File name: | htmlhelp.exe |
Full analysis: | https://app.any.run/tasks/4a059ff3-24cf-40be-a473-f8e9382e450e |
Verdict: | Malicious activity |
Analysis date: | February 15, 2024, 15:01:07 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MS CAB-Installer self-extracting archive |
MD5: | FFDE6013C622C033D31FB892B283A1CE |
SHA1: | BE3CA09DA0F21616577C8FB3D3A508804D4F9281 |
SHA256: | CF8FE5A02D3C2BF0C8728DD399DC3B2587C4139FFB23EF4268F34535A6157B87 |
SSDEEP: | 98304:W7v2Oa/flWOgi1sf/vbVTyblUc8cNrpt3r0izJJbsBWza8a4gKuSUMN3W4CB3k8w:YOmcrPGC1 |
.exe | | | InstallShield setup (38.2) |
---|---|---|
.exe | | | Win32 Executable MS Visual C++ (generic) (27.7) |
.exe | | | Win64 Executable (generic) (24.5) |
.exe | | | Win32 Executable (generic) (4) |
.exe | | | Win16/32 Executable Delphi generic (1.8) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 1997:07:15 11:48:12+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit, No debug |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 36864 |
InitializedDataSize: | 3458560 |
UninitializedDataSize: | - |
EntryPoint: | 0x2723 |
OSVersion: | 5 |
ImageVersion: | 5 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 4.71.1015.0 |
ProductVersionNumber: | 4.71.1015.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Microsoft Corporation |
FileDescription: | Microsoft® HTML Help Author |
FileVersion: | 4.74.8703 |
InternalName: | htmlhelp.exe |
LegalCopyright: | Copyright © Microsoft Corp. |
OriginalFileName: | htmlhelp.exe |
ProductName: | HTML Help Workshop Install |
ProductVersion: | 4.74.8703 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2124 | grpconv.exe -o | C:\Windows\System32\grpconv.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Progman Group Converter Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2328 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | htmlhelp.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2340 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\hhupd.exe /C:"setup.exe NoDlg" /R:N | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\hhupd.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® HTML Help Control Exit code: 0 Version: 4.74.8793 Modules
| |||||||||||||||
3948 | "C:\Users\admin\AppData\Local\Temp\htmlhelp.exe" | C:\Users\admin\AppData\Local\Temp\htmlhelp.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® HTML Help Author Exit code: 0 Version: 4.74.8703 Modules
| |||||||||||||||
3972 | "C:\Users\admin\AppData\Local\Temp\htmlhelp.exe" | C:\Users\admin\AppData\Local\Temp\htmlhelp.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® HTML Help Author Exit code: 3221226540 Version: 4.74.8703 Modules
|
(PID) Process: | (3948) htmlhelp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
Operation: | write | Name: | wextract_cleanup0 |
Value: rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\" | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
Operation: | write | Name: | SM_AccessoriesName |
Value: Accessories | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
Operation: | write | Name: | PF_AccessoriesName |
Value: Accessories | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\hhw.exe |
Operation: | write | Name: | Path |
Value: C:\Program Files\HTML Help Workshop | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\HTML Help Workshop |
Operation: | write | Name: | InstallDir |
Value: C:\Program Files\HTML Help Workshop | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HTML Help Workshop |
Operation: | write | Name: | DisplayName |
Value: HTML Help Workshop | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HTML Help Workshop |
Operation: | write | Name: | UninstallString |
Value: C:\Program Files\HTML Help Workshop\setup.exe Uninstall | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
Operation: | write | Name: | dl.cl |
Value: DialogLayout.class | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
Operation: | write | Name: | e.cl |
Value: Element.class | |||
(PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
Operation: | write | Name: | el.cl |
Value: ElementList.class |
PID | Process | Filename | Type | |
---|---|---|---|---|
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\readme.txt | text | |
MD5:5D8D3F3D1F5FA3990F7DAB2BE722845C | SHA256:B95EBA0470D1D86E1B8667EEAF96040F27940E7403085C0CF6AA7C34ED8A0787 | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\uninst.inf | text | |
MD5:7FFD66883AB1B09AC39645796CA29C5C | SHA256:6D47D1E896F8848C57946AB77FF50919191FC0FA95AAAB2D7559689089683E27 | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\htmlhelp.inf | text | |
MD5:7047C5055E964726F7CB1263069BE84E | SHA256:306DF5556418F8E1B6AA9B7FF0E5C9568F551FB69C2CD50070EEC03C613A031F | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\advpack.dll | executable | |
MD5:5889BD69A008FC924B71592F7FB5731D | SHA256:53E84096F700C80F217F685548502395F3C6B3BA0842F867FE323930343589FD | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\htmlhelp.lib | obj | |
MD5:190F479A7400722BF03EA392F89C78F3 | SHA256:9B87BC6975304666CD28CA3F45BA22AF54C6025F6EEBAC24A883E97059E15E60 | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\flash.exe | executable | |
MD5:00B936FD8CA57BB037C8C6A7FB890A3E | SHA256:BEE39BF6A5B012A3DBA2E261CDA7E6D9D5AB6A434EB05BACE3EF55E8B4323B42 | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\cnvtoc.dll | executable | |
MD5:D5647D4E32EE37918A77DE955978A0DF | SHA256:2109014D425366152D32B13BCC448CB369D81B3A3AD17B0BE0CF7D6F019F49BD | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\gencnv.dll | executable | |
MD5:DD9222E6168D4D9E685EF746083E8C1E | SHA256:0ED37582FF42DB391E33E1D283958AD57C5D1BCF8FAAFDC7F719BA33ABC63F3F | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.ini | ini | |
MD5:977E121DFD1AEE11190FB85E8753AB7B | SHA256:C526AD0557965F77CD086A97D55B53E51445E8886AE66A2DEF7568725AE7315E | |||
3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\cnvcnt.dll | executable | |
MD5:E3AD8E51AE1475DA90660240F997A87F | SHA256:61EFE4D842898126D3A945289313C7FB20A7AB7696EAD3606A4133359C74B724 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |