File name:

C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING

Full analysis: https://app.any.run/tasks/3430fdb9-674e-4540-ba20-23a7947edbbc
Verdict: Malicious activity
Analysis date: November 26, 2023, 11:51:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/octet-stream
File info: data
MD5:

DC84B0D741E5BEAE8070013ADDCC8C28

SHA1:

802F4A6A20CBF157AAF6C4E07E4301578D5936A2

SHA256:

81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06

SSDEEP:

3:e:e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • wmplayer.exe (PID: 1900)
      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • wmplayer.exe (PID: 3572)
  • INFO

    • Reads the computer name

      • vlc.exe (PID: 2876)
      • wmplayer.exe (PID: 1900)
      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • wmpnscfg.exe (PID: 2520)
      • wmpshare.exe (PID: 3372)
      • wmplayer.exe (PID: 3572)
    • Manual execution by a user

      • wmplayer.exe (PID: 1900)
      • wmpnscfg.exe (PID: 2520)
      • wmplayer.exe (PID: 3572)
    • Checks supported languages

      • wmplayer.exe (PID: 1900)
      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • vlc.exe (PID: 2876)
      • wmpshare.exe (PID: 3372)
      • wmpnscfg.exe (PID: 2520)
      • wmplayer.exe (PID: 3572)
    • Reads Environment values

      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • wmplayer.exe (PID: 3572)
    • Reads the machine GUID from the registry

      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • wmpnscfg.exe (PID: 2520)
      • wmplayer.exe (PID: 3572)
    • Process checks computer location settings

      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
      • wmplayer.exe (PID: 3572)
    • Create files in a temporary directory

      • setup_wm.exe (PID: 3056)
      • wmplayer.exe (PID: 3868)
    • Checks proxy server information

      • wmplayer.exe (PID: 3868)
      • wmplayer.exe (PID: 3572)
    • Creates files or folders in the user directory

      • wmplayer.exe (PID: 3868)
      • wmplayer.exe (PID: 3572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.mp3 | MP3 audio (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start vlc.exe wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs wmplayer.exe wmpshare.exe no specs wmpnscfg.exe no specs wmplayer.exe

Process information

PID
CMD
Path
Indicators
Parent process
276"C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeededC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1900"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1C:\Program Files\Windows Media Player\wmplayer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2416C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibraryC:\Windows\System32\unregmp2.exesetup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Player Setup Utility
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\unregmp2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2520"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2876"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Downloads\TESTING.mp3"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
3221225547
Version:
3.0.11
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3056"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1C:\Program Files\Windows Media Player\setup_wm.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Media Configuration Utility
Exit code:
1
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\setup_wm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3372"C:\Program Files\Windows Media Player\wmpshare.exe" C:\Program Files\Windows Media Player\wmpshare.exewmplayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Folder Sharing Executable
Exit code:
0
Version:
12.0.7601.24499 (win7sp1_ldr.190612-0600)
Modules
Images
c:\program files\windows media player\wmpshare.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3572"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1C:\Program Files\Windows Media Player\wmplayer.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3868"C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch /prefetch:1C:\Program Files\Windows Media Player\wmplayer.exe
setup_wm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player
Exit code:
0
Version:
12.0.7601.23517 (win7sp1_ldr.160812-0732)
Modules
Images
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 661
Read events
6 431
Write events
222
Delete events
8

Modification events

(PID) Process:(1900) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1900) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1900) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1900) wmplayer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3056) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AcceptedPrivacyStatement
Value:
0
(PID) Process:(3056) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AcceptedPrivacyStatement
Value:
1
(PID) Process:(3056) setup_wm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\UserOptions
Operation:writeName:DesktopShortcut
Value:
no
(PID) Process:(2416) unregmp2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrentDownloadCount
Value:
0
(PID) Process:(2416) unregmp2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrent500ServerErrorCount
Value:
0
(PID) Process:(2416) unregmp2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrent503ServerErrorCount
Value:
0
Executable files
5
Suspicious files
13
Text files
38
Unknown types
0

Dropped files

PID
Process
Filename
Type
2876vlc.exe
MD5:
SHA256:
2876vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.Hp2876text
MD5:DDC0C9DB78B2D253A9EFFC44F2DA54DC
SHA256:011EDD629147AD09B30BD581E4625B792B5678AB56DB8C7B981EA0044C51E3E0
2876vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.locktext
MD5:DAA7279978831CFA04C2CA7D1290E503
SHA256:DDD981A87A39DD73B7574AC28C3A8CF44D9DE9B8841B620DCDE5C943B141E070
2876vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.initext
MD5:DDC0C9DB78B2D253A9EFFC44F2DA54DC
SHA256:011EDD629147AD09B30BD581E4625B792B5678AB56DB8C7B981EA0044C51E3E0
2876vlc.exeC:\Users\admin\AppData\Roaming\vlc\ml.xspfxml
MD5:781602441469750C3219C8C38B515ED4
SHA256:81970DBE581373D14FBD451AC4B3F96E5F69B79645F1EE1CA715CFF3AF0BF20D
3868wmplayer.exeC:\Users\admin\AppData\Local\Temp\wmplog00.sqmbinary
MD5:94E39FDE662650BB9ECD1CBDF7035BFA
SHA256:CD5B5B1ED9E34F43E429CB23CAA8F4FD2090EF86E0CDFE119053A3DCB0BFE7A8
2416unregmp2.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdbbinary
MD5:3B8E4FAD2454F5CF97B5B401A8369E91
SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5
3868wmplayer.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wplhtml
MD5:159E63275630EC4C9747B664BD063938
SHA256:D54745665432625A904636E7675612C85026DA07E68F4E9D8DACBE98E5DEE844
2876vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.ini.Uh2876text
MD5:B2DA0C05979783B6ADD95F44B27B65D6
SHA256:3B0CBE02A7867807963886E32E3E8FB5E1E6CAA7990F0109124FCFA2B0A66AF7
276unregmp2.exeC:\ProgramData\Microsoft\Windows\DRM\drmstore.hdsbinary
MD5:859C146742B30B530EB01E73F150FBE7
SHA256:6BFCC25703FA23D8049906DDAB75706F199092550E5D9F27AB7E9B8C6AA61D2F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
12
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3868
wmplayer.exe
GET
302
2.21.20.154:80
http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
unknown
3868
wmplayer.exe
GET
200
23.216.77.37:80
http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
xml
546 b
unknown
3868
wmplayer.exe
GET
200
23.216.77.37:80
http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
text
523 b
unknown
3868
wmplayer.exe
GET
200
23.216.77.10:80
http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png
unknown
image
2.00 Kb
unknown
3868
wmplayer.exe
GET
302
2.21.20.154:80
http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16
unknown
unknown
3868
wmplayer.exe
GET
200
23.216.77.10:80
http://images.windowsmedia.com/svcswitch/media_guide_16x16.png
unknown
image
897 b
unknown
3572
wmplayer.exe
GET
302
2.21.20.154:80
http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409
unknown
unknown
3868
wmplayer.exe
GET
302
2.21.20.154:80
http://redir.metaservices.microsoft.com/redir/getmdrcdposturlbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&requestID=FC84615C-98A6-4549-A38B-16861DE03F4D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
95.101.148.135:80
Akamai International B.V.
NL
unknown
868
svchost.exe
184.30.20.134:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
3868
wmplayer.exe
2.21.20.154:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
unknown
3868
wmplayer.exe
23.216.77.37:80
onlinestores.metaservices.microsoft.com
Akamai International B.V.
DE
unknown
3868
wmplayer.exe
23.216.77.10:80
images.windowsmedia.com
Akamai International B.V.
DE
unknown
3572
wmplayer.exe
2.21.20.154:80
redir.metaservices.microsoft.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 184.30.20.134
whitelisted
sqm.msn.com
unknown
redir.metaservices.microsoft.com
  • 2.21.20.154
  • 2.21.20.148
whitelisted
onlinestores.metaservices.microsoft.com
  • 23.216.77.37
  • 23.216.77.24
whitelisted
images.windowsmedia.com
  • 23.216.77.10
  • 23.216.77.27
whitelisted
toc.music.metaservices.microsoft.com
unknown
info.music.metaservices.microsoft.com
unknown

Threats

No threats detected
Process
Message
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright © 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
vlc.exe
main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
vlc.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc.exe
main libvlc debug: searching plug-in modules
vlc.exe
main libvlc debug: using multimedia timers as clock source
vlc.exe
main libvlc debug: plug-ins loaded: 494 modules