| File name: | SmartPlayer.exe |
| Full analysis: | https://app.any.run/tasks/7d9ecc59-0e68-4c23-a387-3e58292e523e |
| Verdict: | Malicious activity |
| Analysis date: | February 26, 2024, 00:39:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 23472F2189B3DDE069FFB527A84E3668 |
| SHA1: | 51CE355914EBEB90892437832862140A0C991F1F |
| SHA256: | 1C03B7ADAAF5C03A970AB75BA103FEB8231920DDEF9736950D390BF0C6FCBC20 |
| SSDEEP: | 98304:ONnlJTBD7l2oQVbqPgR1RkJP5baXpTEr6/txxGvlRNJ6D/O2lHBSEMq8ZXkTWRSi:qHXh71n |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:18 08:04:06+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 61440 |
| InitializedDataSize: | 2240512 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x7478 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2160 | "C:\Users\admin\AppData\Local\Temp\SmartPlayer.exe" | C:\Users\admin\AppData\Local\Temp\SmartPlayer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3348 | "C:\Users\admin\AppData\Roaming\SPTemp\SmartPlayer.exe" C:\Users\admin\AppData\Local\Temp | C:\Users\admin\AppData\Roaming\SPTemp\SmartPlayer.exe | — | SmartPlayer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Smart Player Exit code: 0 Version: Modules
| |||||||||||||||
| (PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2160) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: SmartPlayer.exe | |||
| (PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: SmartPlayer.exe | |||
| (PID) Process: | (3348) SmartPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication |
| Operation: | write | Name: | ID |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_date_disable.png | image | |
MD5:8BB639351D774DEB41FCDDAFCF802D7B | SHA256:CD4E65B46619528A0F59F62207C694E6985507A1526CD97AD3D94C1B013ED94A | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_filelisttitle.png | image | |
MD5:9A742979B291FC7E4BEAB9319B5C1462 | SHA256:024D759D6ADC6BE3467747F56D68DAE765C5E8BCCB96319CAE5EE85406354FDE | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_display.png | image | |
MD5:99FEDC2DCDE642206D21D920169E64C9 | SHA256:80055BDE9E18FD6AC48E717FF056F19EB44E1CE35762C4834B8521D15716ECBA | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\SmartPlayer.7z | compressed | |
MD5:E3705E4F18A64057FC8C0254DB1EE5C4 | SHA256:AFC7008B5A5A759C0B09B13201CBFF0BF8AF676B83A9D924533E459AE604BF6C | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_popdlg.png | image | |
MD5:1566E97C5E23B0B1772F0EBC986DE874 | SHA256:27E2069BF301B91E77C75B7325D97CBA02AA3A818A1FC06D66FDBEB8615A00B0 | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_customerlayout.png | image | |
MD5:D234DB7FF87DFCD7C81FC9F5C4FB8AF3 | SHA256:91C6BA1882CE592971D066F12C46222394AA448E49CD1381DC5D58CB496E5E22 | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_monitor.png | image | |
MD5:10FC711D6064CC815B8FD8D4F798A015 | SHA256:8B85E5C405B63D5D9DAD299DC1DDBAEF7226114C964233D17765CB32EFB4D23C | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_date_nor.png | image | |
MD5:35446196B68FA4CEB3BB93794EC7C93B | SHA256:62158A7421C90C7E492F5A863F354CD2D86FD7A3BD2950BE825E33592F9E7FDB | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\BackwardDisable.png | image | |
MD5:3E063D76B6A214FA695BAE4D598B91AE | SHA256:91D530BD7BBFC2F5949D7821AF3CC358004EB65CDADFC5100289A5278E593FF1 | |||
| 2160 | SmartPlayer.exe | C:\Users\admin\AppData\Roaming\SPTemp\Skin\bg_date_down.png | image | |
MD5:30AB95522E715182C76E9B17326C00CF | SHA256:426326243A3E7486E2910FD12C6144D12C5CC1A8A98798C5C0F89893A6EC4658 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Process | Message |
|---|---|
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | start 7zUnzip main! |
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | Extract7zZip succeed! |
SmartPlayer.exe |
ERROR: |
SmartPlayer.exe | ShellExecute succeed! |