File name:

暴风影音播放器.exe

Full analysis: https://app.any.run/tasks/18422824-fb83-4c74-9308-f1d9b98a9fb1
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 13, 2020, 07:08:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
trojan
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

577552DEDB19ADC7A97063A012CEA526

SHA1:

0D4274535A3982353E3A6038A0599F4322D2420B

SHA256:

B8F024CC1D620EC43BFA56CCAF156B99C50A440606F58B4B5469F781C40C675B

SSDEEP:

24576:bAM59/cmPOXoeFZYJS6cYE0eMZWAGJrXN3GlHdZkqC7ZFwDjm0eQiUMBCYN:bAM59/cmGXo2+JS6cYERMZDNHkrXEmya

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Downloads executable files from the Internet

      • 暴风影音播放器.exe (PID: 2956)
      • kxetray.exe (PID: 1548)
    • Changes the autorun value in the registry

      • 暴风影音播放器.exe (PID: 2956)
    • Loads dropped or rewritten executable

      • 暴风影音播放器.exe (PID: 2956)
      • ksoftmgr.exe (PID: 3640)
      • kavlog2.exe (PID: 3372)
      • kislive.exe (PID: 2760)
      • kxescore.exe (PID: 2220)
      • kxetray.exe (PID: 1688)
      • kxescore.exe (PID: 3880)
      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
      • rcmdhelper.exe (PID: 3776)
      • keyemain.exe (PID: 3284)
      • rcmdhelper.exe (PID: 2940)
      • rcmdhelper.exe (PID: 1744)
      • keyemain.exe (PID: 3708)
      • rcmdhelper.exe (PID: 3572)
      • rcmdhelper.exe (PID: 2472)
      • rcmdhelper.exe (PID: 3336)
      • rcmdhelper.exe (PID: 3892)
      • rcmdhelper.exe (PID: 3912)
      • rcmdhelper.exe (PID: 3340)
      • explorer.exe (PID: 372)
      • DllHost.exe (PID: 528)
      • DllHost.exe (PID: 4788)
    • Application was dropped or rewritten from another process

      • ksoftmgr.exe (PID: 3640)
      • kavlog2.exe (PID: 3372)
      • kxescore.exe (PID: 2220)
      • kxetray.exe (PID: 1688)
      • kislive.exe (PID: 2760)
      • kxescore.exe (PID: 3880)
      • kxetray.exe (PID: 1548)
      • khealtheye.exe (PID: 1492)
      • keyemain.exe (PID: 3284)
      • keyemain.exe (PID: 3708)
      • ksoftmgr.exe (PID: 2060)
      • rcmdhelper.exe (PID: 2940)
      • rcmdhelper.exe (PID: 1744)
      • rcmdhelper.exe (PID: 3776)
      • rcmdhelper.exe (PID: 3572)
      • rcmdhelper.exe (PID: 3892)
      • rcmdhelper.exe (PID: 2472)
      • rcmdhelper.exe (PID: 3336)
      • rcmdhelper.exe (PID: 3912)
      • rcmdhelper.exe (PID: 3340)
    • Connects to CnC server

      • 暴风影音播放器.exe (PID: 2956)
      • kxetray.exe (PID: 1548)
    • Changes settings of System certificates

      • ksoftmgr.exe (PID: 2060)
      • kxetray.exe (PID: 1548)
      • kxescore.exe (PID: 3880)
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • 暴风影音播放器.exe (PID: 2372)
      • 暴风影音播放器.exe (PID: 2956)
    • Creates a software uninstall entry

      • 暴风影音播放器.exe (PID: 2956)
      • kxetray.exe (PID: 1548)
    • Reads Internet Cache Settings

      • 暴风影音播放器.exe (PID: 2956)
      • ksoftmgr.exe (PID: 3640)
      • ksoftmgr.exe (PID: 2060)
    • Creates files in the driver directory

      • 暴风影音播放器.exe (PID: 2956)
      • kxescore.exe (PID: 3880)
    • Creates COM task schedule object

      • 暴风影音播放器.exe (PID: 2956)
      • kxescore.exe (PID: 3880)
    • Creates files in the Windows directory

      • kavlog2.exe (PID: 3372)
      • 暴风影音播放器.exe (PID: 2956)
      • kxescore.exe (PID: 3880)
    • Removes files from Windows directory

      • 暴风影音播放器.exe (PID: 2956)
      • kxescore.exe (PID: 3880)
    • Reads internet explorer settings

      • ksoftmgr.exe (PID: 3640)
      • ksoftmgr.exe (PID: 2060)
    • Executable content was dropped or overwritten

      • 暴风影音播放器.exe (PID: 2956)
      • khealtheye.exe (PID: 1492)
      • kxetray.exe (PID: 1548)
      • kxescore.exe (PID: 3880)
    • Creates files in the program directory

      • 暴风影音播放器.exe (PID: 2956)
      • kislive.exe (PID: 2760)
      • kxescore.exe (PID: 2220)
      • kxetray.exe (PID: 1688)
      • khealtheye.exe (PID: 1492)
      • kxescore.exe (PID: 3880)
      • rcmdhelper.exe (PID: 1744)
      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
    • Executed as Windows Service

      • kxescore.exe (PID: 3880)
    • Application launched itself

      • kxetray.exe (PID: 1688)
    • Creates files in the user directory

      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • 暴风影音播放器.exe (PID: 2956)
    • Creates or modifies windows services

      • kxescore.exe (PID: 3880)
      • kxetray.exe (PID: 1548)
    • Searches for installed software

      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
    • Uses NETSH.EXE for network configuration

      • ksoftmgr.exe (PID: 2060)
    • Adds / modifies Windows certificates

      • ksoftmgr.exe (PID: 2060)
      • kxetray.exe (PID: 1548)
      • kxescore.exe (PID: 3880)
    • Connects to server without host name

      • ksoftmgr.exe (PID: 2060)
      • kxetray.exe (PID: 1548)
  • INFO

    • Manual execution by user

      • 暴风影音播放器.exe (PID: 2956)
      • 暴风影音播放器.exe (PID: 3000)
    • Dropped object may contain Bitcoin addresses

      • 暴风影音播放器.exe (PID: 2956)
      • khealtheye.exe (PID: 1492)
      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
    • Reads settings of System Certificates

      • kxescore.exe (PID: 3880)
      • kxetray.exe (PID: 1548)
      • ksoftmgr.exe (PID: 2060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1970:01:16 05:05:20+01:00
PEType: PE32
LinkerVersion: 8
CodeSize: 720896
InitializedDataSize: 585728
UninitializedDataSize: -
EntryPoint: 0x91e24
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 16-Jan-1970 04:05:20
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • e:\KINGSOFT_DUBA\Build\Build_Src\kisengine\kisengine\product\win32\dbginfo\kinstuiofficial.pdb

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 16-Jan-1970 04:05:20
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000AF14C
0x000B0000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.63384
.rdata
0x000B1000
0x00024A94
0x00025000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.9016
.data
0x000D6000
0x0000B580
0x00006000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.69483
.rsrc
0x000E2000
0x00063064
0x00064000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.57498

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.253
1054
Latin 1 / Western European
English - United States
RT_MANIFEST
2
2.54353
296
Latin 1 / Western European
Chinese - PRC
RT_ICON
3
4.35478
3752
Latin 1 / Western European
Chinese - PRC
RT_ICON
4
5.17501
2216
Latin 1 / Western European
Chinese - PRC
RT_ICON
5
3.47748
1384
Latin 1 / Western European
Chinese - PRC
RT_ICON
6
2.83156
9640
Latin 1 / Western European
Chinese - PRC
RT_ICON
7
3.44197
4264
Latin 1 / Western European
Chinese - PRC
RT_ICON
8
4.05874
1128
Latin 1 / Western European
Chinese - PRC
RT_ICON
9
6.44522
38056
Latin 1 / Western European
Chinese - PRC
RT_ICON
10
6.56924
9640
Latin 1 / Western European
Chinese - PRC
RT_ICON

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
MSIMG32.dll
OLEAUT32.dll
PSAPI.DLL
RASAPI32.dll
SHELL32.dll
SHLWAPI.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
76
Monitored processes
28
Malicious processes
18
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start 暴风影音播放器.exe 暴风影音播放器.exe 暴风影音播放器.exe kavlog2.exe ksoftmgr.exe kxetray.exe no specs kxescore.exe no specs kislive.exe no specs kxescore.exe kxetray.exe khealtheye.exe keyemain.exe no specs ksoftmgr.exe keyemain.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs netsh.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs rcmdhelper.exe no specs explorer.exe Thumbnail Cache Out of Proc Server no specs Thumbnail Cache Out of Proc Server no specs 暴风影音播放器.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
528C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1492"c:\program files\kingsoft\kingsoft antivirus\khealtheye.exe" /at=591 /independent=0 /from=3c:\program files\kingsoft\kingsoft antivirus\khealtheye.exe
kxescore.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
护眼大师安装程序
Exit code:
0
Version:
2019,01,23,100
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\khealtheye.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
1548"c:\program files\kingsoft\kingsoft antivirus\kxetray.exe" /autorun /hidefloatwin /silentinstrcmdc:\program files\kingsoft\kingsoft antivirus\kxetray.exe
kxetray.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 金山毒霸
Exit code:
0
Version:
2019,12,25,23534
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\kxetray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1688"c:\program files\kingsoft\kingsoft antivirus\kxetray.exe" /autorun /hidefloatwin /silentinstrcmdc:\program files\kingsoft\kingsoft antivirus\kxetray.exe暴风影音播放器.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 金山毒霸
Exit code:
1
Version:
2019,12,25,23534
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\kxetray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1744"c:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exe" -kdeskcanrcmdc:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exeksoftmgr.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Rcmd Helper
Exit code:
1
Version:
2019,07,23,22409
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2060"c:\program files\kingsoft\kingsoft antivirus\ksoftmgr.exe" -detail:60000030c:\program files\kingsoft\kingsoft antivirus\ksoftmgr.exe
暴风影音播放器.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 软件管家
Exit code:
1
Version:
2019,12,23,23522
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\ksoftmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2220"c:\program files\kingsoft\kingsoft antivirus\kxescore.exe" /start kxescorec:\program files\kingsoft\kingsoft antivirus\kxescore.exe暴风影音播放器.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 防御服务
Exit code:
0
Version:
2019,08,06,22504
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\kxescore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2372"C:\Users\admin\Desktop\暴风影音播放器.exe" C:\Users\admin\Desktop\暴风影音播放器.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\暴风影音播放器.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2472"c:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exe" -updatetaguserc:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exekxetray.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Rcmd Helper
Exit code:
0
Version:
2019,07,23,22409
Modules
Images
c:\program files\kingsoft\kingsoft antivirus\rcmdhelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
6 986
Read events
4 970
Write events
1 937
Delete events
79

Modification events

(PID) Process:(372) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2372) 暴风影音播放器.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
Operation:writeName:idex
Value:
7b9d4d24532ae17d47a04dc0589adcc2
(PID) Process:(2372) 暴风影音播放器.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7A98EC-7EF9-468c-ACC8-37C793DBD7E0}\Implemented Categories\{A5F7140E-4311-4ef9-AABC-F55941B5EBE5}
Operation:writeName:idno
Value:
1
(PID) Process:(2372) 暴风影音播放器.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79B5BC47-CEA1-4772-B433-7D1B3139F278}\Implemented Categories\{607568DD-B059-434b-B7E7-38EC51998F8E}
Operation:writeName:did
Value:
F1D3DCAFB3A799CBB703C72CA49CDFA3
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\Qrfxgbc\暴风影音播放器.rkr
Value:
00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000003F000000500000006BA925000A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED01
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\Qrfxgbc\暴风影音播放器.rkr
Value:
0000000000000000010000008B100000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000003F00000050000000F6B925000A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED01
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\Qrfxgbc\暴风影音播放器.rkr
Value:
0000000000000000020000008B100000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000003F00000051000000F6B925000A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED010A00000018000000868F0F007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005CE9ED0100000000000000000000000000000000480B20020000000005000000D80B200200000000340C200270E9ED01C0E9ED010000000000000000C0DB2002050000002000000000000000000000000100000064666C7464666C7400000000400000000459A377AD0501A70000000000000000010000000000000000000000B02D0C08A82C0C08A4E9ED013DA9D27600000000FBFFFF7FC8E9ED01987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000371054065310540637105406000000000000000000000000080000002E006C006E006B0000006E006400200011000000483D3200403D32002E006C006E006B0000002F0080EA0000C85704AB34EAED018291D27680EAED01EC430000E45704AB48EAED01B69CD276F04311024C06000060EAED01603F11026CEAED0111000000483D3200403D320060EAED01803F1102D0EA0000BC5704AB80EAED018291D276D0EAED0184EAED012795D27600000000EC431102ACEAED01CD94D276EC43110258EBED01603F1102E194D27600000000603F110258EBED01B4EAED01
Executable files
259
Suspicious files
408
Text files
817
Unknown types
594

Dropped files

PID
Process
Filename
Type
2372暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\jcqgx.ini
MD5:
SHA256:
2372暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\kdb_semrjgj.dll
MD5:
SHA256:
2956暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\jcqgx.ini
MD5:
SHA256:
2956暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\kdb_semrjgj.dll
MD5:
SHA256:
2372暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\install_res\installconfig.initext
MD5:
SHA256:
2956暴风影音播放器.exeC:\ProgramData\Kingsoft\KIS\hg.dattext
MD5:
SHA256:
2956暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\kantivirus\kavsetup.logtext
MD5:
SHA256:
2956暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\install_res\installconfig.initext
MD5:
SHA256:
2372暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\install_res\100.pngimage
MD5:A64D7F2A825F5547182E9E3EE25B4544
SHA256:E78B678846C177786E70E29D5111359D4AFF20D9AC5935FAD2BE87B17D7F9FC9
2372暴风影音播放器.exeC:\Users\admin\AppData\Local\Temp\install_res\6001.xmltext
MD5:AC3635EC35DE21D91356384473146AE5
SHA256:0697478EAEDADC34A220BF4A4530352B6282CC771B039900DF2642F7B093BFC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
381
TCP/UDP connections
247
DNS requests
56
Threats
412

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2372
暴风影音播放器.exe
HEAD
200
183.134.21.34:80
http://cd002.www.duba.net/duba/install/packages/ever/kavsetup_sem_20191231.dat
CN
malicious
2372
暴风影音播放器.exe
GET
183.134.21.34:80
http://cd002.www.duba.net/duba/install/packages/ever/kavsetup_sem_20191231.dat
CN
malicious
2956
暴风影音播放器.exe
HEAD
200
183.134.21.34:80
http://dubacdn.cmcmcdn.com/sem/installer/28.png
CN
malicious
2372
暴风影音播放器.exe
GET
200
180.163.149.242:80
http://config.i.duba.net/seminstall/166/28.xml?time=1581577762
CN
text
2.00 Kb
whitelisted
2372
暴风影音播放器.exe
GET
200
183.134.21.34:80
http://dubacdn.cmcmcdn.com/sem/installer/28.png
CN
image
21.3 Kb
malicious
2372
暴风影音播放器.exe
POST
200
203.195.145.151:80
http://infoc0.duba.net/c/
CN
binary
43 b
whitelisted
2372
暴风影音播放器.exe
POST
200
203.195.145.151:80
http://infoc0.duba.net/c/
CN
binary
43 b
whitelisted
2372
暴风影音播放器.exe
POST
200
203.195.145.151:80
http://infoc0.duba.net/c/
CN
binary
43 b
whitelisted
2372
暴风影音播放器.exe
POST
200
203.195.145.151:80
http://infoc0.duba.net/c/
CN
binary
43 b
whitelisted
2372
暴风影音播放器.exe
POST
200
203.195.145.151:80
http://infoc0.duba.net/c/
CN
binary
43 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2956
暴风影音播放器.exe
139.199.215.55:80
ct.duba.net
Shenzhen Tencent Computer Systems Company Limited
CN
malicious
2372
暴风影音播放器.exe
218.24.18.20:80
2398.35go.net
CHINA UNICOM China169 Backbone
CN
suspicious
2372
暴风影音播放器.exe
203.195.145.151:80
infoc0.duba.net
Shenzhen Tencent Computer Systems Company Limited
CN
malicious
2372
暴风影音播放器.exe
183.134.21.34:80
dubacdn.cmcmcdn.com
No.31,Jin-rong Street
CN
malicious
2372
暴风影音播放器.exe
193.112.235.183:80
infoc0.duba.net
CN
malicious
2956
暴风影音播放器.exe
218.24.18.20:80
2398.35go.net
CHINA UNICOM China169 Backbone
CN
suspicious
2956
暴风影音播放器.exe
183.134.21.34:80
dubacdn.cmcmcdn.com
No.31,Jin-rong Street
CN
malicious
2956
暴风影音播放器.exe
193.112.235.183:80
infoc0.duba.net
CN
malicious
2372
暴风影音播放器.exe
180.163.149.242:80
config.i.duba.net
China Telecom (Group)
CN
suspicious
3640
ksoftmgr.exe
58.254.181.35:80
softmgr.duba.net
China Unicom IP network China169 Guangdong province
CN
malicious

DNS requests

Domain
IP
Reputation
2398.35go.net
  • 111.230.214.130
  • 218.24.18.18
  • 218.24.18.13
  • 218.24.18.20
  • 218.24.18.21
  • 218.24.18.12
whitelisted
infoc0.duba.net
  • 203.195.145.151
  • 193.112.235.183
  • 119.29.47.96
whitelisted
dubacdn.cmcmcdn.com
  • 183.134.21.34
  • 183.134.21.45
malicious
www.baidu.com
  • 103.235.46.39
whitelisted
config.i.duba.net
  • 180.163.149.242
  • 180.163.149.240
  • 180.163.149.239
  • 180.163.149.248
  • 180.163.149.244
  • 180.163.149.241
  • 180.163.149.243
  • 180.163.149.238
whitelisted
cd002.www.duba.net
  • 183.134.21.34
  • 183.134.21.45
  • 59.83.229.36
malicious
did.ijinshan.com
  • 139.199.218.80
malicious
ct.duba.net
  • 139.199.215.55
whitelisted
softmgr.duba.net
  • 58.254.181.35
malicious
hm.baidu.com
  • 103.235.46.191
whitelisted

Threats

PID
Process
Class
Message
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Misc activity
ADWARE [PTsecurity] PUP.Win32/KingSoft.E
2372
暴风影音播放器.exe
Misc activity
ADWARE [PTsecurity] PUP.Win32/KingSoft.E
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Misc activity
ADWARE [PTsecurity] PUP.Win32/KingSoft.E
2372
暴风影音播放器.exe
Potentially Bad Traffic
ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2372
暴风影音播放器.exe
Misc activity
ADWARE [PTsecurity] PUP.Win32/KingSoft.E
12 ETPRO signatures available at the full report
Process
Message
暴风影音播放器.exe
07:12:09|~04032| [KAVMENU] reg_duba_32bit
kavlog2.exe
_tWinMain End.
kxescore.exe
c:\program files\kingsoft\kingsoft antivirus\ksapi.dll
kxescore.exe
c:\program files\kingsoft\kingsoft antivirus\ksapi.dll
kxetray.exe
c:\program files\kingsoft\kingsoft antivirus\ksapi.dll
kxetray.exe
c:\program files\kingsoft\kingsoft antivirus\ksapi.dll
kxetray.exe
g_recent_newskin:false -- print
kxetray.exe
RestoreNormalSmallFloatWin -- print
kxetray.exe
SqRestoreCore -- print
kxetray.exe
SqBallShowOptionChange:3 -- print