URL: | https://www.wmzhe.com/soft-48019.html |
Full analysis: | https://app.any.run/tasks/b6cb1a96-27a7-4816-9399-ca96a30af07e |
Verdict: | Malicious activity |
Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
Analysis date: | December 04, 2024, 13:16:52 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MD5: | 97E934991448CC23648CFB24D6683C1C |
SHA1: | 6BBF7017B93A0D710FA6AA506616CA6D78A5156B |
SHA256: | D360896DBF0EA7C9B2D432CEB0376FA069773D2A12ABDAC1702C0841E50440B8 |
SSDEEP: | 3:N8DSLEGKmKaXLG:2OLSmvLG |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
628 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6256 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
1276 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1344 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=4152 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
1620 | "C:\Users\admin\AppData\Local\Temp\kantivirus\InstallHelper.exe" -Pid:"5400" -LogFileName:"C:\Users\admin\AppData\Local\Temp\kantivirus\semPacketDllLog.log" -InstallPath:"C:\Users\admin\AppData\Local\Temp\kantivirus" -Tid1:"168" -Tid2:"100" -Tod1:"211" -Tod2:"1" -IId:"210749396" -UUID:"93D3778DCF0E56EC006B1D3EAC568239" -TryNo:"1335" -SvrId:"2024.SP4.7" -StrategyList:"0;1;2;3;4|0;2;3;4" -Version:"3" -ProductInstalled:"0" -CompetitorMask:"0" -CompetitorInstalled:"0" | C:\Users\admin\AppData\Local\Temp\kantivirus\InstallHelper.exe | Q-Dir_sm60047595e.exe | ||||||||||||
User: admin Company: Kingsoft Corporation Integrity Level: HIGH Description: Kingsoft Security - 安装程序 Exit code: 0 Version: 2022,09,20,1992 Modules
| |||||||||||||||
2008 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6928 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
2092 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6596 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 3221225506 Version: 122.0.2365.59 | |||||||||||||||
2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2280 | "C:\Users\admin\Downloads\Q-Dir_sm60047595e.exe" | C:\Users\admin\Downloads\Q-Dir_sm60047595e.exe | explorer.exe | ||||||||||||
User: admin Company: Kingsoft Corporation Integrity Level: HIGH Description: Kingsoft Security - 安装程序 Exit code: 0 Version: 2024,03,12,2625 Modules
| |||||||||||||||
2408 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5268 --field-trial-handle=2304,i,15940551499277918686,4390123971874575039,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
2408 | "c:\program files (x86)\kingsoft\kingsoft antivirus\kxewsc.exe" /service | C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxewsc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Kingsoft Corporation Integrity Level: SYSTEM Description: Kingsoft Internet Security Version: 2023,11,27,738 Modules
|
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Version |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Date |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | write | Name: | SecurityDescriptor |
Value: D:P(A;;FA;;;SY)(A;;FRFX;;;LS)(A;;FRFX;;;BA) | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Source |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Author |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Description |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Documentation |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | write | Name: | URI |
Value: \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Data |
Value: | |||
(PID) Process: | (1276) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0BAB1E0-8FAF-482E-B71A-58DFBB3B502F} |
Operation: | delete value | Name: | Package |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF135344.TMP | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF135344.TMP | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF135344.TMP | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF135353.TMP | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF135353.TMP | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
6380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | — |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | — |
6988 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | — |
4076 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | — |
4076 | SIHClient.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
488 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
1576 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
5064 | SearchApp.exe | 92.123.104.58:443 | www.bing.com | Akamai International B.V. | DE | unknown |
6688 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6380 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
6688 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6688 | msedge.exe | 61.164.113.248:443 | www.wmzhe.com | WENZHOU, ZHEJIANG Province, P.R.China. | CN | unknown |
Domain | IP | Reputation |
---|---|---|
www.bing.com |
| unknown |
config.edge.skype.com |
| unknown |
www.wmzhe.com |
| unknown |
edge.microsoft.com |
| unknown |
business.bing.com |
| unknown |
edge-mobile-static.azureedge.net |
| unknown |
bzib.nelreports.net |
| unknown |
img.wmzhe.top |
| unknown |
upcdn.b0.upaiyun.com |
| unknown |
hm.baidu.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
Process | Message |
---|---|
Q-Dir_sm60047595e.exe | 13:20:46|~01080| [KAVMENU] unreg_duba_64bit |
Q-Dir_sm60047595e.exe | 13:20:46|~01080| [KAVMENU] reg_duba_64bit |
kavlog2.exe | _tWinMain End. |
ksoftmgr.exe | [magic cube] loading file : c:\program files (x86)\kingsoft\kingsoft antivirus\data\magiccube_version.dat |
ksoftmgr.exe | [magic cube] local cache file not exist,reset data |
ksoftmgr.exe | [magic cube] already init |
ksoftmgr.exe | [magic cube] query url : https://ups.ksmobile.net/cfduba/getversions.php?lan=cn&apkversion=1&channelid=1335&mcc=cn&version=1&osversion=12&platform=1&pkg=com.cmcm.cfduba&aid=&countryCode= |
ksoftmgr.exe | [magic cube] loading file : c:\program files (x86)\kingsoft\kingsoft antivirus\data\magiccube_version.dat |
ksoftmgr.exe | [magic cube] local cache file not exist,reset data |
ksoftmgr.exe | [magic cube] query url : https://ws.ksmobile.net/api/GetCloudMsgAdv?lan=cn&apkversion=1&channelid=1335&mcc=cn&version=1&osversion=12&platform=1&pkg=com.cmcm.cfduba&aid=&countryCode= |