File name:

Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx

Full analysis: https://app.any.run/tasks/455b1686-1ea5-4356-a8de-61dfaeb014a3
Verdict: Malicious activity
Analysis date: February 24, 2022, 12:24:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract
MD5:

8236F3FD7C66C87A6317F1CCE8409AD1

SHA1:

802751E9362FFF89A4BF744AF51D8FBF0E421492

SHA256:

0DB2C96E6530413BF92FD6F58FA2B35E34CFA0A1D4D6A96900337DBE7D3DCF11

SSDEEP:

49152:xo0aWr8/rHMGReefN8V8gTH+FOzDWr+kGzh5NdI3J7MwLo975cVlplqTmFG6xNoo:xol/HMGke8ygTeFXikQhf8LIWVJ/LNz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2840)
      • Explorer.EXE (PID: 1096)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1060)
      • vlc.exe (PID: 3316)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Checks supported languages

      • WinRAR.exe (PID: 1060)
      • vlc.exe (PID: 3316)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Reads the date of Windows installation

      • WinRAR.exe (PID: 1060)
      • rundll32.exe (PID: 2272)
    • Reads default file associations for system extensions

      • WinRAR.exe (PID: 1060)
      • Explorer.EXE (PID: 1096)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1060)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
    • Uses RUNDLL32.EXE to load library

      • Explorer.EXE (PID: 1096)
    • Creates files in the user directory

      • Explorer.EXE (PID: 1096)
      • vlc.exe (PID: 3316)
  • INFO

    • Checks supported languages

      • explorer.exe (PID: 2848)
      • Explorer.EXE (PID: 1096)
      • SearchProtocolHost.exe (PID: 2840)
      • rundll32.exe (PID: 2272)
      • rundll32.exe (PID: 2324)
      • rundll32.exe (PID: 2008)
    • Reads the computer name

      • explorer.exe (PID: 2848)
      • SearchProtocolHost.exe (PID: 2840)
      • rundll32.exe (PID: 2272)
      • rundll32.exe (PID: 2008)
      • rundll32.exe (PID: 2324)
    • Manual execution by user

      • explorer.exe (PID: 2848)
      • rundll32.exe (PID: 2272)
      • WinRAR.exe (PID: 3356)
      • WinRAR.exe (PID: 1304)
      • rundll32.exe (PID: 2008)
    • Reads Microsoft Office registry keys

      • Explorer.EXE (PID: 1096)
    • Changes default file association

      • rundll32.exe (PID: 2272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Assets/contrast-black/HEVCCodecAppList.scale-100_contrast-black.png
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:02:08 23:58:00
ZipCompression: None
ZipBitFlag: 0x0008
ZipRequiredVersion: 45
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe explorer.exe no specs rundll32.exe no specs vlc.exe winrar.exe searchprotocolhost.exe no specs winrar.exe rundll32.exe no specs explorer.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1060"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1096C:\Windows\Explorer.EXEC:\Windows\Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1304"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip" C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2008"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\EnablerService.HEVC.dllC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2272"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.AppxC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2324"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\x86\HEVCDECODER_STORE.dllC:\Windows\system32\rundll32.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2840"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2848"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3316"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx"C:\Program Files\VideoLAN\VLC\vlc.exe
rundll32.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
3221225547
Version:
3.0.11
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3356"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
23 262
Read events
22 435
Write events
826
Delete events
1

Modification events

(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1060) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx.zip
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
18
Suspicious files
5
Text files
589
Unknown types
9

Dropped files

PID
Process
Filename
Type
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-400_contrast-black.pngimage
MD5:9E99243EBD1D9E8851B7FF71C573691A
SHA256:C8A0C8563D7EAE76F24333673E6912C04425E02E626808C331BC330F502C5E2C
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-200_contrast-black.pngimage
MD5:71B4BD90BEB7BCFDF010119A71A5A3AE
SHA256:0175A4E7AA6A3318188BC2F3E68A975BBB39F0F60EEE360A177058251E5340FD
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-16_contrast-black.pngimage
MD5:B8381F318836267AD84FE4A45EDF35DC
SHA256:1550C590DF2EC141B5706994F40ED289535DE02DF352C7244A29C029AF80AC5B
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-24_contrast-black.pngimage
MD5:59D4350F3FEC2C960770B0FC2EAD8C1B
SHA256:5F05F760B6EC69FF2963F7D41E0EF643AC8D442DB7AAD850AD6EBE027E8D384A
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-150_contrast-black.pngimage
MD5:87A87E7D81065D629853AD7EE112FAE7
SHA256:E1B981FAB35168D81E60AFB2A9EFDE86964E306EF7E822DE7FEE58C84E220498
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-256_altform-unplated_contrast-black.pngimage
MD5:4285F0893A8B3695EE23FD1D7AD78CBF
SHA256:09A7FE5B8C0DCD7C9C217C289E9F5A4C5465AA281BD9C2A25A57396E57D2C3FF
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-256_contrast-black.pngimage
MD5:4285F0893A8B3695EE23FD1D7AD78CBF
SHA256:09A7FE5B8C0DCD7C9C217C289E9F5A4C5465AA281BD9C2A25A57396E57D2C3FF
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.scale-125_contrast-black.pngimage
MD5:67664033F26E9EB2AC34B9A4F43E0ABB
SHA256:26D2A12208E42EB256EC0C503AEAE789117AD91AA7256B35977C8D3C4A629DA6
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-20_contrast-black.pngimage
MD5:C89CC9671D7178FD0693458B89972A19
SHA256:EF285313ED240A36798F2BD31042523083EAF3ED54BEE0D48F3C36AC0EE3B93F
1060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Microsoft.HEVCVideoExtension_1.0.50361.0_x64__8wekyb3d8bbwe.Appx\Assets\contrast-black\HEVCCodecAppList.targetsize-24_altform-unplated_contrast-black.pngimage
MD5:59D4350F3FEC2C960770B0FC2EAD8C1B
SHA256:5F05F760B6EC69FF2963F7D41E0EF643AC8D442DB7AAD850AD6EBE027E8D384A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
vlc.exe
main libvlc debug: VLC media player - 3.0.11 Vetinari
vlc.exe
main libvlc debug: Copyright � 1996-2020 the VideoLAN team
vlc.exe
main libvlc debug: revision 3.0.11-0-gdc0c5ced72
vlc.exe
main libvlc debug: configured with ../extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-dvdread' '--enable-shout' '--enable-goom' '--enable-caca' '--enable-qt' '--enable-skins2' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' 'host_alias=i686-w64-mingw32' 'PKG_CONFIG_LIBDIR=/home/jenkins/workspace/vlc-release/windows/vlc-release-win32-x86/contrib/i686-w64-mingw32/lib/pkgconfig'
vlc.exe
main libvlc debug: using multimedia timers as clock source
vlc.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc.exe
main libvlc debug: searching plug-in modules
vlc.exe
main libvlc debug: loading plugins cache file C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
vlc.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc.exe
main libvlc debug: plug-ins loaded: 494 modules