URL: | get.videolan.org/vlc/3.0.20/win32/vlc-3.0.20-win32.exe |
Full analysis: | https://app.any.run/tasks/7f9924bb-e432-4421-b136-bb43cd592a7e |
Verdict: | Malicious activity |
Analysis date: | April 10, 2024, 05:55:03 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MD5: | 284E3656F50EA643672D885B39B23AC7 |
SHA1: | 5E51A744D82BEED8124FB39B9C089C877787526E |
SHA256: | 17462F307B4D3E99E1B2D3D4A436DF89C433D30746851B83EF1D42A75720AACE |
SSDEEP: | 3:/SELoC0UL1MLQIIrVQ1An:/SEUorIIrVgA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
316 | "C:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe" C:\Program Files\VideoLAN\VLC\plugins | C:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe | nsCFEC.tmp | ||||||||||||
User: admin Company: VideoLAN Integrity Level: HIGH Description: VLC media player Exit code: 0 Version: 3.0.20 Modules
| |||||||||||||||
1692 | "C:\Program Files\Internet Explorer\iexplore.exe" "get.videolan.org/vlc/3.0.20/win32/vlc-3.0.20-win32.exe" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
2384 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\vlc-3.0.20-win32.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\vlc-3.0.20-win32.exe | iexplore.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
2620 | "C:\Users\admin\AppData\Local\Temp\nscD176.tmp\nsCFEC.tmp" "C:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe" C:\Program Files\VideoLAN\VLC\plugins | C:\Users\admin\AppData\Local\Temp\nscD176.tmp\nsCFEC.tmp | — | vlc-3.0.20-win32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2968 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\vlc-3.0.20-win32.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\vlc-3.0.20-win32.exe | — | iexplore.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
3960 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1692 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31099659 | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31099659 | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
(PID) Process: | (1692) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\vlc-3.0.20-win32[1].htm | html | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ipb[1].png | image | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\logoGrey[1].png | image | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\style.min[1].css | text | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\logoOrange[1].png | image | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\bootstrap.min[1].js | text | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\bootstrap.min[1].css | text | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.min[1].js | text | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\download[1].css | text | |
MD5:— | SHA256:— | |||
3960 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\facebook[1].svg | image | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3960 | iexplore.exe | GET | 200 | 213.36.253.2:80 | http://images.videolan.org/js/bootstrap.min.js | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 213.36.253.2:80 | http://images.videolan.org/js/jquery.min.js | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 213.36.253.2:80 | http://images.videolan.org/images/icons/social/facebook.svg | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 213.36.253.2:80 | http://images.videolan.org/images/icons/social/twitter.svg | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 304 | 23.32.238.211:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?75da8a5a03433697 | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 304 | 23.32.238.219:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ea8f83a797d8d650 | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 304 | 23.32.238.232:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76c0798e321302df | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 195.154.241.219:80 | http://get.videolan.org/vlc/3.0.20/win32/vlc-3.0.20-win32.exe | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 195.154.241.219:80 | http://get.videolan.org/download.css | unknown | — | — | unknown |
3960 | iexplore.exe | GET | 200 | 172.217.16.195:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3960 | iexplore.exe | 195.154.241.219:80 | get.videolan.org | Online S.a.s. | FR | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3960 | iexplore.exe | 213.36.253.2:80 | images.videolan.org | Free SAS | FR | unknown |
3960 | iexplore.exe | 142.250.186.110:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
3960 | iexplore.exe | 18.173.206.159:443 | do69ll745l27z.cloudfront.net | — | US | unknown |
3960 | iexplore.exe | 23.32.238.232:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3960 | iexplore.exe | 23.32.238.211:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
get.videolan.org |
| unknown |
images.videolan.org |
| whitelisted |
www.google-analytics.com |
| whitelisted |
do69ll745l27z.cloudfront.net |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
www.googletagmanager.com |
| whitelisted |
Process | Message |
---|---|
vlc-cache-gen.exe | main libvlc debug: ignoring plugins cache file
|
vlc-cache-gen.exe | main libvlc debug: Copyright © 1996-2023 the VideoLAN team
|
vlc-cache-gen.exe | main libvlc debug: using multimedia timers as clock source
|
vlc-cache-gen.exe | main libvlc debug: configured with /builds/videolan/vlc/extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-shout' '--enable-goom' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=i686-w64-mingw32' '--with-contrib=../contrib/i686-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' '--enable-qt' '--enable-skins2' '--enable-dvdread' '--enable-caca' 'host_alias=i686-w64-mingw32' 'CFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'CXXFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'PKG_CONFIG=pkg-config' 'PKG_CONFIG_LIBDIR=/usr/i686-w64-mingw32/lib/pkgconfig:/usr/lib/i686-w64-mingw32/pkgconfig'
|
vlc-cache-gen.exe | main libvlc debug: min period: 1 ms, max period: 1000000 ms
|
vlc-cache-gen.exe | main libvlc debug: searching plug-in modules
|
vlc-cache-gen.exe | main libvlc debug: VLC media player - 3.0.20 Vetinari
|
vlc-cache-gen.exe | main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
|
vlc-cache-gen.exe | main libvlc debug: revision 3.0.20-0-g6f0d0ab126
|
vlc-cache-gen.exe | main libvlc debug: saving plugins cache C:\Program Files\VideoLAN\VLC\plugins\plugins.dat
|