File name:

VLC media player (64 Bit) - CHIP Installer _MmGVv.exe

Full analysis: https://app.any.run/tasks/a0accde7-0122-4afc-a29e-599bfbffed5e
Verdict: Malicious activity
Analysis date: May 28, 2025, 17:14:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 11 sections
MD5:

F5980F17F44DA870072C5CE396EB01BF

SHA1:

22CE208ACB16875CDD9D42A794557A56068220C2

SHA256:

2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B

SSDEEP:

49152:xhx7dxx15qe01xtgx41J/StY/yuiYWLmgpaRZkDuZdTNACtn:JV1JALgvz4ACtn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • There is functionality for taking screenshot (YARA)

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Searches for installed software

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
  • INFO

    • The sample compiled with english language support

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Reads the software policy settings

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Reads the machine GUID from the registry

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Reads the computer name

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Checks supported languages

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Checks proxy server information

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
    • Compiled with Borland Delphi (YARA)

      • VLC media player (64 Bit) - CHIP Installer _MmGVv.exe (PID: 2980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (49.6)
.exe | DOS Executable Generic (49.5)
.vxd | VXD Driver (0.7)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:04:16 09:34:08+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 4237824
InitializedDataSize: 1083392
UninitializedDataSize: -
EntryPoint: 0x3f8020
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 1.0.100.6
ProductVersionNumber: 1.0.100.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: CHIP Digital GmbH
FileDescription: CHIP Secured Installer
FileVersion: 1.0.100.6
LegalCopyright: Copyright 2021 CHIP Digital GmbH
ProductName: LgInstall
ProductVersion: 1.0.100.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc media player (64 bit) - chip installer _mmgvv.exe sppextcomobj.exe no specs slui.exe vlc media player (64 bit) - chip installer _mmgvv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1348"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2980"C:\Users\admin\AppData\Local\Temp\VLC media player (64 Bit) - CHIP Installer _MmGVv.exe" C:\Users\admin\AppData\Local\Temp\VLC media player (64 Bit) - CHIP Installer _MmGVv.exe
explorer.exe
User:
admin
Company:
CHIP Digital GmbH
Integrity Level:
HIGH
Description:
CHIP Secured Installer
Exit code:
0
Version:
1.0.100.6
Modules
Images
c:\users\admin\appdata\local\temp\vlc media player (64 bit) - chip installer _mmgvv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6740C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7640"C:\Users\admin\AppData\Local\Temp\VLC media player (64 Bit) - CHIP Installer _MmGVv.exe" C:\Users\admin\AppData\Local\Temp\VLC media player (64 Bit) - CHIP Installer _MmGVv.exeexplorer.exe
User:
admin
Company:
CHIP Digital GmbH
Integrity Level:
MEDIUM
Description:
CHIP Secured Installer
Exit code:
3221226540
Version:
1.0.100.6
Modules
Images
c:\users\admin\appdata\local\temp\vlc media player (64 bit) - chip installer _mmgvv.exe
c:\windows\system32\ntdll.dll
Total events
7 388
Read events
7 386
Write events
0
Delete events
2

Modification events

(PID) Process:(2980) VLC media player (64 Bit) - CHIP Installer _MmGVv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFavoritesInitialSelection
Value:
(PID) Process:(2980) VLC media player (64 Bit) - CHIP Installer _MmGVv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry
Operation:delete valueName:AddToFeedsInitialSelection
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
38
DNS requests
21
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6544
svchost.exe
40.126.32.133:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
whitelisted
172.211.123.248:443
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
2980
VLC media player (64 Bit) - CHIP Installer _MmGVv.exe
83.125.106.237:443
chip-cluster.de
3U TELECOM GmbH
DE
unknown
3216
svchost.exe
172.211.123.248:443
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
40.126.32.74:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7480
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
nexusrules.officeapps.live.com
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.78
whitelisted
chip-cluster.de
  • 83.125.106.237
unknown
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
  • 2603:1030:c02:2::284
whitelisted
171.39.242.20.in-addr.arpa
unknown
4.8.2.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.0.c.0.0.3.0.1.3.0.6.2.ip6.arpa
unknown

Threats

No threats detected
No debug info