| File name: | 个人团队拖算记帐明细.exe |
| Full analysis: | https://app.any.run/tasks/a0fc1bb7-ccc4-4318-9be5-8f68fd2aeb16 |
| Verdict: | Malicious activity |
| Analysis date: | August 28, 2024, 07:20:09 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 7414B4CAC0C3315F16FBBE56FD375A1E |
| SHA1: | E7F0630D1F2FC7F0CD4DF8A0BA510F847DD922F7 |
| SHA256: | C4C8D1077FF59CD74C9085DD0D6D450D5C4D5A5ACD5A6664E812DF36E2200946 |
| SSDEEP: | 49152:YyL4t3nxi+W8gLy+UBhe26CXLl4p2La9fNLWhLtPXDXTt1SaT1A0:T4t3xhpGy+U/T66o2La9f9ELtPTXTSa5 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:08:23 14:56:36+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 10 |
| CodeSize: | 7680 |
| InitializedDataSize: | 1738240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2610 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1316 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1480 | "C:\Program Files\StarRail.exe" | C:\Program Files\StarRail.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 1920 | C:\WINDOWS\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3964 | cmd /c move C:\WINDOWS\temp\1220578 "C:\Program Files\StarRailBase.dll" | C:\Windows\System32\cmd.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3984 | cmd /c move C:\WINDOWS\temp\1220468 "C:\Program Files\StarRail.exe" | C:\Windows\System32\cmd.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4804 | cmd /c move C:\WINDOWS\temp\1220687 "C:\Program Files\StarRailBase.dat" | C:\Windows\System32\cmd.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5088 | "C:\Users\admin\Desktop\个人团队拖算记帐明细.exe" | C:\Users\admin\Desktop\个人团队拖算记帐明细.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5152 | "C:\WINDOWS\system32\WinDefScan\StarRail.exe" -svc | C:\Windows\System32\WinDefScan\StarRail.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: 上海米哈游网络科技股份有限公司 Integrity Level: SYSTEM Description: Star Rail Exit code: 0 Version: 2019.4.34.1463972 Modules
| |||||||||||||||
| 5724 | C:\WINDOWS\system32\svchost.exe -Install | C:\Windows\System32\svchost.exe | StarRail.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6752 | C:\WINDOWS\system32\dllhost.exe /Processid:{F8284233-48F4-4680-ADDD-F8284233} | C:\Windows\System32\dllhost.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AF3602-9179-4BAE-85B3-74A4EF5CF51F} |
| Operation: | write | Name: | DynamicInfo |
Value: 03000000BDCB09F80A59DA01492E22B81AF9DA010000000000000000927933BA1AF9DA01 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB5CE85E-303A-486F-B7F1-956D2D90533C} |
| Operation: | write | Name: | DynamicInfo |
Value: 030000000324C327AAB7D801492E22B81AF9DA010000000000000000906469BB1AF9DA01 | |||
| (PID) Process: | (5724) svchost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\shell32.dll,-50176 |
Value: File Operation | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | SD |
Value: 01000480B4000000C400000000000000140000000200A00007000000001018009F011F0001020000000000052000000020020000001014009F011F00010100000000000512000000001014008900120001010000000000050B0000000010140089001200010100000000000513000000001014008900120001010000000000051400000000101800FF011F000102000000000005200000002002000000001400890012000101000000000005120000000000000001020000000000052000000020020000010100000000000512000000 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | Id |
Value: {B5B552FB-3C7E-4EA0-B377-C4BD7C641B51} | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | Index |
Value: 1 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51} |
| Operation: | write | Name: | Path |
Value: \Microsoft\Windows\WinDefScan | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51} |
| Operation: | write | Name: | Hash |
Value: 5BDCA39ACA14D8A0DDAB5A0E01882A68CEB956F12F0EBB400D9A1525523B83E2 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51} |
| Operation: | write | Name: | Schema |
Value: 65538 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51} |
| Operation: | delete value | Name: | Version |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5724 | svchost.exe | C:\Windows\System32\WinDefScan\StarRailBase.dll | executable | |
MD5:7A8543A2FAA9E9A70661A4AC195B7B88 | SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19 | |||
| 3984 | cmd.exe | C:\Program Files\StarRail.exe | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 6792 | 个人团队拖算记帐明细.exe | C:\Windows\Temp\1220468 | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 1316 | svchost.exe | C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan | xml | |
MD5:11954764DE4745B35A42219A7C5E2DCA | SHA256:997FCF971A38394C30D9E5CA0C6B36E782630E83B52D2664C56F1DEFBA54CB6C | |||
| 6792 | 个人团队拖算记帐明细.exe | C:\Windows\Temp\1220578 | executable | |
MD5:7A8543A2FAA9E9A70661A4AC195B7B88 | SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19 | |||
| 6792 | 个人团队拖算记帐明细.exe | C:\Windows\Temp\1220687 | binary | |
MD5:F452FD4A33F300AB7FF2B66205BAFE5D | SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266 | |||
| 5724 | svchost.exe | C:\Windows\System32\WinDefScan\StarRail.exe | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 4804 | cmd.exe | C:\Program Files\StarRailBase.dat | binary | |
MD5:F452FD4A33F300AB7FF2B66205BAFE5D | SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266 | |||
| 5724 | svchost.exe | C:\Windows\System32\WinDefScan\StarRailBase.dat | binary | |
MD5:F452FD4A33F300AB7FF2B66205BAFE5D | SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266 | |||
| 3964 | cmd.exe | C:\Program Files\StarRailBase.dll | executable | |
MD5:7A8543A2FAA9E9A70661A4AC195B7B88 | SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4316 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6020 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1920 | svchost.exe | 83.229.127.205:6639 | — | — | NG | unknown |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4316 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4324 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |