| File name: | htmlhelp.exe |
| Full analysis: | https://app.any.run/tasks/4a059ff3-24cf-40be-a473-f8e9382e450e |
| Verdict: | Malicious activity |
| Analysis date: | February 15, 2024, 15:01:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MS CAB-Installer self-extracting archive |
| MD5: | FFDE6013C622C033D31FB892B283A1CE |
| SHA1: | BE3CA09DA0F21616577C8FB3D3A508804D4F9281 |
| SHA256: | CF8FE5A02D3C2BF0C8728DD399DC3B2587C4139FFB23EF4268F34535A6157B87 |
| SSDEEP: | 98304:W7v2Oa/flWOgi1sf/vbVTyblUc8cNrpt3r0izJJbsBWza8a4gKuSUMN3W4CB3k8w:YOmcrPGC1 |
| .exe | | | InstallShield setup (38.2) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (27.7) |
| .exe | | | Win64 Executable (generic) (24.5) |
| .exe | | | Win32 Executable (generic) (4) |
| .exe | | | Win16/32 Executable Delphi generic (1.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1997:07:15 11:48:12+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 36864 |
| InitializedDataSize: | 3458560 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2723 |
| OSVersion: | 5 |
| ImageVersion: | 5 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.71.1015.0 |
| ProductVersionNumber: | 4.71.1015.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft® HTML Help Author |
| FileVersion: | 4.74.8703 |
| InternalName: | htmlhelp.exe |
| LegalCopyright: | Copyright © Microsoft Corp. |
| OriginalFileName: | htmlhelp.exe |
| ProductName: | HTML Help Workshop Install |
| ProductVersion: | 4.74.8703 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2124 | grpconv.exe -o | C:\Windows\System32\grpconv.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Progman Group Converter Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | htmlhelp.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2340 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\hhupd.exe /C:"setup.exe NoDlg" /R:N | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\hhupd.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® HTML Help Control Exit code: 0 Version: 4.74.8793 Modules
| |||||||||||||||
| 3948 | "C:\Users\admin\AppData\Local\Temp\htmlhelp.exe" | C:\Users\admin\AppData\Local\Temp\htmlhelp.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® HTML Help Author Exit code: 0 Version: 4.74.8703 Modules
| |||||||||||||||
| 3972 | "C:\Users\admin\AppData\Local\Temp\htmlhelp.exe" | C:\Users\admin\AppData\Local\Temp\htmlhelp.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® HTML Help Author Exit code: 3221226540 Version: 4.74.8703 Modules
| |||||||||||||||
| (PID) Process: | (3948) htmlhelp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | wextract_cleanup0 |
Value: rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\" | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
| Operation: | write | Name: | SM_AccessoriesName |
Value: Accessories | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion |
| Operation: | write | Name: | PF_AccessoriesName |
Value: Accessories | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\hhw.exe |
| Operation: | write | Name: | Path |
Value: C:\Program Files\HTML Help Workshop | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\HTML Help Workshop |
| Operation: | write | Name: | InstallDir |
Value: C:\Program Files\HTML Help Workshop | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HTML Help Workshop |
| Operation: | write | Name: | DisplayName |
Value: HTML Help Workshop | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HTML Help Workshop |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\HTML Help Workshop\setup.exe Uninstall | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
| Operation: | write | Name: | dl.cl |
Value: DialogLayout.class | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
| Operation: | write | Name: | e.cl |
Value: Element.class | |||
| (PID) Process: | (2328) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RenameFiles\HHJava |
| Operation: | write | Name: | el.cl |
Value: ElementList.class | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\license.txt | text | |
MD5:36C61C5B8AF62F6339D7754561BAF69C | SHA256:B631BCDB61BC4FE0EA929ACD8B74B375F7A119935A8944595C232159F34D6CD8 | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\gencnv.dll | executable | |
MD5:DD9222E6168D4D9E685EF746083E8C1E | SHA256:0ED37582FF42DB391E33E1D283958AD57C5D1BCF8FAAFDC7F719BA33ABC63F3F | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\cnvcnt.dll | executable | |
MD5:E3AD8E51AE1475DA90660240F997A87F | SHA256:61EFE4D842898126D3A945289313C7FB20A7AB7696EAD3606A4133359C74B724 | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\readme.txt | text | |
MD5:5D8D3F3D1F5FA3990F7DAB2BE722845C | SHA256:B95EBA0470D1D86E1B8667EEAF96040F27940E7403085C0CF6AA7C34ED8A0787 | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\advpack.dll | executable | |
MD5:5889BD69A008FC924B71592F7FB5731D | SHA256:53E84096F700C80F217F685548502395F3C6B3BA0842F867FE323930343589FD | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\setup.exe | executable | |
MD5:0ABEF65FF07CB92C5640C18D51A34408 | SHA256:61264B9F6B1C75D6FC7C141A43E6465C5838414287CB533C7F457EEBB8A0BC04 | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\htmlhelp.h | text | |
MD5:630F3D680D5B16A3C7B4B977F6650C5D | SHA256:ED1228D4DCD4F58D125ECF2736A0AC929C32471CC8E6BEBAFC102E59468B187A | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\hhcout.dll | executable | |
MD5:7E9C9D6D88830F5A719375E26612B15E | SHA256:C17FB7F8110AB3E6913296F34403D51091C1F1E290F200E0219C93B9544BAFBC | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\htmlhelp.lib | obj | |
MD5:190F479A7400722BF03EA392F89C78F3 | SHA256:9B87BC6975304666CD28CA3F45BA22AF54C6025F6EEBAC24A883E97059E15E60 | |||
| 3948 | htmlhelp.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\navout.dll | executable | |
MD5:B9D916E12371039E242DE602FF87E201 | SHA256:1045A00055CF3AF63F7A9D581639E1EB3AF18519C554B36CA35BD849E18C4B9D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |