| File name: | svd3.exe |
| Full analysis: | https://app.any.run/tasks/01211397-8f09-45e8-be5c-18c0aa76c4c3 |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2024, 15:32:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1E4CA550DFD1630376AB5FC8F48761CE |
| SHA1: | 07B9131C01D939BF3C87B63E972F29AF3988F8E4 |
| SHA256: | 64DFE0993237666144CDB1A2C32649DB640E4E7E37DA831E37209C61B6D5ACAD |
| SSDEEP: | 98304:EUJtekPcllBui6GLjx4BV07ERTni2yUxVsUv+lm+DDV9QSp16tc6v8Z8Uspit2bk:saTs0xjKdjexx85r |
| .exe | | | Wise Installer executable (91.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (5.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.2) |
| .exe | | | Win32 Executable (generic) (0.8) |
| .exe | | | Generic Win/DOS Executable (0.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1999:04:08 20:24:47+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 512 |
| InitializedDataSize: | 6192128 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1000 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.1.0 |
| ProductVersionNumber: | 3.0.1.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | SPEEDbit Ltd. |
| FileDescription: | SPEEDbit Video Downloader |
| FileVersion: | 3.0.1 |
| LegalCopyright: | (c) 2008-2010 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | regsvr32 /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\TbCommonUtils.dll" | C:\Windows\System32\regsvr32.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 664 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1632 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 864 | "C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\tbcore3.dll" | C:\Windows\System32\regsvr32.exe | GLBF32A.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | "C:\Windows\System32\regsvr32.exe" /s "C:\Program Files\SPEEDbit Video Downloader\Toolbar\grabber.dll" | C:\Windows\System32\regsvr32.exe | — | GLBF32A.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1636 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1776 | "C:\Users\admin\AppData\Local\Temp\svd3.exe" | C:\Users\admin\AppData\Local\Temp\svd3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1892 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1512 --field-trial-handle=1400,i,14091723454230080401,7558278538881757821,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2088 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1540 --field-trial-handle=1348,i,13650936701873154012,11041917004900968566,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2124 | "C:\Program Files\SPEEDbit Video Downloader\Toolbar\TbHelper2.exe" -RegServer | C:\Program Files\SPEEDbit Video Downloader\Toolbar\TbHelper2.exe | — | regsvr32.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Toolbar Helper Module Exit code: 0 Version: 4.2.0.75 Modules
| |||||||||||||||
| 2232 | "C:\Users\admin\AppData\Local\Temp\GLJF369.tmp" C:\Program Files\SearchPredict\SearchPredict.dll | C:\Users\admin\AppData\Local\Temp\GLJF369.tmp | — | GLBF32A.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | GRRemove |
Value: | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | Enable Browser Extensions |
Value: YES | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\System32\AniGIF.ocx |
Value: 1 | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_CURRENT_USER\Software\SpeedBit\Video Converter |
| Operation: | write | Name: | EXELOCATION |
Value: C:\Program Files\SPEEDbit Video Downloader\Converter.exe | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter |
| Operation: | write | Name: | EXELOCATION |
Value: C:\Program Files\SPEEDbit Video Downloader\Converter.exe | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter |
| Operation: | write | Name: | FFUseConverter |
Value: 1 | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\SpeedBit\Video Converter |
| Operation: | write | Name: | Install |
Value: C:\Program Files\SPEEDbit Video Downloader\ | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_CURRENT_USER\Software\SpeedBit\SearchPredict |
| Operation: | write | Name: | Count |
Value: 01000000000 | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_CURRENT_USER\Software\SpeedBit\SearchPredict |
| Operation: | write | Name: | Aff |
Value: svd_NONE | |||
| (PID) Process: | (2964) GLBF32A.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions |
| Operation: | write | Name: | searchpredict@speedbit.com |
Value: C:\Program Files\SearchPredict\PRFireFox | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\~GLH0000.TMP | executable | |
MD5:3B2E23D259394C701050486E642D14FA | SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\GLCF359.tmp | executable | |
MD5:8C97D8BB1470C6498E47B12C5A03CE39 | SHA256:A87F19F9FEE475D2B2E82ACFB4589BE6D816B613064CD06826E1D4C147BEB50A | |||
| 1776 | svd3.exe | C:\Users\admin\AppData\Local\Temp\GLBF32A.tmp | executable | |
MD5:748FE5E21D134C63046221A2A04837EE | SHA256:A6B104CD2AE6B54F0734CC2D9DEB0F63633BBB9798C99388AF08EB77F65458A9 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\GLJF369.tmp | executable | |
MD5:6F608D264503796BEBD7CD66B687BE92 | SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\GLKF55E.tmp | executable | |
MD5:D22557EBC659DCD0C89266E4A42A041E | SHA256:0045A481E8F141E10927ABE09B3D1608E3C123B402F8C89A7BE319E088F4A0F5 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\~GLH0002.TMP | html | |
MD5:766291A9D7E573C4415E499DF68CD6F3 | SHA256:58918D7EF4CB5E14C03749CA0E5C4EAD656FA5E705C9B5A3BACD3A8400ABAA51 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\~GLH0001.TMP | executable | |
MD5:626891C542239F7AEBC156F9B244E433 | SHA256:06C30D0CC9C035AF22B69BE795C0A1BAB200E832CC556B41853FD18FBDEDCDAC | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\GLFFF24.tmp | executable | |
MD5:3B2E23D259394C701050486E642D14FA | SHA256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\SVCINST\SpeedBitVideoDownloader.cab | compressed | |
MD5:E82945B4E4D15C0F5E46C79582804F0F | SHA256:8C8A34B2579233C7A14B8A34E1EABCBB1917984B900CC17B1EA4FD4701E2D811 | |||
| 2964 | GLBF32A.tmp | C:\Users\admin\AppData\Local\Temp\SVCINST\Grabber.dll | executable | |
MD5:175C8B9CBEFC7F2FC1CEB420D3B80BDE | SHA256:7ABC5C8809FE79896F2C8123FD3942853504221707114CF5CA9FD92F86895785 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4000 | Converter.exe | GET | — | 108.156.61.182:80 | http://download.speedbit.com/ffmpeg.zip | unknown | — | — | unknown |
4000 | Converter.exe | GET | — | 108.156.61.182:80 | http://download.speedbit.com/ffmpeg.zip | unknown | — | — | unknown |
4000 | Converter.exe | GET | — | 108.156.61.182:80 | http://download.speedbit.com/ffmpeg.zip | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4000 | Converter.exe | 108.156.61.182:80 | download.speedbit.com | AMAZON-02 | US | unknown |
4000 | Converter.exe | 173.239.4.56:80 | online.speedbit.com | WEBAIR-INTERNET | US | unknown |
1636 | msedge.exe | 173.239.4.63:80 | www.speedbit.com | WEBAIR-INTERNET | US | unknown |
2772 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1636 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1636 | msedge.exe | 131.253.33.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1636 | msedge.exe | 92.123.104.66:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
download.speedbit.com |
| whitelisted |
online.speedbit.com |
| unknown |
www.speedbit.com |
| malicious |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
regsvr32.exe | [SbTracer::UpdateAllParameters]
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Level
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Destination
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Backup
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Time Limit
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Time Stamp
|
regsvr32.exe | [SbTracer::ReadConfiguration] ___Warning - No Trace Max Size
|
regsvr32.exe | [SbTracer::ReadConfiguration] Done
|
regsvr32.exe | [SbTracer::FormatFilePath] ___Warning - No Log folder: C:\Windows\System32\
|
regsvr32.exe | [SbTracer::FormatFilePath] Log Path: C:\Windows\System32\Grabber.log
|