File name:

WebPlayer.exe

Full analysis: https://app.any.run/tasks/9fecbcc9-7d8f-42df-8879-345d12a3dffd
Verdict: Malicious activity
Analysis date: February 17, 2025, 22:56:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

58EC6581947927432B9C2787A3E14D1A

SHA1:

CEF20989D3E263E13E211120686A0D7057D66245

SHA256:

3FBF5274B4422D421332049128A028E9F0BA68588C184C8A4CA717A0EA041661

SSDEEP:

98304:JdH1yEGxn2nfUA8gM/Q1lTPU/VcAXkOU/sJpH79juy3ExJBy8irDgiH3Ywschr8/:ADtm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • WebPlayer.exe (PID: 4024)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • WebPlayer.exe (PID: 4024)
    • The process creates files with name similar to system file names

      • WebPlayer.exe (PID: 4024)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • WebPlayer.exe (PID: 4024)
    • Executable content was dropped or overwritten

      • WebPlayer.exe (PID: 4024)
  • INFO

    • Checks supported languages

      • WebPlugin_NVR.exe (PID: 6448)
      • WebPlayer.exe (PID: 4024)
    • Reads the computer name

      • WebPlugin_NVR.exe (PID: 6448)
      • WebPlayer.exe (PID: 4024)
    • The sample compiled with english language support

      • WebPlayer.exe (PID: 4024)
    • Create files in a temporary directory

      • WebPlayer.exe (PID: 4024)
    • The sample compiled with chinese language support

      • WebPlayer.exe (PID: 4024)
    • Creates files in the program directory

      • WebPlayer.exe (PID: 4024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:44:50+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 162816
UninitializedDataSize: 1024
EntryPoint: 0x3348
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.5.13.0
ProductVersionNumber: 1.5.13.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
FileDescription: WebPlugin NVR Setup
FileVersion: 0.0.0.0
ProductName: WebPlugin NVR
ProductVersion: 1.5.13.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start webplayer.exe webplugin_nvr.exe no specs webplayer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\WebPlayer.exe" C:\Users\admin\AppData\Local\Temp\WebPlayer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WebPlugin NVR Setup
Exit code:
3221226540
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\webplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4024"C:\Users\admin\AppData\Local\Temp\WebPlayer.exe" C:\Users\admin\AppData\Local\Temp\WebPlayer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
WebPlugin NVR Setup
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\webplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6448"C:\Program Files (x86)\WebPlugin NVR\WebPlugin_NVR.exe"C:\Program Files (x86)\WebPlugin NVR\WebPlugin_NVR.exeWebPlayer.exe
User:
admin
Integrity Level:
HIGH
Description:
WebPlugin NVR.exe
Version:
0, 0, 0, 0
Modules
Images
c:\program files (x86)\webplugin nvr\webplugin_nvr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
430
Read events
415
Write events
13
Delete events
2

Modification events

(PID) Process:(4024) WebPlayer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete keyName:(default)
Value:
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:DisplayName
Value:
WebPlugin_NVR 1.5.13.0
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\WebPlugin NVR\uninst.exe
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\WebPlugin NVR\WebPlugin_NVR.exe
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:DisplayVersion
Value:
1.5.13.0
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:URLInfoAbout
Value:
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:Publisher
Value:
Surveillance Viewer
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebPluginNVR
Operation:writeName:URL Protocol
Value:
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Operation:writeName:C:\Program Files (x86)\WebPlugin NVR\WebPlugin_NVR.exe
Value:
RUNASADMIN
(PID) Process:(4024) WebPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WebPlugin_NVR
Operation:writeName:EstimatedSize
Value:
3214
Executable files
19
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\dsp_audio_aac_enc.dllexecutable
MD5:83C31DB15A229C1B5C26EC20B0E57490
SHA256:E48C3D9BA1CCDF817866AF308D5BA23348543A0C2D1C0A15A4FB9BB94957D6D7
4024WebPlayer.exeC:\Users\admin\AppData\Local\Temp\nsf4AE8.tmp\LangDLL.dllexecutable
MD5:9648B84AEC426C8426E8312B73956216
SHA256:B60AEC1C8956D2140FC1539F216768913F39F5731D708B0E060851823B4FF319
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\dsp_audio_g711.dllexecutable
MD5:B5089264FF83EED7FFD449D5ECB63FB0
SHA256:84FB2B5C467DD8F4A0572A0E05C15E8ECA8553C56BF4179DBA9C65BF16C75B3C
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\dsp_audio_aac.dllexecutable
MD5:75A0BF17F63237F82D697811D0100DED
SHA256:1C970E8049D0C0ADB0A659C1B63718E458D52F4975756B070BD66590AB6ADF65
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\NDAO.dllexecutable
MD5:D788156EE656946423AFCCC8702B75EF
SHA256:085ABBDD396DFF3AA73B7FF7676C53A9299B833194C6C8EAFD678F2D13ABA210
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\NDRM_Module.dllexecutable
MD5:7FD9B9195B3D5F67034BFEB81C475A2D
SHA256:EA1DAE4AC0598947E69404A3EE96CF344832DBA5B2E68B0B9DABFE21AD656CB8
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\dsp_video_h264_1.dllexecutable
MD5:B0731FB9A6429CFFAC618FD4A5CAD8A4
SHA256:3CE93268D5E1AE6570D74BA0334D5250843007EEEAA27D2DF7826E2CC3FE0F06
4024WebPlayer.exeC:\Users\admin\AppData\Local\Temp\nsf4AE8.tmp\FindProcDLL.dllexecutable
MD5:8614C450637267AFACAD1645E23BA24A
SHA256:0FA04F06A6DE18D316832086891E9C23AE606D7784D5D5676385839B21CA2758
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\dsp_video_mjpeg.dllexecutable
MD5:A1F852D4231D86394E7BE0E843751884
SHA256:4FE45E430FBD510949E2D7B886341BEBAD06905E6E569F7715B21527535C2CB6
4024WebPlayer.exeC:\Program Files (x86)\WebPlugin NVR\WebPlugin_NVR.exeexecutable
MD5:0BF9B7D18F3D8787796876F3E1254171
SHA256:E2DC3B0A5E8A85C210CBEA2B831C3F1BF33AD4D2220FF5685EB3886BA1E00A7F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
26
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3732
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6716
SIHClient.exe
GET
200
92.123.22.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6716
SIHClient.exe
GET
200
92.123.22.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4188
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
3976
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2356
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.16.204.161:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.18.97.227:443
go.microsoft.com
Akamai International B.V.
FR
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.16.204.161
  • 2.16.204.141
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
login.live.com
  • 40.126.31.1
  • 20.190.159.23
  • 40.126.31.71
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.75
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 92.123.22.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted

Threats

No threats detected
No debug info