File name:

starplayer_agent_1.4.26.30.exe

Full analysis: https://app.any.run/tasks/0b6705a9-a4aa-441a-8d4e-eca3d211da0c
Verdict: Malicious activity
Analysis date: January 06, 2026, 16:17:29
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

56AE83A688B91D8B4D581380F9D5734E

SHA1:

B8BA426C53ED5B1AB695555BBDE027DDC9F2F4FF

SHA256:

D1B12901F4E81EFA55FA952FFBD3B94C589303941241EDD47A560F505097B2C9

SSDEEP:

98304:LjStDQFd9z/d8i41MsMmWaKjw+fSV0GoM1OaDWWKEWZDrcpYOYDfmRxH1tPLzY5q:RVKUgLgXu/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • Root_Sectigo_RootCA_import.exe (PID: 7912)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
    • Uses TASKKILL.EXE to kill process

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • The process creates files with name similar to system file names

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
    • Adds/modifies Windows certificates

      • Root_Sectigo_RootCA_import.exe (PID: 7912)
      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • Changes settings of the software policy

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • Executes as Windows Service

      • StarPlayerAgent64.exe (PID: 8124)
    • Application launched itself

      • StarPlayerAgent64.exe (PID: 8124)
    • Reads security settings of Internet Explorer

      • StarPlayerAgent64.exe (PID: 8124)
      • StarPlayerAgent64.exe (PID: 8180)
  • INFO

    • The sample compiled with english language support

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • Checks supported languages

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
      • StarPlayerAgent64.exe (PID: 8064)
      • StarPlayerAgent64.exe (PID: 8124)
      • StarPlayerAgent64.exe (PID: 8180)
      • StarPlayerAgent64.exe (PID: 7956)
    • Reads the computer name

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
      • StarPlayerAgent64.exe (PID: 7956)
      • StarPlayerAgent64.exe (PID: 8124)
      • StarPlayerAgent64.exe (PID: 8064)
      • StarPlayerAgent64.exe (PID: 8180)
    • Create files in a temporary directory

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
    • Creates files in the program directory

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
      • Root_Sectigo_RootCA_import.exe (PID: 7912)
    • The sample compiled with korean language support

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • Reads the machine GUID from the registry

      • Root_Sectigo_RootCA_import.exe (PID: 7912)
      • StarPlayerAgent64.exe (PID: 8180)
    • Checks proxy server information

      • StarPlayerAgent64.exe (PID: 8124)
      • StarPlayerAgent64.exe (PID: 8180)
    • Creates a software uninstall entry

      • starplayer_agent_1.4.26.30.exe (PID: 7740)
    • Creates files or folders in the user directory

      • StarPlayerAgent64.exe (PID: 8180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.4.26.30
ProductVersionNumber: 1.4.26.30
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Axissoft
FileDescription: StarPlayer Agent for html5
FileVersion: 1,4,26,30
LegalCopyright: Copyright(c) Axissoft. All rights reserved.
LegalTrademarks: Axissoft
ProductName: StarPlayer
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
12
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
6156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeStarPlayerAgent64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7584"C:\Users\admin\AppData\Local\Temp\starplayer_agent_1.4.26.30.exe" C:\Users\admin\AppData\Local\Temp\starplayer_agent_1.4.26.30.exeexplorer.exe
User:
admin
Company:
Axissoft
Integrity Level:
MEDIUM
Description:
StarPlayer Agent for html5
Exit code:
3221226540
Version:
1,4,26,30
Modules
Images
c:\users\admin\appdata\local\temp\starplayer_agent_1.4.26.30.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7740"C:\Users\admin\AppData\Local\Temp\starplayer_agent_1.4.26.30.exe" C:\Users\admin\AppData\Local\Temp\starplayer_agent_1.4.26.30.exe
explorer.exe
User:
admin
Company:
Axissoft
Integrity Level:
HIGH
Description:
StarPlayer Agent for html5
Exit code:
0
Version:
1,4,26,30
Modules
Images
c:\users\admin\appdata\local\temp\starplayer_agent_1.4.26.30.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7776taskkill /IM "StarPlayerAgent64.exe" /FC:\Windows\SysWOW64\taskkill.exestarplayer_agent_1.4.26.30.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7784\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7912"C:\Program Files (x86)\Axissoft\StarPlayerAgent\Root_Sectigo_RootCA_import.exe"C:\Program Files (x86)\Axissoft\StarPlayerAgent\Root_Sectigo_RootCA_import.exe
starplayer_agent_1.4.26.30.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\axissoft\starplayeragent\root_sectigo_rootca_import.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7956"C:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exe" uninstallC:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exestarplayer_agent_1.4.26.30.exe
User:
admin
Company:
Axissoft
Integrity Level:
HIGH
Description:
StarPlayer Agent
Exit code:
0
Version:
1.4.26.30
Modules
Images
c:\program files (x86)\axissoft\starplayeragent\starplayeragent64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7964\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeStarPlayerAgent64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8064"C:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exe" installC:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exe
starplayer_agent_1.4.26.30.exe
User:
admin
Company:
Axissoft
Integrity Level:
HIGH
Description:
StarPlayer Agent
Exit code:
0
Version:
1.4.26.30
Modules
Images
c:\program files (x86)\axissoft\starplayeragent\starplayeragent64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
8072\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeStarPlayerAgent64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
11 686
Read events
11 659
Write events
20
Delete events
7

Modification events

(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:D1EB23A46D17D68FD92564C2F1F1601764D8E349
Value:
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349
Operation:writeName:Blob
Value:
030000000100000014000000D1EB23A46D17D68FD92564C2F1F1601764D8E349200000000100000036040000308204323082031AA003020102020101300D06092A864886F70D0101050500307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C18414141204365727469666963617465205365727669636573301E170D3034303130313030303030305A170D3238313233313233353935395A307B310B3009060355040613024742311B301906035504080C1247726561746572204D616E636865737465723110300E06035504070C0753616C666F7264311A3018060355040A0C11436F6D6F646F204341204C696D697465643121301F06035504030C1841414120436572746966696361746520536572766963657330820122300D06092A864886F70D01010105000382010F003082010A0282010100BE409DF46EE1EA76871C4D45448EBE46C883069DC12AFE181F8EE402FAF3AB5D508A16310B9A06D0C57022CD492D5463CCB66E68460B53EACB4C24C0BC724EEAF115AEF4549A120AC37AB23360E2DA8955F32258F3DEDCCFEF8386A28C944F9F68F29890468427C776BFE3CC352C8B5E07646582C048B0A891F9619F762050A891C766B5EB78620356F08A1A13EA31A31EA099FD38F6F62732586F07F56BB8FB142BAFB7AACCD6635F738CDA0599A838A8CB17783651ACE99EF4783A8DCF0FD942E2980CAB2F9F0E01DEEF9F9949F12DDFAC744D1B98B547C5E529D1F99018C7629CBE83C7267B3E8A25C7C0DD9DE6356810209D8FD8DED2C3849C0D5EE82FC90203010001A381C03081BD301D0603551D0E04160414A0110A233E96F107ECE2AF29EF82A57FD030A4B4300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF307B0603551D1F047430723038A036A0348632687474703A2F2F63726C2E636F6D6F646F63612E636F6D2F414141436572746966696361746553657276696365732E63726C3036A034A0328630687474703A2F2F63726C2E636F6D6F646F2E6E65742F414141436572746966696361746553657276696365732E63726C300D06092A864886F70D010105050003820101000856FC02F09BE8FFA4FAD67BC64480CE4FC4C5F60058CCA6B6BC1449680476E8E6EE5DEC020F60D68D50184F264E01E3E6B0A5EEBFBC745441BFFDFC12B8C74F5AF48960057F60B7054AF3F6F1C2BFC4B97486B62D7D6BCCD2F346DD2FC6E06AC3C334032C7D96DD5AC20EA70A99C1058BAB0C2FF35C3ACF6C37550987DE53406C58EFFCB6AB656E04F61BDC3CE05A15C69ED9F15948302165036CECE92173EC9B03A1E037ADA015188FFABA02CEA72CA910132CD4E50826AB229760F8905E74D4A29A53BDF2A968E0A26EC2D76CB1A30F9EBFEB68E756F2AEF2E32B383A0981B56B85D7BE2DED3F1AB7B263E2F5622C82D46A004150F139839F95E93696986E
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0
Value:
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0
Operation:writeName:Blob
Value:
030000000100000014000000D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF02000000001000000930200003082028F30820215A00302010202105C8B99C55A94C5D27156DECD8980CC26300A06082A8648CE3D040303308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374204543432043657274696669636174696F6E20417574686F726974793076301006072A8648CE3D020106052B81040022036200041AAC545AA9F96823E77AD5246F53C65AD84BABC6D5B6D1E67371AEDD9CD60C61FDDBA08903B80514EC57CEEE5D3FE221B3CEF7D48A79E0A3837E2D97D061C4F199DC259163AB7F30A3B470E2C7A1339CF3BF2E5C53B15FB37D327F8A34E37979A3423040301D0603551D0E041604143AE10986D4CF19C29676744976DCE035C663639A300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300A06082A8648CE3D040303036800306502303667A11608DCE49700411D4EBEE16301CF3BAA421164A09D94390211795C7B1DFA64B9EE1642B3BF8AC209C4ECE4B14D023100E92A61478C524A4B4E1870F6D644D66EF583BA6D58BD24D95648EAEFC4A24681886A3A46D1A99B4DC961DAD15D576A18
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Value:
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
0300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E2000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
(PID) Process:(8064) StarPlayerAgent64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\General
Operation:writeName:UniqueID
Value:
{6EFB3C55-A4B0-4F3B-B286-E7E7B2415169}
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:02FAF3E291435468607857694DF5E45B68851868
Value:
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\02FAF3E291435468607857694DF5E45B68851868
Operation:writeName:Blob
Value:
03000000010000001400000002FAF3E291435468607857694DF5E45B6885186820000000010000003A040000308204363082031EA003020102020101300D06092A864886F70D0101050500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100B7F71A33E6F200042D39E04E5BED1FBC6C0FCDB5FA23B6CEDE9B113397A4294C7D939FBD4ABC93ED031AE38FCFE56D505AD69729945A80B0497ADB2E95FDB8CABF37382D1E3E9141AD7056C7F04F3FE8329E74CAC89054E9C65F0F789D9A403C0EAC61AA5E148F9E87A16A50DCD79A4EAF05B3A671949C71B350600AC7139D38078602A8E9A869261890AB4CB04F23AB3A4F84D8DFCE9FE1696FBBD742D76B44E4C7ADEE6D415F725A710837B37965A459A09437F7002F0DC29272DAD03872DB14A845C45D2A7DB7B4D6C4EEACCD1344B7C92BDD430025FA61B9696A582311B7A7338F567559F5CD29D746B70A2B65B6D3426F15B2B87BFBEFE95D53D5345A270203010001A381DC3081D9301D0603551D0E04160414ADBD987A34B426F7FAC42654EF03BDE024CB541A300B0603551D0F040403020106300F0603551D130101FF040530030101FF3081990603551D2304819130818E8014ADBD987A34B426F7FAC42654EF03BDE024CB541AA173A471306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74820101300D06092A864886F70D01010505000382010100B09BE08525C2D623E20F9606929D41989CD9847981D91E5B14072336658FB0D877BBAC416C47608351B0F9323DE7FCF62613C78016A5BF5AFC87CF787989219AE24C070A8635BCF2DE51C4D296B7DC7E4EEE70FD1C39EB0C0251142D8EBD16E0C1DF4675E724ADECF442B48593701067BA9D06354A18D32B7ACC5142A17A63D1E6BBA1C52BC236BE130DE6BD637E797BA7090D40AB6ADD8F8AC3F6F68C1A420551D445F59FA76221681520433C99E77CBD24D8A9911773883F561B313818B4710F9ACDC80E9E8E2E1BE18C9883CB1F31F1444CC604734976600FC7F8BD17806B2EE9CC4C0E5A9A790F200A2ED59E63261E559294D882175A7BD0BCC78F4E8604
(PID) Process:(7912) Root_Sectigo_RootCA_import.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:EE869387FFFD8349AB5AD14322588789A457B012
Value:
Executable files
8
Suspicious files
0
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
7740starplayer_agent_1.4.26.30.exeC:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent.exeexecutable
MD5:92AEE83250EFB718DAE8557957EDDE00
SHA256:4D9036EB638F0AACF16A65AF04BCBE9B8049354DC4EE43E4EE4621A6E642A6E1
7740starplayer_agent_1.4.26.30.exeC:\Program Files (x86)\Axissoft\StarPlayerAgent\LICENSEtext
MD5:D3AAB34BEBF5FFEBC2EA452D1F21BA9A
SHA256:93A906B366481538197B61D2E79B77C2A56E2C95CD8691AF69E6CF0091840696
7912Root_Sectigo_RootCA_import.exeC:\Program Files (x86)\KICA\addCert\RootCA(COMODO).crttext
MD5:D69CE7A8DD1F98B2083BA464C340BC3C
SHA256:6A14E7E8F0F1E40C32E085BED567837562F905A40FDA81CC11BA2A86AF705890
7912Root_Sectigo_RootCA_import.exeC:\Program Files (x86)\KICA\addCert\RootCA(AddTrust).crttext
MD5:F85D1FF17B0079709F131F3CE3F288D2
SHA256:0459C4EFF856FDF7837EF4971BADCC095C2CB6F785C179DDE6F858210C3B8662
7740starplayer_agent_1.4.26.30.exeC:\Users\admin\AppData\Local\Temp\nsqDFC9.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
7740starplayer_agent_1.4.26.30.exeC:\Users\admin\AppData\Local\Temp\nsqDFC9.tmp\nsExec.dllexecutable
MD5:11092C1D3FBB449A60695C44F9F3D183
SHA256:2CD3A2D4053954DB1196E2526545C36DFC138C6DE9B81F6264632F3132843C77
7912Root_Sectigo_RootCA_import.exeC:\Program Files (x86)\KICA\addCert\RootCA(AAA).crttext
MD5:B821EE78C10EDA973C40A382FA5CA457
SHA256:028FD01CCC988386D6718EDA921F6131044A61C06E0F84574D4911918E4659F3
7740starplayer_agent_1.4.26.30.exeC:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exeexecutable
MD5:FAB533E08F574B0B6E878078E4D9B255
SHA256:D3A537C49E9CFC2F0525B74E54BDD7AF438E389BDFA1EE59070A6AD0445B7650
7740starplayer_agent_1.4.26.30.exeC:\Program Files (x86)\Axissoft\StarPlayerAgent\Root_Sectigo_RootCA_import.exeexecutable
MD5:E30F12CCCB18F43DBE143CB23D8ECB6A
SHA256:235A48F176599C33DA4C5347D9A4B0848624AAF799720FD66465197841A4A61B
7740starplayer_agent_1.4.26.30.exeC:\Program Files (x86)\Axissoft\StarPlayerAgent\server.pemtext
MD5:9B4DB1CF3F4754AE1DAABC42BFA1B55D
SHA256:F0ABA0ECFB9E71348558C364D20DBF6E1B1D8DFC7C2E0722B92C47214393D640
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
26
DNS requests
16
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
8096
SIHClient.exe
GET
200
20.242.39.171:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
8096
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
8096
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
2240
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
2240
svchost.exe
POST
200
40.126.32.136:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
2240
svchost.exe
POST
200
40.126.32.136:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
1156
svchost.exe
GET
200
2.16.164.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
1156
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1156
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2760
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2292
svchost.exe
224.0.0.251:5353
whitelisted
2292
svchost.exe
224.0.0.252:5355
whitelisted
8180
StarPlayerAgent64.exe
218.153.11.167:80
cab-starplayer.service.concdn.com
KIXS-AS-KR Korea Telecom
KR
unknown
2240
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
cab-starplayer.service.concdn.com
  • 218.153.11.167
  • 183.111.14.45
unknown
login.live.com
  • 40.126.32.136
  • 20.190.160.128
  • 40.126.32.74
  • 20.190.160.66
  • 20.190.160.22
  • 40.126.32.76
  • 40.126.32.134
  • 20.190.160.64
whitelisted
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 2.16.164.112
  • 2.16.164.113
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted

Threats

PID
Process
Class
Message
8180
StarPlayerAgent64.exe
Misc activity
ET INFO Observed UA-CPU Header
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
StarPlayerAgent64.exe
Complete installed
StarPlayerAgent64.exe
Started service
StarPlayerAgent64.exe
work...
StarPlayerAgent64.exe
C:\Program Files (x86)\Axissoft\StarPlayerAgent\StarPlayerAgent64.exe work
StarPlayerAgent64.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\localhost.axissoft.co.kr.2024.09.pem[1].txt
StarPlayerAgent64.exe
starplayer_monitoring.onopen...