| File name: | PC.zip |
| Full analysis: | https://app.any.run/tasks/ec005845-afe7-4694-9058-7dcf3ad2a2ad |
| Verdict: | Malicious activity |
| Analysis date: | April 11, 2020, 09:52:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | F44F64756354566A215944FE2640A21E |
| SHA1: | 5CD7DE1BD7216831D02A375B1F3A52F16FC834B6 |
| SHA256: | 09FF88A1DA882E07C2DE50F67D2F459EA1168DFEBF5DDCBE1AF6E85A2BD37D0F |
| SSDEEP: | 49152:EI/WucgyiXl3ZwJjafYZXNyWhCPKhxJrvFNM:ECcgy82jDNyWhCPKfJzTM |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2013:05:02 14:50:18 |
| ZipCRC: | 0x224752e7 |
| ZipCompressedSize: | 2333257 |
| ZipUncompressedSize: | 2428234 |
| ZipFileName: | ViewPlayCap.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1524 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.10861\ViewPlayCap.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.10861\ViewPlayCap.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1852 | "C:\Program Files\ViewPlayCap\ViewPlayCap.exe" | C:\Program Files\ViewPlayCap\ViewPlayCap.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: ViewPlayCap Exit code: 3221225477 Version: 3, 0, 0, 0 Modules
| |||||||||||||||
| 2632 | C:\Windows\system32\WerFault.exe -u -p 1852 -s 744 | C:\Windows\system32\WerFault.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3160 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.13527\ViewPlayCap.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.13527\ViewPlayCap.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 255 Modules
| |||||||||||||||
| 3504 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.10861\ViewPlayCap.exe" -el -s2 "-dC:\Program Files\ViewPlayCap" "-p" "-sp" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.10861\ViewPlayCap.exe | ViewPlayCap.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3568 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PC.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3900 | "C:\Program Files\ViewPlayCap\ViewPlayCap.exe" | C:\Program Files\ViewPlayCap\ViewPlayCap.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: ViewPlayCap Exit code: 0 Version: 3, 0, 0, 0 Modules
| |||||||||||||||
| 3984 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\PC.zip | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3568) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3504 | ViewPlayCap.exe | C:\Users\admin\Desktop\ViewPlayCap.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3504 | ViewPlayCap.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ViewPlayCap.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3504 | ViewPlayCap.exe | C:\Program Files\ViewPlayCap\ViewPlayCap.exe | executable | |
MD5:969EFC4F3304909E5DD6173432B1F5C5 | SHA256:24D7D197FE1BBE7584DA4EB488213647147DAE3EC7E313ECB59B8B2F1E419C81 | |||
| 3504 | ViewPlayCap.exe | C:\Program Files\ViewPlayCap\SMIUtility.dll | executable | |
MD5:AEA0D6ACC43D8915A7887D91F690813B | SHA256:1EE6C041276CD5B1A3E14B2A833982DC6F9197694E0F1CD3F55453655427AD40 | |||
| 3568 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.10861\ViewPlayCap.exe | executable | |
MD5:BCDD8DA242AC5BE6D2A7D86A13BE812F | SHA256:85309B4A5739A95743A0DB87A17A9458F14D84AB2CCE2EE46FFD0C63C6E1DE7F | |||
| 3568 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3568.13527\ViewPlayCap.exe | executable | |
MD5:BCDD8DA242AC5BE6D2A7D86A13BE812F | SHA256:85309B4A5739A95743A0DB87A17A9458F14D84AB2CCE2EE46FFD0C63C6E1DE7F | |||
| 3504 | ViewPlayCap.exe | C:\Program Files\ViewPlayCap\d3dx9_31.dll | executable | |
MD5:797E24743937D67D69F28F2CF5052EE8 | SHA256:E2065619FE6EB0034833B1DC0369DEB4A6EDC3110E38A1132EEAFCF430C578A5 | |||
| 2632 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\ViewPlayCap.exe.1852.dmp | dmp | |
MD5:— | SHA256:— | |||
| 2632 | WerFault.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_ViewPlayCap.exe_7d88865a1a8d81e35ce871f5608af6c4bab618f_0ae0a3e0\Report.wer | binary | |
MD5:— | SHA256:— | |||
| 3900 | ViewPlayCap.exe | C:\Users\admin\AppData\Local\VirtualStore\Program Files\ViewPlayCap\ViewPlayCap.ini | ini | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
ViewPlayCap.exe | g_pSM370Pool->m_pSM370[0] is NULL
|
ViewPlayCap.exe | SMI_GetVIDPIDByIdx:CheckSMInterfacePointer failed!idx=0
|
ViewPlayCap.exe | No Video Input Device
|
ViewPlayCap.exe | g_pSM370Pool->m_pSM370[0] is NULL
|
ViewPlayCap.exe | SMI_GetVIDPIDByIdx:CheckSMInterfacePointer failed!idx=0
|
ViewPlayCap.exe | No Video Input Device
|