File name:

SFVipPlayer.exe

Full analysis: https://app.any.run/tasks/92ed4e4b-82b4-4fa1-ade7-7c2c901b689f
Verdict: No threats detected
Analysis date: December 09, 2024, 11:05:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

8B1206F88226F88497E505C718BC0660

SHA1:

A4D4129036776F6D45A85290A01C1510AE21BD59

SHA256:

2725953E50C778C4A275EADE8A51D1D7C2F8C58F41417484A91C9D77B8D33B01

SSDEEP:

6144:KIXQtZWmPtalRexU5PeCzWpYKZlDAQlhGNoG4fABn3onkpZqjZhWYlNln2p5:KIXyOAU5mCzWTXDANb4f43okcrrw5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • SFVipPlayer.exe (PID: 3364)
  • INFO

    • Reads the computer name

      • SFVipPlayer.exe (PID: 3364)
    • Checks supported languages

      • SFVipPlayer.exe (PID: 3364)
    • Checks proxy server information

      • WerFault.exe (PID: 6188)
    • Reads the machine GUID from the registry

      • SFVipPlayer.exe (PID: 3364)
    • Reads the software policy settings

      • WerFault.exe (PID: 6188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2059:06:14 09:55:39+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 817664
InitializedDataSize: 79360
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.7.88
ProductVersionNumber: 1.2.7.88
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: SFVipPlayer
FileVersion: 1.2.7.88
InternalName: SFVipPlayer.exe
LegalCopyright: Copyright © salezli 2024
LegalTrademarks: -
OriginalFileName: SFVipPlayer.exe
ProductName: SFVipPlayer
ProductVersion: 1.2.7.88
AssemblyVersion: 1.2.7.88
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sfvipplayer.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
3364"C:\Users\admin\AppData\Local\Temp\SFVipPlayer.exe" C:\Users\admin\AppData\Local\Temp\SFVipPlayer.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SFVipPlayer
Exit code:
3762504530
Version:
1.2.7.88
Modules
Images
c:\users\admin\appdata\local\temp\sfvipplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6188C:\WINDOWS\system32\WerFault.exe -u -p 3364 -s 1000C:\Windows\System32\WerFault.exe
SFVipPlayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
3 782
Read events
3 782
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6188WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SFVipPlayer.exe_f8ba63499db4ca248925f87fc8b62b841378c44_ca20608f_a758ea41-44e1-43a1-9bcc-acb5cb67915f\Report.wer
MD5:
SHA256:
6188WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\SFVipPlayer.exe.3364.dmp
MD5:
SHA256:
6188WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER66DB.tmp.dmpbinary
MD5:06AEAE1A6B8A724E2D1160E53CBBD60D
SHA256:A1B50B111854F776EC00C95997A66402B0DFFCCFB21D37D661FB181253E0DF08
6188WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER69CB.tmp.xmlxml
MD5:4EDD96FD87494F542DDBEC2A368E3B08
SHA256:5AAF66134BAD51EEF9A40E0F0AA68F58E897E23A517192410B8A38FBD08AC8F2
6188WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER699B.tmp.WERInternalMetadata.xmlxml
MD5:A1A0B2B1CD4788C8E58293B5EC930A47
SHA256:D2D9343AD4CE72735C5BFF802EFABA4EDCF42CEA2D563BC6359B0FA3BF75CE56
6188WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:D62FB0BE4B0E872AB513829E92FE0C35
SHA256:25DFA9A52D83369F7EBEC7D8E64D6078DB7BBE34494D86D71C8E9AED45C07C15
6188WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:F0CF5B1794ECA7CD73F9C020DAAB8EF2
SHA256:2AF00EDCE7EF3266897E52DC81E8DE3B7A079028C0F1F96EAFF9E38AD342F617
6188WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:F6F53CD09A41E968C363419B279D3112
SHA256:6D2BB01CC7A9BADE2113B219CAC1BDA86B2733196B7E1BD0C807CE1E396B1892
6188WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:129A5AE13F65B4F118156A3EDD727335
SHA256:A87AC1A166539CF4F95682230E32B1FF25652796FB57915BD438C0AC302CDCBE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6188
WerFault.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6188
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7008
SIHClient.exe
GET
200
2.18.97.123:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7008
SIHClient.exe
GET
200
2.18.97.123:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.209.177:443
Akamai International B.V.
GB
unknown
4
System
192.168.100.255:138
whitelisted
6188
WerFault.exe
20.189.173.21:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6188
WerFault.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6188
WerFault.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5972
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.18.97.123
whitelisted
google.com
  • 142.250.74.206
whitelisted
watson.events.data.microsoft.com
  • 20.189.173.21
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 2.19.86.20
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info