| File name: | WMPPlus-2.10.exe |
| Full analysis: | https://app.any.run/tasks/9dec50f4-cf5f-4635-894d-7ef2bb10b18e |
| Verdict: | Malicious activity |
| Analysis date: | June 30, 2024, 11:31:23 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F000593DECA255C8DE9E9488C0FB0D22 |
| SHA1: | 3EE28AF7345D2A4DABEA7686EEC8B1BB2D3A1C89 |
| SHA256: | 3FF227D8C19ECEF336F0B004D2541A15C01F782B1052A2BBA2CEE1E3B0969EEC |
| SSDEEP: | 49152:UzPTeenby1/Os4QFuqFAOF57WYQXNvWmH/cJTEZq5J9jNC57W6YpqXVpMYOqVHL8:wPTeeboOg/6YBWlNvWmHITKGJ9jNC5iP |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.10.0.0 |
| ProductVersionNumber: | 2.10.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | BM-productions |
| FileDescription: | Windows Media Player Plus! Setup |
| FileVersion: | 2.10 |
| LegalCopyright: | Copyright © 2018 BM-productions - All rights reserved |
| ProductName: | Windows Media Player Plus! |
| ProductVersion: | 2.10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | "C:\Users\admin\AppData\Local\Temp\is-0PD5J.tmp\WMPPlus-2.10.tmp" /SL5="$60284,692320,57856,C:\Users\admin\AppData\Local\Temp\WMPPlus-2.10.exe" | C:\Users\admin\AppData\Local\Temp\is-0PD5J.tmp\WMPPlus-2.10.tmp | — | WMPPlus-2.10.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1052 | "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Relaunch | C:\Program Files (x86)\Windows Media Player\wmplayer.exe | setup_wm.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 3221226525 Version: 12.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1120 | "sdbinst.exe" -q "C:\Users\admin\AppData\Local\Temp\is-VFUTE.tmp\WMPx64PluginFix.sdb" | C:\Windows\SysWOW64\sdbinst.exe | — | WMPPlus-2.10.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Application Compatibility Database Installer Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1272 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1052 -s 4532 | C:\Windows\SysWOW64\WerFault.exe | wmplayer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1320 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1052 -s 4388 | C:\Windows\SysWOW64\WerFault.exe | wmplayer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1324 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 1648 | "C:\Users\admin\AppData\Local\Temp\WMPPlus-2.10.exe" /SPAWNWND=$302A0 /NOTIFYWND=$60284 | C:\Users\admin\AppData\Local\Temp\WMPPlus-2.10.exe | WMPPlus-2.10.tmp | ||||||||||||
User: admin Company: BM-productions Integrity Level: HIGH Description: Windows Media Player Plus! Setup Exit code: 0 Version: 2.10 Modules
| |||||||||||||||
| 1924 | "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" | C:\Program Files (x86)\Windows Media Player\wmplayer.exe | — | WMPPlus-2.10.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2392 | "C:\Windows\System32\unregmp2.exe" /AsyncFirstLogon | C:\Windows\SysWOW64\unregmp2.exe | — | wmplayer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Player Setup Utility Exit code: 0 Version: 12.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2412 | "C:\Program Files (x86)\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" | C:\Program Files (x86)\Windows Media Player\setup_wm.exe | — | wmplayer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Configuration Utility Exit code: 1 Version: 12.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 141600004FC8570DE1CADA01 | |||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: E02D94AFFD7B97BAFA233FBD5219A39519732CC9EBF38713811098A12DB201B0 | |||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files (x86)\Windows Media Player Plus!\WMPPlus.dll | |||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 247EE2FCEF0F16E54BBD5FDDA2E8D41D0B2BFEC402522EE8BDEC88B5F0920BCB | |||
| (PID) Process: | (5652) WMPPlus-2.10.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls |
| Operation: | write | Name: | C:\Program Files (x86)\Windows Media Player\wmp.dll |
Value: 1 | |||
| (PID) Process: | (3580) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BM-productions\WMPHook\HookDlls |
| Operation: | write | Name: | WMPPlus |
Value: C:\Program Files (x86)\Windows Media Player Plus!\WMPPlus.dll | |||
| (PID) Process: | (3580) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MediaPlayer\UIPlugins\{5FA68D2D-062E-4C61-856D-53B388F9FA16} |
| Operation: | write | Name: | FriendlyName |
Value: Windows Media Player Plus! | |||
| (PID) Process: | (3580) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MediaPlayer\UIPlugins\{5FA68D2D-062E-4C61-856D-53B388F9FA16} |
| Operation: | write | Name: | Description |
Value: Various enhancements for Windows Media Player. | |||
| (PID) Process: | (3580) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MediaPlayer\UIPlugins\{5FA68D2D-062E-4C61-856D-53B388F9FA16} |
| Operation: | write | Name: | Capabilities |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player Plus!\is-74GBU.tmp | executable | |
MD5:1180AD1077D455C8AD55B78B325F8E36 | SHA256:9EF89E427C4238C6A7874787600975BC7431AB2202BAB924D74F511BA8E9CE64 | |||
| 1648 | WMPPlus-2.10.exe | C:\Users\admin\AppData\Local\Temp\is-H1AHQ.tmp\WMPPlus-2.10.tmp | executable | |
MD5:832DAB307E54AA08F4B6CDD9B9720361 | SHA256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3 | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player\wmp.dll | executable | |
MD5:23AFC87309886F1072CD69BCA1893604 | SHA256:FFF4BB68569061812D8EB1DE1EFBB29B8B933A44BDD34E00B3F0FB148FCB7294 | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player\is-3G44Q.tmp | executable | |
MD5:23AFC87309886F1072CD69BCA1893604 | SHA256:FFF4BB68569061812D8EB1DE1EFBB29B8B933A44BDD34E00B3F0FB148FCB7294 | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player Plus!\WMPATF.htm | html | |
MD5:EE5433D861707274FE6E5B22C382159F | SHA256:F0E8DA2B81237CABFF19631F66E0E55019CF2D2598F6D2A23D6D13837E830A1F | |||
| 5652 | WMPPlus-2.10.tmp | C:\Users\admin\AppData\Local\Temp\is-VFUTE.tmp\is-TBTJ0.tmp | binary | |
MD5:66A5716DD101938655A4045B09B76C5A | SHA256:BA29ECDCB7DFB329DC0ECBAC7C72FEBE9CF03E5A0F3DB129D8E87A60CAB6DC88 | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player Plus!\is-11SEF.tmp | html | |
MD5:EE5433D861707274FE6E5B22C382159F | SHA256:F0E8DA2B81237CABFF19631F66E0E55019CF2D2598F6D2A23D6D13837E830A1F | |||
| 5652 | WMPPlus-2.10.tmp | C:\Users\admin\AppData\Local\Temp\is-VFUTE.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player Plus!\unins000.exe | executable | |
MD5:69CCBB2882111F9D1FCCC0EEA5F1C182 | SHA256:34588C29EB31AA83EC4E4A507C51CCDA90F5F669B2BE7F0093272567AD484ADD | |||
| 5652 | WMPPlus-2.10.tmp | C:\Program Files (x86)\Windows Media Player Plus!\is-EMNQL.tmp | executable | |
MD5:69CCBB2882111F9D1FCCC0EEA5F1C182 | SHA256:34588C29EB31AA83EC4E4A507C51CCDA90F5F669B2BE7F0093272567AD484ADD | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4820 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4020 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3040 | OfficeClickToRun.exe | 20.189.173.26:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1052 | wmplayer.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1272 | WerFault.exe | 20.189.173.20:443 | watson.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1320 | WerFault.exe | 20.189.173.20:443 | watson.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
self.events.data.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
watson.events.data.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
wmplayer.exe | Hooking of wmplayer.exe : 801 |
wmplayer.exe | Hooking of KernelBase.dll : 1000 |
wmplayer.exe | Hooking of kernel32.dll : 1000 |
wmplayer.exe | Hooking of shell32.dll : 440 |
wmplayer.exe | Hooking of KernelBase.dll : 20 |
wmplayer.exe | Hooking of wmp.dll : 4E93 |
wmplayer.exe | Unhooking of KernelBase.dll success |
wmplayer.exe | Globally hooked libraries : 7ED3 |
wmplayer.exe | Loading hook DLL: C:\Program Files (x86)\Windows Media Player Plus!\WMPPlus.dll |