File name:

RealPlayer.exe

Full analysis: https://app.any.run/tasks/53dbd2c3-fdf0-4a5a-9020-fcf4e01e37d9
Verdict: Malicious activity
Analysis date: December 01, 2023, 12:24:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1974B069E6789BA4FC80BE68C026F0D3

SHA1:

3D0AD5039D37F4281547E4E07DDE00911DED2D93

SHA256:

3F6F582974C843690805059AAB8C7249AC7DB079E359AE5F909D6456E691D7A0

SSDEEP:

49152:8LbGMWxIChd+qqLdUd1D1/FBxL/s+VNrUt:8/sxICh8qzH7LG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • RealPlayer.exe (PID: 2644)
      • rnsetup0.exe (PID: 1556)
  • SUSPICIOUS

    • Reads the Internet Settings

      • rnsetup0.exe (PID: 1556)
      • RealPlayer.exe (PID: 2644)
  • INFO

    • Create files in a temporary directory

      • RealPlayer.exe (PID: 2644)
      • rnsetup0.exe (PID: 1556)
    • Checks supported languages

      • RealPlayer.exe (PID: 2644)
      • rnsetup0.exe (PID: 1556)
      • wmpnscfg.exe (PID: 2300)
    • Reads the computer name

      • RealPlayer.exe (PID: 2644)
      • rnsetup0.exe (PID: 1556)
      • wmpnscfg.exe (PID: 2300)
    • Reads the machine GUID from the registry

      • rnsetup0.exe (PID: 1556)
    • Checks proxy server information

      • rnsetup0.exe (PID: 1556)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2300)
    • Creates files in the program directory

      • rnsetup0.exe (PID: 1556)
    • Creates files or folders in the user directory

      • rnsetup0.exe (PID: 1556)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:05 19:06:58+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 59904
InitializedDataSize: 82944
UninitializedDataSize: -
EntryPoint: 0x4504
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 9.8.0.31
ProductVersionNumber: 9.8.0.31
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: RealNetworks, Inc.
FileDescription: RealNetworks Installer
InternalName: RealNetworks Installer
ProductName: RealNetworks Installer (32-bit)
OriginalFileName: rnsetup.EXE
FileVersion: 9.8.0.31
ProductVersion: 9.8.0.31
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start realplayer.exe no specs rnsetup0.exe no specs rnsetup0.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1556"C:\Users\admin\AppData\Local\Temp\rnsetup0.exe" /orgexename="RealPlayer.exe" C:\Users\admin\AppData\Local\Temp\rnsetup0.exe
RealPlayer.exe
User:
admin
Company:
RealNetworks, Inc.
Integrity Level:
HIGH
Description:
RealNetworks Installer
Exit code:
0
Version:
9.8.0.31
Modules
Images
c:\users\admin\appdata\local\temp\rnsetup0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2300"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2644"C:\Users\admin\AppData\Local\Temp\RealPlayer.exe" C:\Users\admin\AppData\Local\Temp\RealPlayer.exeexplorer.exe
User:
admin
Company:
RealNetworks, Inc.
Integrity Level:
MEDIUM
Description:
RealNetworks Installer
Exit code:
0
Version:
9.8.0.31
Modules
Images
c:\users\admin\appdata\local\temp\realplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3976"C:\Users\admin\AppData\Local\Temp\rnsetup0.exe" /orgexename="RealPlayer.exe" C:\Users\admin\AppData\Local\Temp\rnsetup0.exeRealPlayer.exe
User:
admin
Company:
RealNetworks, Inc.
Integrity Level:
MEDIUM
Description:
RealNetworks Installer
Exit code:
3221226540
Version:
9.8.0.31
Modules
Images
c:\users\admin\appdata\local\temp\rnsetup0.exe
c:\windows\system32\ntdll.dll
Total events
1 190
Read events
1 122
Write events
68
Delete events
0

Modification events

(PID) Process:(2644) RealPlayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2644) RealPlayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2644) RealPlayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2644) RealPlayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(1556) rnsetup0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
DA8D9D535124DA01
Executable files
11
Suspicious files
2
Text files
220
Unknown types
0

Dropped files

PID
Process
Filename
Type
1556rnsetup0.exeC:\ProgramData\Real\RealPlayer\S-1-5-21-1302019708-1500728564-335382590-1000text
MD5:47EAA5FFE66C593B3F05606FAA69186F
SHA256:839F76D6F335170255F2C91543D63AAD4B640BF06A802D8F0527A8A00DE85BC9
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\log[1].txttext
MD5:5751D1AAFDB7375CBD1BB221E286CEBA
SHA256:5BC8F416A15291783D353DA675B9283C4E06E547D9FD93F89F1962FCB9CCF431
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\log[2].txttext
MD5:5751D1AAFDB7375CBD1BB221E286CEBA
SHA256:5BC8F416A15291783D353DA675B9283C4E06E547D9FD93F89F1962FCB9CCF431
1556rnsetup0.exeC:\Users\admin\AppData\Local\Temp\rninst~0\ui_data\stubinst_pkg_en-us.cabcompressed
MD5:43C14BDA8CA82DB8D9E736744AE578CD
SHA256:49B719BF21A5E92104C920C54D42E82938CABDE99AB4D59D6701EE5ECE172D9F
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\log[1].txttext
MD5:5751D1AAFDB7375CBD1BB221E286CEBA
SHA256:5BC8F416A15291783D353DA675B9283C4E06E547D9FD93F89F1962FCB9CCF431
1556rnsetup0.exeC:\Users\admin\AppData\Local\Temp\rninst~0\ui_data\inst_config\DotSetupSDK.dllexecutable
MD5:4708285EE8BB5D17FE2BAD5293D03DB5
SHA256:971469A6AF8EBCEDF747A0AA48B3E9D652D00E11EC96DD28CA9B94C83201D0DA
1556rnsetup0.exeC:\Users\admin\AppData\Local\Temp\rninst~0\ui_data\inst_config\gtapi.dllexecutable
MD5:23700AA70D1751D592D8641FC0E0660F
SHA256:45B1A3BB2AE9622FEFC1F131E7D4E6D32EB4F761DBBCCCFE9E239B49F3B78521
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\stubinst_pkg_en-us[1].cabcompressed
MD5:43C14BDA8CA82DB8D9E736744AE578CD
SHA256:49B719BF21A5E92104C920C54D42E82938CABDE99AB4D59D6701EE5ECE172D9F
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\stubinst_config_en[1].xmlxml
MD5:E24E35A95CE74D9C8E329085939A6663
SHA256:AA5D4BF4B274DBD2D312111AAC7533CC617EE26354DB3DD626875E13DC02FAD6
1556rnsetup0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\log[1].txttext
MD5:5751D1AAFDB7375CBD1BB221E286CEBA
SHA256:5BC8F416A15291783D353DA675B9283C4E06E547D9FD93F89F1962FCB9CCF431
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
11
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1556
rnsetup0.exe
GET
200
152.199.20.39:80
http://log.realone.com/rpinst/log.txt?action=installerstarted&value=normal&procid=Intel(R)Core(TM)i5-6400CPU@2.70GHz&gpuid=StandardVGAGraphicsAdapter&dotnetver=2.0.50727|3.0|3.5|4&exename="realplayer.exe"&webuserid=&prod=stub&version=9.8.0.31&distcode=T22END01&sessionid=1401115644&seq=2&loc=none&region=&userid=840cab49d1d34f309bc681bc212ca980&sysid=c0ded323f8a14aaca45312e47fd37e6d&stampcode=T22END01&payload=RealPlayer&li=en&os=6.1.7601|SP1|en&ie=11.00.9600.16428&origcode=&overcode=&xml_id=&pkg_id=
unknown
text
24 b
unknown
1556
rnsetup0.exe
GET
302
52.10.206.47:80
http://switchboard.real.com/geoloc/index.html
unknown
text
171 b
unknown
1556
rnsetup0.exe
GET
44.235.47.129:80
http://switchboard.real.com/geoloc/index.html
unknown
unknown
1556
rnsetup0.exe
GET
52.10.206.47:80
http://switchboard.real.com/geoloc/index.html
unknown
unknown
1556
rnsetup0.exe
GET
152.199.20.39:80
http://log.realone.com/rpinst/log.txt?action=error&value=geolookup_failure&prod=stub&version=9.8.0.31&distcode=T22END01&sessionid=1401115644&seq=3&loc=fail&region=&userid=840cab49d1d34f309bc681bc212ca980&sysid=c0ded323f8a14aaca45312e47fd37e6d&stampcode=T22END01&payload=RealPlayer&li=en&os=6.1.7601|SP1|en&ie=11.00.9600.16428&origcode=&overcode=&xml_id=&pkg_id=
unknown
unknown
1556
rnsetup0.exe
GET
200
152.199.20.39:80
http://log.realone.com/rpinst/log.txt?action=uhcom&value=stubstarted_standalone&prod=stub&version=9.8.0.31&distcode=T22END01&sessionid=1401115644&seq=1&loc=none&region=&userid=840cab49d1d34f309bc681bc212ca980&sysid=c0ded323f8a14aaca45312e47fd37e6d&stampcode=T22END01&payload=RealPlayer&li=en&os=6.1.7601|SP1|en&ie=11.00.9600.16428&origcode=&overcode=&xml_id=&pkg_id=
unknown
text
24 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
1556
rnsetup0.exe
152.199.20.39:80
log.realone.com
EDGECAST
US
unknown
1556
rnsetup0.exe
44.235.47.129:80
switchboard.real.com
AMAZON-02
US
unknown
1556
rnsetup0.exe
52.10.206.47:80
switchboard.real.com
AMAZON-02
US
unknown
1556
rnsetup0.exe
35.83.82.253:443
peoplesearch.real.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
log.realone.com
  • 152.199.20.39
whitelisted
switchboard.real.com
  • 44.235.47.129
  • 52.10.206.47
unknown
peoplesearch.real.com
  • 35.83.82.253
  • 52.38.202.35
  • 35.160.233.74
unknown

Threats

No threats detected
No debug info