File name:

dovidka.chm

Full analysis: https://app.any.run/tasks/4743fa0e-f1d2-4094-9d12-83b3bd52393f
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: December 08, 2024, 14:47:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/vnd.ms-htmlhelp
File info: MS Windows HtmlHelp Data
MD5:

2556A9E1D5E9874171F51620E5C5E09A

SHA1:

AFFC2B19D9FB8080A7211C3ED0718F2C3D3887DF

SHA256:

7F0511B09B1AB3A64C8827DD8AF017ACBF7D2688DB31A5D98FEA8A5029A89D56

SSDEEP:

6144:6hK9QF9IF78JuiKgnheEVfh+x6I/c0mGkBZ6w5+2yrBnx:d9QFq78JuiBnheEVqvcBZ6ws7nx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RANSOMWARE has been detected

      • wmplayer.exe (PID: 3316)
  • SUSPICIOUS

    • Reads the Internet Settings

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Reads Internet Explorer settings

      • hh.exe (PID: 1848)
    • Reads Microsoft Outlook installation path

      • hh.exe (PID: 1848)
    • Reads security settings of Internet Explorer

      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
  • INFO

    • Create files in a temporary directory

      • hh.exe (PID: 1848)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Reads the machine GUID from the registry

      • hh.exe (PID: 1848)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Reads security settings of Internet Explorer

      • hh.exe (PID: 1848)
    • Checks proxy server information

      • hh.exe (PID: 1848)
      • wmplayer.exe (PID: 3316)
    • Manual execution by a user

      • explorer.exe (PID: 1800)
      • wmpconfig.exe (PID: 1048)
      • wmpconfig.exe (PID: 3076)
      • wmplayer.exe (PID: 3040)
      • wmpshare.exe (PID: 1180)
      • wmpnscfg.exe (PID: 3732)
    • Checks supported languages

      • wmpshare.exe (PID: 1180)
      • wmpconfig.exe (PID: 3076)
      • wmplayer.exe (PID: 3040)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
      • wmpnscfg.exe (PID: 3732)
    • The process uses the downloaded file

      • hh.exe (PID: 1848)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3040)
    • Reads the computer name

      • wmplayer.exe (PID: 3040)
      • wmpshare.exe (PID: 1180)
      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
      • wmpnscfg.exe (PID: 3732)
    • Reads Environment values

      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3348)
      • wmplayer.exe (PID: 3316)
    • Creates files or folders in the user directory

      • wmplayer.exe (PID: 3316)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.chi | Windows HELP Index (81)
.chm | Windows HELP File (18.9)

EXIF

EXE

CHMVersion: 3
LanguageCode: English (U.S.)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
11
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start hh.exe no specs explorer.exe no specs wmpshare.exe no specs wmpconfig.exe no specs wmpconfig.exe wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs THREAT wmplayer.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Program Files\Windows Media Player\wmpconfig.exe" C:\Program Files\Windows Media Player\wmpconfig.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Configuration
Exit code:
3221226540
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpconfig.exe
c:\windows\system32\ntdll.dll
1180"C:\Program Files\Windows Media Player\wmpshare.exe" C:\Program Files\Windows Media Player\wmpshare.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Folder Sharing Executable
Exit code:
0
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpshare.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1800"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1848"C:\Windows\hh.exe" C:\Users\admin\Desktop\dovidka.chmC:\Windows\hh.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® HTML Help Executable
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
2472"C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeededC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3040"C:\Program Files\Windows Media Player\wmplayer.exe" C:\Program Files\Windows Media Player\wmplayer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3076"C:\Program Files\Windows Media Player\wmpconfig.exe" C:\Program Files\Windows Media Player\wmpconfig.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Media Player Configuration
Exit code:
0
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3316"C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch C:\Program Files\Windows Media Player\wmplayer.exe
setup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3348"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" C:\Program Files\Windows Media Player\setup_wm.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Configuration Utility
Exit code:
1
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3492C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibraryC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
5 621
Read events
5 245
Write events
301
Delete events
75

Modification events

(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1848) hh.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Operation:writeName:ProcessedCount
Value:
0
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Operation:writeName:Folders
Value:
0
(PID) Process:(1180) wmpshare.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ErrorFolders
Operation:writeName:Folders
Value:
0
Executable files
0
Suspicious files
5
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
3316wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg
MD5:
SHA256:
3316wmplayer.exeC:\Users\Public\Music\Sample Music\Folder.jpg
MD5:
SHA256:
2472unregmp2.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hdsbinary
MD5:30A89AB774AC15C7ED7EA2F8B4FD09D6
SHA256:39704443D21664049A868E5E0CF94067F688F1B8D76BEDD577EA53C17A670204
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\mg4_wmp12_30x30_2[1].pngimage
MD5:2FB401B99E4B8728820A2FC6A80E89BB
SHA256:1BE5955F420DF102CC84E1A7CD470EA81DED6E2A4AC13409DCDD24541522837E
3492unregmp2.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdbbinary
MD5:3B8E4FAD2454F5CF97B5B401A8369E91
SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5
3316wmplayer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-msbinary
MD5:3DB3814B65589F1A0E304610C29970D0
SHA256:2BB4E260FBA17E0B319EA7263B2E99B31489E5B10283B2BDF0E30FAC326D8045
3316wmplayer.exeC:\Users\admin\AppData\Local\Temp\wmplog00.sqmbinary
MD5:50275EDFD51B70DB4D5FE7537F19E35F
SHA256:644505B1835AF3D92159713CB38FEFDBDBF3C22BC9E2E36AC38BC0CD630CCE46
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\media_guide_16x16[1].pngimage
MD5:595006285CDF63EDD55A1D0C1F59CD54
SHA256:07265D4602D9E3F6F9E9E78C0A19488A1877404850B73C8C3E39575C9674F4E3
3316wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpgimage
MD5:352F8528C8352EDAC56BD888154F0F0B
SHA256:571F502E024B209AABFF0E025FA51B43D55EC16E0357834E5E32EB313C3A818A
3316wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wplhtml
MD5:159E63275630EC4C9747B664BD063938
SHA256:D54745665432625A904636E7675612C85026DA07E68F4E9D8DACBE98E5DEE844
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
13
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3316
wmplayer.exe
POST
301
204.79.197.203:80
http://sqm.msn.com/sqm/wmp/sqmserver.dll
unknown
whitelisted
3316
wmplayer.exe
GET
204.79.197.203:80
http://www.msn.com/sqm/wmp/sqmserver.dll
unknown
whitelisted
3316
wmplayer.exe
GET
302
184.24.77.39:80
http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.169:80
http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.169:80
http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.150:80
http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png
unknown
whitelisted
3316
wmplayer.exe
GET
200
23.48.23.150:80
http://images.windowsmedia.com/svcswitch/media_guide_16x16.png
unknown
whitelisted
3316
wmplayer.exe
GET
302
184.24.77.39:80
http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
3536
svchost.exe
239.255.255.250:1900
whitelisted
3316
wmplayer.exe
204.79.197.203:80
sqm.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3316
wmplayer.exe
184.24.77.39:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
whitelisted
3316
wmplayer.exe
23.48.23.169:80
onlinestores.metaservices.microsoft.com
Akamai International B.V.
DE
whitelisted
3316
wmplayer.exe
23.48.23.150:80
images.windowsmedia.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
sqm.msn.com
  • 204.79.197.203
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted
redir.metaservices.microsoft.com
  • 184.24.77.39
  • 184.24.77.8
whitelisted
onlinestores.metaservices.microsoft.com
  • 23.48.23.169
  • 23.48.23.133
whitelisted
images.windowsmedia.com
  • 23.48.23.150
  • 23.48.23.132
whitelisted
toc.music.metaservices.microsoft.com
whitelisted

Threats

PID
Process
Class
Message
3316
wmplayer.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info