File name:

Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx

Full analysis: https://app.any.run/tasks/455b1686-1ea5-4356-a8de-61dfaeb014a3
Verdict: Malicious activity
Analysis date: February 24, 2022, 12:24:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract
MD5:

8236F3FD7C66C87A6317F1CCE8409AD1

SHA1:

802751E9362FFF89A4BF744AF51D8FBF0E421492

SHA256:

0DB2C96E6530413BF92FD6F58FA2B35E34CFA0A1D4D6A96900337DBE7D3DCF11

SSDEEP:

49152:xo0aWr8/rHMGReefN8V8gTH+FOzDWr+kGzh5NdI3J7MwLo975cVlplqTmFG6xNoo:xol/HMGke8ygTeFXikQhf8LIWVJ/LNz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2840)
      • Explorer.EXE (PID: 1096)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 1060)
      • vlc.exe (PID: 3316)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Reads the computer name

      • WinRAR.exe (PID: 1060)
      • vlc.exe (PID: 3316)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Reads default file associations for system extensions

      • WinRAR.exe (PID: 1060)
      • Explorer.EXE (PID: 1096)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Reads the date of Windows installation

      • WinRAR.exe (PID: 1060)
      • rundll32.exe (PID: 2272)
    • Uses RUNDLL32.EXE to load library

      • Explorer.EXE (PID: 1096)
    • Creates files in the user directory

      • vlc.exe (PID: 3316)
      • Explorer.EXE (PID: 1096)
  • INFO

    • Checks supported languages

      • explorer.exe (PID: 2848)
      • SearchProtocolHost.exe (PID: 2840)
      • Explorer.EXE (PID: 1096)
      • rundll32.exe (PID: 2272)
      • rundll32.exe (PID: 2324)
      • rundll32.exe (PID: 2008)
    • Reads the computer name

      • explorer.exe (PID: 2848)
      • SearchProtocolHost.exe (PID: 2840)
      • rundll32.exe (PID: 2272)
      • rundll32.exe (PID: 2324)
      • rundll32.exe (PID: 2008)
    • Manual execution by user

      • explorer.exe (PID: 2848)
      • rundll32.exe (PID: 2272)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
      • rundll32.exe (PID: 2008)
    • Reads Microsoft Office registry keys

      • Explorer.EXE (PID: 1096)
    • Changes default file association

      • rundll32.exe (PID: 2272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Assets/contrast-black/HEVCCodecAppList.scale-100_contrast-black.png
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:02:08 23:58:00
ZipCompression: None
ZipBitFlag: 0x0008
ZipRequiredVersion: 45
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe explorer.exe no specs rundll32.exe no specs vlc.exe winrar.exe searchprotocolhost.exe no specs winrar.exe rundll32.exe no specs explorer.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1060"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1096C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1304"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip" C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2008"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\EnablerService.HEVC.dllC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2272"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.AppxC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2324"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\x86\HEVCDECODER_STORE.dllC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2840"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3316"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx"C:\Program Files\VideoLAN\VLC\vlc.exe
rundll32.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
3221225547
Version:
3.0.11
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3356"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
23 262
Read events
22 435
Write events
826
Delete events
1

Modification events

(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1060) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
18
Suspicious files
5
Text files
589
Unknown types
9

Dropped files

PID
Process
Filename
Type
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-16_altform-unplated_contrast-black.pngimage
MD5:B8381F318836267AD84FE4A45EDF35DC
SHA256:1550C590DF2EC141B5706994F40ED289535DE02DF352C7244A29C029AF80AC5B
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-150_contrast-black.pngimage
MD5:87A87E7D81065D629853AD7EE112FAE7
SHA256:E1B981FAB35168D81E60AFB2A9EFDE86964E306EF7E822DE7FEE58C84E220498
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-24_altform-unplated_contrast-black.pngimage
MD5:59D4350F3FEC2C960770B0FC2EAD8C1B
SHA256:5F05F760B6EC69FF2963F7D41E0EF643AC8D442DB7AAD850AD6EBE027E8D384A
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-100_contrast-black.pngimage
MD5:C50155029ACBD52CA3A8AFB2B0BE2CE5
SHA256:76CD350E5973B37286E4F95BBD4B9A41AEEED0D861885D9B294ED03CFC4581EE
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-16_contrast-black.pngimage
MD5:B8381F318836267AD84FE4A45EDF35DC
SHA256:1550C590DF2EC141B5706994F40ED289535DE02DF352C7244A29C029AF80AC5B
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-30_altform-unplated_contrast-black.pngimage
MD5:A8FCB94F33BC14FC13B73ADC2E44F780
SHA256:8783242A88D259739FCD66CE88CB28B8338085A6A0349B2ACA783862C37D50AE
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-30_contrast-black.pngimage
MD5:A8FCB94F33BC14FC13B73ADC2E44F780
SHA256:8783242A88D259739FCD66CE88CB28B8338085A6A0349B2ACA783862C37D50AE
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-40_altform-unplated_contrast-black.pngimage
MD5:05DF2B2BF9EB1EFD3AA42BDA1E5ABF90
SHA256:E902CAA131A2C00B7E64616AC43D43CEB1D0CB28EB482F1EF60AB5588AA8BD2C
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-36_altform-unplated_contrast-black.pngimage
MD5:44DC3796D54C57B1D208002BE63DE7ED
SHA256:DD9C45080B53769C8D27AF365C0D327F969DF4F7AC3DB19BE6D857755B4F0B74
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-36_contrast-black.pngimage
MD5:44DC3796D54C57B1D208002BE63DE7ED
SHA256:DD9C45080B53769C8D27AF365C0D327F969DF4F7AC3DB19BE6D857755B4F0B74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright � 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72
vlc.exe
main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
vlc.exe
main libvlc debug: using multimedia timers as clock source
vlc.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc.exe
main libvlc debug: searching plug-in modules
vlc.exe
main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
vlc.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc.exe
main libvlc debug: plug-ins loaded: 494 modules