download: | nijtkikjkkkhkhklkpkpjtkikjklkkkokpknjtlwjtkikjkkkhkhklkpkpjtkikjklkkkokpknjtkhjtkikpkqknkmkqov |
Full analysis: | https://app.any.run/tasks/fbd576df-48eb-438d-a393-8b3b5e836f80 |
Verdict: | Malicious activity |
Analysis date: | June 04, 2019, 21:10:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/html |
File info: | HTML document, ASCII text, with very long lines, with CRLF line terminators |
MD5: | CF0547F87055D97CE56986FCCC2B66D9 |
SHA1: | 541D4CBCBCE0C9C8BEE3A8DDC22FEA473868EA28 |
SHA256: | 70210F34EE310467044D7CFD00856BBD1E530DB5B69DBCBBA0AE57FA1536ECF5 |
SSDEEP: | 96:GfuC58VULmDfjvKn2tAcyQgsVkMt/TbApEpquRlXtr2Z9AHgQ75ozpz0YRv:G2C2VrDfzw2ycyQg6kuT1/rG9m7529n1 |
Title: | Opt-Out |
---|---|
Robots: | noindex,nofollow,noarchive |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
792 | "C:\Program Files\Windows Media Player\wmplayer.exe" /SkipFUE /RemoteOCXLaunch /SuppressDialogs | C:\Program Files\Windows Media Player\wmplayer.exe | ehshell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1928 | "C:\Windows\eHome\EhTray.exe" /nav:-2 | C:\Windows\eHome\EhTray.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Center Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2604 | C:\Windows\ehome\ehsched.exe | C:\Windows\ehome\ehsched.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Media Center Scheduler Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2884 | C:\Windows\ehome\ehRec.exe -Embedding | C:\Windows\ehome\ehRec.exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Media Center Host Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3032 | "C:\Windows\eHome\ehshell.exe" "C:\Users\admin\AppData\Local\Temp\nijtkikjkkkhkhklkpkpjtkikjklkkkokpknjtlwjtkikjkkkhkhklkpkpjtkikjklkkkokpknjtkhjtkikpkqknkmkqov" | C:\Windows\eHome\ehshell.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Center Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3372 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\nijtkikjkkkhkhklkpkpjtkikjklkkkokpknjtlwjtkikjkkkhkhklkpkpjtkikjklkkkokpknjtkhjtkikpkqknkmkqov | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | LangID |
Value: 0904 | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Value: Adobe Acrobat Reader DC | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Program Files\Internet Explorer\iexplore.exe |
Value: Internet Explorer | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Windows\system32\mspaint.exe |
Value: Paint | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
(PID) Process: | (3372) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player |
PID | Process | Filename | Type | |
---|---|---|---|---|
1928 | EhTray.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\S8HM27G5Z6EWQ4ZMJZ7O.temp | — | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CNOHLLE9N309AG1XPAK7.temp | — | |
MD5:— | SHA256:— | |||
1928 | EhTray.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3W0WTI9BNBA46D882YY5.temp | — | |
MD5:— | SHA256:— | |||
3032 | ehshell.exe | C:\ProgramData\Microsoft\eHome\logs\FirstRun.log | xml | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
3032 | ehshell.exe | C:\ProgramData\Microsoft\eHome\logs\~ehshell.exe.3032.sqm | sqm | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg | image | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\Public\Music\Sample Music\Folder.jpg | image | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg | image | |
MD5:— | SHA256:— | |||
792 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg | image | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
792 | wmplayer.exe | GET | 302 | 2.16.186.41:80 | http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 | unknown | — | — | whitelisted |
792 | wmplayer.exe | GET | 200 | 2.16.186.90:80 | http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 | unknown | xml | 546 b | whitelisted |
792 | wmplayer.exe | GET | 200 | 2.16.186.90:80 | http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 | unknown | text | 523 b | whitelisted |
792 | wmplayer.exe | GET | 200 | 2.16.186.64:80 | http://images.windowsmedia.com/svcswitch/media_guide_16x16.png | unknown | image | 897 b | whitelisted |
792 | wmplayer.exe | GET | 200 | 2.16.186.64:80 | http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png | unknown | image | 2.00 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
792 | wmplayer.exe | 2.16.186.41:80 | redir.metaservices.microsoft.com | Akamai International B.V. | — | whitelisted |
792 | wmplayer.exe | 2.16.186.90:80 | onlinestores.metaservices.microsoft.com | Akamai International B.V. | — | whitelisted |
792 | wmplayer.exe | 2.16.186.64:80 | images.windowsmedia.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
---|---|---|
redir.metaservices.microsoft.com |
| whitelisted |
onlinestores.metaservices.microsoft.com |
| whitelisted |
images.windowsmedia.com |
| whitelisted |
Process | Message |
---|---|
ehshell.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
ehshell.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cppĒ |
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
ehshell.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
ehshell.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|