| File name: | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe |
| Full analysis: | https://app.any.run/tasks/253ffb76-386e-4581-9a32-da1d8ae176b9 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | February 06, 2022, 16:18:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | C32B97185C230FC6838F628D5D47F1F7 |
| SHA1: | 7EAAAE62EBE58F3AB2CD12A4BE84FC40554CC08E |
| SHA256: | 2DD27F73835D10EDA68972EB15F2F3950CEB770D822688BD2E7C07B2DA61D047 |
| SSDEEP: | 12288:HiM418tl76F3eRKRDPNKT1zH3CRAmjlPtaR1sDfOQSvJqFZ6Yo5wFLDnC:HXTXyuMRDu173CTPG1szLSvJw15DC |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| ProductVersion: | 1.9.76 |
|---|---|
| ProductName: | Televzr Light |
| LegalCopyright: | Copyright © 2021 ITPRODUCTDEV LTD |
| FileVersion: | 1.9.76 |
| FileDescription: | Televzr Light Desktop |
| CompanyName: | ITPRODUCTDEV LTD |
| CharacterSet: | Windows, Latin1 |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0000 |
| ProductVersionNumber: | 1.9.76.0 |
| FileVersionNumber: | 1.9.76.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 5.1 |
| ImageVersion: | 6 |
| OSVersion: | 5.1 |
| EntryPoint: | 0x39ed |
| UninitializedDataSize: | 16384 |
| InitializedDataSize: | 483840 |
| CodeSize: | 30208 |
| LinkerVersion: | 14 |
| PEType: | PE32 |
| TimeStamp: | 2020:02:12 17:15:17+01:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 12-Feb-2020 16:15:17 |
| Detected languages: |
|
| CompanyName: | ITPRODUCTDEV LTD |
| FileDescription: | Televzr Light Desktop |
| FileVersion: | 1.9.76 |
| LegalCopyright: | Copyright © 2021 ITPRODUCTDEV LTD |
| ProductName: | Televzr Light |
| ProductVersion: | 1.9.76 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 12-Feb-2020 16:15:17 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000074A8 | 0x00007600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.43313 |
.rdata | 0x00009000 | 0x00002B6A | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.5076 |
.data | 0x0000C000 | 0x00072318 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.99541 |
.ndata | 0x0007F000 | 0x00164000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x001E3000 | 0x00021860 | 0x00021A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84069 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.30199 | 1070 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 7.9836 | 36993 | UNKNOWN | English - United States | RT_ICON |
3 | 6.19493 | 16936 | UNKNOWN | English - United States | RT_ICON |
4 | 6.18833 | 4264 | UNKNOWN | English - United States | RT_ICON |
5 | 6.15312 | 1128 | UNKNOWN | English - United States | RT_ICON |
102 | 2.71813 | 180 | UNKNOWN | English - United States | RT_DIALOG |
103 | 2.67841 | 76 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.73893 | 514 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.91148 | 248 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.89887 | 238 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=none --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --standard-schemes=app --secure-schemes=app --bypasscsp-schemes --cors-schemes=fs --fetch-schemes=app,fs --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=1268 /prefetch:8 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 3221226091 Version: 1.9.76 Modules
| |||||||||||||||
| 588 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=audio --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --standard-schemes=app --secure-schemes=app --bypasscsp-schemes --cors-schemes=fs --fetch-schemes=app,fs --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=992 /prefetch:8 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 1073807364 Version: 1.9.76 Modules
| |||||||||||||||
| 764 | C:\Windows\system32\reg.exe ADD HKCU\Software\Classes\.mkv\OpenWithProgids /f | C:\Windows\system32\reg.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 804 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=gpu-process --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --gpu-preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHAAAADQAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=2356 /prefetch:2 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 3221226091 Version: 1.9.76 Modules
| |||||||||||||||
| 1024 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=none --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --standard-schemes=app --secure-schemes=app --bypasscsp-schemes --cors-schemes=fs --fetch-schemes=app,fs --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=1248 /prefetch:8 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | Televzr Light.exe | ||||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 1073807364 Version: 1.9.76 Modules
| |||||||||||||||
| 1144 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --lang=en-US --service-sandbox-type=none --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --standard-schemes=app --secure-schemes=app --bypasscsp-schemes --cors-schemes=fs --fetch-schemes=app,fs --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=2564 /prefetch:8 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 3221226091 Version: 1.9.76 Modules
| |||||||||||||||
| 1332 | C:\Windows\system32\reg.exe ADD HKCU\Software\Classes\.mp4\OpenWithProgids /v televzr /t REG_SZ /d "" /f | C:\Windows\system32\reg.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1440 | "C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\vcredist_x86.exe" /install /quiet /norestart | C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\vcredist_x86.exe | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2010 x86 Redistributable Setup Exit code: 3010 Version: 10.0.40219.325 Modules
| |||||||||||||||
| 1488 | "C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\vcredist_x86.exe" /install /quiet /norestart | C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\vcredist_x86.exe | — | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Visual C++ 2010 x86 Redistributable Setup Exit code: 3221226540 Version: 10.0.40219.325 Modules
| |||||||||||||||
| 1748 | "C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe" --type=gpu-process --field-trial-handle=1088,9262706666364521985,11957057323668717937,131072 --disable-features=CookiesWithoutSameSiteMustBeSecure,HardwareMediaKeyHandling,SameSiteByDefaultCookies,SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --no-sandbox --user-data-dir="C:\Users\admin\AppData\Roaming\Televzr Light" --gpu-preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHAAAADQAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --mojo-platform-channel-handle=1224 /prefetch:2 | C:\Users\admin\AppData\Local\televzr_light\Televzr Light.exe | — | Televzr Light.exe | |||||||||||
User: admin Company: ITPRODUCTDEV LTD Integrity Level: MEDIUM Description: Televzr Light Exit code: 3221226091 Version: 1.9.76 Modules
| |||||||||||||||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\5a86d928-e527-5a16-9156-f025bf9f7e0e |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Local\televzr_light | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Televzr Light |
| Operation: | write | Name: | vid |
Value: 693 | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000003B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3344) VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\televzr_light-1.9.76-ia32.nsis[1].7z | — | |
MD5:— | SHA256:— | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\package.7z | — | |
MD5:— | SHA256:— | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\icudtl.dat | — | |
MD5:— | SHA256:— | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\LICENSES.chromium.html | — | |
MD5:— | SHA256:— | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\chrome_100_percent.pak | pgc | |
MD5:109EE8FFD715C63E3E2248C2AD5CA559 | SHA256:B581F176C6BDBF8A152947FB37AF9C0E6D7651616408CB7312B336C37A704580 | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\locales\ca.pak | pgc | |
MD5:E285AD8235B1EE37782EC312A1F26568 | SHA256:39702855F1542560AA20A36F243A87C29488AC9F16C702CC775D8A451720B1C7 | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\Temp\nsd3928.tmp\StdUtils.dll | executable | |
MD5:C6A6E03F77C313B267498515488C5740 | SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\locales\bg.pak | pgc | |
MD5:9C5A545DA2150EAE00A0240097FD423F | SHA256:A47C73AE35583C284941793A1ED8B80B3BC8A3E2AC1A049354A3B1C408232B00 | |||
| 3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | C:\Users\admin\AppData\Local\televzr_light\uninstallerIcon.ico | image | |
MD5:8F2EF8A0DE5E45B055AAF8F063E86E3D | SHA256:43C553C23DE2A9014E4C106240C9B9D5459340E25EDF57F4F418A769970BF53A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | POST | — | 216.58.212.174:80 | http://www.google-analytics.com/collect | US | — | — | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | GET | 302 | 104.26.7.209:80 | http://desktop.televzr.com/download/updater/latest/televzr_light.nsis.7z | US | text | 84 b | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | GET | 200 | 104.26.13.53:80 | http://cdn-televzr.com/light/televzr_light-1.9.76-ia32.nsis.7z | US | compressed | 70.0 Mb | suspicious |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | GET | 200 | 104.26.13.53:80 | http://cdn-televzr.com/vcredist_x86.exe | US | executable | 8.57 Mb | suspicious |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | POST | 200 | 216.58.212.174:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
1024 | Televzr Light.exe | GET | 200 | 172.67.71.131:80 | http://desktop.televzr.com/api/geo | US | text | 2 b | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | POST | 200 | 216.58.212.174:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | GET | 200 | 104.26.13.53:80 | http://cdn-televzr.com/vcredist_x86.exe.sha512 | US | text | 128 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | 216.58.212.174:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | 104.26.7.209:80 | desktop.televzr.com | Cloudflare Inc | US | unknown |
1024 | Televzr Light.exe | 172.67.71.131:80 | desktop.televzr.com | — | US | unknown |
1024 | Televzr Light.exe | 142.250.185.110:443 | redirector.gvt1.com | Google Inc. | US | whitelisted |
3344 | VideoDownloader-[1923487830.1644164269,693,yt-Uw23PG3XYu4,,].exe | 104.26.13.53:80 | cdn-televzr.com | Cloudflare Inc | US | shared |
1024 | Televzr Light.exe | 216.58.212.174:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
1024 | Televzr Light.exe | 194.9.25.80:443 | r5---sn-5uh5o-f5fs.gvt1.com | ATM S.A. | PL | whitelisted |
1024 | Televzr Light.exe | 104.26.0.178:443 | sf-helper.com | Cloudflare Inc | US | suspicious |
1024 | Televzr Light.exe | 142.250.184.206:443 | m.youtube.com | Google Inc. | US | whitelisted |
1024 | Televzr Light.exe | 142.250.74.206:443 | www.youtube.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google-analytics.com |
| whitelisted |
desktop.televzr.com |
| whitelisted |
cdn-televzr.com |
| suspicious |
redirector.gvt1.com |
| whitelisted |
r5---sn-5uh5o-f5fs.gvt1.com |
| whitelisted |
sf-helper.com |
| whitelisted |
m.youtube.com |
| whitelisted |
www.youtube.com |
| whitelisted |
www.youtube-nocookie.com |
| whitelisted |
rr7---sn-5uh5o-f5f6.googlevideo.com |
| whitelisted |
Process | Message |
|---|---|
msiexec.exe | Failed to release Service
|
Setup.exe | The requested operation is successful. Changes will not be effective until the system is rebooted.
|