| File name: | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING |
| Full analysis: | https://app.any.run/tasks/3430fdb9-674e-4540-ba20-23a7947edbbc |
| Verdict: | Malicious activity |
| Analysis date: | November 26, 2023, 11:51:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | data |
| MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
| SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
| SHA256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
| SSDEEP: | 3:e:e |
| .mp3 | | | MP3 audio (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeeded | C:\Windows\System32\unregmp2.exe | — | setup_wm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Player Setup Utility Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1900 | "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1 | C:\Program Files\Windows Media Player\wmplayer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| 2416 | C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibrary | C:\Windows\System32\unregmp2.exe | — | setup_wm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Player Setup Utility Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2520 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2876 | "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Downloads\TESTING.mp3" | C:\Program Files\VideoLAN\VLC\vlc.exe | explorer.exe | ||||||||||||
User: admin Company: VideoLAN Integrity Level: MEDIUM Description: VLC media player Exit code: 3221225547 Version: 3.0.11 Modules
| |||||||||||||||
| 3056 | "C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1 | C:\Program Files\Windows Media Player\setup_wm.exe | — | wmplayer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Configuration Utility Exit code: 1 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3372 | "C:\Program Files\Windows Media Player\wmpshare.exe" | C:\Program Files\Windows Media Player\wmpshare.exe | — | wmplayer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Folder Sharing Executable Exit code: 0 Version: 12.0.7601.24499 (win7sp1_ldr.190612-0600) Modules
| |||||||||||||||
| 3572 | "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1 | C:\Program Files\Windows Media Player\wmplayer.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| 3868 | "C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch /prefetch:1 | C:\Program Files\Windows Media Player\wmplayer.exe | setup_wm.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| (PID) Process: | (1900) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1900) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1900) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1900) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3056) setup_wm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AcceptedPrivacyStatement |
Value: 0 | |||
| (PID) Process: | (3056) setup_wm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AcceptedPrivacyStatement |
Value: 1 | |||
| (PID) Process: | (3056) setup_wm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\UserOptions |
| Operation: | write | Name: | DesktopShortcut |
Value: no | |||
| (PID) Process: | (2416) unregmp2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrentDownloadCount |
Value: 0 | |||
| (PID) Process: | (2416) unregmp2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrent500ServerErrorCount |
Value: 0 | |||
| (PID) Process: | (2416) unregmp2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences |
| Operation: | write | Name: | AutoMetadataCurrent503ServerErrorCount |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2876 | vlc.exe | — | ||
MD5:— | SHA256:— | |||
| 2876 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.Hp2876 | text | |
MD5:DDC0C9DB78B2D253A9EFFC44F2DA54DC | SHA256:011EDD629147AD09B30BD581E4625B792B5678AB56DB8C7B981EA0044C51E3E0 | |||
| 2876 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.lock | text | |
MD5:DAA7279978831CFA04C2CA7D1290E503 | SHA256:DDD981A87A39DD73B7574AC28C3A8CF44D9DE9B8841B620DCDE5C943B141E070 | |||
| 2876 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini | text | |
MD5:DDC0C9DB78B2D253A9EFFC44F2DA54DC | SHA256:011EDD629147AD09B30BD581E4625B792B5678AB56DB8C7B981EA0044C51E3E0 | |||
| 2876 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\ml.xspf | xml | |
MD5:781602441469750C3219C8C38B515ED4 | SHA256:81970DBE581373D14FBD451AC4B3F96E5F69B79645F1EE1CA715CFF3AF0BF20D | |||
| 3868 | wmplayer.exe | C:\Users\admin\AppData\Local\Temp\wmplog00.sqm | binary | |
MD5:94E39FDE662650BB9ECD1CBDF7035BFA | SHA256:CD5B5B1ED9E34F43E429CB23CAA8F4FD2090EF86E0CDFE119053A3DCB0BFE7A8 | |||
| 2416 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | binary | |
MD5:3B8E4FAD2454F5CF97B5B401A8369E91 | SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5 | |||
| 3868 | wmplayer.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wpl | html | |
MD5:159E63275630EC4C9747B664BD063938 | SHA256:D54745665432625A904636E7675612C85026DA07E68F4E9D8DACBE98E5DEE844 | |||
| 2876 | vlc.exe | C:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.Uh2876 | text | |
MD5:B2DA0C05979783B6ADD95F44B27B65D6 | SHA256:3B0CBE02A7867807963886E32E3E8FB5E1E6CAA7990F0109124FCFA2B0A66AF7 | |||
| 276 | unregmp2.exe | C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds | binary | |
MD5:859C146742B30B530EB01E73F150FBE7 | SHA256:6BFCC25703FA23D8049906DDAB75706F199092550E5D9F27AB7E9B8C6AA61D2F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3868 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409 | unknown | — | — | unknown |
3868 | wmplayer.exe | GET | 200 | 23.216.77.37:80 | http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409 | unknown | xml | 546 b | unknown |
3868 | wmplayer.exe | GET | 200 | 23.216.77.37:80 | http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409 | unknown | text | 523 b | unknown |
3868 | wmplayer.exe | GET | 200 | 23.216.77.10:80 | http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png | unknown | image | 2.00 Kb | unknown |
3868 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16 | unknown | — | — | unknown |
3868 | wmplayer.exe | GET | 200 | 23.216.77.10:80 | http://images.windowsmedia.com/svcswitch/media_guide_16x16.png | unknown | image | 897 b | unknown |
3572 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409 | unknown | — | — | unknown |
3868 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdposturlbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&requestID=FC84615C-98A6-4549-A38B-16861DE03F4D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
868 | svchost.exe | 95.101.148.135:80 | — | Akamai International B.V. | NL | unknown |
868 | svchost.exe | 184.30.20.134:80 | armmf.adobe.com | AKAMAI-AS | DE | unknown |
3868 | wmplayer.exe | 2.21.20.154:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
3868 | wmplayer.exe | 23.216.77.37:80 | onlinestores.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
3868 | wmplayer.exe | 23.216.77.10:80 | images.windowsmedia.com | Akamai International B.V. | DE | unknown |
3572 | wmplayer.exe | 2.21.20.154:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |
sqm.msn.com |
| unknown |
redir.metaservices.microsoft.com |
| whitelisted |
onlinestores.metaservices.microsoft.com |
| whitelisted |
images.windowsmedia.com |
| whitelisted |
toc.music.metaservices.microsoft.com |
| unknown |
info.music.metaservices.microsoft.com |
| unknown |
Process | Message |
|---|---|
vlc.exe | main libvlc debug: revision 3.0.11-0-gdc0c5ced72
|
vlc.exe | main libvlc debug: VLC media player - 3.0.11 Vetinari
|
vlc.exe | main libvlc debug: Copyright © 1996-2020 the VideoLAN team
|
vlc.exe | main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
|
vlc.exe | main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
|
vlc.exe | main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
|
vlc.exe | main libvlc debug: min period: 1 ms, max period: 1000000 ms
|
vlc.exe | main libvlc debug: searching plug-in modules
|
vlc.exe | main libvlc debug: using multimedia timers as clock source
|
vlc.exe | main libvlc debug: plug-ins loaded: 494 modules
|