A05800000000000000757365722D70630000000000000000005CF1A7C03D50454982D81E2FB6820766434489E508DEE911972D5254004A04AF5CF1A7C03D50454982D81E2FB6820766434489E508DEE911972D5254004A04AF00000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3352 | UUAbroad-1.0.3.exe | C:\Program Files\Netease\UUGameBooster\uu_temp\uu.zip | — | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\tap_driver\i386\netease_uu_tap_0909.cat | cat | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\tap_driver\x64\netease_uu_tap_0921.cat | cat | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\tap_driver\x64\netease_uu_tap_0909.cat | cat | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\lspinst_x64.exe | executable | |
MD5:— | SHA256:— | |||
| 3352 | UUAbroad-1.0.3.exe | C:\Program Files\Netease\UUGameBooster\uu_temp\7za.exe | executable | |
MD5:C6D72642721E84D227DEFC3EC4AB12E6 | SHA256:0CC0DE83B51DAE55A4FCAE559DEFC87BEA8448010D064C316ABCFE9459ECE035 | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\drvinst_x64.exe | executable | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\apiinstall_x64.exe | executable | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\uninstall.exe | executable | |
MD5:— | SHA256:— | |||
| 576 | 7za.exe | C:\Program Files\Netease\UUGameBooster\http_server.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3460 | uu.exe | 103.72.17.10:443 | uu.update.netease.com | — | CN | unknown |
3460 | uu.exe | 52.214.48.7:443 | ieov.uu.163.com | Amazon.com, Inc. | IE | unknown |
3460 | uu.exe | 54.251.132.77:9080 | glgov.uu.163.com | Amazon.com, Inc. | SG | unknown |
3460 | uu.exe | 143.204.212.90:443 | uuov.update.netease.com | — | US | unknown |
3460 | uu.exe | 143.204.202.24:443 | uu.163.com | — | US | suspicious |
2356 | uu_ball.exe | 52.214.48.7:443 | ieov.uu.163.com | Amazon.com, Inc. | IE | unknown |
2356 | uu_ball.exe | 52.69.210.41:50442 | unipush.x.netease.com | Amazon.com, Inc. | JP | unknown |
3460 | uu.exe | 34.246.57.170:443 | ieov.uu.163.com | Amazon.com, Inc. | IE | unknown |
3460 | uu.exe | 163.171.133.124:443 | uu.fp.ps.netease.com | — | US | malicious |
Domain | IP | Reputation |
|---|---|---|
uuov.update.netease.com |
| unknown |
ieov.uu.163.com |
| unknown |
uu.update.netease.com |
| unknown |
glgov.uu.163.com |
| unknown |
logov.uu.163.com |
| unknown |
uu.fp.ps.netease.com |
| malicious |
uu.163.com |
| malicious |
unipush.x.netease.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2356 | uu_ball.exe | Generic Protocol Command Decode | SURICATA Applayer Detect protocol only one direction |
Process | Message |
|---|---|
UUAbroad-1.0.3.exe | no install |
UUAbroad-1.0.3.exe | is_upgrade false |
uu.exe | 0
|
uu.exe | AppService::ParseGameZoneServerListJson in
|
uu.exe | AppService::ParseGameZoneServerListJson out
|
uu.exe | CAdWebForm::Init |
uu.exe | mouseenter
|
uu.exe | ad_pic |
uu.exe | ad_pic |
uu.exe | mouseleave |