| File name: | MiniPlayer.exe |
| Full analysis: | https://app.any.run/tasks/09863b16-de9c-4d82-8e25-d78ee1c8b072 |
| Verdict: | Malicious activity |
| Analysis date: | February 09, 2024, 12:32:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 5BBB89F52A28E20B5A8147C827705EB3 |
| SHA1: | 43059F4AA65798E3624CB1B9959C16045CD3E32D |
| SHA256: | 674C6A9AF16EE87F05A0CF94B68AC332AB13F6334E8DA3422A7EFDE4C6ED33A7 |
| SSDEEP: | 98304:4A1Q0JN47S8EgwfDsXYoSrAfVJLHqiMurubH2CN6gOSD9izP2OGmntvfTV5GbbIo:9Wa5BPKwTxhn5 |
| .exe | | | Wise Installer executable (91.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (5.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.2) |
| .exe | | | Win32 Executable (generic) (0.8) |
| .exe | | | Generic Win/DOS Executable (0.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:08:13 17:13:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 8704 |
| InitializedDataSize: | 5632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21af |
| OSVersion: | 4 |
| ImageVersion: | 4 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Tiandy |
| FileDescription: | MiniPlayer 安装 |
| FileVersion: | - |
| LegalCopyright: | Tiandy |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\pthreadVC2.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AviConvert.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 864 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\libeay32.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1040 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AVShowSDK.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1496 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\AVFilterSDK.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1836 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\OsCore.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2120 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\MultiMedia.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2184 | "C:\Program Files\MiniPlayer\MiniPlayer.exe" | C:\Program Files\MiniPlayer\MiniPlayer.exe | explorer.exe | ||||||||||||
User: admin Company: MiniPlayer Integrity Level: MEDIUM Exit code: 2 Version: 5, 2, 0, 0 Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\SPDecSDK.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2408 | "C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp" C:\Program Files\MiniPlayer\SvacDecLib.dll | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | — | MiniPlayer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (2848) MiniPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiniPlayer |
| Operation: | write | Name: | DisplayName |
Value: MiniPlayer | |||
| (PID) Process: | (2848) MiniPlayer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiniPlayer |
| Operation: | write | Name: | UninstallString |
Value: C:\PROGRA~1\MINIPL~1\UNWISE.EXE C:\PROGRA~1\MINIPL~1\INSTALL.LOG | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\~GLH0001.TMP | executable | |
MD5:2B85FE26CA828485BFF6A454B881A295 | SHA256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00 | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\~GLH0006.TMP | executable | |
MD5:2EAA7D90C8B68E2C56B9A8893547C554 | SHA256:8A4F1CAFC6EB63F042E91E79D8CD4BCAA0CAC6C276F53D8A1E2682F0ACEE7AA4 | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\~GLH0002.TMP | executable | |
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55 | SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822 | |||
| 2848 | MiniPlayer.exe | C:\PROGRA~1\MINIPL~1\temp.000 | executable | |
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55 | SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822 | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\UNWISE.EXE | executable | |
MD5:2B85FE26CA828485BFF6A454B881A295 | SHA256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00 | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\~GLH0003.TMP | executable | |
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55 | SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822 | |||
| 2848 | MiniPlayer.exe | C:\Users\admin\AppData\Local\Temp\GLKA2E.tmp | executable | |
MD5:517419CAE37F6C78C80F9B7D0FBB8661 | SHA256:BFE7E013CFB85E78B994D3AD34ECA08286494A835CB85F1D7BCED3DF6FE93A11 | |||
| 2848 | MiniPlayer.exe | C:\Users\admin\AppData\Local\Temp\GLJ81A.tmp | executable | |
MD5:6F608D264503796BEBD7CD66B687BE92 | SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\AudioDecAMR.dll | executable | |
MD5:9EBA2EFEA00C163E5BBEDBBB3CC0EC55 | SHA256:4965A21A87149EB5CF92576BAED081FC19C1F9C9C00FCCFA4076F462C2D57822 | |||
| 2848 | MiniPlayer.exe | C:\Program Files\MiniPlayer\~GLH0004.TMP | executable | |
MD5:FDC8349520BAA65559E4B9F2FF3121E9 | SHA256:47AD405C0891861CFDE2B25ADF4EAB5B8F0DF30745156BECC8DC865EA3F53534 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Process | Message |
|---|---|
MiniPlayer.exe | "C:\Program Files\MiniPlayer\MiniPlayer.exe" |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |
MiniPlayer.exe | Use language ini rc |