File name:

C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\Cache_Data\f_0000e8

Full analysis: https://app.any.run/tasks/3e8aec6d-9fb8-44c6-aceb-39e07288b69c
Verdict: Malicious activity
Analysis date: November 27, 2023, 12:38:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CC4805556AFBAD7A49B6D2D32770977E

SHA1:

0DC67AA9AABF25BC6920432FFD3F70FCFF532222

SHA256:

DC5FC727D8478BD4069E5FBC75044EF1166140AB5CBBE2CBB41520C66E0646A0

SSDEEP:

98304:Qs09dMO3/N0Kdbgnvr+DpGRoPct/uN7cZzb8m/3uji6eWYw9wNdlk8CyNShgyIfV:dfIxwn1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • f_0000e8.exe (PID: 2684)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • f_0000e8.exe (PID: 2684)
    • Reads the Internet Settings

      • f_0000e8.exe (PID: 2684)
    • Reads Internet Explorer settings

      • f_0000e8.exe (PID: 2684)
  • INFO

    • Reads the computer name

      • f_0000e8.exe (PID: 2684)
      • wmpnscfg.exe (PID: 3188)
    • Checks proxy server information

      • f_0000e8.exe (PID: 2684)
    • Checks supported languages

      • f_0000e8.exe (PID: 2684)
      • wmpnscfg.exe (PID: 3188)
    • Create files in a temporary directory

      • f_0000e8.exe (PID: 2684)
    • Reads the machine GUID from the registry

      • f_0000e8.exe (PID: 2684)
      • wmpnscfg.exe (PID: 3188)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:29 19:25:35+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2723328
InitializedDataSize: 2256896
UninitializedDataSize: -
EntryPoint: 0x263f3f
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 13.0.0.0
ProductVersionNumber: 13.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: PixelSee Player Installer
CompanyName: SIA Circle Solutions
FileDescription: PixelSee Player Installer
FileVersion: 13.0.0.0
InternalName: pixelsee
LegalCopyright: Copyright © 2022-2023 SIA Circle Solutions
OriginalFileName: pixelsee
PrivateBuild: -
ProductName: PixelSee
ProductVersion: 13.0.0.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start f_0000e8.exe wmpnscfg.exe no specs f_0000e8.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2684"C:\Users\admin\AppData\Local\Temp\f_0000e8.exe" C:\Users\admin\AppData\Local\Temp\f_0000e8.exe
explorer.exe
User:
admin
Company:
SIA Circle Solutions
Integrity Level:
HIGH
Description:
PixelSee Player Installer
Exit code:
0
Version:
13.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\f_0000e8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2708"C:\Users\admin\AppData\Local\Temp\f_0000e8.exe" C:\Users\admin\AppData\Local\Temp\f_0000e8.exeexplorer.exe
User:
admin
Company:
SIA Circle Solutions
Integrity Level:
MEDIUM
Description:
PixelSee Player Installer
Exit code:
3221226540
Version:
13.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\f_0000e8.exe
c:\windows\system32\ntdll.dll
3188"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
501
Read events
486
Write events
10
Delete events
5

Modification events

(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2684) f_0000e8.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3188) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2A6FE570-72DC-4318-98F6-7B8EBE19B471}\{751EEBAD-639F-4458-918F-085477CB5E40}
Operation:delete keyName:(default)
Value:
(PID) Process:(3188) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{52796525-FF23-494A-9D27-D65C091FE3AA}\{751EEBAD-639F-4458-918F-085477CB5E40}
Operation:delete keyName:(default)
Value:
(PID) Process:(3188) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{52796525-FF23-494A-9D27-D65C091FE3AA}
Operation:delete keyName:(default)
Value:
(PID) Process:(3188) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{2A6FE570-72DC-4318-98F6-7B8EBE19B471}
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2684f_0000e8.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\preloader.htmlhtml
MD5:37A05031BEC9D3E093388407848AF66F
SHA256:CF38F4F8663028BEFF3A7650A9D426B4116891E8547029B66B8D2A13FAD63A48
2684f_0000e8.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\main-icon-big.pngimage
MD5:0E5FEA82CC4F4A8225532E5B2F45C6C8
SHA256:81B5F50491579127D13E050847EF6D817265AB4B70D2796FB74021463B778BB9
2684f_0000e8.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\Montserrat-Regular.eotbinary
MD5:2DD0A1DE870AF34D48D43B7CAD82B8D9
SHA256:057BC6C47C47AACCDF31ADC48A6B401F6090A02C28E354099EFF80907DC2AF32
2684f_0000e8.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\curl-ca-bundle.crttext
MD5:BE2B0736EA029FFF398559FA7DF4E646
SHA256:C05A79296D61E3B2A2EBAF5AF476839B976D69A5ACB6F581A667E60E681049A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2684
f_0000e8.exe
51.158.130.233:443
pixelsee.app
Online S.a.s.
FR
unknown

DNS requests

Domain
IP
Reputation
pixelsee.app
  • 51.158.130.233
unknown

Threats

No threats detected
No debug info