File name:

MiniPlayer.exe

Full analysis: https://app.any.run/tasks/09863b16-de9c-4d82-8e25-d78ee1c8b072
Verdict: Malicious activity
Analysis date: February 09, 2024, 12:32:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5BBB89F52A28E20B5A8147C827705EB3

SHA1:

43059F4AA65798E3624CB1B9959C16045CD3E32D

SHA256:

674C6A9AF16EE87F05A0CF94B68AC332AB13F6334E8DA3422A7EFDE4C6ED33A7

SSDEEP:

98304:4A1Q0JN47S8EgwfDsXYoSrAfVJLHqiMurubH2CN6gOSD9izP2OGmntvfTV5GbbIo:9Wa5BPKwTxhn5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • MiniPlayer.exe (PID: 2848)
    • Drops the executable file immediately after the start

      • MiniPlayer.exe (PID: 2848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MiniPlayer.exe (PID: 2848)
    • Searches for installed software

      • MiniPlayer.exe (PID: 2848)
    • Creates a software uninstall entry

      • MiniPlayer.exe (PID: 2848)
    • Starts application with an unusual extension

      • MiniPlayer.exe (PID: 2848)
  • INFO

    • Checks supported languages

      • GLJ81A.tmp (PID: 2444)
      • GLJ81A.tmp (PID: 3304)
      • GLJ81A.tmp (PID: 4060)
      • GLJ81A.tmp (PID: 3500)
      • GLJ81A.tmp (PID: 4004)
      • MiniPlayer.exe (PID: 2848)
      • GLJ81A.tmp (PID: 1040)
      • GLJ81A.tmp (PID: 3996)
      • GLJ81A.tmp (PID: 2408)
      • GLJ81A.tmp (PID: 116)
      • GLJ81A.tmp (PID: 2908)
      • GLJ81A.tmp (PID: 864)
      • GLJ81A.tmp (PID: 2672)
      • GLJ81A.tmp (PID: 2120)
      • GLJ81A.tmp (PID: 2860)
      • GLJ81A.tmp (PID: 1836)
      • GLJ81A.tmp (PID: 1496)
      • GLJ81A.tmp (PID: 3180)
      • GLJ81A.tmp (PID: 2960)
      • GLJ81A.tmp (PID: 2256)
      • GLJ81A.tmp (PID: 3516)
      • GLJ81A.tmp (PID: 2688)
      • GLJ81A.tmp (PID: 848)
      • MiniPlayer.exe (PID: 2184)
    • Create files in a temporary directory

      • MiniPlayer.exe (PID: 2848)
    • Manual execution by a user

      • MiniPlayer.exe (PID: 2184)
    • Reads the computer name

      • MiniPlayer.exe (PID: 2848)
    • Creates files in the program directory

      • MiniPlayer.exe (PID: 2848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (91.7)
.exe | Win64 Executable (generic) (5.3)
.dll | Win32 Dynamic Link Library (generic) (1.2)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:08:13 17:13:38+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Tiandy
FileDescription: MiniPlayer 安装
FileVersion: -
LegalCopyright: Tiandy
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
25
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start miniplayer.exe glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs glj81a.tmp no specs miniplayer.exe miniplayer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\pthreadVC2.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
848"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AviConvert.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
864"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\libeay32.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1040"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AVShowSDK.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1496"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AVFilterSDK.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1836"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\OsCore.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2120"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\MultiMedia.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2184"C:\Program Files\MiniPlayer\MiniPlayer.exe" C:\Program Files\MiniPlayer\MiniPlayer.exe
explorer.exe
User:
admin
Company:
MiniPlayer
Integrity Level:
MEDIUM
Exit code:
2
Version:
5, 2, 0, 0
Modules
Images
c:\program files\miniplayer\miniplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2256"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\SPDecSDK.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2408"C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\SvacDecLib.dllC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpMiniPlayer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\glj81a.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
2 353
Read events
2 351
Write events
2
Delete events
0

Modification events

(PID) Process:(2848) MiniPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiniPlayer
Operation:writeName:DisplayName
Value:
MiniPlayer
(PID) Process:(2848) MiniPlayer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiniPlayer
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\MINIPL~1\UNWISE.EXE C:\PROGRA~1\MINIPL~1\INSTALL.LOG
Executable files
121
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2848MiniPlayer.exeC:\Program Files\MiniPlayer\~GLH0001.TMPexecutable
MD5:2B85FE26CA828485BFF6A454B881A295
SHA256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00
2848MiniPlayer.exeC:\Program Files\MiniPlayer\~GLH0006.TMPexecutable
MD5:2EAA7D90C8B68E2C56B9A8893547C554
SHA256:8A4F1CAFC6EB63F042E91E79D8CD4BCAA0CAC6C276F53D8A1E2682F0ACEE7AA4
2848MiniPlayer.exeC:\Program Files\MiniPlayer\~GLH0002.TMPexecutable
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55
SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822
2848MiniPlayer.exeC:\PROGRA~1\MINIPL~1\temp.000executable
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55
SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822
2848MiniPlayer.exeC:\Program Files\MiniPlayer\UNWISE.EXEexecutable
MD5:2B85FE26CA828485BFF6A454B881A295
SHA256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00
2848MiniPlayer.exeC:\Program Files\MiniPlayer\~GLH0003.TMPexecutable
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55
SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822
2848MiniPlayer.exeC:\Users\admin\AppData\Local\Temp\GLKA2E.tmpexecutable
MD5:517419CAE37F6C78C80F9B7D0FBB8661
SHA256:BFE7E013CFB85E78B994D3AD34ECA08286494A835CB85F1D7BCED3DF6FE93A11
2848MiniPlayer.exeC:\Users\admin\AppData\Local\Temp\GLJ81A.tmpexecutable
MD5:6F608D264503796BEBD7CD66B687BE92
SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
2848MiniPlayer.exeC:\Program Files\MiniPlayer\AudioDecAMR.dllexecutable
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55
SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822
2848MiniPlayer.exeC:\Program Files\MiniPlayer\~GLH0004.TMPexecutable
MD5:FDC8349520BAA65559E4B9F2FF3121E9
SHA256:47AD405C0891861CFDE2B25ADF4EAB5B8F0DF30745156BECC8DC865EA3F53534
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
Process
Message
MiniPlayer.exe
"C:\Program Files\MiniPlayer\MiniPlayer.exe"
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc
MiniPlayer.exe
Use language ini rc