File name:

for卡巴派送.exe

Full analysis: https://app.any.run/tasks/876033e6-ab79-4f4e-b6d8-3961317052f3
Verdict: Malicious activity
Analysis date: October 19, 2024, 13:35:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

824E386BAE478821DA0FCF00F38D98A0

SHA1:

0E3C55A467DB0B20DDBE93607584408C5CA34E65

SHA256:

E565F5698A7702F0E447703EA702A12B42B2D275DB88E6133F1DF78F445FCD8E

SSDEEP:

98304:gYQQdpepppPK0mPeyd23oO1yLu2OzE7vMhN8FnaRCMrw1mFan3dCQTuznumE88Kb:lEXhNqI5L4xErwENrmbrx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • for卡巴派送.exe (PID: 3792)
    • Changes the autorun value in the registry

      • rundll32.exe (PID: 5100)
  • SUSPICIOUS

    • Application launched itself

      • for卡巴派送.exe (PID: 5160)
    • Reads security settings of Internet Explorer

      • for卡巴派送.exe (PID: 5160)
    • Executable content was dropped or overwritten

      • for卡巴派送.exe (PID: 3792)
      • wmcSystem7.exe (PID: 3396)
      • rundll32.exe (PID: 5100)
    • Creates or modifies Windows services

      • for卡巴派送.exe (PID: 3792)
      • wmcSystem7.exe (PID: 2692)
    • Creates a software uninstall entry

      • for卡巴派送.exe (PID: 3792)
    • Likely accesses (executes) a file from the Public directory

      • reg.exe (PID: 6152)
      • wmcUpdater.exe (PID: 7080)
    • The process exported the data from the registry

      • for卡巴派送.exe (PID: 3792)
    • Creates files in the driver directory

      • wmcSystem7.exe (PID: 3396)
    • Executes as Windows Service

      • wmcSystem7.exe (PID: 2692)
      • wmcUpdater.exe (PID: 7124)
    • Uses RUNDLL32.EXE to load library

      • wmcSystem7.exe (PID: 3396)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 5892)
      • regsvr32.exe (PID: 1344)
    • Starts itself from another location

      • wmcUpdater.exe (PID: 7080)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • for卡巴派送.exe (PID: 3792)
    • Executes application which crashes

      • cscript.exe (PID: 6392)
    • Connects to unusual port

      • wmcSystem7.exe (PID: 2692)
    • The process executes VB scripts

      • wmcSystem7.exe (PID: 2692)
    • Drops a system driver (possible attempt to evade defenses)

      • wmcSystem7.exe (PID: 3396)
  • INFO

    • Sends debugging messages

      • for卡巴派送.exe (PID: 5160)
      • for卡巴派送.exe (PID: 3792)
    • Reads the computer name

      • for卡巴派送.exe (PID: 5160)
      • for卡巴派送.exe (PID: 3792)
      • wmcSystem7.exe (PID: 6264)
      • wmcSystem7.exe (PID: 3396)
      • wmcSystem7.exe (PID: 2692)
    • Checks supported languages

      • for卡巴派送.exe (PID: 5160)
      • for卡巴派送.exe (PID: 3792)
      • wmcSystem7.exe (PID: 3396)
      • wmcSystem7.exe (PID: 6264)
      • wmcSystem7.exe (PID: 2692)
    • The process uses the downloaded file

      • for卡巴派送.exe (PID: 5160)
      • runonce.exe (PID: 1084)
    • Creates files in the program directory

      • for卡巴派送.exe (PID: 3792)
      • wmcSystem7.exe (PID: 3396)
      • wmcSystem7.exe (PID: 2692)
    • Reads the machine GUID from the registry

      • wmcSystem7.exe (PID: 3396)
      • wmcSystem7.exe (PID: 6264)
      • wmcSystem7.exe (PID: 2692)
    • Create files in a temporary directory

      • reg.exe (PID: 6152)
    • Process checks computer location settings

      • for卡巴派送.exe (PID: 5160)
    • Reads the time zone

      • runonce.exe (PID: 1084)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 1084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:06 07:32:46+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 200704
InitializedDataSize: 12730880
UninitializedDataSize: -
EntryPoint: 0x21ca8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 23.9.6.0
ProductVersionNumber: 23.9.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Traditional)
CharacterSet: Unicode
CompanyName: Sun & Moon Rise
FileDescription: SMR應用程式
FileVersion: 23.9.6.0
InternalName: SMR
LegalCopyright: Copyright (C) 2020 Sun & Moon Rise Co., Ltd.
ProductName: SMR應用程式
ProductVersion: 23.9.6.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
34
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start for卡巴派送.exe for卡巴派送.exe reg.exe no specs wmcsystem7.exe conhost.exe no specs wmcsystem7.exe no specs wmcsystem7.exe rundll32.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs runonce.exe no specs grpconv.exe no specs wmcupdater.exe conhost.exe no specs wmcupdater.exe conhost.exe no specs wmcupdater.exe netsh.exe no specs conhost.exe no specs regsvr32.exe no specs scheduletask.exe wmcupdater.exe conhost.exe no specs wmcupdater.exe conhost.exe no specs cscript.exe conhost.exe no specs werfault.exe cscript.exe no specs conhost.exe no specs cscript.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Windows\SysWOW64\wmcUpdater.exe" -smr_runC:\Windows\SysWOW64\wmcUpdater.exe
for卡巴派送.exe
User:
admin
Company:
Copyright (C) 2020 Sun & Moon Rise Co., Ltd.
Integrity Level:
HIGH
Description:
WinMaster7 Update Services
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\windows\syswow64\wmcupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
204C:\Windows\System32\cscript.exe "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" /dstatusC:\Windows\System32\cscript.exewmcSystem7.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1084"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\System32\runonce.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
1344 /s "C:\Program Files\WW2017CF\FoxSDKU32w.dll"C:\Windows\SysWOW64\regsvr32.exeregsvr32.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1452\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewmcUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1884\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execscript.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2280C:\WINDOWS\system32\netsh.exe advfirewall firewall delete rule name="WinMasterServices V7 Client7"C:\Windows\SysWOW64\netsh.exefor卡巴派送.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2692"C:\Program Files\WW2017CF\wmcSystem7.exe"C:\Program Files\WW2017CF\wmcSystem7.exe
services.exe
User:
SYSTEM
Company:
TODO: <公司名稱>
Integrity Level:
SYSTEM
Description:
wmcSystem7
Version:
1.0.0.1
Modules
Images
c:\program files\ww2017cf\wmcsystem7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3396"C:\Program Files\WW2017CF\wmcSystem7.exe" -diC:\Program Files\WW2017CF\wmcSystem7.exe
for卡巴派送.exe
User:
admin
Company:
TODO: <公司名稱>
Integrity Level:
HIGH
Description:
wmcSystem7
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\program files\ww2017cf\wmcsystem7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3792"C:\Users\admin\AppData\Local\Temp\for卡巴派送.exe" C:\Users\admin\AppData\Local\Temp\for卡巴派送.exe
for卡巴派送.exe
User:
admin
Company:
Sun & Moon Rise
Integrity Level:
HIGH
Description:
SMR應用程式
Exit code:
1
Version:
23.9.6.0
Modules
Images
c:\users\admin\appdata\local\temp\for卡巴派送.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
19 789
Read events
19 611
Write events
141
Delete events
37

Modification events

(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:delete keyName:(default)
Value:
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win
Operation:writeName:TestValue
Value:
0
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win
Operation:delete valueName:TestValue
Value:
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win
Operation:delete keyName:(default)
Value:
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:License
Value:
180270007700003001900006400360000140337220455
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:Version
Value:
7.23.1015
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:SerialNumber
Value:
4101-2DQH-59MS
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:ConsolePublicKey
Value:
0602000000A400005253413100040000010001002905C54F13EFA7442EE88EF6CE5F537211291F51F3104104FDE1FC2D821E2CBF3A434554BE87206795340803BCEE483D7E512AAB8FFFAFCD50865FBA7AACD637775C5B2DACCB6DBED2E1B22409A0C21141D2A9E130360F893ED3C1D2AB9D21131A6DD9A33714A23788907E85F9EB01BE0B178F876396B993E2E2BFF2B3F2D6CB
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:SignedPublicKey
Value:
060200000024000052534131000800000100010069185E7FE5EA713C888E3B1278218F5E0529E8FDDFAC38843A29C2A05EAB66FDBB63937B4C38CA6FA7AE37F8B86AA8FCABBCEA95A0D67A4B80050E44D48CAAE4D9691C921E805C9E2AB752BEF796899B848522713CB6170860859623CBFAD5C01F2D63A9FCF12F866D165AC9723ADFAA5113093FA1E856B01F1D5FE9FBBEF69AFA4F9D761C294386E421F0D0FE0C372D63EC37086600F5CE8F3D393D0516D326A7A7C5B9B62A54096B5E546C5785953F2A88AE1F18AF1F8CC7059A54324F42A26E730EFA4BB01E34A52F7455E60A37B40BDF6FBD7D90A2A3CA02C9A2DD4ED99E5A42976861125AF0B37DF33DF4A81A783BC01055CAF76A92B0FC06703D44FAE4
(PID) Process:(3792) for卡巴派送.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Win-Win7
Operation:writeName:ConsoleIdentify
Value:
09819BEE1B40B356E9BC9A81E1B1DB38AE538AE47471CA3673DAF9EBCAA7F9CD0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
52
Suspicious files
13
Text files
16
Unknown types
2

Dropped files

PID
Process
Filename
Type
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7ClientPackage.cab
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\cbfsfilter20.dll
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\cbfsfilter2064.dll
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\cbregistry.cab
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\PolicyViewer20.exe
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\PolicyViewer40.exe
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\ServerSchTask.dat
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\winet.lnk
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\WM7installTemp\WinNetDaily.dll
MD5:
SHA256:
3792for卡巴派送.exeC:\Users\Public\SMR7\Debug\ManualUpdate\2024_10_19_DESKTOP-JGLLJLD.logtext
MD5:32598E073B42A5903DFF0BB9F6CDB898
SHA256:6424715C4864885E2E7A6F08D12CFFC9314A8EE808FEFD13C18667D938BC6AA7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
64
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6392
cscript.exe
GET
404
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
6392
cscript.exe
GET
404
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
92.123.104.33:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
92.123.104.19:443
www.bing.com
Akamai International B.V.
DE
whitelisted
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2692
wmcSystem7.exe
203.71.84.107:8150
National Taiwan University
TW
unknown
6392
cscript.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
www.bing.com
  • 92.123.104.33
  • 92.123.104.19
  • 92.123.104.11
  • 92.123.104.59
  • 92.123.104.34
  • 92.123.104.62
  • 92.123.104.32
  • 92.123.104.31
whitelisted
google.com
  • 142.250.186.142
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
watson.events.data.microsoft.com
  • 104.208.16.94
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.73
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.71
  • 20.190.159.0
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted

Threats

No threats detected
Process
Message
for卡巴派送.exe
[ManualUpdate] Read Install Dat(2)
for卡巴派送.exe
[ManualUpdate] Elevate(Dat size Error or Empty)
for卡巴派送.exe
Elevate Run: C:\Users\admin\AppData\Local\Temp\for????.exe
for卡巴派送.exe
2024-10-19 13:35:56_385[3604]:### Build-20241019_133551(23.9.6.0) Initial Informations [C:\Users\admin\AppData\Local\Temp\for????.exe] OS is Windows 10 Enterprise 2009 (CurrentBuildNumber:19045) ###
for卡巴派送.exe
2024-10-19 13:35:56_385[3604]:[admin][3792] ?????? Mutex ??!!
for卡巴派送.exe
2024-10-19 13:35:57_401[3604]:?????????
for卡巴派送.exe
2024-10-19 13:35:57_401[3604]:??????????Dbug??:??[??????_WM7.23.1015-1] ??IP[] AutoWebIP[203.71.84.107] ????[7.23.1015] ????[0] [0] [1] [0] [0] [1] [0] [0] [0] AD?[0] AD?[0] ResetSN[0] NoDriver[0] SerialNumber[4101-2DQH-59MS] CPK[0x0602000000A400005253413100040000010001002905C54F13EFA7442EE88EF6CE5F537211291F51F3104104FDE1FC2D821E2CBF3A434554BE87206795340803BCEE483D7E512AAB8FFFAFCD50865FBA7AACD637775C5B2DACCB6DBED2E1B22409A0C21141D2A9E130360F893ED3C1D2AB9D21131A6DD9A33714A23788907E85F9EB01BE0B178F876396B993E2E2BFF2B3F2D6CB] CID[656]
for卡巴派送.exe
2024-10-19 13:35:57_401[3604]:??????,??<??????>?????
for卡巴派送.exe
2024-10-19 13:35:57_401[3604]:??????????Dbug??:??[??????_WM7.23.1015-1] ??IP[] ????[7.23.1015] ????[0] [0] [1] [0] [0] [1] [0] [0] [0] AD?[0] AD?[0] ResetSN[0] NoDriver[0] SerialNumber[4101-2DQH-59MS] CPK[0x0602000000A400005253413100040000010001002905C54F13EFA7442EE88EF6CE5F537211291F51F3104104FDE1FC2D821E2CBF3A434554BE87206795340803BCEE483D7E512AAB8FFFAFCD50865FBA7AACD637775C5B2DACCB6DBED2E1B22409A0C21141D2A9E130360F893ED3C1D2AB9D21131A6DD9A33714A23788907E85F9EB01BE0B178F876396B993E2E2BFF2B3F2D6CB] CID[656]
for卡巴派送.exe
2024-10-19 13:35:57_494[3604]:????«??????_WM7.23.1015-1»??????