File name:

C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING

Full analysis: https://app.any.run/tasks/22a2fc57-7ed3-4042-8f77-13c77a89c87d
Verdict: Malicious activity
Analysis date: November 27, 2023, 04:43:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/octet-stream
File info: data
MD5:

DC84B0D741E5BEAE8070013ADDCC8C28

SHA1:

802F4A6A20CBF157AAF6C4E07E4301578D5936A2

SHA256:

81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06

SSDEEP:

3:e:e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • wmplayer.exe (PID: 2304)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
    • Checks Windows Trust Settings

      • setup_wm.exe (PID: 3564)
    • Reads security settings of Internet Explorer

      • setup_wm.exe (PID: 3564)
    • Reads settings of System Certificates

      • setup_wm.exe (PID: 3564)
  • INFO

    • Manual execution by a user

      • explorer.exe (PID: 2972)
      • vlc.exe (PID: 944)
      • wmpnscfg.exe (PID: 3496)
      • rundll32.exe (PID: 1628)
    • Checks supported languages

      • vlc.exe (PID: 944)
      • wmplayer.exe (PID: 2304)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
      • wmpnscfg.exe (PID: 3496)
    • Reads the computer name

      • vlc.exe (PID: 944)
      • wmplayer.exe (PID: 2304)
      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
      • wmpnscfg.exe (PID: 3496)
    • Reads Environment values

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
    • Create files in a temporary directory

      • setup_wm.exe (PID: 3564)
    • Reads the machine GUID from the registry

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
      • wmpnscfg.exe (PID: 3496)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3564)
      • wmplayer.exe (PID: 3044)
    • Creates files or folders in the user directory

      • wmplayer.exe (PID: 3044)
    • Checks proxy server information

      • wmplayer.exe (PID: 3044)
    • Application launched itself

      • firefox.exe (PID: 2376)
      • firefox.exe (PID: 4036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.mp3 | MP3 audio (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
21
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start notepad.exe no specs explorer.exe no specs vlc.exe wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs wmplayer.exe wmpnscfg.exe no specs rundll32.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564"C:\Windows\System32\notepad.exe" C:\Users\admin\Desktop\TESTING.mp3C:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
944"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\TESTING.mp3"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
3221225547
Version:
3.0.11
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1212"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.6.517601606\292781871" -childID 3 -isForBrowser -prefsHandle 4016 -prefMapHandle 3960 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {005990f1-80b7-4da6-b109-e4019c4f3692} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 4032 18ae0e00 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1628"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\TESTING.mp3C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.4.1151254023\109407023" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 2948 -prefMapHandle 2960 -prefsLen 34225 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {af3df299-edd1-4e35-a09b-e5b630c3c93d} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 3048 ee296b0 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2076"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.3.630234776\175375718" -parentBuildID 20230710165010 -prefsHandle 2900 -prefMapHandle 2896 -prefsLen 34225 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e6e37c7b-ac9b-4598-a80c-21a16b57dec6} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 2912 16a87120 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2304"C:\Program Files\Windows Media Player\wmplayer.exe" /Play -EmbeddingC:\Program Files\Windows Media Player\wmplayer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2304"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.9.1502992534\212741908" -childID 6 -isForBrowser -prefsHandle 4568 -prefMapHandle 4572 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e62792cd-89c9-4297-83cc-5aa1d22ce991} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 4556 1918f560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2376"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\Desktop\TESTING.mp3"C:\Program Files\Mozilla Firefox\firefox.exerundll32.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2836"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.0.872479145\825958005" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34c61e61-122a-49b2-8d4a-05426d11194b} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 1180 d3aa860 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
18 709
Read events
18 437
Write events
263
Delete events
9

Modification events

(PID) Process:(2304) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2304) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2304) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2304) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3564) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AcceptedPrivacyStatement
Value:
0
(PID) Process:(3564) setup_wm.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3564) setup_wm.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:C:\Program Files\Windows Media Player\wmplayer.exe
Value:
Windows Media Player
(PID) Process:(3564) setup_wm.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(3564) setup_wm.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:delete valueName:C:\Program Files\VideoLAN\VLC\vlc.exe
Value:
VLC media player
(PID) Process:(3564) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AcceptedPrivacyStatement
Value:
1
Executable files
2
Suspicious files
36
Text files
26
Unknown types
0

Dropped files

PID
Process
Filename
Type
944vlc.exe
MD5:
SHA256:
3044wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg
MD5:
SHA256:
3044wmplayer.exeC:\Users\Public\Music\Sample Music\Folder.jpg
MD5:
SHA256:
3044wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg
MD5:
SHA256:
3044wmplayer.exeC:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg
MD5:
SHA256:
944vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.initext
MD5:494A5065A3EFE199DBDBB4DBEDCDA53A
SHA256:BF7FB51210F3F290CFB8E486042A11C767F778213A8CAE7F9FEA5057920FC276
944vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.qHp944text
MD5:494A5065A3EFE199DBDBB4DBEDCDA53A
SHA256:BF7FB51210F3F290CFB8E486042A11C767F778213A8CAE7F9FEA5057920FC276
944vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.locktext
MD5:C5F4C3A31D679482637C4B072816FB75
SHA256:42106D3B3AC2BB926DD218F3A12F3A8743FE729FB6F077321F8299DCDF671661
944vlc.exeC:\Users\admin\AppData\Roaming\vlc\ml.xspfxml
MD5:781602441469750C3219C8C38B515ED4
SHA256:81970DBE581373D14FBD451AC4B3F96E5F69B79645F1EE1CA715CFF3AF0BF20D
3428unregmp2.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdbbinary
MD5:3B8E4FAD2454F5CF97B5B401A8369E91
SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
32
DNS requests
78
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4036
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
4036
firefox.exe
POST
200
142.250.186.35:80
http://ocsp.pki.goog/gts1c3
unknown
binary
472 b
4036
firefox.exe
POST
23.53.40.161:80
http://r3.o.lencr.org/
unknown
4036
firefox.exe
POST
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/
unknown
binary
471 b
4036
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
4036
firefox.exe
POST
23.53.40.161:80
http://r3.o.lencr.org/
unknown
4036
firefox.exe
POST
23.53.40.161:80
http://r3.o.lencr.org/
unknown
4036
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
4036
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
4036
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1080
svchost.exe
23.32.238.186:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3044
wmplayer.exe
2.21.20.148:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
unknown
4036
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
unknown
4036
firefox.exe
142.250.186.74:443
safebrowsing.googleapis.com
unknown
4036
firefox.exe
34.117.237.239:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
4036
firefox.exe
34.206.103.169:443
spocs.getpocket.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.32.238.186
  • 23.32.238.193
  • 23.32.238.194
  • 23.32.238.225
  • 23.32.238.192
  • 23.32.238.184
unknown
redir.metaservices.microsoft.com
  • 2.21.20.148
  • 2.21.20.154
unknown
toc.music.metaservices.microsoft.com
unknown
detectportal.firefox.com
  • 34.107.221.82
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
unknown
example.org
  • 93.184.216.34
unknown
ipv4only.arpa
  • 192.0.0.170
  • 192.0.0.171
unknown
contile.services.mozilla.com
  • 34.117.237.239
unknown
spocs.getpocket.com
  • 34.206.103.169
  • 34.226.161.51
  • 50.17.137.162
  • 54.175.23.143
unknown
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com
  • 54.175.23.143
  • 34.226.161.51
  • 50.17.137.162
  • 34.206.103.169
unknown

Threats

No threats detected
Process
Message
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright © 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
vlc.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc.exe
main libvlc debug: using multimedia timers as clock source
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72
vlc.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc.exe
main libvlc debug: searching plug-in modules
vlc.exe
main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
vlc.exe
main libvlc debug: opening config file (C:\Users\admin\AppData\Roaming\vlc\vlcrc)