| File name: | 02322339_2 |
| Full analysis: | https://app.any.run/tasks/08e9b64e-6f98-47b5-a2dc-b8b008ad3112 |
| Verdict: | Malicious activity |
| Analysis date: | November 30, 2020, 01:05:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 27527EAE13155667B4DFF4F5CE8868F4 |
| SHA1: | EB8200DEFD9CAC2087AED54EAF875F4184F9C7FB |
| SHA256: | 9CD541BC6FB15931AED14CF8EC3E2FD797D27B9F53BEE069E3DB500394A300D4 |
| SSDEEP: | 98304:a8tNw4DU2IIfn5P3NMdtRt0yYvI1hnf4icH:9waUcf5P3NMvsxEhfc |
| .exe | | | Win32 Executable (generic) (3.6) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (1.6) |
| .exe | | | DOS Executable Generic (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:06:08 13:09:44+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 937472 |
| InitializedDataSize: | 2706432 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa05fa |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.2.30.608 |
| ProductVersionNumber: | 2.2.30.608 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| FileDescription: | 游戏微端 |
| FileVersion: | 2.2.30.608 |
| InternalName: | LiteGameBox2_externel |
| LegalCopyright: | 版权所有 (C) 2008-2020 www.ludashi.com |
| OriginalFileName: | LiteGameBox2 |
| ProductName: | 游戏微端 |
| ProductVersion: | 2.2.30.608 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2844 | "C:\Users\admin\AppData\Local\Temp\02322339_2.exe" | C:\Users\admin\AppData\Local\Temp\02322339_2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: 游戏微端 Exit code: 0 Version: 2.2.30.608 Modules
| |||||||||||||||
| 3552 | "C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.exe" | C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.exe | 02322339_2.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: 游戏微端 Exit code: 0 Version: 2.2.30.608 Modules
| |||||||||||||||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION |
| Operation: | write | Name: | 02322339_2.exe |
Value: 11001 | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | InstallDir |
Value: C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | InstallTime |
Value: 2020-11-30 01:06:02 | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | ExePath |
Value: C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.exe | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | DisplayName |
Value: 裁决战歌 | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | Version |
Value: 2.2.30.608 | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | PID |
Value: lds | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | SubPID |
Value: qh | |||
| (PID) Process: | (2844) 02322339_2.exe | Key: | HKEY_CURRENT_USER\Software\LDSLiteGameBox\cjzg |
| Operation: | write | Name: | Channel |
Value: lds | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2844 | 02322339_2.exe | C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\裁决战歌.lnk | lnk | |
MD5:— | SHA256:— | |||
| 2844 | 02322339_2.exe | C:\Users\admin\AppData\Local\Temp\LiteGameBox_cjzg\cjzg.ico | image | |
MD5:— | SHA256:— | |||
| 2844 | 02322339_2.exe | C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.ico | image | |
MD5:— | SHA256:— | |||
| 2844 | 02322339_2.exe | C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.json | text | |
MD5:— | SHA256:— | |||
| 3552 | cjzg.exe | C:\Users\admin\AppData\Local\Temp\LiteGameBox2Run_cjzg\cjzg.ui | compressed | |
MD5:— | SHA256:— | |||
| 2844 | 02322339_2.exe | C:\Users\admin\AppData\Roaming\LiteGameBox_cjzg\cjzg.ui | compressed | |
MD5:— | SHA256:— | |||
| 3552 | cjzg.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\upload[1].jpg | image | |
MD5:— | SHA256:— | |||
| 3552 | cjzg.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\main[1].css | text | |
MD5:— | SHA256:— | |||
| 3552 | cjzg.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\nav[1].png | image | |
MD5:— | SHA256:— | |||
| 2844 | 02322339_2.exe | C:\Users\admin\Desktop\裁决战歌.lnk | lnk | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/reg.png?t=20200105 | CN | image | 167 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/upload.jpg | CN | image | 37.0 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/nav.png | CN | image | 16.5 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/bg.png?t=20200105 | CN | image | 149 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 139.129.105.182:80 | http://wan.ludashi.com/micro/cjzg/index_lds.html?channel=mnds&from=mnds_wd_cjzg | CN | html | 3.04 Kb | unknown |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/checkbox.png?t=20191021 | CN | image | 867 b | suspicious |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/log_btn.png?t=20191021 | CN | image | 61.2 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/wan/micro/cjzg/assets_lds/input_reg_code.png?t=20191021 | CN | image | 1.79 Kb | suspicious |
3552 | cjzg.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D | US | der | 471 b | whitelisted |
3552 | cjzg.exe | GET | 200 | 101.226.26.228:80 | http://cdn-file.ludashi.com/assets/jquery/jquery183.js | CN | text | 37.8 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3552 | cjzg.exe | 101.226.26.228:80 | cdn-file.ludashi.com | China Telecom (Group) | CN | unknown |
3552 | cjzg.exe | 180.163.121.216:80 | cdn-wan.ludashi.com | China Telecom (Group) | CN | unknown |
3552 | cjzg.exe | 139.129.105.182:80 | wan.ludashi.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3552 | cjzg.exe | 101.226.26.230:443 | cdn-file.ludashi.com | China Telecom (Group) | CN | unknown |
3552 | cjzg.exe | 120.27.82.56:80 | i.ludashi.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3552 | cjzg.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
wan.ludashi.com |
| unknown |
cdn-file.ludashi.com |
| suspicious |
cdn-wan.ludashi.com |
| suspicious |
cdn-ssl-wan.ludashi.com |
| malicious |
ocsp.digicert.com |
| whitelisted |
status.rapidssl.com |
| shared |
i.ludashi.com |
| unknown |
dns.msftncsi.com |
| shared |