File name:

wps_lid.lid-s8LZft8YqPE9.exe

Full analysis: https://app.any.run/tasks/b5003ccf-390b-4c29-92f3-efd1cab09e9f
Verdict: Malicious activity
Analysis date: July 15, 2024, 07:57:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E452C1739EA95161D71F94E9201FAF50

SHA1:

B94FC76ED193DEDD09EE85F083125BBA8DA126BD

SHA256:

B37B5FCCB67396C78C443DD5C52FAA3BD27505350804040FF3948ECB7E5445B8

SSDEEP:

98304:9Ss0xsuCgqheF23zUHlItIvO5ElBP+RLixTNaY1DEWI4Cv62DPZmSbqwPG1kutqc:VHsA+7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
  • INFO

    • Reads the machine GUID from the registry

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
    • Checks supported languages

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
    • Reads the computer name

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
    • Process checks computer location settings

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
    • Reads the software policy settings

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
    • Creates files or folders in the user directory

      • wps_lid.lid-s8LZft8YqPE9.exe (PID: 3384)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:30 06:07:28+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.24
CodeSize: 4083712
InitializedDataSize: 1759232
UninitializedDataSize: -
EntryPoint: 0x26e6d7
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 12.2.0.17117
ProductVersionNumber: 12.2.0.17117
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Zhuhai Kingsoft Office Software Co.,Ltd
FileDescription: WPS Office Setup
FileVersion: 12,2,0,17117
InternalName: konlinesetup_xa
LegalCopyright: Copyright©2024 Kingsoft Corporation. All rights reserved.
OriginalFileName: konlinesetup_xa.exe
ProductName: WPS Office
ProductVersion: 12,2,0,17117
MIMEType: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wps_lid.lid-s8lzft8yqpe9.exe

Process information

PID
CMD
Path
Indicators
Parent process
3384"C:\Users\admin\AppData\Local\Temp\wps_lid.lid-s8LZft8YqPE9.exe" C:\Users\admin\AppData\Local\Temp\wps_lid.lid-s8LZft8YqPE9.exe
explorer.exe
User:
admin
Company:
Zhuhai Kingsoft Office Software Co.,Ltd
Integrity Level:
MEDIUM
Description:
WPS Office Setup
Version:
12,2,0,17117
Modules
Images
c:\users\admin\appdata\local\temp\wps_lid.lid-s8lzft8yqpe9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
8 204
Read events
8 182
Write events
22
Delete events
0

Modification events

(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\kwpsonlinesetup
Operation:writeName:infoGuid
Value:
4EE95870EA6F45EC8A79A50FD7939821
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\kwpsonlinesetup
Operation:writeName:infoHdid
Value:
c025f6f8e94d489dbb614d7a940be493
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\kwpsonlinesetup
Operation:writeName:onlinesetup_penetrate_id_type
Value:
web
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\kwpsonlinesetup
Operation:writeName:onlinesetup_penetrate_id
Value:
lid-s8LZft8YqPE9
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\Office\6.0\Common
Operation:writeName:newGuideShow
Value:
1
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:countrycode
Value:
DE
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:lastupdatecountrycode
Value:
1721030278020
(PID) Process:(3384) wps_lid.lid-s8LZft8YqPE9.exeKey:HKEY_CURRENT_USER\Software\kingsoft\Office\6.0\plugins\kdcsdk
Operation:writeName:lastUpdateDeviceInfoDate
Value:
2024/7/15
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1060
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?11acddbe1ebd82b3
unknown
whitelisted
1372
svchost.exe
GET
200
2.16.164.32:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1372
svchost.exe
GET
200
88.221.125.143:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3384
wps_lid.lid-s8LZft8YqPE9.exe
142.250.186.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
3384
wps_lid.lid-s8LZft8YqPE9.exe
90.84.175.86:443
api.wps.com
Orange
FR
unknown
1060
svchost.exe
224.0.0.252:5355
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
3384
wps_lid.lid-s8LZft8YqPE9.exe
104.16.84.69:443
wdl1.pcfg.cache.wpscdn.com
CLOUDFLARENET
unknown
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
www.google-analytics.com
  • 142.250.186.142
whitelisted
api.wps.com
  • 90.84.175.86
whitelisted
wdl1.pcfg.cache.wpscdn.com
  • 104.16.84.69
  • 104.16.83.69
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 2.16.164.32
  • 2.16.164.99
  • 2.16.164.9
  • 2.16.164.106
  • 2.16.164.34
  • 2.16.164.18
  • 2.16.164.81
  • 2.16.164.97
  • 2.16.164.114
whitelisted
www.microsoft.com
  • 88.221.125.143
whitelisted

Threats

No threats detected
No debug info