| File name: | BrowsingHistoryView.exe |
| Full analysis: | https://app.any.run/tasks/815bc3f2-742b-4d6f-ad26-7116563801b1 |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2023, 15:33:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1796576CE29ECA1E8A4D280025984A23 |
| SHA1: | 21AA4C07E946EE3F39DF1E8E8EA28D3D65566559 |
| SHA256: | CC878FB48ACE3AAE8B067DDFA1879FCD747AE95AA8CBD2348AE39EEADD8BBF72 |
| SSDEEP: | 12288:BHf9BV/GPLarNGs2jbdqFKTBgB3A/xV/nzKXnmoBjO17mHU9RS:BHFjyLarNd2jjxV/nzT72cR |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:08:30 16:03:11+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 470528 |
| InitializedDataSize: | 95232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x193e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.5.6.30 |
| ProductVersionNumber: | 2.5.6.30 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | NirSoft |
| FileDescription: | Web Browser History Viewer |
| FileVersion: | 2.56 |
| LegalCopyright: | Copyright © 2012 - 2023 Nir Sofer |
| OriginalFileName: | BrowsingHistoryView.exe |
| ProductName: | BrowsingHistoryView |
| ProductVersion: | 2.56 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2904 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3440 | "C:\Users\admin\Desktop\BrowsingHistoryView.exe" | C:\Users\admin\Desktop\BrowsingHistoryView.exe | explorer.exe | ||||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Web Browser History Viewer Exit code: 0 Version: 2.56 Modules
| |||||||||||||||
| (PID) Process: | (2904) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B2CE9E65-512A-4A03-86AF-133223ABF3A6}\{72EDE687-1C69-4BEF-93A9-6F9BDF1A1DD8} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2904) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B2CE9E65-512A-4A03-86AF-133223ABF3A6} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2904) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{CF43B087-CF78-4A37-856A-A6264E6FCDB8} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3440 | BrowsingHistoryView.exe | C:\Users\admin\AppData\Local\Temp\bhv8E3B.tmp | — | |
MD5:— | SHA256:— | |||
| 3440 | BrowsingHistoryView.exe | C:\Users\admin\AppData\Local\Temp\sqp8FA3.tmp | — | |
MD5:— | SHA256:— | |||
| 3440 | BrowsingHistoryView.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3440 | BrowsingHistoryView.exe | C:\Users\admin\AppData\Local\Temp\sqp8FA3.tmp-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 3440 | BrowsingHistoryView.exe | C:\Users\admin\Desktop\BrowsingHistoryView.cfg | text | |
MD5:E5E097439FC06378CE5A0D83E90ADD8E | SHA256:07F0B46C80FDE4945A34CA0B8B6322504549DB87B0C28C35D73C8458E925CCEE | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |