analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

File_Sample.zip

Full analysis: https://app.any.run/tasks/8ac01db5-e724-4843-9d24-6a47d5f669ad
Verdict: Malicious activity
Analysis date: July 06, 2023, 05:20:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E46CC66CD320187EC4EEB431F26B68E9

SHA1:

192516BAA93A05D2265362E9C3ACE7160E5D506D

SHA256:

A3827035F7F272B73BE9163D9CA67BF92F32362B26435728EC127B3CF1A5A51E

SSDEEP:

98304:QnGJPGPyPb5OEXDDjWfyrIe6vZZ0Vxwpyp6to5wyU2U:Qn6FPscDqarI1j0nwpypx5a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3864)
      • 360secore.exe (PID: 3840)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Loads dropped or rewritten executable

      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3864)
      • 360secore.exe (PID: 3840)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Steals credentials from Web Browsers

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
    • Actions looks like stealing of personal data

      • 360huabao.exe (PID: 3192)
      • 360secore.exe (PID: 616)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360se13.1.6055.0.exe (PID: 3340)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 3048)
      • 360secore.exe (PID: 616)
      • 360secore.exe (PID: 3864)
    • Reads the Internet Settings

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Reads security settings of Internet Explorer

      • 360huabaosetup.exe (PID: 1464)
      • 360secore.exe (PID: 616)
    • Reads settings of System Certificates

      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3440)
    • Checks Windows Trust Settings

      • 360huabaosetup.exe (PID: 1464)
      • 360secore.exe (PID: 616)
    • Searches for installed software

      • 360huabaosetup.exe (PID: 1464)
    • The process verifies whether the antivirus software is installed

      • 360huabaosetup.exe (PID: 1464)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 3192)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 3548)
    • Application launched itself

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 2064)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
    • Reads Mozilla Firefox installation path

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
    • Adds/modifies Windows certificates

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
    • Checks for Java to be installed

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 3756)
    • Process requests binary or script from the Internet

      • 360secore.exe (PID: 616)
  • INFO

    • Checks supported languages

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360se13.1.6055.0.exe (PID: 3340)
      • 360huabao.exe (PID: 1472)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • wmpnscfg.exe (PID: 3248)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3840)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Reads the computer name

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • 360se13.1.6055.0.exe (PID: 3340)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • wmpnscfg.exe (PID: 3248)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • The process checks LSA protection

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 3816)
      • 360huabaosetup.exe (PID: 2624)
      • 360secore.exe (PID: 616)
      • wmpnscfg.exe (PID: 3248)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 3680)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3008)
    • Create files in a temporary directory

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabao.exe (PID: 3192)
      • 360se13.1.6055.0.exe (PID: 3340)
      • setup.exe (PID: 3548)
      • 360secore.exe (PID: 616)
      • 360huabao.exe (PID: 3048)
    • Manual execution by a user

      • 360hb4.0.136.0 (1).exe (PID: 1924)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • wmpnscfg.exe (PID: 3248)
    • Checks proxy server information

      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • setup.exe (PID: 3548)
      • 360huabaosetup.exe (PID: 2624)
      • 360secore.exe (PID: 616)
    • Reads the machine GUID from the registry

      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 1964)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • wmpnscfg.exe (PID: 3248)
      • 360huabao.exe (PID: 2064)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3440)
    • Reads Environment values

      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360huabaosetup.exe (PID: 2624)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 3680)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Creates files or folders in the user directory

      • 360huabaosetup.exe (PID: 1464)
      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 1472)
      • setup.exe (PID: 3548)
      • 360huabao.exe (PID: 784)
      • 360huabao.exe (PID: 2264)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 1964)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360secore.exe (PID: 616)
      • 360huabaosetup.exe (PID: 2624)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 3672)
      • 360huabao.exe (PID: 2064)
      • 360secore.exe (PID: 3864)
      • 360huabao.exe (PID: 3680)
      • 360huabao.exe (PID: 1428)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 2592)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 3700)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 3440)
      • 360huabao.exe (PID: 1356)
      • 360huabao.exe (PID: 3392)
    • Dropped object may contain TOR URL's

      • setup.exe (PID: 3548)
      • 360secore.exe (PID: 616)
      • 360secore.exe (PID: 3864)
    • Process checks computer location settings

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 2896)
      • 360huabao.exe (PID: 3816)
      • 360huabao.exe (PID: 4000)
      • 360huabao.exe (PID: 2816)
      • 360huabao.exe (PID: 2064)
      • 360huabao.exe (PID: 3680)
      • 360huabao.exe (PID: 1472)
      • 360huabao.exe (PID: 3180)
      • 360huabao.exe (PID: 2268)
      • 360huabao.exe (PID: 3756)
      • 360huabao.exe (PID: 1356)
    • Reads CPU info

      • 360huabao.exe (PID: 3192)
      • 360huabao.exe (PID: 3048)
      • 360huabao.exe (PID: 3756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2023:07:06 04:58:20
ZipCRC: 0x38697a0f
ZipCompressedSize: 4117554
ZipUncompressedSize: 4198120
ZipFileName: 360hb4.0.136.0 (1).exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
33
Malicious processes
21
Suspicious processes
10

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe 360hb4.0.136.0 (1).exe 360huabaosetup.exe 360huabao.exe 360huabao.exe 360se13.1.6055.0.exe setup.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360secore.exe 360huabaosetup.exe wmpnscfg.exe no specs 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360secore.exe 360secore.exe no specs 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe 360huabao.exe

Process information

PID
CMD
Path
Indicators
Parent process
3008"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\File_Sample.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
1924"C:\Users\admin\Desktop\File_Sample\360hb4.0.136.0 (1).exe" C:\Users\admin\Desktop\File_Sample\360hb4.0.136.0 (1).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸 服务组件
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\users\admin\desktop\file_sample\360hb4.0.136.0 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1464"C:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\360huabaosetup.exe" --user /exename:360hb4.0.136.0 (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\360huabaosetup.exe
360hb4.0.136.0 (1).exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸 服务组件
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\users\admin\appdata\local\temp\360hb_tmp\4.0.136.0\360huabaosetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3192"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" /deskC:\Users\admin\AppData\Roaming\360huabao\360huabao.exe
360huabaosetup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1472"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" /deskC:\Users\admin\AppData\Roaming\360huabao\360huabao.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
3340"C:\Users\admin\AppData\Local\Temp\360se13.1.6055.0.exe" --secore-install --secore-forsdk --silent-installC:\Users\admin\AppData\Local\Temp\360se13.1.6055.0.exe
360huabao.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360安全浏览器
Exit code:
0
Version:
13.1.6055.0
Modules
Images
c:\users\admin\appdata\local\temp\360se13.1.6055.0.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3548"C:\Users\admin\AppData\Local\Temp\CR_3AD7C.tmp\setup.exe" --exe-path="C:\Users\admin\AppData\Local\Temp\360se13.1.6055.0.exe" --secore-install --secore-forsdk --silent-installC:\Users\admin\AppData\Local\Temp\CR_3AD7C.tmp\setup.exe
360se13.1.6055.0.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360安全浏览器
Exit code:
0
Version:
13.1.6055.0
Modules
Images
c:\users\admin\appdata\local\temp\cr_3ad7c.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
784"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" /deskC:\Users\admin\AppData\Roaming\360huabao\360huabao.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2264"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" /deskC:\Users\admin\AppData\Roaming\360huabao\360huabao.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Exit code:
0
Version:
4.0.136.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
3048"C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe" /hb:1C:\Users\admin\AppData\Roaming\360huabao\360huabao.exe
360huabao.exe
User:
admin
Integrity Level:
MEDIUM
Description:
360壁纸
Version:
4.0.136.0
Modules
Images
c:\users\admin\appdata\roaming\360huabao\360huabao.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
33 753
Read events
33 294
Write events
433
Delete events
26

Modification events

(PID) Process:(3008) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3008) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
77
Suspicious files
293
Text files
410
Unknown types
7

Dropped files

PID
Process
Filename
Type
1464360huabaosetup.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\1288.8441[1].gifimage
MD5:DC1FAA7A890085C88096DF9D5D611594
SHA256:9FACCAC8EA389A38814E46D03B2D4704BC2CAF3BED368F3D6A694CFEBCBF1D29
1464360huabaosetup.exeC:\Users\admin\AppData\Roaming\360huabao\4.0.136.0\360huabao_uninstall.zipcompressed
MD5:CCDDF17A27991B46BC19DEC16EFD941C
SHA256:3B322940B4351471E585459D2143228ED18E2C46199CA8C11465A6E2AFD827A6
1924360hb4.0.136.0 (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\wallpaper_exception.zipcompressed
MD5:9FE2BC0205B508D569644C4CE51197C3
SHA256:AE551CA9105E2D78277C5CE7231435423AABAE6D3D49A2CE4B0876AFAF9C6F5D
1464360huabaosetup.exeC:\Users\admin\AppData\Roaming\360huabao\4.0.136.0\wallpaper_video.zipcompressed
MD5:DFB429F2B1B44010C452D3923B5A453A
SHA256:A60E3FEEEDBD7C4E9353151660C6BCE24FA086496284B13A71C5E404A3742BBD
1924360hb4.0.136.0 (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\360Huabao_shell.zipcompressed
MD5:EEF84F636CD356C57E8E16EA6F1F9AB6
SHA256:B07E859EFBF093320005756386BB535D6411BB929C5CF8FE3A10A15E0BD440DF
1464360huabaosetup.exeC:\Users\admin\AppData\Roaming\360huabao\4.0.136.0\HuabaoUtil.dllexecutable
MD5:97A2089F4693BF4E48E999ADB46B5AE3
SHA256:68D774049017E0C86D1D70F9FDF17001DEBD7D27823EC4FFDA64F8F9094DFC79
1924360hb4.0.136.0 (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\DropDown.zipcompressed
MD5:8E2CAE3269201C2970CF74F5A3F6B251
SHA256:3E8F804987B30B27AFFE2D5549D6A0CAA7E3B2A30B4F0AD4548CEE2001E0772C
1924360hb4.0.136.0 (1).exeC:\Users\admin\AppData\Local\Temp\360hb_tmp\4.0.136.0\360huabao_uninstall.zipcompressed
MD5:CCDDF17A27991B46BC19DEC16EFD941C
SHA256:3B322940B4351471E585459D2143228ED18E2C46199CA8C11465A6E2AFD827A6
1464360huabaosetup.exeC:\Users\admin\AppData\Roaming\360huabao\4.0.136.0\wallpaper_exception.zipcompressed
MD5:9FE2BC0205B508D569644C4CE51197C3
SHA256:AE551CA9105E2D78277C5CE7231435423AABAE6D3D49A2CE4B0876AFAF9C6F5D
1464360huabaosetup.exeC:\Users\admin\AppData\Roaming\360huabao\4.0.136.0\360Huabao_shell.zipcompressed
MD5:EEF84F636CD356C57E8E16EA6F1F9AB6
SHA256:B07E859EFBF093320005756386BB535D6411BB929C5CF8FE3A10A15E0BD440DF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
262
DNS requests
93
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1464
360huabaosetup.exe
GET
200
171.8.167.89:80
http://s.360.cn/360huabao/inst.htm?ver=4.0.136.0&pid=360hb&type=install&mid=9e890a671265c5c253d18ca1660a45cd&m2=&ccsrc=&ss=0&os=2&w64=0&sf=0&wb=0&im=1&ach=0_0_0
CN
whitelisted
616
360secore.exe
GET
104.192.108.20:80
http://dl.360safe.com/sev3/nblk_3.0.0.0027.cab
US
whitelisted
2624
360huabaosetup.exe
GET
200
171.8.167.89:80
http://s.360.cn/360huabao/update.htm?ver=4.0.136.0&to=0_0_0_2&pid=360hb&mid=9e890a671265c5c253d18ca1660a45cd&guid=9e890a671265c5c253d18ca1660a45cd&m2=&m=0&ss=0&w64=0&wb=0&ach=0_0_0&wscore=0&des=0&pic=0&unpic=0&im=1&ents=0
CN
whitelisted
3548
setup.exe
GET
200
39.156.85.201:80
http://seupdate.360safe.com/inst.htm?ver=13.1.6055.0&pid=360secore&type=install&mid=9e890a671265c5c253d18ca1660a45cd&m2=eeeeeeeee9a4e42dc278db3d0cbafd6a76b4ffda2ba6&pid2=&opid=&ss=0&os=2&w64=0&sf=0
CN
suspicious
3548
setup.exe
GET
200
39.156.85.200:80
http://seapp.stat.360safe.com/q.html?name=setup6&sever=13.1.6055.0&appver=13.1.6055.0&mid=9e890a671265c5c253d18ca1660a45cd&c=0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_0_301_704_0_0_0&pid=360secore&pid2=&m2=eeeeeeeee9a4e42dc278db3d0cbafd6a76b4ffda2ba6&opid=&ss=0&os=2&w64=0&sf=0
CN
suspicious
1964
360huabao.exe
GET
200
180.163.251.137:80
http://tt.browser.360.cn/t.html?p=360secore&data_source=8Ju1cx0BGLZDrtVjQYebRw==&t=2134328556&mid=9e890a671265c5c253d18ca1660a45cd
CN
unknown
3192
360huabao.exe
GET
200
104.192.108.21:80
http://dl.360tpcdn.com/se/hbenginedll.cab
US
compressed
2.20 Mb
malicious
1964
360huabao.exe
GET
200
101.198.2.228:80
http://dd.browser.360.cn/static/a/1230.3771.gif?t=5124370746&m=9e890a671265c5c253d18ca1660a45cd
CN
image
6 b
unknown
3192
360huabao.exe
POST
200
180.163.251.24:80
http://cloud.browser.360.cn/hp/sea
CN
whitelisted
3048
360huabao.exe
GET
200
180.163.246.110:80
http://uapi.mp.360.cn/mp/push?m=9e890a671265c5c253d18ca1660a45cd&m2=eeeeeeeee9a4e42dc278db3d0cbafd6a76b4ffda2ba6
CN
binary
65 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1076
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
292
svchost.exe
239.255.255.250:1900
whitelisted
1464
360huabaosetup.exe
180.163.246.72:443
dd.browser.360.cn
China Telecom Group
CN
unknown
1464
360huabaosetup.exe
171.8.167.89:80
s.360.cn
Luoyang, Henan Province, P.R.China.
CN
suspicious
3192
360huabao.exe
180.163.251.24:443
cloud.browser.360.cn
China Telecom Group
CN
unknown
484
lsass.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
484
lsass.exe
104.18.14.101:80
crl.comodoca.com
CLOUDFLARENET
unknown
484
lsass.exe
104.18.15.101:80
crl.comodoca.com
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
dd.browser.360.cn
  • 180.163.246.72
  • 36.99.172.51
  • 101.198.2.228
unknown
s.360.cn
  • 171.8.167.89
  • 101.198.2.147
  • 180.163.251.231
  • 171.13.14.66
whitelisted
cloud.browser.360.cn
  • 180.163.251.24
  • 180.163.252.144
unknown
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
crl.comodoca.com
  • 104.18.15.101
  • 104.18.14.101
whitelisted
ocsp.usertrust.com
  • 104.18.14.101
  • 104.18.15.101
whitelisted
ocsp.crlocsp.cn
  • 101.198.193.5
suspicious
crl.crlocsp.cn
  • 36.110.213.84
  • 101.198.2.196
  • 171.8.167.65
  • 101.198.193.5
  • 180.163.251.149
unknown
dl.360tpcdn.com
  • 104.192.108.21
  • 104.192.108.17
  • 104.192.108.19
  • 104.192.108.20
malicious
dl.360safe.com
  • 104.192.108.21
  • 104.192.108.17
  • 104.192.108.19
  • 104.192.108.20
whitelisted

Threats

PID
Process
Class
Message
616
360secore.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag false)
616
360secore.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag true change port flag false)
616
360secore.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag true)
616
360secore.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag false)
616
360secore.exe
Generic Protocol Command Decode
ET INFO Session Traversal Utilities for NAT (STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change IP flag false change port flag false)
Process
Message
360huabao.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
360huabao.exe
TIMER_MOUSE_ENTER
360huabao.exe
UIEVENT_MOUSELEAVE
360huabao.exe
TIMER_MOUSE_ENTER
360huabao.exe
UIEVENT_MOUSELEAVE
360huabao.exe
TIMER_MOUSE_ENTER
360huabao.exe
UIEVENT_MOUSELEAVE