File name: | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING |
Full analysis: | https://app.any.run/tasks/22a2fc57-7ed3-4042-8f77-13c77a89c87d |
Verdict: | Malicious activity |
Analysis date: | November 27, 2023, 04:43:43 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/octet-stream |
File info: | data |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SSDEEP: | 3:e:e |
.mp3 | | | MP3 audio (100) |
---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
564 | "C:\Windows\System32\notepad.exe" C:\Users\admin\Desktop\TESTING.mp3 | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
944 | "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\TESTING.mp3" | C:\Program Files\VideoLAN\VLC\vlc.exe | explorer.exe | ||||||||||||
User: admin Company: VideoLAN Integrity Level: MEDIUM Description: VLC media player Exit code: 3221225547 Version: 3.0.11 Modules
| |||||||||||||||
1212 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.6.517601606\292781871" -childID 3 -isForBrowser -prefsHandle 4016 -prefMapHandle 3960 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {005990f1-80b7-4da6-b109-e4019c4f3692} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 4032 18ae0e00 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
1628 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\TESTING.mp3 | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.4.1151254023\109407023" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 2948 -prefMapHandle 2960 -prefsLen 34225 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {af3df299-edd1-4e35-a09b-e5b630c3c93d} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 3048 ee296b0 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2076 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.3.630234776\175375718" -parentBuildID 20230710165010 -prefsHandle 2900 -prefMapHandle 2896 -prefsLen 34225 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e6e37c7b-ac9b-4598-a80c-21a16b57dec6} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 2912 16a87120 rdd | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2304 | "C:\Program Files\Windows Media Player\wmplayer.exe" /Play -Embedding | C:\Program Files\Windows Media Player\wmplayer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
2304 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.9.1502992534\212741908" -childID 6 -isForBrowser -prefsHandle 4568 -prefMapHandle 4572 -prefsLen 29102 -prefMapSize 244195 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e62792cd-89c9-4297-83cc-5aa1d22ce991} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 4556 1918f560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2376 | "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "C:\Users\admin\Desktop\TESTING.mp3" | C:\Program Files\Mozilla Firefox\firefox.exe | — | rundll32.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
2836 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4036.0.872479145\825958005" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {34c61e61-122a-49b2-8d4a-05426d11194b} 4036 "\\.\pipe\gecko-crash-server-pipe.4036" 1180 d3aa860 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
|
(PID) Process: | (2304) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2304) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2304) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2304) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | AcceptedPrivacyStatement |
Value: 0 | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | delete value | Name: | C:\Program Files\Windows Media Player\wmplayer.exe |
Value: Windows Media Player | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | delete value | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | delete value | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player | |||
(PID) Process: | (3564) setup_wm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
Operation: | write | Name: | AcceptedPrivacyStatement |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
944 | vlc.exe | — | ||
MD5:— | SHA256:— | |||
3044 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg | — | |
MD5:— | SHA256:— | |||
3044 | wmplayer.exe | C:\Users\Public\Music\Sample Music\Folder.jpg | — | |
MD5:— | SHA256:— | |||
3044 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg | — | |
MD5:— | SHA256:— | |||
3044 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg | — | |
MD5:— | SHA256:— | |||
944 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini | text | |
MD5:494A5065A3EFE199DBDBB4DBEDCDA53A | SHA256:BF7FB51210F3F290CFB8E486042A11C767F778213A8CAE7F9FEA5057920FC276 | |||
944 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.qHp944 | text | |
MD5:494A5065A3EFE199DBDBB4DBEDCDA53A | SHA256:BF7FB51210F3F290CFB8E486042A11C767F778213A8CAE7F9FEA5057920FC276 | |||
944 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.lock | text | |
MD5:C5F4C3A31D679482637C4B072816FB75 | SHA256:42106D3B3AC2BB926DD218F3A12F3A8743FE729FB6F077321F8299DCDF671661 | |||
944 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\ml.xspf | xml | |
MD5:781602441469750C3219C8C38B515ED4 | SHA256:81970DBE581373D14FBD451AC4B3F96E5F69B79645F1EE1CA715CFF3AF0BF20D | |||
3428 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | binary | |
MD5:3B8E4FAD2454F5CF97B5B401A8369E91 | SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4036 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | text | 8 b | — |
4036 | firefox.exe | POST | 200 | 142.250.186.35:80 | http://ocsp.pki.goog/gts1c3 | unknown | binary | 472 b | — |
4036 | firefox.exe | POST | — | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | — | — | — |
4036 | firefox.exe | POST | 200 | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/ | unknown | binary | 471 b | — |
4036 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4036 | firefox.exe | POST | — | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | — | — | — |
4036 | firefox.exe | POST | — | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | — | — | — |
4036 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4036 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
4036 | firefox.exe | POST | 200 | 23.53.40.161:80 | http://r3.o.lencr.org/ | unknown | binary | 503 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 23.32.238.186:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3044 | wmplayer.exe | 2.21.20.148:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
4036 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | unknown |
4036 | firefox.exe | 142.250.186.74:443 | safebrowsing.googleapis.com | — | — | unknown |
4036 | firefox.exe | 34.117.237.239:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
4036 | firefox.exe | 34.206.103.169:443 | spocs.getpocket.com | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
---|---|---|
ctldl.windowsupdate.com |
| unknown |
redir.metaservices.microsoft.com |
| unknown |
toc.music.metaservices.microsoft.com |
| unknown |
detectportal.firefox.com |
| unknown |
prod.detectportal.prod.cloudops.mozgcp.net |
| unknown |
example.org |
| unknown |
ipv4only.arpa |
| unknown |
contile.services.mozilla.com |
| unknown |
spocs.getpocket.com |
| unknown |
proxyserverecs-1736642167.us-east-1.elb.amazonaws.com |
| unknown |
Process | Message |
---|---|
vlc.exe | main libvlc debug: VLC media player - 3.0.11 Vetinari
|
vlc.exe | main libvlc debug: Copyright © 1996-2020 the VideoLAN team
|
vlc.exe | main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
|
vlc.exe | main libvlc debug: min period: 1 ms, max period: 1000000 ms
|
vlc.exe | main libvlc debug: using multimedia timers as clock source
|
vlc.exe | main libvlc debug: revision 3.0.11-0-gdc0c5ced72
|
vlc.exe | main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
|
vlc.exe | main libvlc debug: searching plug-in modules
|
vlc.exe | main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
|
vlc.exe | main libvlc debug: opening config file (C:\Users\admin\AppData\Roaming\vlc\vlcrc)
|