File name:

Badanamu Cadets Theme Song l Nursery Rhymes & Kids Songs.mp4

Full analysis: https://app.any.run/tasks/0e3faf72-977d-42b4-8d8a-11827058ad80
Verdict: No threats detected
Analysis date: December 21, 2019, 00:42:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: video/mp4
File info: ISO Media, MP4 Base Media v1 [IS0 14496-12:2003]
MD5:

97F1332FCF58F46F6567740972C0667E

SHA1:

DAA4B5CAA195634FAA6A815C7B1B48B271F0FFAB

SHA256:

587244A6D415EF0CC8CE1DE417C2FF244452A8C8F6BE88CCB547ED4892200F5D

SSDEEP:

98304:ez4DwSBROErCe2lCOxXk7t5Lokfw29Of9fucC4EGAWmkd9FmfePMl+/k/2Iph1LM:vxjOD1JkR5HcCIAWmH2PMlD/Ph1+g8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • vlc.exe (PID: 2748)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.m4v | MPEG-4 Video (54.8)
.3g2 | 3GPP2 multimedia audio/video (38)
.mov | QuickTime Movie (3.9)
.mp4 | Generic MP4 container (2.3)
.abr | Adobe PhotoShop Brush (0.7)

EXIF

QuickTime

MajorBrand: MP4 Base Media v1 [IS0 14496-12:2003]
MinorVersion: 0.2.0
CompatibleBrands:
  • isom
  • iso2
  • avc1
  • mp41
MovieDataSize: 6358878
MovieDataOffset: 48
MovieHeaderVersion: -
CreateDate: 2018:06:21 05:06:35
ModifyDate: 2018:06:21 05:06:35
TimeScale: 1000
Duration: 0:00:49
PreferredRate: 1
PreferredVolume: 100.00%
PreviewTime: 0 s
PreviewDuration: 0 s
PosterTime: 0 s
SelectionTime: 0 s
SelectionDuration: 0 s
CurrentTime: 0 s
NextTrackID: 3
TrackHeaderVersion: -
TrackCreateDate: 2018:06:21 05:06:35
TrackModifyDate: 2018:06:21 05:06:35
TrackID: 1
TrackDuration: 0:00:49
TrackLayer: -
TrackVolume: 0.00%
ImageWidth: 854
ImageHeight: 480
CompressorID: avc1
SourceImageWidth: 854
SourceImageHeight: 480
XResolution: 72
YResolution: 72
BitDepth: 24
VideoFrameRate: 24
GraphicsMode: srcCopy
OpColor: 0 0 0
MatrixStructure: 1 0 0 0 1 0 0 0 1
MediaHeaderVersion: -
MediaCreateDate: 2018:06:21 04:58:48
MediaModifyDate: 2018:06:21 04:58:48
MediaTimeScale: 44100
MediaDuration: 0:00:49
MediaLanguageCode: eng
HandlerType: Audio Track
HandlerDescription: SoundHandler
AudioFormat: mp4a
AudioChannels: 2
AudioBitsPerSample: 16
AudioSampleRate: 44100
Balance: -

Composite

AvgBitrate: 1.03 Mbps
ImageSize: 854x480
Megapixels: 0.41
Rotation: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc.exe

Process information

PID
CMD
Path
Indicators
Parent process
2748"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\AppData\Local\Temp\Badanamu Cadets Theme Song l Nursery Rhymes & Kids Songs.mp4"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
0
Version:
2.2.6
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
362
Read events
361
Write events
1
Delete events
0

Modification events

(PID) Process:(2748) vlc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
vlc.exe
Executable files
0
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB512.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB60D.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB60E.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB60F.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB610.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB611.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB612.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB613.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB614.tmp
MD5:
SHA256:
2748vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB615.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
vlc.exe
core libvlc: one instance mode ENABLED
vlc.exe
core libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
vlc.exe
direct3d vout display error: Could not read adapter capabilities. (hr=0x8876086A)
vlc.exe
direct3d vout display error: Direct3D could not be initialized