| URL: | http://sandai.net |
| Full analysis: | https://app.any.run/tasks/f2203062-7b98-473f-8514-0d0c9ec3fbf6 |
| Verdict: | Malicious activity |
| Analysis date: | November 25, 2020, 10:47:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | CC80E812F43F6118F32B34B856BDCB4A |
| SHA1: | 25AE762D81E246EDC386801DDE78EAD7D0317C1A |
| SHA256: | BB639465677F8D0D60979D9CAEEE651B21CE034E5E73ABEC516EA1AC5EED907B |
| SSDEEP: | 3:N1KNELjo:CW4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | C:\Windows\system32\netsh.exe advfirewall firewall delete rule name="DownloadSDKServer" dir=in action=allow program="C:\Users\admin\AppData\Local\Temp\XmpInstall\6.1.7.810\SDK\DownloadSDKServer.exe" | C:\Windows\system32\netsh.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 292 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="APlayer" dir=in action=allow program="C:\Program Files\Thunder Network\Xmp\Program\APlayer.exe" | C:\Windows\system32\netsh.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 396 | "C:\Program Files\Thunder Network\Xmp\Program\XLServicePlatform.exe" -p | C:\Program Files\Thunder Network\Xmp\Program\XLServicePlatform.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: ShenZhen Xunlei Networking Technologies,LTD Integrity Level: HIGH Description: XLServicePlatform Exit code: 0 Version: 2, 0, 0, 5 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\Downloads\XMPSetup6.1.7.810xmpdl.exe" | C:\Users\admin\Downloads\XMPSetup6.1.7.810xmpdl.exe | chrome.exe | ||||||||||||
User: admin Company: ShenZhen Xunlei Networking Technologies,LTD Integrity Level: HIGH Description: XmpSetup6.1.7.810xmpdl Exit code: 0 Version: 6.1.7.810 Modules
| |||||||||||||||
| 564 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "http://sandai.net" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 784 | C:\Windows\system32\netsh.exe advfirewall firewall add rule name="DownloadSDKServer" dir=in action=allow program="C:\Program Files\Thunder Network\Xmp\Program\resources\bin\SDK\DownloadSDKServer.exe" | C:\Windows\system32\netsh.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 860 | C:\Windows\system32\netsh.exe advfirewall firewall delete rule name="APlayer" dir=in action=allow program="C:\Program Files\Thunder Network\Xmp\Program\APlayer.exe" | C:\Windows\system32\netsh.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 896 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2268 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1000,6668019728418415023,4073725586304577716,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9794691009315178700 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3748 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1080 | "C:\Program Files\Thunder Network\Xmp\Program\AssociateHelper.exe" --associate=.3g2;.3gp;.3gp2;.3gpp;.aac;.ac3;.acc;.aiff;.amr;.amv;.ape;.asf;.ass;.au;.avi;.bik;.cda;.csf;.divx;.dts;.dvd;.evo;.f4v;.flac;.flv;.hlv;.letv;.m1a;.m1v;.m2a;.m2p;.m2ts;.m2v;.m4a;.m4b;.m4p;.m4r;.m4v;.mid;.midi;.mka;.mkv;.mod;.mov;.mp2;.mp2v;.mp3;.mp4;.mpa;.mpc;.mpe;.mpeg;.mpeg1;.mpeg2;.mpeg4;.mpg;.mpv2;.mts;.oga;.ogg;.ogm;.ogv;.ogx;.psb;.pmp;.pva;.qt;.ra;.ram;.rm;.rmvb;.rpm;.rt;.scm;.smi;.smil;.srt;.ssa;.sub;.sup;.swf;.tp;.tpr;.ts;.tta;.usf;.vob;.vp6;.wav;.wm;.wma;.wmp;.wmv;.wv;.xlmv;.hflv;.f5v;.hmp4;.mp5;.hmkv;.mk5; | C:\Program Files\Thunder Network\Xmp\Program\AssociateHelper.exe | — | XMPSetup6.1.7.810xmpdl.exe | |||||||||||
User: admin Company: ShenZhen Xunlei Networking Technologies,LTD Integrity Level: HIGH Description: AssociateHelper Exit code: 0 Version: 1.0.0.3 Modules
| |||||||||||||||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (896) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 564-13250774836917000 |
Value: 259 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (564) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FBE3635-234.pma | — | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | — | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\29b0dbfd-9839-4ff4-a104-6b4a4f02cb85.tmp | — | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF154262.TMP | text | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF154213.TMP | text | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs | binary | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF1542bf.TMP | text | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 564 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF15437b.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/ | CN | html | 7.10 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/homepage.css?h=33931c | CN | text | 9.54 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 103.235.46.191:80 | http://hm.baidu.com/hm.js?eff9bb8c1851f3f4e2fb515943970a1d | HK | text | 14.9 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/earth02.png?h=10e885 | CN | image | 111 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/earth03.png?h=ab2f78 | CN | image | 106 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/earth01.png?h=9bbded | CN | image | 102 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/android.png?h=4bc7d3 | CN | image | 22.9 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/banner_bgmask.png?h=11c08a | CN | image | 44.9 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/banner_bg.jpg?h=b150bd | CN | image | 231 Kb | whitelisted |
2496 | chrome.exe | GET | 200 | 39.104.39.191:80 | http://sandai.net/v2018/dist/spr_common.png?h=26ef6d | CN | image | 13.6 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2496 | chrome.exe | 172.217.18.109:443 | accounts.google.com | Google Inc. | US | suspicious |
2496 | chrome.exe | 39.104.39.191:80 | sandai.net | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2496 | chrome.exe | 27.148.149.248:443 | www.xunlei.com | Fuzhou | CN | suspicious |
2496 | chrome.exe | 120.39.202.103:443 | img-vip-ssl.a.88cdn.com | No.31,Jin-rong Street | CN | unknown |
2496 | chrome.exe | 172.217.21.206:443 | clients1.google.com | Google Inc. | US | whitelisted |
2496 | chrome.exe | 101.133.169.157:80 | res-etl-ssl.xunlei.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2496 | chrome.exe | 103.235.46.191:80 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
2496 | chrome.exe | 103.235.46.191:443 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
2496 | chrome.exe | 47.101.181.191:80 | etl-xlmc-ssl.xunlei.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2496 | chrome.exe | 172.217.22.227:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
sandai.net |
| whitelisted |
accounts.google.com |
| shared |
www.xunlei.com |
| malicious |
img-vip-ssl.a.88cdn.com |
| malicious |
safebrowsing.googleapis.com |
| whitelisted |
bbs.xunlei.com |
| unknown |
beian.miit.gov.cn |
| whitelisted |
biz.xunlei.com |
| malicious |
box.onethingpcs.com |
| unknown |
dl.xunlei.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2380 | DownloadSDKServer.exe | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |