File name:

102181033_416a1a379c78b1c4bd885d0074c18cf0.exe

Full analysis: https://app.any.run/tasks/8bb90bd8-c423-4b83-ac8e-44e943dff7e5
Verdict: Malicious activity
Analysis date: August 29, 2019, 08:45:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

416A1A379C78B1C4BD885D0074C18CF0

SHA1:

16A64196112555DBB38121F92359E004B91E6F3D

SHA256:

C4F5F3DFEBFC69082EED1B79F4762C0BAA366EF3BAAFE2673F46570301558D1E

SSDEEP:

196608:sehz7ydxHLVBU16b6IcXOJUZXEiDztAJ0rk/RaUdoJTUiCXx6E8xq:sqoRRGA+gmZDzacFUJP0ls

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe (PID: 2700)
      • 360DrvMgr.exe (PID: 3328)
      • ComputerZService.exe (PID: 2512)
      • LiveUpdate360.exe (PID: 3520)
      • ScriptExecute.exe (PID: 2528)
    • Application was dropped or rewritten from another process

      • ScriptExecute.exe (PID: 2528)
      • ComputerZService.exe (PID: 2512)
      • 360DrvMgr.exe (PID: 3328)
      • LiveUpdate360.exe (PID: 3520)
      • ComputerZService.exe (PID: 3336)
    • Changes the autorun value in the registry

      • DrvInst.exe (PID: 2156)
      • 360DrvMgr.exe (PID: 3328)
  • SUSPICIOUS

    • Creates files in the program directory

      • 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe (PID: 2700)
      • ComputerZService.exe (PID: 2512)
      • LiveUpdate360.exe (PID: 3520)
    • Creates a software uninstall entry

      • 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe (PID: 2700)
    • Low-level read access rights to disk partition

      • 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe (PID: 2700)
      • ComputerZService.exe (PID: 2512)
      • 360DrvMgr.exe (PID: 3328)
    • Creates files in the user directory

      • 360DrvMgr.exe (PID: 3328)
      • ComputerZService.exe (PID: 2512)
      • LiveUpdate360.exe (PID: 3520)
    • Executable content was dropped or overwritten

      • 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe (PID: 2700)
      • 360DrvMgr.exe (PID: 3328)
      • DrvInst.exe (PID: 2156)
    • Creates files in the Windows directory

      • wusa.exe (PID: 3952)
      • 360DrvMgr.exe (PID: 3328)
      • DrvInst.exe (PID: 1744)
      • DrvInst.exe (PID: 2156)
    • Executed as Windows Service

      • vssvc.exe (PID: 2868)
    • Executed via COM

      • DrvInst.exe (PID: 1744)
      • DrvInst.exe (PID: 3028)
      • rundll32.exe (PID: 2776)
      • DrvInst.exe (PID: 2156)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 1744)
      • DrvInst.exe (PID: 2156)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 1744)
      • DrvInst.exe (PID: 2156)
      • 360DrvMgr.exe (PID: 3328)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 2868)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 1744)
    • Dropped object may contain Bitcoin addresses

      • ComputerZService.exe (PID: 2512)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:26 08:29:14+01:00
PEType: PE32
LinkerVersion: 9
CodeSize: 403968
InitializedDataSize: 9542656
UninitializedDataSize: -
EntryPoint: 0x39228
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.1440
ProductVersionNumber: 2.0.0.1440
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: 360驱动大师
CompanyName: 360.cn
FileDescription: 360驱动大师安装程序
FileVersion: 2.0.0.1440
InternalName: 360DrvMgrInstaller
LegalCopyright: 360.cn
OriginalFileName: 360DrvMgrInstaller.exe
ProductName: 360驱动大师
ProductVersion: 2.0.0.1440

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 26-Dec-2018 07:29:14
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • D:\驱动大师\DriverManager-2.0.0.1440-20181226-2.0.0.1420-temp\Setup\install\ReleaseInstaller.pdb
Comments: 360驱动大师
CompanyName: 360.cn
FileDescription: 360驱动大师安装程序
FileVersion: 2.0.0.1440
InternalName: 360DrvMgrInstaller
LegalCopyright: 360.cn
OriginalFilename: 360DrvMgrInstaller.exe
ProductName: 360驱动大师
ProductVersion: 2.0.0.1440

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 26-Dec-2018 07:29:14
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0006295B
0x00062A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.62587
.rdata
0x00064000
0x000141E2
0x00014200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.83071
.data
0x00079000
0x0000996C
0x00003000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.90851
.rsrc
0x00083000
0x008F8348
0x008F8400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.99976
.reloc
0x0097C000
0x0000A5D4
0x0000A600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
3.88687

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.77792
357
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.22888
166
Latin 1 / Western European
Chinese - PRC
RT_STRING
3
6.08017
1128
Latin 1 / Western European
Chinese - PRC
RT_ICON
128
2.45849
48
Latin 1 / Western European
Chinese - PRC
RT_GROUP_ICON
201
3.936
828
Latin 1 / Western European
Chinese - PRC
RT_DIALOG
225
4.59527
83
Latin 1 / Western European
Chinese - PRC
PNG
226
6.2781
177
Latin 1 / Western European
Chinese - PRC
PNG
232
7.5617
692
Latin 1 / Western European
Chinese - PRC
PNG
233
7.74355
1240
Latin 1 / Western European
Chinese - PRC
PNG
234
7.61152
1138
Latin 1 / Western European
Chinese - PRC
PNG

Imports

ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
CRYPT32.dll
GDI32.dll
KERNEL32.dll
MSIMG32.dll
NETAPI32.dll
OLEAUT32.dll
PSAPI.DLL
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
13
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe 360drvmgr.exe scriptexecute.exe no specs computerzservice.exe no specs liveupdate360.exe wusa.exe no specs vssvc.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe rundll32.exe no specs computerzservice.exe no specs 102181033_416a1a379c78b1c4bd885d0074c18cf0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1744DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{098f825f-ecda-74b9-4749-d754d796447e}\cwawdm.inf" "0" "61229d273" "000005A0" "WinSta0\Default" "000003A4" "208" "C:\360驱动大师目录\下载保存目录\audio_crystal_6.13.10.4048_xp32"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2156DrvInst.exe "2" "211" "PCI\VEN_8086&DEV_2415&SUBSYS_11001AF4&REV_01\3&13C0B0C5&0&38" "C:\Windows\INF\oem4.inf" "cwawdm.inf:Crystal:cs429x:6.13.10.4048:pci\ven_8086&dev_2415" "6972eedc3" "000005A0" "000003C8" "000005CC"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2512"C:\Program Files\360\360DrvMgr\ComputerZService.exe" C:\Program Files\360\360DrvMgr\ComputerZService.exe360DrvMgr.exe
User:
admin
Integrity Level:
HIGH
Description:
鲁大师核心服务模块
Exit code:
1073807364
Version:
3, 2, 0, 1015
Modules
Images
c:\program files\360\360drvmgr\computerzservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2528"C:\Program Files\360\360DrvMgr\ScriptExecute.exe" /uninstallSrvC:\Program Files\360\360DrvMgr\ScriptExecute.exe360DrvMgr.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360驱动大师模块
Exit code:
1
Version:
2.0.0.1320
Modules
Images
c:\program files\360\360drvmgr\scriptexecute.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2700"C:\Users\admin\AppData\Local\Temp\102181033_416a1a379c78b1c4bd885d0074c18cf0.exe" C:\Users\admin\AppData\Local\Temp\102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
explorer.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360驱动大师安装程序
Exit code:
0
Version:
2.0.0.1440
Modules
Images
c:\users\admin\appdata\local\temp\102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2776C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2868C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3028DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "000005C0" "000005A0"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3328"C:\Program Files\360\360DrvMgr\360DrvMgr.exe" /run_by_installerC:\Program Files\360\360DrvMgr\360DrvMgr.exe
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360驱动大师主程序
Exit code:
1073807364
Version:
2.0.0.1410
Modules
Images
c:\program files\360\360drvmgr\360drvmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3336"C:\Program Files\360\360DrvMgr\ComputerZService.exe" C:\Program Files\360\360DrvMgr\ComputerZService.exe360DrvMgr.exe
User:
admin
Integrity Level:
HIGH
Description:
鲁大师核心服务模块
Exit code:
0
Version:
3, 2, 0, 1015
Total events
2 078
Read events
1 380
Write events
679
Delete events
19

Modification events

(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A893393-71A8-4a50-95A1-2B89DE87B24C}
Operation:writeName:
Value:
49
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A893393-71A8-4a50-95A1-2B89DE87B24C}
Operation:delete keyName:
Value:
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\{523A0E97-547D-4c4e-9CF8-A2BD0B38E003}.tmp
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\360DrvMgr
Operation:writeName:UEEnabled
Value:
1
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:DisplayName
Value:
360驱动大师
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:DisplayIcon
Value:
C:\Program Files\360\360DrvMgr\360DrvMgr.exe
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:UninstallString
Value:
C:\Program Files\360\360DrvMgr\uninst.exe
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:DisplayVersion
Value:
2.0.0.1440
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:URLInfoAbout
Value:
http://www.360.cn/qudongdashi/
(PID) Process:(2700) 102181033_416a1a379c78b1c4bd885d0074c18cf0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360DrvMgr
Operation:writeName:Publisher
Value:
360安全中心
Executable files
48
Suspicious files
32
Text files
681
Unknown types
12

Dropped files

PID
Process
Filename
Type
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{F521CD0A-CB71-4a4d-916F-19BA6347B091}.tmp
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{3C8294B8-80FB-487b-906C-E56403760C8F}.tmp\7z.dll
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{5307C096-42BA-4375-A3C3-739EE6E81CDA}.tmp
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\config\config.xml
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\config\defaultskin\MiniUI.xml
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\360LibDrvmgr.dat
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\config\defaultskin\defaultskin.ui
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\360DrvMgr.exe
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\feedback\360ScreenCapture.exe
MD5:
SHA256:
2700102181033_416a1a379c78b1c4bd885d0074c18cf0.exeC:\Users\admin\AppData\Local\Temp\{614E4AAC-1359-4d41-83B4-5FD9FF91E167}.tmp\ComputerZService.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
29
DNS requests
12
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3328
360DrvMgr.exe
GET
104.192.108.18:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3328
360DrvMgr.exe
GET
104.192.108.21:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3328
360DrvMgr.exe
GET
104.192.108.18:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3328
360DrvMgr.exe
GET
200
1.192.137.108:80
http://res.qhsetup.com/drv/inst.htm?type=0&in=1&o=6.1.7601&p=32&i=1507195196&g=0&m=cfe1ce9b8f5123cc37f394accff90c49&ver=2.0.0.1440&dm=1
CN
malicious
3328
360DrvMgr.exe
GET
104.192.108.18:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3328
360DrvMgr.exe
GET
104.192.108.18:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3328
360DrvMgr.exe
GET
104.192.108.18:80
http://dlleak6.360safe.com/leak/win7/kmdf-1.11-Win-6.1-x86.msu
US
malicious
3520
LiveUpdate360.exe
GET
5.254.23.242:80
http://driver.360safe.com/asus/audio_crystal_6.13.10.4048_xp32.zip
RO
malicious
3520
LiveUpdate360.exe
GET
5.254.23.242:80
http://driver.360safe.com/asus/audio_crystal_6.13.10.4048_xp32.zip
RO
malicious
3520
LiveUpdate360.exe
GET
5.254.23.242:80
http://driver.360safe.com/asus/audio_crystal_6.13.10.4048_xp32.zip
RO
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3328
360DrvMgr.exe
104.192.108.21:80
dlleak6.360safe.com
Beijing Qihu Technology Company Limited
US
malicious
3328
360DrvMgr.exe
1.192.137.108:80
res.qhsetup.com
No.31,Jin-rong Street
CN
malicious
3520
LiveUpdate360.exe
1.192.136.135:80
tr.p.360.cn
No.31,Jin-rong Street
CN
unknown
3520
LiveUpdate360.exe
1.192.136.136:3478
st.p.360.cn
No.31,Jin-rong Street
CN
unknown
3328
360DrvMgr.exe
104.192.108.18:80
dlleak6.360safe.com
Beijing Qihu Technology Company Limited
US
suspicious
3520
LiveUpdate360.exe
61.130.28.182:80
update.leak.360.cn
No.31,Jin-rong Street
CN
unknown
3520
LiveUpdate360.exe
5.254.23.242:80
driver.360safe.com
RO
malicious
3328
360DrvMgr.exe
47.254.135.106:443
api.driver.360safe.com
Alibaba (China) Technology Co., Ltd.
US
unknown
3520
LiveUpdate360.exe
47.246.43.228:80
sd.p.360.cn
US
malicious

DNS requests

Domain
IP
Reputation
res.qhsetup.com
  • 1.192.137.108
  • 36.110.213.38
  • 180.163.237.138
malicious
api.driver.360safe.com
  • 47.254.135.106
  • 8.209.82.80
  • 47.254.155.75
unknown
dlleak6.360safe.com
  • 104.192.108.18
  • 104.192.108.21
malicious
agd.p.360.cn
  • 119.188.66.33
whitelisted
st.p.360.cn
  • 1.192.136.170
  • 1.192.136.136
whitelisted
update.leak.360.cn
  • 61.130.28.182
  • 61.133.127.158
unknown
driver.360safe.com
  • 5.254.23.242
malicious
agt.p.360.cn
  • 1.192.136.132
  • 1.192.136.133
whitelisted
tr.p.360.cn
  • 180.163.229.168
  • 180.163.229.167
  • 180.163.229.164
  • 180.163.229.165
  • 1.192.136.132
  • 1.192.136.133
  • 1.192.136.134
  • 1.192.136.135
suspicious
sd.p.360.cn
  • 47.246.43.228
  • 47.246.43.227
  • 47.246.43.226
  • 47.246.43.225
  • 47.246.43.224
  • 47.246.43.223
  • 47.246.43.230
  • 47.246.43.229
whitelisted

Threats

PID
Process
Class
Message
3520
LiveUpdate360.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag false)
3520
LiveUpdate360.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag true change port flag false)
3520
LiveUpdate360.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag true)
Process
Message
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)
102181033_416a1a379c78b1c4bd885d0074c18cf0.exe
(0,0):(618,399)