| File name: | image002.wmz |
| Full analysis: | https://app.any.run/tasks/d23ebb26-71cf-41b7-99d2-c155a1519496 |
| Verdict: | Malicious activity |
| Analysis date: | November 15, 2023, 17:33:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/gzip |
| File info: | gzip compressed data, max speed, from NTFS filesystem (NT), original size modulo 2^32 427552 |
| MD5: | 51BF08D7B474FB2695C696A998FEF8A1 |
| SHA1: | 539FA1F04A27609A87685B563A129BB86857EAD8 |
| SHA256: | DFDA016E7B4F9765EEBCC9E2D93EC0596D2CE2C57905EA4DC9408824EC32C5C2 |
| SSDEEP: | 12288:IGPcK6snmb+grLReikqZQ9U9bcs/M3JZodajFWTS9IWgxq8pJVHBl+:rPcK6sn6+49cqZQ9U9bcs/M3JZodaj8k |
| .z/gz/gzip | | | GZipped data (100) |
|---|
| Compression: | Deflated |
|---|---|
| Flags: | (none) |
| ModifyDate: | 0000:00:00 00:00:00 |
| ExtraFlags: | Fastest Algorithm |
| OperatingSystem: | NTFS filesystem (NT) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\image002 | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4040 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1208 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4012 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1508 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3680 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1608 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3844 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1616 | "C:\Program Files\Windows Media Player\wmplayer.exe" /layout:"C:\Users\admin\Desktop\image002.wmz" | C:\Program Files\Windows Media Player\wmplayer.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| 1756 | "C:\Program Files\Windows Media Player\wmplayer.exe" /layout:"C:\Users\admin\Desktop\image002.wmz" | C:\Program Files\Windows Media Player\wmplayer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| 1904 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2516 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2380 | "C:\Program Files\Windows Media Player\wmplayer.exe" /layout:"C:\Users\admin\Desktop\image002.wmz" | C:\Program Files\Windows Media Player\wmplayer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Exit code: 0 Version: 12.0.7601.23517 (win7sp1_ldr.160812-0732) Modules
| |||||||||||||||
| 2380 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --mojo-platform-channel-handle=3664 --field-trial-handle=1228,i,14929100015715998098,1301933121383208851,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3540) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3540) wmplayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3612 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg | — | |
MD5:— | SHA256:— | |||
| 3612 | wmplayer.exe | C:\Users\Public\Music\Sample Music\Folder.jpg | — | |
MD5:— | SHA256:— | |||
| 3612 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg | — | |
MD5:— | SHA256:— | |||
| 3612 | wmplayer.exe | C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg | — | |
MD5:— | SHA256:— | |||
| 3564 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | binary | |
MD5:3B8E4FAD2454F5CF97B5B401A8369E91 | SHA256:A69C8FB196478BF95A1C0AF91E67F7CFA5E7828DB8D0FEC22F5F47E108A237D5 | |||
| 3612 | wmplayer.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wpl | html | |
MD5:159E63275630EC4C9747B664BD063938 | SHA256:D54745665432625A904636E7675612C85026DA07E68F4E9D8DACBE98E5DEE844 | |||
| 3612 | wmplayer.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\02_Music_added_in_the_last_month.wpl | html | |
MD5:907BFC98CE854AE312127C952D8BE0F2 | SHA256:C475DC7423C2AD60F25ADAAC754CD8B68B57FF04F26ECEF78F3E5961B986A324 | |||
| 3612 | wmplayer.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\{BBE7F0E5-2884-49A9-B335-E5A2E66DF4FC}.jpg | image | |
MD5:FD5FD28E41676618AAC733B243AD54DB | SHA256:A26544648EF8CEFFAD6C789A3677031BE3C515918627D7C8F8E0587D3033C431 | |||
| 3612 | wmplayer.exe | C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\05_Pictures_taken_in_the_last_month.wpl | html | |
MD5:821D2BE672F05514127C117CEF460C6E | SHA256:3ABDB6CBD88AD1557054ECE3F10DD1A8494ED32F423B3CF8321B18DECC489474 | |||
| 3612 | wmplayer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms | binary | |
MD5:3DB3814B65589F1A0E304610C29970D0 | SHA256:2BB4E260FBA17E0B319EA7263B2E99B31489E5B10283B2BDF0E30FAC326D8045 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4088 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdposturlbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&requestID=B6CD8E4C-DBF7-424E-8772-635E4664326B | unknown | — | — | unknown |
3612 | wmplayer.exe | GET | 302 | 2.21.20.148:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16 | unknown | — | — | unknown |
4088 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16 | unknown | — | — | unknown |
1616 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdposturlbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&requestID=49B9ED6C-0514-423F-815A-3BF11867A0B5 | unknown | — | — | unknown |
3508 | msedge.exe | GET | 302 | 2.19.246.123:80 | http://go.microsoft.com/fwlink/?LinkId=120764&mpver=12.0.7601.24499&id=C00D0FEC&contextid=13&originalid=C00D0FEC | unknown | — | — | unknown |
1616 | wmplayer.exe | GET | 302 | 2.21.20.154:80 | http://redir.metaservices.microsoft.com/redir/getmdrcdbackground/?locale=409&geoid=f4&version=12.0.7601.24499&userlocale=409&wmid=5FA05D35-A682-4AF6-96F7-0773E42D4D16 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3612 | wmplayer.exe | 2.21.20.148:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
4088 | wmplayer.exe | 2.21.20.154:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
1616 | wmplayer.exe | 2.21.20.154:80 | redir.metaservices.microsoft.com | Akamai International B.V. | DE | unknown |
3508 | msedge.exe | 2.19.246.123:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3508 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3508 | msedge.exe | 51.104.176.40:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
redir.metaservices.microsoft.com |
| whitelisted |
toc.music.metaservices.microsoft.com |
| unknown |
info.music.metaservices.microsoft.com |
| unknown |
go.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
support.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |