Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report


General Information

Sample URL:https://down-package.ludashicdn.com/downloader/temp_package/2024-07/%E8%85%BE%E8%AE%AF%E4%BC%9A.%E8%AE%AE_4496905339.exe
Analysis ID:1478577


Range:0 - 100


Multi AV Scanner detection for dropped file
Chrome blocked dangerous download
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Tries to detect virtualization through RDTSC time measurements
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Contains capabilities to detect virtual machines
Downloads executable code via HTTP
Drops PE files
Found dropped PE file which has not been started or loaded
Is looking for software installed on the system
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries disk information (often used to detect virtual machines)
Sigma detected: File Download From Browser Process Via Inline URL
Stores files to the Windows start menu directory


  • System is w10x64_ra
  • chrome.exe (PID: 876 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://down-package.ludashicdn.com/downloader/temp_package/2024-07/???.?_4496905339.exe MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6188 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6888 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5584 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • ???.?_4496905339.exe (PID: 6852 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
    • ???.?_4496905339.exe (PID: 6756 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
    • ???.?_4496905339.exe (PID: 7748 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • rundll32.exe (PID: 7888 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • ???.?_4496905339.exe (PID: 8064 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • ???.?_4496905339.exe (PID: 8116 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • ???.?_4496905339.exe (PID: 7620 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • ???.?_4496905339.exe (PID: 4880 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • ???.?_4496905339.exe (PID: 3964 cmdline: "C:\Users\user\Downloads\???.?_4496905339.exe" MD5: 3490DC6FE080B01509AE7ADF52D6F3D0)
  • cleanup
No yara matches
Source: Process startedAuthor: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://down-package.ludashicdn.com/downloader/temp_package/2024-07/???.?_4496905339.exe, CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://down-package.ludashicdn.com/downloader/temp_package/2024-07/???.?_4496905339.exe, CommandLine|base64offset|contains: -j~b,, Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 3816, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://down-package.ludashicdn.com/downloader/temp_package/2024-07/???.?_4496905339.exe, ProcessId: 876, ProcessName: chrome.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

Source: C:\Users\user\Downloads\Unconfirmed 665717.crdownloadReversingLabs: Detection: 54%
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2


Source: screenshotOCR Text: Untitled ' ik_449690S339.exe m/downloader/temp_package/2024-07/EIF, Keep 4496905339.exe Blocked Dangerous 13:59 ENG p Type here to search SG 22/07/2024
Source: screenshotOCR Text: Untitled ' ik_449690S339.exe /downloader/temp_package/2024-07/EIF, Keep 4496905339.exe Blocked Dangerous 13:59 ENG p Type here to search SG 22/07/2024
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: application/octet-streamContent-Length: 88904672Connection: keep-aliveAccept-Ranges: bytesAge: 989920Etag: "C081926BCE36136646044B124BB34D1E"Last-Modified: Fri, 28 Jun 2024 12:15:16 GMTX-Bdcdn-Cache-Status: TCP_HITX-Oss-Hash-Crc64ecma: 16312945158841337521X-Oss-Meta-Mtime: 1719568454X-Oss-Object-Type: NormalX-Oss-Request-Id: 668F83499C75C63032383725X-Oss-Server-Time: 73X-Oss-Storage-Class: StandardX-Request-Id: e4617eda184e00a71d130ef6ee054f3bX-Request-Ip: edge_hitX-Response-Cinfo: id=5Date: Mon, 22 Jul 2024 18:00:08 GMTvia: cache04.hsct02Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 58 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 5b 03 1e 2f 1f 62 70 7c 1f 62 70 7c 1f 62 70 7c ab fe 81 7c 09 62 70 7c ab fe 83 7c b1 62 70 7c ab fe 82 7c 3f 62 70 7c 88 0b 75 7d 19 62 70 7c 89 0b 78 7d 1d 62 70 7c 1f 62 70 7c 1e 62 70 7c 5e 05 75 7d 0a 62 70 7c 87 0b 75 7d 19 62 70 7c 81 c2 b7 7c 1c 62 70 7c 4d 0a 73 7d 06 62 70 7c 4d 0a 74 7d 3b 62 70 7c 4d 0a 75 7d 9f 62 70 7c 16 1a f3 7c 18 62 70 7c 16 1a e3 7c 36 62 70 7c 1f 62 71 7c 1b 60 70 7c 89 0b 74 7d 1e 62 70 7c 89 0b 75 7d 79 62 70 7c 89 0b 70 7d 1e 62 70 7c 89 0b 8f 7c 1e 62 70 7c 1f 62 e7 7c 1d 62 70 7c 89 0b 72 7d 1e 62 70 7c 52 69 63 68 1f 62 70 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 3e 35 fd 65 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 10 00 24 18 00 00 b0 36 00 00 00 00 00 2b d9 0a 00 00 10 00 00 00 40 18 00 00 00 00 10 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 4f 00 00 04 00 00 7a f1 4c 05 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 80 1c 1d 00 58 00 00 00 d8 1c 1d 00 a4 01 00 00 00 20 1e 00 bc c9 2f 00 00 00 00 00 00 00 00 00 00 6a 4c 05 e0 29 00 00 00 f0 4d 00 d0 47 01 00 70 f9 1a 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 fa 1a 00 Data Ascii: MZ@X!L!This program cannot be run in DOS mode.$[/bp|bp|bp||bp||bp||?bp|u}bp|x}bp|bp|bp|^u}bp|u}bp||bp|Ms}bp|Mt};bp|Mu}bp||bp||6bp|bq|`p|t}bp|u}ybp|p}bp||bp|b|bp|r}bp|Richbp|PEL>5e!$6+@@OzL@X /jL)MGpTh
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: application/octet-streamContent-Length: 88904672Connection: keep-aliveAccept-Ranges: bytesAge: 989920Etag: "C081926BCE36136646044B124BB34D1E"Last-Modified: Fri, 28 Jun 2024 12:15:16 GMTX-Bdcdn-Cache-Status: TCP_HITX-Oss-Hash-Crc64ecma: 16312945158841337521X-Oss-Meta-Mtime: 1719568454X-Oss-Object-Type: NormalX-Oss-Request-Id: 668F83499C75C63032383725X-Oss-Server-Time: 73X-Oss-Storage-Class: StandardX-Request-Id: e4617eda184e00a71d130ef6ee054f3bX-Request-Ip: edge_hitX-Response-Cinfo: id=5Date: Mon, 22 Jul 2024 18:00:08 GMTvia: cache04.hsct02Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 58 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 5b 03 1e 2f 1f 62 70 7c 1f 62 70 7c 1f 62 70 7c ab fe 81 7c 09 62 70 7c ab fe 83 7c b1 62 70 7c ab fe 82 7c 3f 62 70 7c 88 0b 75 7d 19 62 70 7c 89 0b 78 7d 1d 62 70 7c 1f 62 70 7c 1e 62 70 7c 5e 05 75 7d 0a 62 70 7c 87 0b 75 7d 19 62 70 7c 81 c2 b7 7c 1c 62 70 7c 4d 0a 73 7d 06 62 70 7c 4d 0a 74 7d 3b 62 70 7c 4d 0a 75 7d 9f 62 70 7c 16 1a f3 7c 18 62 70 7c 16 1a e3 7c 36 62 70 7c 1f 62 71 7c 1b 60 70 7c 89 0b 74 7d 1e 62 70 7c 89 0b 75 7d 79 62 70 7c 89 0b 70 7d 1e 62 70 7c 89 0b 8f 7c 1e 62 70 7c 1f 62 e7 7c 1d 62 70 7c 89 0b 72 7d 1e 62 70 7c 52 69 63 68 1f 62 70 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 3e 35 fd 65 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 10 00 24 18 00 00 b0 36 00 00 00 00 00 2b d9 0a 00 00 10 00 00 00 40 18 00 00 00 00 10 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 4f 00 00 04 00 00 7a f1 4c 05 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 80 1c 1d 00 58 00 00 00 d8 1c 1d 00 a4 01 00 00 00 20 1e 00 bc c9 2f 00 00 00 00 00 00 00 00 00 00 6a 4c 05 e0 29 00 00 00 f0 4d 00 d0 47 01 00 70 f9 1a 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 fa 1a 00 Data Ascii: MZ@X!L!This program cannot be run in DOS mode.$[/bp|bp|bp||bp||bp||?bp|u}bp|x}bp|bp|bp|^u}bp|u}bp||bp|Ms}bp|Mt};bp|Mu}bp||bp||6bp|bq|`p|t}bp|u}ybp|p}bp||bp|b|bp|r}bp|Richbp|PEL>5e!$6+@@OzL@X /jL)MGpTh
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: application/octet-streamContent-Length: 88904672Connection: keep-aliveAccept-Ranges: bytesAge: 989920Etag: "C081926BCE36136646044B124BB34D1E"Last-Modified: Fri, 28 Jun 2024 12:15:16 GMTX-Bdcdn-Cache-Status: TCP_HITX-Oss-Hash-Crc64ecma: 16312945158841337521X-Oss-Meta-Mtime: 1719568454X-Oss-Object-Type: NormalX-Oss-Request-Id: 668F83499C75C63032383725X-Oss-Server-Time: 73X-Oss-Storage-Class: StandardX-Request-Id: e4617eda184e00a71d130ef6ee054f3bX-Request-Ip: edge_hitX-Response-Cinfo: id=5Date: Mon, 22 Jul 2024 18:00:08 GMTvia: cache04.hsct02Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 58 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 5b 03 1e 2f 1f 62 70 7c 1f 62 70 7c 1f 62 70 7c ab fe 81 7c 09 62 70 7c ab fe 83 7c b1 62 70 7c ab fe 82 7c 3f 62 70 7c 88 0b 75 7d 19 62 70 7c 89 0b 78 7d 1d 62 70 7c 1f 62 70 7c 1e 62 70 7c 5e 05 75 7d 0a 62 70 7c 87 0b 75 7d 19 62 70 7c 81 c2 b7 7c 1c 62 70 7c 4d 0a 73 7d 06 62 70 7c 4d 0a 74 7d 3b 62 70 7c 4d 0a 75 7d 9f 62 70 7c 16 1a f3 7c 18 62 70 7c 16 1a e3 7c 36 62 70 7c 1f 62 71 7c 1b 60 70 7c 89 0b 74 7d 1e 62 70 7c 89 0b 75 7d 79 62 70 7c 89 0b 70 7d 1e 62 70 7c 89 0b 8f 7c 1e 62 70 7c 1f 62 e7 7c 1d 62 70 7c 89 0b 72 7d 1e 62 70 7c 52 69 63 68 1f 62 70 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 3e 35 fd 65 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 10 00 24 18 00 00 b0 36 00 00 00 00 00 2b d9 0a 00 00 10 00 00 00 40 18 00 00 00 00 10 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 4f 00 00 04 00 00 7a f1 4c 05 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 80 1c 1d 00 58 00 00 00 d8 1c 1d 00 a4 01 00 00 00 20 1e 00 bc c9 2f 00 00 00 00 00 00 00 00 00 00 6a 4c 05 e0 29 00 00 00 f0 4d 00 d0 47 01 00 70 f9 1a 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 fa 1a 00 Data Ascii: MZ@X!L!This program cannot be run in DOS mode.$[/bp|bp|bp||bp||bp||?bp|u}bp|x}bp|bp|bp|^u}bp|u}bp||bp|Ms}bp|Mt};bp|Mu}bp||bp||6bp|bq|`p|t}bp|u}ybp|p}bp||bp|b|bp|r}bp|Richbp|PEL>5e!$6+@@OzL@X /jL)MGpTh
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: application/octet-streamContent-Length: 88904672Connection: keep-aliveAccept-Ranges: bytesAge: 989934Etag: "C081926BCE36136646044B124BB34D1E"Last-Modified: Fri, 28 Jun 2024 12:15:16 GMTX-Bdcdn-Cache-Status: TCP_HITX-Oss-Hash-Crc64ecma: 16312945158841337521X-Oss-Meta-Mtime: 1719568454X-Oss-Object-Type: NormalX-Oss-Request-Id: 668F83499C75C63032383725X-Oss-Server-Time: 73X-Oss-Storage-Class: StandardX-Request-Id: fc12987cd5bf68518f0093ed8a923d4bX-Request-Ip: edge_hitX-Response-Cinfo: id=5Date: Mon, 22 Jul 2024 18:00:22 GMTvia: cache01.hsct02Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 58 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 5b 03 1e 2f 1f 62 70 7c 1f 62 70 7c 1f 62 70 7c ab fe 81 7c 09 62 70 7c ab fe 83 7c b1 62 70 7c ab fe 82 7c 3f 62 70 7c 88 0b 75 7d 19 62 70 7c 89 0b 78 7d 1d 62 70 7c 1f 62 70 7c 1e 62 70 7c 5e 05 75 7d 0a 62 70 7c 87 0b 75 7d 19 62 70 7c 81 c2 b7 7c 1c 62 70 7c 4d 0a 73 7d 06 62 70 7c 4d 0a 74 7d 3b 62 70 7c 4d 0a 75 7d 9f 62 70 7c 16 1a f3 7c 18 62 70 7c 16 1a e3 7c 36 62 70 7c 1f 62 71 7c 1b 60 70 7c 89 0b 74 7d 1e 62 70 7c 89 0b 75 7d 79 62 70 7c 89 0b 70 7d 1e 62 70 7c 89 0b 8f 7c 1e 62 70 7c 1f 62 e7 7c 1d 62 70 7c 89 0b 72 7d 1e 62 70 7c 52 69 63 68 1f 62 70 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 3e 35 fd 65 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 10 00 24 18 00 00 b0 36 00 00 00 00 00 2b d9 0a 00 00 10 00 00 00 40 18 00 00 00 00 10 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 4f 00 00 04 00 00 7a f1 4c 05 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 80 1c 1d 00 58 00 00 00 d8 1c 1d 00 a4 01 00 00 00 20 1e 00 bc c9 2f 00 00 00 00 00 00 00 00 00 00 6a 4c 05 e0 29 00 00 00 f0 4d 00 d0 47 01 00 70 f9 1a 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 fa 1a 00 Data Ascii: MZ@X!L!This program cannot be run in DOS mode.$[/bp|bp|bp||bp||bp||?bp|u}bp|x}bp|bp|bp|^u}bp|u}bp||bp|Ms}bp|Mt};bp|Mu}bp||bp||6bp|bq|`p|t}bp|u}ybp|p}bp||bp|b|bp|r}bp|Richbp|PEL>5e!$6+@@OzL@X /jL)MGpTh
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: application/octet-streamContent-Length: 88904672Connection: keep-aliveAccept-Ranges: bytesAge: 989955Etag: "C081926BCE36136646044B124BB34D1E"Last-Modified: Fri, 28 Jun 2024 12:15:16 GMTX-Bdcdn-Cache-Status: TCP_HITX-Oss-Hash-Crc64ecma: 16312945158841337521X-Oss-Meta-Mtime: 1719568454X-Oss-Object-Type: NormalX-Oss-Request-Id: 668F83499C75C63032383725X-Oss-Server-Time: 73X-Oss-Storage-Class: StandardX-Request-Id: ca42b42edd7a4993ecfecb0c8e2f531aX-Request-Ip: edge_hitX-Response-Cinfo: id=5Date: Mon, 22 Jul 2024 18:00:43 GMTvia: cache05.hsct02Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 58 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 5b 03 1e 2f 1f 62 70 7c 1f 62 70 7c 1f 62 70 7c ab fe 81 7c 09 62 70 7c ab fe 83 7c b1 62 70 7c ab fe 82 7c 3f 62 70 7c 88 0b 75 7d 19 62 70 7c 89 0b 78 7d 1d 62 70 7c 1f 62 70 7c 1e 62 70 7c 5e 05 75 7d 0a 62 70 7c 87 0b 75 7d 19 62 70 7c 81 c2 b7 7c 1c 62 70 7c 4d 0a 73 7d 06 62 70 7c 4d 0a 74 7d 3b 62 70 7c 4d 0a 75 7d 9f 62 70 7c 16 1a f3 7c 18 62 70 7c 16 1a e3 7c 36 62 70 7c 1f 62 71 7c 1b 60 70 7c 89 0b 74 7d 1e 62 70 7c 89 0b 75 7d 79 62 70 7c 89 0b 70 7d 1e 62 70 7c 89 0b 8f 7c 1e 62 70 7c 1f 62 e7 7c 1d 62 70 7c 89 0b 72 7d 1e 62 70 7c 52 69 63 68 1f 62 70 7c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 3e 35 fd 65 00 00 00 00 00 00 00 00 e0 00 02 21 0b 01 0e 10 00 24 18 00 00 b0 36 00 00 00 00 00 2b d9 0a 00 00 10 00 00 00 40 18 00 00 00 00 10 00 10 00 00 00 02 00 00 05 00 01 00 00 00 00 00 05 00 01 00 00 00 00 00 00 40 4f 00 00 04 00 00 7a f1 4c 05 02 00 40 01 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 80 1c 1d 00 58 00 00 00 d8 1c 1d 00 a4 01 00 00 00 20 1e 00 bc c9 2f 00 00 00 00 00 00 00 00 00 00 6a 4c 05 e0 29 00 00 00 f0 4d 00 d0 47 01 00 70 f9 1a 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 fa 1a 00 Data Ascii: MZ@X!L!This program cannot be run in DOS mode.$[/bp|bp|bp||bp||bp||?bp|u}bp|x}bp|bp|bp|^u}bp|u}bp||bp|Ms}bp|Mt};bp|Mu}bp||bp||6bp|bq|`p|t}bp|u}ybp|p}bp||bp|b|bp|r}bp|Richbp|PEL>5e!$6+@@OzL@X /jL)MGpTh
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: global trafficHTTP traffic detected: GET /inst/get3 HTTP/1.1Accept: */*Accept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: softmgr-cfg.ludashi.comContent-Length: 192Cache-Control: no-cacheData Raw: 54 43 54 79 36 30 49 76 77 39 5a 57 4d 46 34 56 4e 45 79 50 6b 45 2b 37 4a 6b 55 4f 79 45 34 48 70 70 76 6b 4b 6b 44 7a 72 73 62 48 6f 32 75 48 6e 4b 57 5a 68 2b 2f 34 59 36 52 4d 78 65 50 49 41 2f 70 64 6f 67 62 6d 36 79 57 73 31 53 58 68 4a 44 6b 4c 58 41 33 44 36 71 5a 64 35 6d 79 35 2b 79 6a 65 56 72 64 6b 52 37 6d 73 44 2f 4e 30 36 50 35 77 4b 47 4a 52 48 55 2b 4b 61 64 71 2f 6e 33 6a 78 77 57 75 4d 33 64 30 36 7a 39 4b 30 4b 59 56 63 57 37 61 56 7a 79 76 67 57 41 69 4d 72 66 31 63 4e 71 77 42 7a 70 4d 79 4f 5a 73 2b 6d 2b 58 65 72 7a 75 77 30 75 6f 56 77 2b 79 41 Data Ascii: TCTy60Ivw9ZWMF4VNEyPkE+7JkUOyE4HppvkKkDzrsbHo2uHnKWZh+/4Y6RMxePIA/pdogbm6yWs1SXhJDkLXA3D6qZd5my5+yjeVrdkR7msD/N06P5wKGJRHU+Kadq/n3jxwWuM3d06z9K0KYVcW7aVzyvgWAiMrf1cNqwBzpMyOZs+m+Xerzuw0uoVw+yA
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=run&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=ldsdownstart&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl015sq7bvbJV HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-pc-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /inst/get3 HTTP/1.1Accept: */*Accept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: softmgr-cfg.ludashi.comContent-Length: 192Cache-Control: no-cacheData Raw: 54 43 54 79 36 30 49 76 77 39 5a 57 4d 46 34 56 4e 45 79 50 6b 45 2b 37 4a 6b 55 4f 79 45 34 48 70 70 76 6b 4b 6b 44 7a 72 73 62 48 6f 32 75 48 6e 4b 57 5a 68 2b 2f 34 59 36 52 4d 78 65 50 49 41 2f 70 64 6f 67 62 6d 36 79 57 73 31 53 58 68 4a 44 6b 4c 58 41 33 44 36 71 5a 64 35 6d 79 35 2b 79 6a 65 56 72 64 6b 52 37 6d 73 44 2f 4e 30 36 50 35 77 4b 47 4a 52 48 55 2b 4b 61 64 71 2f 6e 33 6a 78 77 57 75 4d 33 64 30 36 7a 39 4b 30 4b 59 56 63 57 37 61 56 7a 79 76 67 57 41 69 4d 72 66 31 63 4e 71 77 42 7a 70 4d 79 4f 5a 73 2b 6d 2b 58 65 72 7a 75 77 30 75 6f 56 77 2b 79 41 Data Ascii: TCTy60Ivw9ZWMF4VNEyPkE+7JkUOyE4HppvkKkDzrsbHo2uHnKWZh+/4Y6RMxePIA/pdogbm6yWs1SXhJDkLXA3D6qZd5my5+yjeVrdkR7msD/N06P5wKGJRHU+Kadq/n3jxwWuM3d06z9K0KYVcW7aVzyvgWAiMrf1cNqwBzpMyOZs+m+Xerzuw0uoVw+yA
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=run&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=ldsdownstart&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl016CO7bvq8y HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-pc-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=2188&ex_ary[errcode]=14_200_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst/get3 HTTP/1.1Accept: */*Accept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: softmgr-cfg.ludashi.comContent-Length: 192Cache-Control: no-cacheData Raw: 54 43 54 79 36 30 49 76 77 39 5a 57 4d 46 34 56 4e 45 79 50 6b 45 2b 37 4a 6b 55 4f 79 45 34 48 70 70 76 6b 4b 6b 44 7a 72 73 62 48 6f 32 75 48 6e 4b 57 5a 68 2b 2f 34 59 36 52 4d 78 65 50 49 41 2f 70 64 6f 67 62 6d 36 79 57 73 31 53 58 68 4a 44 6b 4c 58 41 33 44 36 71 5a 64 35 6d 79 35 2b 79 6a 65 56 72 64 6b 52 37 6d 73 44 2f 4e 30 36 50 35 77 4b 47 4a 52 48 55 2b 4b 61 64 71 2f 6e 33 6a 78 77 57 75 4d 33 64 30 36 7a 39 4b 30 4b 59 56 63 57 37 61 56 7a 79 76 67 57 41 69 4d 72 66 31 63 4e 71 77 42 7a 70 4d 79 4f 5a 73 2b 6d 2b 58 65 72 7a 75 77 30 75 6f 56 77 2b 79 41 Data Ascii: TCTy60Ivw9ZWMF4VNEyPkE+7JkUOyE4HppvkKkDzrsbHo2uHnKWZh+/4Y6RMxePIA/pdogbm6yWs1SXhJDkLXA3D6qZd5my5+yjeVrdkR7msD/N06P5wKGJRHU+Kadq/n3jxwWuM3d06z9K0KYVcW7aVzyvgWAiMrf1cNqwBzpMyOZs+m+Xerzuw0uoVw+yA
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=run&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=ldsdownstart&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl016u_7bw9kP HTTP/1.1Accept: */*Accept-Encoding: gzip,deflate,brAccept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: cdn-pc-thunder.ludashi.comCache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=2500&ex_ary[errcode]=14_200_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=2500&ex_ary[errcode]=14_200_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@827643332481 HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.3; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: s.ludashi.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /inst/get3 HTTP/1.1Accept: */*Accept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: softmgr-cfg.ludashi.comContent-Length: 192Cache-Control: no-cacheData Raw: 54 43 54 79 36 30 49 76 77 39 5a 57 4d 46 34 56 4e 45 79 50 6b 45 2b 37 4a 6b 55 4f 79 45 34 48 70 70 76 6b 4b 6b 44 7a 72 73 62 48 6f 32 75 48 6e 4b 57 5a 68 2b 2f 34 59 36 52 4d 78 65 50 49 41 2f 70 64 6f 67 62 6d 36 79 57 73 31 53 58 68 4a 44 6b 4c 58 41 33 44 36 71 5a 64 35 6d 79 35 2b 79 6a 65 56 72 64 6b 52 37 6d 73 44 2f 4e 30 36 50 35 77 4b 47 4a 52 48 55 2b 4b 61 64 71 2f 6e 33 6a 78 77 57 75 4d 33 64 30 36 7a 39 4b 30 4b 59 56 63 57 37 61 56 7a 79 76 67 57 41 69 4d 72 66 31 63 4e 71 77 42 7a 70 4d 79 4f 5a 73 2b 6d 2b 58 65 72 7a 75 77 30 75 6f 56 77 2b 79 41 Data Ascii: TCTy60Ivw9ZWMF4VNEyPkE+7JkUOyE4HppvkKkDzrsbHo2uHnKWZh+/4Y6RMxePIA/pdogbm6yWs1SXhJDkLXA3D6qZd5my5+yjeVrdkR7msD/N06P5wKGJRHU+Kadq/n3jxwWuM3d06z9K0KYVcW7aVzyvgWAiMrf1cNqwBzpMyOZs+m+Xerzuw0uoVw+yA
Source: global trafficDNS traffic detected: DNS query: down-package.ludashicdn.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: softmgr-cfg.ludashi.com
Source: global trafficDNS traffic detected: DNS query: softmgr-stat.ludashi.com
Source: global trafficDNS traffic detected: DNS query: s.ludashi.com
Source: global trafficDNS traffic detected: DNS query: cdn-thunder.ludashi.com
Source: global trafficDNS traffic detected: DNS query: paint-s.ludashi.com
Source: global trafficDNS traffic detected: DNS query: cdn-pc-thunder.ludashi.com
Source: unknownHTTP traffic detected: POST /downloader/soft/reportNew HTTP/1.1Accept: */*Accept-Language: zh-CN,zh;q=0.9Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.4044.92 Safari/537.36Host: softmgr-stat.ludashi.comContent-Length: 352Cache-Control: no-cacheData Raw: 38 6a 34 39 4e 37 65 56 70 61 68 37 6b 78 4c 61 47 39 2b 4b 63 54 77 56 65 71 78 71 34 37 69 48 72 69 43 45 75 49 64 69 4e 53 64 45 68 4d 58 76 64 33 6f 31 71 67 36 35 33 54 35 67 4d 54 73 66 67 6a 58 6e 4f 73 49 76 62 74 6c 37 63 57 74 72 32 2b 44 68 2f 59 35 6d 33 6b 41 69 59 4f 48 76 55 6e 4c 51 6e 4a 45 54 6f 7a 79 54 38 58 72 47 52 72 79 41 7a 6b 2f 67 32 79 64 6b 48 6e 61 55 42 79 42 32 77 56 77 54 77 49 77 4e 30 7a 50 6c 69 70 2f 63 46 6e 32 74 53 30 57 73 5a 69 4a 32 71 58 70 62 70 6e 4f 64 61 47 77 73 37 4a 38 70 6e 75 63 6b 34 32 71 42 64 6e 56 67 6c 38 57 64 75 78 69 4a 72 34 2f 5a 66 74 6e 64 55 7a 49 43 47 39 58 45 52 4d 38 6e 55 69 6b 53 33 47 52 64 30 50 50 51 48 4e 75 47 43 64 38 33 31 43 73 77 74 34 4c 4d 66 4d 35 6a 73 74 79 31 4f 2b 6c 2b 2f 45 78 66 68 44 59 6c 35 4d 2f 34 47 58 53 6b 50 47 35 6f 48 75 77 53 54 35 56 4b 69 43 33 32 4c 70 6f 56 61 46 47 55 6f 2b 33 78 70 37 49 43 38 6e 59 75 5a 42 63 57 4c 2b 78 6f 44 69 42 39 7a 4d 66 42 30 73 74 63 52 79 2f 38 31 4f 55 43 55 78 44 70 61 41 7a 56 4b 6f 69 6e 2b 6f 72 6e Data Ascii: 8j49N7eVpah7kxLaG9+KcTwVeqxq47iHriCEuIdiNSdEhMXvd3o1qg653T5gMTsfgjXnOsIvbtl7cWtr2+Dh/Y5m3kAiYOHvUnLQnJETozyT8XrGRryAzk/g2ydkHnaUByB2wVwTwIwN0zPlip/cFn2tS0WsZiJ2qXpbpnOdaGws7J8pnuck42qBdnVgl8WduxiJr4/ZftndUzICG9XERM8nUikS3GRd0PPQHNuGCd831Cswt4LMfM5jsty1O+l+/ExfhDYl5M/4GXSkPG5oHuwST5VKiC32LpoVaFGUo+3xp7IC8nYuZBcWL+xoDiB9zMfB0stcRy/81OUCUxDpaAzVKoin+orn
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory allocated: 77650000 page execute and read and write
Source: classification engineClassification label: mal60.evad.win@29/20@15/159
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile created: C:\Program Files (x86)\Ludashi
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Users\user\Downloads\???.?_4496905339.exeMutant created: \Sessions\1\BaseNamedObjects\CUSERSuserAPPDATAROAMINGDOWNLOADERDOWNLOADERLOG
Source: C:\Users\user\Downloads\???.?_4496905339.exeMutant created: \Sessions\1\BaseNamedObjects\ThunderMissionDownloadingMutex
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile created: C:\Users\user\AppData\Local\Temp\{CBD60465-8C6A-454a-9911-61083ABC1FB3}.tf
Source: C:\Users\user\Downloads\???.?_4496905339.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://down-package.ludashicdn.com/downloader/temp_package/2024-07/???.?_4496905339.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5584 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5584 --field-trial-handle=1916,i,517428189521506084,16175199301985379620,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: unknownProcess created: C:\Users\user\Downloads\???.?_4496905339.exe "C:\Users\user\Downloads\???.?_4496905339.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: apphelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: msasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: gpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptnet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: profapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netbios.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: version.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wininet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iertutil.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: sspicli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winhttp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mswsock.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winnsi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: urlmon.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: srvcli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netutils.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: atlthunk.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windowscodecs.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: schannel.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ntasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncrypt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: msasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: gpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptnet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: profapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netbios.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: version.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wininet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iertutil.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: sspicli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winhttp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mswsock.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winnsi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: urlmon.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: srvcli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netutils.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: atlthunk.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windowscodecs.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: schannel.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ntasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncrypt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: msasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: gpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptnet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: profapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netbios.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: version.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wininet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iertutil.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: sspicli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winhttp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mswsock.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winnsi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: urlmon.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: srvcli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netutils.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: atlthunk.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windowscodecs.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: schannel.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ntasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncrypt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dbghelp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: firewallapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpolicyiomgr.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wldp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: msasn1.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: gpapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: cryptnet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: profapi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netapi32.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netbios.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: version.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: wininet.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: iertutil.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: sspicli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winhttp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: mswsock.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: winnsi.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: urlmon.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: srvcli.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: netutils.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\???.?_4496905339.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{304CE942-6E39-40D8-943A-B913C40C9CD4}\InprocServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\791539ef-d6b9-4d91-82dd-13eaac0fa897.tmpJump to dropped file
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\AN5UOLP8\ludashi_lite_sem[1].dllJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\Unconfirmed 665717.crdownloadJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk

Hooking and other Techniques for Hiding and Protection

Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 11F0005 value: E9 2B BA 4B 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 776ABA30 value: E9 DA 45 B4 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 1540008 value: E9 8B 8E 1B 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 776F8E90 value: E9 80 71 E4 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 1550005 value: E9 8B 4D 41 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 76964D90 value: E9 7A B2 BE 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 16D0005 value: E9 EB EB 2A 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 7697EBF0 value: E9 1A 14 D5 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 16E0005 value: E9 8B 8A 50 74
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 75BE8A90 value: E9 7A 75 AF 8B
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 16F0005 value: E9 2B 02 52 74
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6852 base: 75C10230 value: E9 DA FD AD 8B
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 1690005 value: E9 2B BA 01 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 776ABA30 value: E9 DA 45 FE 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 3260008 value: E9 8B 8E 49 74
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 776F8E90 value: E9 80 71 B6 8B
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 3280005 value: E9 8B 4D 6E 73
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 76964D90 value: E9 7A B2 91 8C
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 32A0005 value: E9 EB EB 6D 73
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 7697EBF0 value: E9 1A 14 92 8C
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 32B0005 value: E9 8B 8A 93 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 75BE8A90 value: E9 7A 75 6C 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 33D0005 value: E9 2B 02 84 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 6756 base: 75C10230 value: E9 DA FD 7B 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 830005 value: E9 2B BA E7 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 776ABA30 value: E9 DA 45 18 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 840008 value: E9 8B 8E EB 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 776F8E90 value: E9 80 71 14 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 850005 value: E9 8B 4D 11 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 76964D90 value: E9 7A B2 EE 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 2CE0005 value: E9 EB EB C9 73
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 7697EBF0 value: E9 1A 14 36 8C
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 2CF0005 value: E9 8B 8A EF 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 75BE8A90 value: E9 7A 75 10 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 2D00005 value: E9 2B 02 F1 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7748 base: 75C10230 value: E9 DA FD 0E 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 660005 value: E9 2B BA 04 77
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 776ABA30 value: E9 DA 45 FB 88
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 670008 value: E9 8B 8E 08 77
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 776F8E90 value: E9 80 71 F7 88
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 680005 value: E9 8B 4D 2E 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 76964D90 value: E9 7A B2 D1 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 6A0005 value: E9 EB EB 2D 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 7697EBF0 value: E9 1A 14 D2 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 7C0005 value: E9 8B 8A 42 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 75BE8A90 value: E9 7A 75 BD 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 7D0005 value: E9 2B 02 44 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 8116 base: 75C10230 value: E9 DA FD BB 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 850005 value: E9 2B BA E5 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 776ABA30 value: E9 DA 45 1A 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 1230008 value: E9 8B 8E 4C 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 776F8E90 value: E9 80 71 B3 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 1240005 value: E9 8B 4D 72 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 76964D90 value: E9 7A B2 8D 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 1260005 value: E9 EB EB 71 75
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 7697EBF0 value: E9 1A 14 8E 8A
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 1370005 value: E9 8B 8A 87 74
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 75BE8A90 value: E9 7A 75 78 8B
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 1380005 value: E9 2B 02 89 74
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 7620 base: 75C10230 value: E9 DA FD 76 8B
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 1550005 value: E9 2B BA 15 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 776ABA30 value: E9 DA 45 EA 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 16C0008 value: E9 8B 8E 03 76
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 776F8E90 value: E9 80 71 FC 89
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 3270005 value: E9 8B 4D 6F 73
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 76964D90 value: E9 7A B2 90 8C
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 3290005 value: E9 EB EB 6E 73
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 7697EBF0 value: E9 1A 14 91 8C
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 32A0005 value: E9 8B 8A 94 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 75BE8A90 value: E9 7A 75 6B 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 32B0005 value: E9 2B 02 96 72
Source: C:\Users\user\Downloads\???.?_4496905339.exeMemory written: PID: 3964 base: 75C10230 value: E9 DA FD 69 8D
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT
Source: C:\Users\user\Downloads\???.?_4496905339.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\???.?_4496905339.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\???.?_4496905339.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

Source: C:\Users\user\Downloads\???.?_4496905339.exeRDTSC instruction interceptor: First address: 9B2B2C second address: 9B2B32 instructions: 0x00000000 rdtsc 0x00000002 movsx eax, sp 0x00000005 pop edi 0x00000006 rdtsc
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001 name: DriverDesc
Source: C:\Users\user\Downloads\???.?_4496905339.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\AN5UOLP8\ludashi_lite_sem[1].dllJump to dropped file
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeRegistry key enumerated: More than 132 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile opened: PhysicalDrive0
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeProcess information queried: ProcessInformation
Source: C:\Users\user\Downloads\???.?_4496905339.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
Process Injection
Credential API Hooking
Query Registry
Remote Services1
Credential API Hooking
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
Registry Run Keys / Startup Folder
Virtualization/Sandbox Evasion
LSASS Memory22
Security Software Discovery
Remote Desktop ProtocolData from Removable Media11
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
Process Injection
Security Account Manager2
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Discovery
Distributed Component Object ModelInput Capture14
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets123
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

https://down-package.ludashicdn.com/downloader/temp_package/2024-07/._4496905339.exe0%Avira URL Cloudsafe
C:\Users\user\Downloads\Unconfirmed 665717.crdownload54%ReversingLabsWin32.Trojan.Generic
No Antivirus matches
No Antivirus matches
http://softmgr-stat.ludashi.com/downloader/soft/reportNew0%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=ldsdownstart&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=thunder&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=run&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://cdn-thunder.ludashi.com/inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll0%Avira URL Cloudsafe
http://softmgr-cfg.ludashi.com/inst/get30%Avira URL Cloudsafe
http://cdn-pc-thunder.ludashi.com/inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl015sq7bvbJV0%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_start&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=0&ex_ary[errcode]=17_0_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=2188&ex_ary[errcode]=14_200_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://cdn-pc-thunder.ludashi.com/inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl016CO7bvq8y0%Avira URL Cloudsafe
http://s.ludashi.com/url2?pid=buysite_1117&type=xzq&action=down_fail&appver=6.1023.1185.719&modver=6.1023.1185.719&mid=476c9762281cd642f0110c29927a8b70&ex_ary[method]=aliyun&ex_ary[time]=2500&ex_ary[errcode]=14_200_0&ex_ary[siteid]=1117&ex_ary[softid]=23080718&ex_ary[os]=10.0.19045&ex_ary[sr]=0&ex_ary[bit]=1&ex_ary[tagid]=soft_lds.fengnue.cn@@8276433324810%Avira URL Cloudsafe
http://cdn-pc-thunder.ludashi.com/inst_pkgs/ludashi/6.1024.4025.626/ludashi_lite_sem.dll?xy_rid=zYl016u_7bw9kP0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation

                          NameMaliciousAntivirus DetectionReputation
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • Avira URL Cloud: safe
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          unknownUnited States
                          unknownUnited States
                          unknownUnited States
                          unknownUnited States
                          unknownUnited States
                          www.google.comUnited States
                          Joe Sandbox version:40.0.0 Tourmaline
                          Analysis ID:1478577
                          Start date and time:2024-07-22 19:59:22 +02:00
                          Joe Sandbox product:CloudBasic
                          Overall analysis duration:
                          Hypervisor based Inspection enabled:false
                          Report type:full
                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                          Sample URL:https://down-package.ludashicdn.com/downloader/temp_package/2024-07/%E8%85%BE%E8%AE%AF%E4%BC%9A.%E8%AE%AE_4496905339.exe
                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                          Number of analysed new started processes analysed:31
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:1
                          • EGA enabled
                          Analysis Mode:stream
                          Analysis stop reason:Timeout
                          • Exclude process from analysis (whitelisted): svchost.exe
                          • Excluded IPs from analysis (whitelisted):,,,
                          • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, clientservices.googleapis.com, clients.l.google.com
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size getting too big, too many NtOpenKeyEx calls found.
                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                          • Report size getting too big, too many NtQueryValueKey calls found.
                          • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                          • VT rate limit hit for: https://down-package.ludashicdn.com/downloader/temp_package/2024-07/._4496905339.exe
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.8409404014017015
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.7356772435069643
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.7555427040902134
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.8409404014017015
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.7356772435069647
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.9660690198796873
                          File Type:ASCII text, with no line terminators
                          Size (bytes):2
                          Entropy (8bit):1.0
                          File Type:ASCII text, with very long lines (1600), with no line terminators
                          Size (bytes):1600
                          Entropy (8bit):5.969265964511363
                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                          Size (bytes):40960
                          Entropy (8bit):6.26977245169501
                          Preview:MZ......................@...................................X...........!..L.!This program cannot be run in DOS mode....$.......[../.bp|.bp|.bp|...|.bp|...|.bp|...|?bp|..u}.bp|..x}.bp|.bp|.bp|^.u}.bp|..u}.bp|..|.bp|M.s}.bp|M.t};bp|M.u}.bp|...|.bp|...|6bp|.bq|.`p|..t}.bp|..u}ybp|..p}.bp|...|.bp|.b.|.bp|..r}.bp|Rich.bp|........................PE..L...>5.e...........!.....$....6.....+........@...............................@O.....z.L...@.............................X............ ..../..........jL..)....M..G..p...T...................h...........@............@..`............................text...W".......$.................. ..`.rdata..&....@.......(..............@..@.data........P.......6..............@....rsrc...../.. ..../.................@..@.reloc...G....M..H....M.............@..B................................................................................................................................................................................................................
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.7684433618710838
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.6631802039763475
                          File Type:data
                          Size (bytes):38
                          Entropy (8bit):2.7158117829237156
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 22 16:59:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2673
                          Entropy (8bit):3.9880849031037577
                          Preview:L..................F.@.. ...$+.,.....C..`...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xx............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 22 16:59:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2675
                          Entropy (8bit):4.008010403255031
                          Preview:L..................F.@.. ...$+.,........`...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xx............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2689
                          Entropy (8bit):4.014748080647959
                          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 22 16:59:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2677
                          Entropy (8bit):4.003182632299254
                          Preview:L..................F.@.. ...$+.,....e...`...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xx............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 22 16:59:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2677
                          Entropy (8bit):3.993512055931813
                          Preview:L..................F.@.. ...$+.,....Y...`...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xx............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 22 16:59:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                          Size (bytes):2679
                          Entropy (8bit):4.0041163601117225
                          Preview:L..................F.@.. ...$+.,........`...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xq.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.Xw.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Xw.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Xw............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Xx............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............5.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Size (bytes):16384
                          Entropy (8bit):7.256384775198924
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...8..d.................:..........,.I......P....@...................................O...@.........................tZt.H...p.o.........=.............O.....................................P... ...@..@.............v.x.....<......................text....8.......................... ..`.rdata...c...P......................@..@.data...............................@....upx0...n.).........................`..`.upx1....ZH...9..\H.................`..`.reloc...............`H.............@..@.rsrc...=............fH.............@..@........................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Size (bytes):5187472
                          Entropy (8bit):7.874859686733168
                          • Antivirus: ReversingLabs, Detection: 54%
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...8..d.................:..........,.I......P....@...................................O...@.........................tZt.H...p.o.........=.............O.....................................P... ...@..@.............v.x.....<......................text....8.......................... ..`.rdata...c...P......................@..@.data...............................@....upx0...n.).........................`..`.upx1....ZH...9..\H.................`..`.reloc...............`H.............@..@.rsrc...=............fH.............@..@........................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                          Size (bytes):0
                          Entropy (8bit):0.0
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...8..d.................:..........,.I......P....@...................................O...@.........................tZt.H...p.o.........=.............O.....................................P... ...@..@.............v.x.....<......................text....8.......................... ..`.rdata...c...P......................@..@.data...............................@....upx0...n.).........................`..`.upx1....ZH...9..\H.................`..`.reloc...............`H.............@..@.rsrc...=............fH.............@..@........................................................................................................................................................................................................................................................................................................................................................
                          No static file info