File name: | SmartPlayer.exe |
Full analysis: | https://app.any.run/tasks/7d9ecc59-0e68-4c23-a387-3e58292e523e |
Verdict: | Malicious activity |
Analysis date: | February 26, 2024, 00:39:00 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 23472F2189B3DDE069FFB527A84E3668 |
SHA1: | 51CE355914EBEB90892437832862140A0C991F1F |
SHA256: | 1C03B7ADAAF5C03A970AB75BA103FEB8231920DDEF9736950D390BF0C6FCBC20 |
SSDEEP: | 98304:ONnlJTBD7l2oQVbqPgR1RkJP5baXpTEr6/txxGvlRNJ6D/O2lHBSEMq8ZXkTWRSi:qHXh71n |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2018:12:18 08:04:06+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 8 |
CodeSize: | 61440 |
InitializedDataSize: | 2240512 |
UninitializedDataSize: | - |
EntryPoint: | 0x7478 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2160 | "C:\Users\admin\AppData\Local\Temp\SmartPlayer.exe" | C:\Users\admin\AppData\Local\Temp\SmartPlayer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
3348 | "C:\Users\admin\AppData\Roaming\SPTemp\SmartPlayer.exe" C:\Users\admin\AppData\Local\Temp | C:\Users\admin\AppData\Roaming\SPTemp\SmartPlayer.exe | — | SmartPlayer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Smart Player Exit code: 0 Version: Modules
|
(PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
Operation: | write | Name: | Name |
Value: SmartPlayer.exe | |||
(PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
Operation: | write | Name: | Name |
Value: SmartPlayer.exe | |||
(PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
Operation: | write | Name: | ID |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_curtime.png | image | |
MD5:0B74792D1EAF9116636C059C92124666 | SHA256:F4BE9045D011310572380579AAF184D3572664EA0B86E0A1D096E5D694CCCDD3 | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\AboutPic.png | image | |
MD5:48FAACCDB27CE68C35F480F97C4ABB2D | SHA256:39D002EF4E338CB16E6E65AE7FB5342D25854D3189E4714FF8ED4ADAAA2D6B6D | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_filelisttitle.png | image | |
MD5:9A742979B291FC7E4BEAB9319B5C1462 | SHA256:024D759D6ADC6BE3467747F56D68DAE765C5E8BCCB96319CAE5EE85406354FDE | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_date_nor.png | image | |
MD5:35446196B68FA4CEB3BB93794EC7C93B | SHA256:62158A7421C90C7E492F5A863F354CD2D86FD7A3BD2950BE825E33592F9E7FDB | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_tabbar.png | image | |
MD5:2B9C8C7DF76186D5CAE41C6F739AD9BF | SHA256:66756117995117E29ABFFFAC6E3704EAA25408F3413D663186546022C468F33E | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_edit.png | image | |
MD5:88E74B102D7886A3E49AA1975C252188 | SHA256:A985F2A067947A621C1FE82FC37077A56D9121C44643B3D8B99C2622EE473A0A | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_date_down.png | image | |
MD5:30AB95522E715182C76E9B17326C00CF | SHA256:426326243A3E7486E2910FD12C6144D12C5CC1A8A98798C5C0F89893A6EC4658 | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_timeline.png | image | |
MD5:31C1439C2CCAE7C83F5727CFFFF465BA | SHA256:B5EB2DA772F3C87CCCB3FEC31EC33AA726B3252CF543C32098608EAB66336CE8 | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_playbar.png | image | |
MD5:3B0F1C454F6D9CF3690B4C0E4365D48A | SHA256:C3A2FBAD98AE9BDCE59A031A0CAE6A2C19966823D1E59F9AC4881CBF462E02D9 | |||
2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_popdlg.png | image | |
MD5:1566E97C5E23B0B1772F0EBC986DE874 | SHA256:27E2069BF301B91E77C75B7325D97CBA02AA3A818A1FC06D66FDBEB8615A00B0 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Process | Message |
---|---|
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | start 7zUnzip main! |
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | Extract7zZip succeed! |
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | ShellExecute succeed! |