| File name: | setup_x86.exe |
| Full analysis: | https://app.any.run/tasks/bd30620d-7c3c-41a7-a10f-0b45d5143de1 |
| Verdict: | Malicious activity |
| Analysis date: | May 20, 2024, 10:42:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | D41F8844A99091CC13FBD552B976F6E2 |
| SHA1: | F010439B05AA2F82CD24E35FEA6FF0009ADD1C2C |
| SHA256: | 1DC1C69CFB49A69475CB72B9A927BEF0D770A439189394EAB8EADD4480B4494E |
| SSDEEP: | 6144:9gmqYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY+JZzZ8NVerj:OZ8NVerXzhurXrHZwqpt1cV |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:12:11 21:50:45+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x32bf |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1056 | "C:\Users\admin\AppData\Local\VLC Plus Player Downloader\vlc-plus-3.0.20-win32.exe" | C:\Users\admin\AppData\Local\VLC Plus Player Downloader\vlc-plus-3.0.20-win32.exe | setup_x86.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1248 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3568 --field-trial-handle=1288,i,12979045587340025431,7335686338688766483,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1284 | "C:\Users\admin\AppData\Local\Temp\nsg365B.tmp\ns36AA.tmp" "schtasks.exe" /create /tn "VLC Plus Player Updater" /tr "'C:\Users\admin\AppData\Local\VLC Plus Player Updater\Updater.exe'" /rl HIGHEST /sc onlogon /f | C:\Users\admin\AppData\Local\Temp\nsg365B.tmp\ns36AA.tmp | inst-updater.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1408 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1316 --field-trial-handle=1288,i,12979045587340025431,7335686338688766483,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1552 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6e52f598,0x6e52f5a8,0x6e52f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1592 | "C:\Users\admin\AppData\Local\Temp\VLC Plus Player\inst-updater.exe" /S | C:\Users\admin\AppData\Local\Temp\VLC Plus Player\inst-updater.exe | vlc-plus-3.0.20-win32.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1816 | "C:\Users\admin\AppData\Local\Temp\VLC Plus Player\vlc-3.0.20-win32.exe" | C:\Users\admin\AppData\Local\Temp\VLC Plus Player\vlc-3.0.20-win32.exe | vlc-plus-3.0.20-win32.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 1932 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.vlc.de/ok/?id=_updater. | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | vlc-plus-3.0.20-win32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2024 | "C:\Users\admin\AppData\Local\VLC Plus Player Downloader\vlc-plus-3.0.20-win32.exe" | C:\Users\admin\AppData\Local\VLC Plus Player Downloader\vlc-plus-3.0.20-win32.exe | — | setup_x86.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2060 | "schtasks.exe" /create /tn "VLC Plus Player Updater" /tr "'C:\Users\admin\AppData\Local\VLC Plus Player Updater\Updater.exe'" /rl HIGHEST /sc onlogon /f | C:\Windows\System32\schtasks.exe | — | ns36AA.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3968) setup_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\vlc-plus-3.0.20-win32[1].exe | — | |
MD5:— | SHA256:— | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\VLC Plus Player Downloader\vlc-plus-3.0.20-win32.exe | — | |
MD5:— | SHA256:— | |||
| 1056 | vlc-plus-3.0.20-win32.exe | C:\Users\admin\AppData\Local\Temp\VLC Plus Player\vlc-3.0.20-win32.exe | — | |
MD5:— | SHA256:— | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\Temp\nsx3DA9.tmp\System.dll | executable | |
MD5:3F176D1EE13B0D7D6BD92E1C7A0B9BAE | SHA256:FA4AB1D6F79FD677433A31ADA7806373A789D34328DA46CCB0449BBF347BD73E | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\Temp\nsx3DA9.tmp\INetC.dll | executable | |
MD5:2B342079303895C50AF8040A91F30F71 | SHA256:2D5D89025911E2E273F90F393624BE4819641DBEE1606DE792362E442E54612F | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\Temp\nsx3DA9.tmp\nsisdl.dll | executable | |
MD5:41F557E065B405F94D0ECE8B5727233B | SHA256:9DE492995D2180635AA3194B88CE6DD94E0C2B001AF5952A73D4A84FBC32B6AB | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\Local\VLC Plus Player Downloader\setup_x86.txt | text | |
MD5:6FE800C6809034D0C6A1CD7F9C70CD26 | SHA256:F92159C1E9D3FA2B149CADD3EA2E3891083CDC82690506575EDA1F6F725EDF8A | |||
| 1552 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma~RF123d11.TMP | binary | |
MD5:886E82F2CA62ECCCE64601B30592078A | SHA256:E5E13D53601100FF3D6BB71514CBCCC4C73FE9B7EF5E930100E644187B42948E | |||
| 1932 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | — | |
MD5:— | SHA256:— | |||
| 3968 | setup_x86.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\68FAF71AF355126BCA00CE2E73CC7374_123B8BA19C64CE9A8B3EAC32000FAF3E | binary | |
MD5:DD47D63BD2E539C8C03D90EFDEC4FACF | SHA256:2AEC9E10DDC9E8EEC58DD4F8149B66F5B2C9833E8ECAB8E9F0B57E0FC6E7C8CD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3968 | setup_x86.exe | GET | 200 | 87.230.43.108:80 | http://www.vlc.de/install/setup_x86.txt | unknown | — | — | unknown |
3968 | setup_x86.exe | GET | 304 | 95.101.54.128:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?85d1e00274ad22f4 | unknown | — | — | unknown |
3968 | setup_x86.exe | GET | 200 | 95.101.111.144:80 | http://subca.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCECbd0itGycRNWmlNOYB%2Bcq0%3D | unknown | — | — | unknown |
1088 | svchost.exe | GET | 304 | 2.19.126.137:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e523dd86aac30a8d | unknown | — | — | unknown |
3968 | setup_x86.exe | GET | 200 | 95.101.111.168:80 | http://dvcasha2.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNcCPjJ499lHmfPUvPsRjzr1YchwQU5TGtvzoRlvSDvFA81LeQm5Du3iUCEB%2BLNUl5VKkVjFCfJqJ03PM%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
3968 | setup_x86.exe | 87.230.43.108:80 | www.vlc.de | Host Europe GmbH | DE | unknown |
3968 | setup_x86.exe | 87.230.43.108:443 | www.vlc.de | Host Europe GmbH | DE | unknown |
3968 | setup_x86.exe | 95.101.54.128:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3968 | setup_x86.exe | 95.101.111.144:80 | subca.ocsp-certum.com | TELXIUS TELXIUS Cable | NL | unknown |
3968 | setup_x86.exe | 95.101.111.168:80 | subca.ocsp-certum.com | TELXIUS TELXIUS Cable | NL | unknown |
1088 | svchost.exe | 2.19.126.137:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2612 | msedge.exe | 87.230.43.108:443 | www.vlc.de | Host Europe GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.vlc.de |
| unknown |
download.vlc.de |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
subca.ocsp-certum.com |
| whitelisted |
dvcasha2.ocsp-certum.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.counter.info |
| unknown |
www.bing.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |