URL:

https://www.wmzhe.com/soft-48019.html

Full analysis: https://app.any.run/tasks/b6cb1a96-27a7-4816-9399-ca96a30af07e
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: December 04, 2024, 13:16:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
arch-html
xor-url
generic
floxif
backdoor
spyware
Indicators:
MD5:

97E934991448CC23648CFB24D6683C1C

SHA1:

6BBF7017B93A0D710FA6AA506616CA6D78A5156B

SHA256:

D360896DBF0EA7C9B2D432CEB0376FA069773D2A12ABDAC1702C0841E50440B8

SSDEEP:

3:N8DSLEGKmKaXLG:2OLSmvLG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Application was injected by another process

      • svchost.exe (PID: 1276)
      • svchost.exe (PID: 2816)
      • svchost.exe (PID: 2192)
    • XORed URL has been found (YARA)

      • ksoftmgr.exe (PID: 7708)
    • Runs injected code in another process

      • kxescore.exe (PID: 7008)
    • FLOXIF has been detected (YARA)

      • ksoftmgr.exe (PID: 7708)
  • SUSPICIOUS

    • Creates files in the driver directory

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Executable content was dropped or overwritten

      • Q-Dir_sm60047595e.exe (PID: 5400)
      • kxescore.exe (PID: 7008)
    • Reads security settings of Internet Explorer

      • Q-Dir_sm60047595e.exe (PID: 5400)
      • ksoftmgr.exe (PID: 3828)
      • ksoftmgr.exe (PID: 7708)
    • Creates a software uninstall entry

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Creates/Modifies COM task schedule object

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Process drops legitimate windows executable

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • The process drops C-runtime libraries

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Reads Internet Explorer settings

      • ksoftmgr.exe (PID: 3828)
      • ksoftmgr.exe (PID: 7708)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • ksoftmgr.exe (PID: 7708)
    • Executes as Windows Service

      • kxescore.exe (PID: 7008)
      • kxewsc.exe (PID: 2408)
    • Searches for installed software

      • ksoftmgr.exe (PID: 7708)
    • Creates or modifies Windows services

      • kxescore.exe (PID: 7008)
    • Checks Windows Trust Settings

      • kxescore.exe (PID: 7008)
    • Drops a system driver (possible attempt to evade defenses)

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • The process verifies whether the antivirus software is installed

      • Q-Dir_sm60047595e.exe (PID: 5400)
  • INFO

    • Executable content was dropped or overwritten

      • msedge.exe (PID: 6380)
      • msedge.exe (PID: 6688)
    • Reads the computer name

      • Q-Dir_sm60047595e.exe (PID: 5400)
      • InstallHelper.exe (PID: 1620)
      • ksoftmgr.exe (PID: 3828)
      • ksoftmgr.exe (PID: 7708)
    • Reads the machine GUID from the registry

      • Q-Dir_sm60047595e.exe (PID: 5400)
      • kxescore.exe (PID: 7008)
    • Creates files in the program directory

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • The process uses the downloaded file

      • msedge.exe (PID: 6380)
    • Process checks computer location settings

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Checks supported languages

      • Q-Dir_sm60047595e.exe (PID: 5400)
      • kavlog2.exe (PID: 3888)
      • InstallHelper.exe (PID: 1620)
      • kxescore.exe (PID: 7008)
      • ksoftmgr.exe (PID: 7708)
    • Sends debugging messages

      • kavlog2.exe (PID: 3888)
      • Q-Dir_sm60047595e.exe (PID: 5400)
      • kxescore.exe (PID: 7008)
      • ksoftmgr.exe (PID: 7708)
      • kupdata.exe (PID: 2792)
    • Checks proxy server information

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Create files in a temporary directory

      • Q-Dir_sm60047595e.exe (PID: 5400)
    • Application launched itself

      • msedge.exe (PID: 6380)
    • Reads the software policy settings

      • kxescore.exe (PID: 7008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
215
Monitored processes
79
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs q-dir_sm60047595e.exe no specs q-dir_sm60047595e.exe msedge.exe no specs q-dir_sm60047595e.exe no specs q-dir_sm60047595e.exe msedge.exe no specs rundll32.exe no specs q-dir_sm60047595e.exe no specs q-dir_sm60047595e.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs installhelper.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs kavlog2.exe ksoftmgr.exe #XOR-URL ksoftmgr.exe netsh.exe no specs conhost.exe no specs kxescore.exe kxewsc.exe no specs kupdata.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs svchost.exe svchost.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6256 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1276C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ScheduleC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
1344"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4152 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1620"C:\Users\admin\AppData\Local\Temp\kantivirus\InstallHelper.exe" -Pid:"5400" -LogFileName:"C:\Users\admin\AppData\Local\Temp\kantivirus\semPacketDllLog.log" -InstallPath:"C:\Users\admin\AppData\Local\Temp\kantivirus" -Tid1:"168" -Tid2:"100" -Tod1:"211" -Tod2:"1" -IId:"210749396" -UUID:"93D3778DCF0E56EC006B1D3EAC568239" -TryNo:"1335" -SvrId:"2024.SP4.7" -StrategyList:"0;1;2;3;4|0;2;3;4" -Version:"3" -ProductInstalled:"0" -CompetitorMask:"0" -CompetitorInstalled:"0"C:\Users\admin\AppData\Local\Temp\kantivirus\InstallHelper.exe
Q-Dir_sm60047595e.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 安装程序
Exit code:
0
Version:
2022,09,20,1992
Modules
Images
c:\users\admin\appdata\local\temp\kantivirus\installhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6928 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6596 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
3221225506
Version:
122.0.2365.59
2192C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2280"C:\Users\admin\Downloads\Q-Dir_sm60047595e.exe" C:\Users\admin\Downloads\Q-Dir_sm60047595e.exe
explorer.exe
User:
admin
Company:
Kingsoft Corporation
Integrity Level:
HIGH
Description:
Kingsoft Security - 安装程序
Exit code:
0
Version:
2024,03,12,2625
Modules
Images
c:\users\admin\downloads\q-dir_sm60047595e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2408"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5268 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2408"c:\program files (x86)\kingsoft\kingsoft antivirus\kxewsc.exe" /service C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxewsc.exeservices.exe
User:
SYSTEM
Company:
Kingsoft Corporation
Integrity Level:
SYSTEM
Description:
Kingsoft Internet Security
Version:
2023,11,27,738
Modules
Images
c:\program files (x86)\kingsoft\kingsoft antivirus\kxewsc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\advapi32.dll
Total events
95 204
Read events
94 647
Write events
332
Delete events
225

Modification events

(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Version
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Date
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:writeName:SecurityDescriptor
Value:
D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA)
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Source
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Author
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Description
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Documentation
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:writeName:URI
Value:
\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Data
Value:
(PID) Process:(1276) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F}
Operation:delete valueName:Package
Value:
Executable files
395
Suspicious files
1 249
Text files
625
Unknown types
2

Dropped files

PID
Process
Filename
Type
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135344.TMP
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135344.TMP
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135344.TMP
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135353.TMP
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135353.TMP
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6380msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
90
DNS requests
80
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
6988
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
4076
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
4076
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
488
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1576
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
unknown
5064
SearchApp.exe
92.123.104.58:443
www.bing.com
Akamai International B.V.
DE
unknown
6688
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6380
msedge.exe
239.255.255.250:1900
unknown
6688
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
6688
msedge.exe
61.164.113.248:443
www.wmzhe.com
WENZHOU, ZHEJIANG Province, P.R.China.
CN
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 92.123.104.58
  • 92.123.104.56
  • 92.123.104.62
  • 92.123.104.51
  • 92.123.104.61
  • 92.123.104.53
  • 92.123.104.59
  • 92.123.104.63
  • 92.123.104.52
unknown
config.edge.skype.com
  • 13.107.42.16
unknown
www.wmzhe.com
  • 61.164.113.248
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
unknown
business.bing.com
  • 13.107.6.158
unknown
edge-mobile-static.azureedge.net
  • 13.107.246.45
unknown
bzib.nelreports.net
  • 23.216.77.152
  • 23.216.77.175
unknown
img.wmzhe.top
  • 185.232.59.134
unknown
upcdn.b0.upaiyun.com
  • 185.232.59.134
unknown
hm.baidu.com
  • 14.215.183.79
  • 111.45.3.198
  • 14.215.182.140
  • 111.45.11.83
  • 183.240.98.228
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
Process
Message
Q-Dir_sm60047595e.exe
13:20:46|~01080| [KAVMENU] unreg_duba_64bit
Q-Dir_sm60047595e.exe
13:20:46|~01080| [KAVMENU] reg_duba_64bit
kavlog2.exe
_tWinMain End.
ksoftmgr.exe
[magic cube] loading file : c:\program files (x86)\kingsoft\kingsoft antivirus\data\magiccube_version.dat
ksoftmgr.exe
[magic cube] local cache file not exist,reset data
ksoftmgr.exe
[magic cube] already init
ksoftmgr.exe
[magic cube] query url : https://ups.ksmobile.net/cfduba/getversions.php?lan=cn&apkversion=1&channelid=1335&mcc=cn&version=1&osversion=12&platform=1&pkg=com.cmcm.cfduba&aid=&countryCode=
ksoftmgr.exe
[magic cube] loading file : c:\program files (x86)\kingsoft\kingsoft antivirus\data\magiccube_version.dat
ksoftmgr.exe
[magic cube] local cache file not exist,reset data
ksoftmgr.exe
[magic cube] query url : https://ws.ksmobile.net/api/GetCloudMsgAdv?lan=cn&apkversion=1&channelid=1335&mcc=cn&version=1&osversion=12&platform=1&pkg=com.cmcm.cfduba&aid=&countryCode=