download:

/th-ch/youtube-music/releases/download/v3.10.0/YouTube-Music-Web-Setup-3.10.0.exe

Full analysis: https://app.any.run/tasks/88072b16-4c71-408d-ac04-f43e2db7dc10
Verdict: Malicious activity
Analysis date: August 08, 2025, 10:48:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

3F6F6247DFD6A0741162342EF3162AB9

SHA1:

05A75310EF2C4872F14537F55C556E3092FAAED0

SHA256:

082870E749A2DFB55AF9C9E3C19A2AFCEB6E0A6FAE30B1F02FDCC4B9447424CF

SSDEEP:

49152:CKGu34HyNt85q2O6ZCmSxbv0kFgQ0Qh1lhUq+kgYxhiKOD:CKDD05FO6smSlvMQ0QrTU2Fhin

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Get information on the list of running processes

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • cmd.exe (PID: 6460)
    • The process creates files with name similar to system file names

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Starts CMD.EXE for commands execution

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Reads security settings of Internet Explorer

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Executable content was dropped or overwritten

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Drops 7-zip archiver for unpacking

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Creates a software uninstall entry

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Process drops legitimate windows executable

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Application launched itself

      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 7084)
      • YouTube Music.exe (PID: 3092)
  • INFO

    • The sample compiled with english language support

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
    • Create files in a temporary directory

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
    • Reads the computer name

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 2524)
      • YouTube Music.exe (PID: 6832)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 5300)
      • YouTube Music.exe (PID: 6256)
      • YouTube Music.exe (PID: 4024)
      • YouTube Music.exe (PID: 7124)
      • YouTube Music.exe (PID: 5476)
    • Reads the machine GUID from the registry

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 5476)
    • Checks supported languages

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 2524)
      • YouTube Music.exe (PID: 6832)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 2992)
      • YouTube Music.exe (PID: 7084)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 4024)
      • YouTube Music.exe (PID: 5284)
      • YouTube Music.exe (PID: 5300)
      • YouTube Music.exe (PID: 6256)
      • YouTube Music.exe (PID: 7124)
      • YouTube Music.exe (PID: 5476)
      • YouTube Music.exe (PID: 2596)
    • Checks proxy server information

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
      • slui.exe (PID: 5368)
    • Reads the software policy settings

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • slui.exe (PID: 5368)
    • Creates files or folders in the user directory

      • YouTube-Music-Web-Setup-3.10.0.exe (PID: 5768)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 6832)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 7124)
      • YouTube Music.exe (PID: 5476)
    • Manual execution by a user

      • YouTube Music.exe (PID: 4832)
    • Reads product name

      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 5300)
      • YouTube Music.exe (PID: 6256)
    • Reads Environment values

      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 6256)
      • YouTube Music.exe (PID: 5300)
    • Process checks computer location settings

      • YouTube Music.exe (PID: 2992)
      • YouTube Music.exe (PID: 4040)
      • YouTube Music.exe (PID: 4832)
      • YouTube Music.exe (PID: 3092)
      • YouTube Music.exe (PID: 5284)
      • YouTube Music.exe (PID: 5300)
      • YouTube Music.exe (PID: 6256)
      • YouTube Music.exe (PID: 2596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.10.0.0
ProductVersionNumber: 3.10.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: th-ch
FileDescription: YouTube Music Desktop App - including custom plugins
FileVersion: 3.10.0
LegalCopyright: Copyright © 2025 th-ch
ProductName: YouTube Music
ProductVersion: 3.10.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
20
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start youtube-music-web-setup-3.10.0.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs slui.exe youtube music.exe no specs youtube music.exe no specs youtube music.exe youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs youtube music.exe youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs youtube music.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2524"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --gpu-preferences=SAAAAAAAAADgAAAIAAAAAAAAAAAAAGAAAQAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1896,i,7809168454360155533,10685506197357219370,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=1884 /prefetch:2C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
LOW
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2596"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --standard-schemes=http,https,mailto --bypasscsp-schemes=http,https --cors-schemes=http,https --fetch-schemes=http,https --service-worker-schemes=http,https --streaming-schemes=http,https --code-cache-schemes=http,https --app-user-model-id=com.github.th-ch.youtube-music --app-path="C:\Users\admin\AppData\Local\Programs\youtube-music\resources\app.asar" --enable-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --time-ticks-at-unix-epoch=-1754648517431968 --launch-time-ticks=1709388285 --field-trial-handle=1856,i,7505936658097805137,2455170739373005116,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=3748 /prefetch:1C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
LOW
Description:
YouTube Music
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
2992"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --standard-schemes=http,https,mailto --bypasscsp-schemes=http,https --cors-schemes=http,https --fetch-schemes=http,https --service-worker-schemes=http,https --streaming-schemes=http,https --code-cache-schemes=http,https --app-user-model-id=com.github.th-ch.youtube-music --app-path="C:\Users\admin\AppData\Local\Programs\youtube-music\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=1896,i,7809168454360155533,10685506197357219370,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=2952 /prefetch:1C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3092"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\combase.dll
4024"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --gpu-preferences=SAAAAAAAAADgAAAIAAAAAAAAAAAAAGAAAQAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1856,i,7505936658097805137,2455170739373005116,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=1852 /prefetch:2C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
LOW
Description:
YouTube Music
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4040"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --standard-schemes=http,https,mailto --bypasscsp-schemes=http,https --cors-schemes=http,https --fetch-schemes=http,https --service-worker-schemes=http,https --streaming-schemes=http,https --code-cache-schemes=http,https --app-user-model-id=com.github.th-ch.youtube-music --app-path="C:\Users\admin\AppData\Local\Programs\youtube-music\resources\app.asar" --no-sandbox --no-zygote --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=1896,i,7809168454360155533,10685506197357219370,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=3660 /prefetch:1C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4724\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4832"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeexplorer.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5284"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --standard-schemes=http,https,mailto --bypasscsp-schemes=http,https --cors-schemes=http,https --fetch-schemes=http,https --service-worker-schemes=http,https --streaming-schemes=http,https --code-cache-schemes=http,https --app-user-model-id=com.github.th-ch.youtube-music --app-path="C:\Users\admin\AppData\Local\Programs\youtube-music\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --time-ticks-at-unix-epoch=-1754648517431968 --launch-time-ticks=1703635819 --field-trial-handle=1856,i,7505936658097805137,2455170739373005116,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=3100 /prefetch:1C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5300"C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\YouTube Music" --standard-schemes=http,https,mailto --bypasscsp-schemes=http,https --cors-schemes=http,https --fetch-schemes=http,https --service-worker-schemes=http,https --streaming-schemes=http,https --code-cache-schemes=http,https --app-user-model-id=com.github.th-ch.youtube-music --app-path="C:\Users\admin\AppData\Local\Programs\youtube-music\resources\app.asar" --no-sandbox --no-zygote --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --time-ticks-at-unix-epoch=-1754648517431968 --launch-time-ticks=1703885771 --field-trial-handle=1856,i,7505936658097805137,2455170739373005116,262144 --enable-features=EnableTransparentHwndEnlargement,OverlayScrollbar,PdfUseShowSaveFilePicker,SharedArrayBuffer,UseOzonePlatform,WaylandWindowDecorations --disable-features=FluentScrollbar,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation,WinDelaySpellcheckServiceInit --variations-seed-version --mojo-platform-channel-handle=3632 /prefetch:1C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exeYouTube Music.exe
User:
admin
Company:
th-ch
Integrity Level:
MEDIUM
Description:
YouTube Music
Exit code:
0
Version:
3.10.0
Modules
Images
c:\users\admin\appdata\local\programs\youtube-music\youtube music.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 510
Read events
7 444
Write events
26
Delete events
40

Modification events

(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\352e3c04-9f15-58b2-adec-0057f1f82f70
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\youtube-music\Uninstall YouTube Music.exe" /currentuser /S
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\352e3c04-9f15-58b2-adec-0057f1f82f70
Operation:writeName:DisplayVersion
Value:
3.10.0
(PID) Process:(5768) YouTube-Music-Web-Setup-3.10.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\352e3c04-9f15-58b2-adec-0057f1f82f70
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\youtube-music\YouTube Music.exe,0
Executable files
22
Suspicious files
157
Text files
57
Unknown types
145

Dropped files

PID
Process
Filename
Type
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\youtube-music-3.10.0-x64.nsis[1].7z
MD5:
SHA256:
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\package.7z
MD5:
SHA256:
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\7z-out\icudtl.dat
MD5:
SHA256:
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\7z-out\LICENSES.chromium.html
MD5:
SHA256:
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:988F6D76290974F7D8B6E0AF68119462
SHA256:5804887373FA3FFB5DA64AF94EEE6EBD30766D6F95CB91D7522AE047C2F9E313
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:936093CE252F5B45057946F1AB1DAB93
SHA256:D0D7B41657A72395EB25608E0A4C28DF80095ABEA1012DF29183254B2AED0E57
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_89854CA6A0F0936A4D2ECA78845CEA25binary
MD5:D0070A64066E06E6F4D77C62023292C9
SHA256:009055946C938B0FAD1E5CF67CB480A7D09D71B419559AA3063C9AF51B1909C7
5768YouTube-Music-Web-Setup-3.10.0.exeC:\Users\admin\AppData\Local\Temp\nsjC976.tmp\SpiderBanner.dllexecutable
MD5:17309E33B596BA3A5693B4D3E85CF8D7
SHA256:996A259E53CA18B89EC36D038C40148957C978C0FD600A268497D4C92F882A93
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
51
DNS requests
56
Threats
44

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5768
YouTube-Music-Web-Setup-3.10.0.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
unknown
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCrZoa1YnvoBZaCEzAShkn1
unknown
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
592
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2940
svchost.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
whitelisted
3672
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5968
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
140.82.121.4:443
github.com
GITHUB
US
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
whitelisted
5768
YouTube-Music-Web-Setup-3.10.0.exe
185.199.109.133:443
release-assets.githubusercontent.com
FASTLY
US
whitelisted
4
System
192.168.100.255:138
whitelisted
592
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
592
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
github.com
  • 140.82.121.4
  • 140.82.121.3
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
release-assets.githubusercontent.com
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.108.133
  • 185.199.111.133
whitelisted
login.live.com
  • 40.126.31.1
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.2
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.0
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.8
  • 23.216.77.42
  • 23.216.77.22
  • 23.216.77.20
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6832
YouTube Music.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info