File name:

5kplayer-setup.exe

Full analysis: https://app.any.run/tasks/6d31700f-d628-4225-8f64-46fba065cf22
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 09, 2024, 09:36:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
opendir
qrcode
loader
arch-doc
attachments
attc-unc
attc-eml
blind-copy
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

0CB8A509B925197BD4B94B4C835C8DB9

SHA1:

B741C00855307AA3A8A3C52C651C2C8D969A4F78

SHA256:

02B4B6CD3A3A78CC764CB0AD573A9BCE3AB0F1681D5E6926C9501E0EBCD7BBBB

SSDEEP:

98304:9kaELUIVkgx1xdcKfAhtsZetTHlIcULI7dtki632QxILe2XHDUD0SBmolhU3OzfW:5pWO/kKi/yASXRfL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • FileRelation.exe (PID: 2428)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 5kplayer-setup.exe (PID: 5920)
      • 5kplayer.exe (PID: 6992)
    • Drops 7-zip archiver for unpacking

      • 5kplayer-setup.exe (PID: 5920)
      • 5kplayer.exe (PID: 6992)
    • Potential Corporate Privacy Violation

      • 5kp.exe (PID: 5940)
    • Process requests binary or script from the Internet

      • 5kp.exe (PID: 5940)
    • There is functionality for taking screenshot (YARA)

      • 5kp.exe (PID: 5940)
    • The process creates files with name similar to system file names

      • 5kplayer.exe (PID: 6992)
    • Process drops python dynamic module

      • 5kplayer.exe (PID: 6992)
    • Process drops legitimate windows executable

      • 5kplayer.exe (PID: 6992)
    • The process drops C-runtime libraries

      • 5kplayer.exe (PID: 6992)
    • Reads security settings of Internet Explorer

      • 5kplayer.exe (PID: 6992)
    • Creates a software uninstall entry

      • 5kplayer.exe (PID: 6992)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • 5kplayer.exe (PID: 6992)
  • INFO

    • Checks supported languages

      • 5kplayer-setup.exe (PID: 5920)
      • 5kp.exe (PID: 5940)
      • 5kplayer.exe (PID: 6992)
      • FileRelation.exe (PID: 2428)
    • Sends debugging messages

      • 5kp.exe (PID: 5940)
    • Reads the computer name

      • 5kp.exe (PID: 5940)
      • 5kplayer.exe (PID: 6992)
    • Create files in a temporary directory

      • 5kplayer-setup.exe (PID: 5920)
      • 5kp.exe (PID: 5940)
      • 5kplayer.exe (PID: 6992)
    • Creates files or folders in the user directory

      • 5kp.exe (PID: 5940)
      • 5kplayer.exe (PID: 6992)
      • FileRelation.exe (PID: 2428)
    • Reads the machine GUID from the registry

      • 5kp.exe (PID: 5940)
    • Checks proxy server information

      • slui.exe (PID: 7160)
    • Reads the software policy settings

      • slui.exe (PID: 5328)
      • slui.exe (PID: 7160)
    • Creates files in the program directory

      • 5kplayer.exe (PID: 6992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:20:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 29696
InitializedDataSize: 489984
UninitializedDataSize: 16896
EntryPoint: 0x38af
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 5kplayer-setup.exe THREAT 5kp.exe sppextcomobj.exe no specs slui.exe 5kplayer.exe slui.exe filerelation.exe 5kplayer-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2428"C:\Program Files (x86)\DearMob\5KPlayer\FileRelation.exe" -installC:\Program Files (x86)\DearMob\5KPlayer\FileRelation.exe
5kplayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\dearmob\5kplayer\filerelation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4072"C:\Users\admin\Downloads\5kplayer-setup.exe" C:\Users\admin\Downloads\5kplayer-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\5kplayer-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5328"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5920"C:\Users\admin\Downloads\5kplayer-setup.exe" C:\Users\admin\Downloads\5kplayer-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\downloads\5kplayer-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5940C:\Users\admin\AppData\Local\Temp\5kplayer\5kp.exeC:\Users\admin\AppData\Local\Temp\5kplayer\5kp.exe
5kplayer-setup.exe
User:
admin
Company:
DearMob
Integrity Level:
HIGH
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\5kplayer\5kp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6992C:\Users\admin\AppData\Local\Temp\5kplayer.exe C:\Users\admin\AppData\Local\Temp\5kplayer.exe
5kp.exe
User:
admin
Company:
DearMob, Inc.
Integrity Level:
HIGH
Description:
5KPlayer
Version:
6.9.0.0
Modules
Images
c:\users\admin\appdata\local\temp\5kplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7104C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7160C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
4 168
Read events
3 891
Write events
250
Delete events
27

Modification events

(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\5KPlayer
Operation:writeName:InstPath
Value:
C:\Program Files (x86)\DearMob\5KPlayer
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:DisplayName
Value:
5KPlayer
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\DearMob\5KPlayer\uninstaller.exe
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\DearMob\5KPlayer\5KPlayer.exe
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:Publisher
Value:
DearMob, Inc.
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:DisplayVersion
Value:
6.9
(PID) Process:(6992) 5kplayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5KPlayer
Operation:writeName:EstimatedSize
Value:
123800
(PID) Process:(2428) FileRelation.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\5KPlayer.xxx\shell\open
Operation:writeName:FriendlyAppName
Value:
5KPlayer
(PID) Process:(2428) FileRelation.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:5KPlayer
Value:
"C:\Program Files (x86)\DearMob\5KPlayer\5KPlayer.exe" -auto
(PID) Process:(2428) FileRelation.exeKey:HKEY_CLASSES_ROOT\.3gp
Operation:writeName:5KPlayer.backup
Value:
VLC.3gp
Executable files
457
Suspicious files
780
Text files
2 667
Unknown types
0

Dropped files

PID
Process
Filename
Type
59205kplayer-setup.exeC:\Users\admin\AppData\Local\Temp\5kplayer\5kp.7z
MD5:
SHA256:
59405kp.exeC:\Users\admin\AppData\Local\Temp\5kplayer.temp
MD5:
SHA256:
59405kp.exeC:\Users\admin\AppData\Local\Temp\5kplayer.exe
MD5:
SHA256:
69925kplayer.exeC:\Program Files (x86)\DearMob\5KPlayer\app.7z
MD5:
SHA256:
59205kplayer-setup.exeC:\Users\admin\AppData\Local\Temp\5kplayer\5kp.exeexecutable
MD5:3E71A7C07BB5BD316F64768D21971CFC
SHA256:E00F8BB3EAAFF144C30CEAC509CA4D5267D73A5BAF6D0FE45B3BF8CC58CE3178
59405kp.exeC:\Users\admin\AppData\Roaming\Digiarty\unique.bintext
MD5:095A9AA1155B7E2E42C6B81AF4D5863F
SHA256:62833E948E1A09E2070991A3BB35E06B19C6CD57C2F6820527A5B94088A8925F
69925kplayer.exeC:\Users\admin\AppData\Local\Temp\nsj11A8.tmp\BgWorker.dllexecutable
MD5:33EC04738007E665059CF40BC0F0C22B
SHA256:50F735AB8F3473423E6873D628150BBC0777BE7B4F6405247CDDF22BB00FB6BE
69925kplayer.exeC:\Program Files (x86)\DearMob\5KPlayer\5KPlayer.exeimage
MD5:E6C40676065283E3E9CF287B11CC5970
SHA256:B99C4162A373BDE7BB9F507CB30888651C998621BD59D490673BAD31DFE2DAA1
69925kplayer.exeC:\Users\admin\AppData\Local\Temp\nsj11A8.tmp\nsis7zU.dllexecutable
MD5:06A47571AC922F82C098622B2F5F6F63
SHA256:E4AB3064F2E094910AE80104EF9D371CCB74EBBEEED592582CF099ACD83F5FE9
59405kp.exeC:\Users\admin\AppData\Local\Temp\5kplayerDownload.configbinary
MD5:7F7787E94821EFF8F71F507FCC814492
SHA256:38C7CC1CC6A4AF13B9A00FC15857B45781706C27B1930067C2B18DB08D960984
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
56
DNS requests
25
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5940
5kp.exe
HEAD
200
67.228.121.193:80
http://dl1.5kplayer.com/download/5kplayer-64bit.exe
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5940
5kp.exe
GET
200
67.228.121.193:80
http://dl1.5kplayer.com/download/onlineload.config
unknown
whitelisted
5940
5kp.exe
GET
206
67.228.121.193:80
http://dl1.5kplayer.com/download/5kplayer-64bit.exe
unknown
whitelisted
5940
5kp.exe
GET
206
67.228.121.193:80
http://dl1.5kplayer.com/download/5kplayer-64bit.exe
unknown
whitelisted
5940
5kp.exe
GET
206
67.228.121.193:80
http://dl1.5kplayer.com/download/5kplayer-64bit.exe
unknown
whitelisted
6376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.164.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4308
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4080
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.23.209.135:443
www.bing.com
Akamai International B.V.
GB
whitelisted
2.23.209.135:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
5940
5kp.exe
67.228.121.196:443
www.5kplayer.com
SOFTLAYER
US
whitelisted
5940
5kp.exe
67.228.121.193:80
dl1.5kplayer.com
SOFTLAYER
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.23.209.135
  • 2.23.209.189
  • 2.23.209.136
  • 2.23.209.143
  • 2.23.209.188
  • 2.23.209.187
  • 2.23.209.150
  • 2.23.209.130
  • 2.23.209.132
  • 92.123.104.44
  • 92.123.104.51
  • 92.123.104.56
  • 92.123.104.60
  • 92.123.104.43
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.54
  • 92.123.104.63
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.5kplayer.com
  • 67.228.121.196
whitelisted
dl1.5kplayer.com
  • 67.228.121.193
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.73
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.73
whitelisted
th.bing.com
  • 2.23.209.171
  • 2.23.209.168
  • 2.23.209.179
  • 2.23.209.183
  • 2.23.209.182
  • 2.23.209.178
  • 2.23.209.176
  • 2.23.209.185
  • 2.23.209.175
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

PID
Process
Class
Message
5940
5kp.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
5 ETPRO signatures available at the full report
Process
Message
5kp.exe
------- "en"
5kp.exe
httpAnalyFinished
5kp.exe
startDownPack "http://dl1.5kplayer.com/download/5kplayer-32bit.exe" "http://dl1.5kplayer.com/download/5kplayer-64bit.exe" "3b3d0ee83dd892a61df44b2ac0a79768" "6a5431dd7ce490ef16b95e4317aa816f" true
5kp.exe
serverMD5 "6a5431dd7ce490ef16b95e4317aa816f"
5kp.exe
start down all new
5kp.exe
delete local file successed true
5kp.exe
start: 43042374 end: 64563560
5kp.exe
start: 21521187 end: 43042373
5kp.exe
connected to network
5kp.exe
start: 0 end: 21521186