File name:

dovidka.chm

Full analysis: https://app.any.run/tasks/4743fa0e-f1d2-4094-9d12-83b3bd52393f
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: December 08, 2024, 14:47:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/vnd.ms-htmlhelp
File info: MS Windows HtmlHelp Data
MD5:

2556A9E1D5E9874171F51620E5C5E09A

SHA1:

AFFC2B19D9FB8080A7211C3ED0718F2C3D3887DF

SHA256:

7F0511B09B1AB3A64C8827DD8AF017ACBF7D2688DB31A5D98FEA8A5029A89D56

SSDEEP:

6144:6hK9QF9IF78JuiKgnheEVfh+x6I/c0mGkBZ6w5+2yrBnx:d9QFq78JuiBnheEVqvcBZ6ws7nx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RANSOMWARE has been detected

      • wmplayer.exe (PID: 3316)
  • SUSPICIOUS

    • Reads the Internet Settings

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Reads Internet Explorer settings

      • hh.exe (PID: 1848)
    • Reads Microsoft Outlook installation path

      • hh.exe (PID: 1848)
    • Reads security settings of Internet Explorer

      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
  • INFO

    • Reads the machine GUID from the registry

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3316)
      • setup_wm.exe (PID: 3348)
    • Create files in a temporary directory

      • hh.exe (PID: 1848)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Reads security settings of Internet Explorer

      • hh.exe (PID: 1848)
    • The process uses the downloaded file

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
    • Checks proxy server information

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3316)
    • Manual execution by a user

      • wmpshare.exe (PID: 1180)
      • wmpconfig.exe (PID: 1048)
      • wmpconfig.exe (PID: 3076)
      • explorer.exe (PID: 1800)
      • wmplayer.exe (PID: 3040)
      • wmpnscfg.exe (PID: 3732)
    • Checks supported languages

      • wmpshare.exe (PID: 1180)
      • wmpconfig.exe (PID: 3076)
      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
      • wmpnscfg.exe (PID: 3732)
    • Reads the computer name

      • wmplayer.exe (PID: 3040)
      • wmpshare.exe (PID: 1180)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
      • wmpnscfg.exe (PID: 3732)
    • Reads Environment values

      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Creates files or folders in the user directory

      • wmplayer.exe (PID: 3316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.chi | Windows HELP Index (81)
.chm | Windows HELP File (18.9)

EXIF

EXE

CHMVersion: 3
LanguageCode: English (U.S.)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
11
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start hh.exe no specs explorer.exe no specs wmpshare.exe no specs wmpconfig.exe no specs wmpconfig.exe wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs THREAT wmplayer.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Program Files\Windows Media Player\wmpconfig.exe" C:\Program Files\Windows Media Player\wmpconfig.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Configuration
Exit code:
3221226540
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpconfig.exe
c:\windows\system32\ntdll.dll
1180"C:\Program Files\Windows Media Player\wmpshare.exe" C:\Program Files\Windows Media Player\wmpshare.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Folder Sharing Executable
Exit code:
0
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpshare.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1800"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1848"C:\Windows\hh.exe" C:\Users\admin\Desktop\dovidka.chmC:\Windows\hh.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® HTML Help Executable
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
2472"C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeededC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3040"C:\Program Files\Windows Media Player\wmplayer.exe" C:\Program Files\Windows Media Player\wmplayer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3076"C:\Program Files\Windows Media Player\wmpconfig.exe" C:\Program Files\Windows Media Player\wmpconfig.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Media Player Configuration
Exit code:
0
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3316"C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch C:\Program Files\Windows Media Player\wmplayer.exe
setup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3348"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" C:\Program Files\Windows Media Player\setup_wm.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Configuration Utility
Exit code:
1
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3492C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibraryC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 621
Read events
5 245
Write events
301
Delete events
75

Modification events

(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Operation:writeName:ProcessedCount
Value:
0
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Operation:writeName:Folders
Value:
0
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ErrorFolders
Operation:writeName:Folders
Value:
0
Executable files
0
Suspicious files
5
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
3316wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg
MD5:
SHA256:
3316wmplayer.exeC:\Users\Public\Music\Sample Music\Folder.jpg
MD5:
SHA256:
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\bing[1].xmltext
MD5:D58DA90D6DC51F97CB84DFBFFE2B2300
SHA256:93ACDB79543D9248CA3FCA661F3AC287E6004E4B3DAFD79D4C4070794FFBF2AD
3316wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpgimage
MD5:80635B038A5A8FB40F1B29E5CE22C8A7
SHA256:ECC2C7A57C1544A2DCDA9F43493B634B9F2FD458FA833CF8C464DD292F76F09C
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wplhtml
MD5:159E63275630EC4C9747B664BD063938
SHA256:D54745665432625A904636E7675612C85026DA07E68F4E9D8DACBE98E5DEE844
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\05_Pictures_taken_in_the_last_month.wplhtml
MD5:821D2BE672F05514127C117CEF460C6E
SHA256:3ABDB6CBD88AD1557054ECE3F10DD1A8494ED32F423B3CF8321B18DECC489474
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\06_Pictures_rated_4_or_5_stars.wplhtml
MD5:0A8A40CA87323DC16893194B00C7FE77
SHA256:9AA433BED2E090CC6904F1C24D5A7B5A1ED6D8F71A997E661B886C69383FD53E
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\mg4_wmp12_30x30_2[1].pngimage
MD5:2FB401B99E4B8728820A2FC6A80E89BB
SHA256:1BE5955F420DF102CC84E1A7CD470EA81DED6E2A4AC13409DCDD24541522837E
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\03_Music_rated_at_4_or_5_stars.wplhtml
MD5:6D791B697AF46D6777182AF7F18C2955
SHA256:4825EB90140F6B2F4F7ED0DF66B24E10FF5D0DA70AF53EA495FD30B3AA791870
3492unregmp2.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdbbinary
MD5:3B8E4FAD2454F5CF97B5B401A8369E91
SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
13
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3316
wmplayer.exe
POST
301
204.79.197.203:80
http://sqm.msn.com/sqm/wmp/sqmserver.dll
unknown
whitelisted
3316
wmplayer.exe
GET
204.79.197.203:80
http://www.msn.com/sqm/wmp/sqmserver.dll
unknown
whitelisted
3316
wmplayer.exe
GET
302
184.24.77.39:80
http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.169:80
http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.169:80
http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
302
184.24.77.39:80
http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.150:80
http://images.windowsmedia.com/svcswitch/media_guide_16x16.png
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.150:80
http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
3536
svchost.exe
239.255.255.250:1900
whitelisted
3316
wmplayer.exe
204.79.197.203:80
sqm.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3316
wmplayer.exe
184.24.77.39:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
whitelisted
3316
wmplayer.exe
23.48.23.169:80
onlinestores.metaservices.microsoft.com
Akamai International B.V.
DE
whitelisted
3316
wmplayer.exe
23.48.23.150:80
images.windowsmedia.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
sqm.msn.com
  • 204.79.197.203
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted
redir.metaservices.microsoft.com
  • 184.24.77.39
  • 184.24.77.8
whitelisted
onlinestores.metaservices.microsoft.com
  • 23.48.23.169
  • 23.48.23.133
whitelisted
images.windowsmedia.com
  • 23.48.23.150
  • 23.48.23.132
whitelisted
toc.music.metaservices.microsoft.com
whitelisted

Threats

PID
Process
Class
Message
3316
wmplayer.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info