download:

ArtearHD.m3u8

Full analysis: https://app.any.run/tasks/224d8f45-054c-4091-be99-8c888c67d81a
Verdict: No threats detected
Analysis date: March 10, 2018, 13:14:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: M3U playlist, ASCII text
MD5:

09D8F3C335DB77AFB97A38A3F665B4FA

SHA1:

607EA3170790BB450FF572FD2061D9673D7B79AD

SHA256:

67D10AE345BD642780BB814E34772991F626D0200DDB4E1347CFEEE954754DF6

SSDEEP:

48:OfFURfMnPfmZhOmP1JcdPArzP8fPd8VPecaVUrmSVKx7Vj49VWnV2a6VB4:OfFcfMHmDO10AafaVQmSVWVkVGVuVG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • vlc.exe (PID: 2760)
  • INFO

    • Dropped object may contain URL's

      • vlc.exe (PID: 2760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc.exe

Process information

PID
CMD
Path
Indicators
Parent process
2760"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\AppData\Local\Temp\ArtearHD.m3u8"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
0
Version:
2.2.6
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
350
Read events
350
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2760vlc.exeC:\Users\admin\AppData\Local\Temp\VLCB9C7.tmp
MD5:
SHA256:
2760vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlcrc.2760
MD5:
SHA256:
2760vlc.exeC:\Users\admin\AppData\Local\Temp\VLCE90.tmp
MD5:
SHA256:
2760vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlcrctext
MD5:
SHA256:
2760vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlc-qt-interface.initext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
vlc.exe
core libvlc: one instance mode ENABLED
vlc.exe
core libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
vlc.exe
httplive stream: HTTP Live Streaming (/C:/Users/admin/AppData/Local/Temp/ArtearHD.m3u8)
vlc.exe
filesystem access error: cannot open file C:\Users\admin\AppData\Local\Temp\ArtearHD-video=678000.m3u8 (No such file or directory)
vlc.exe
core stream error: no suitable access module for `file:///C:/Users/admin/AppData/Local/Temp/ArtearHD-video=678000.m3u8'
vlc.exe
filesystem access error: cannot open file C:\Users\admin\AppData\Local\Temp\ArtearHD-video=1344000.m3u8 (No such file or directory)
vlc.exe
core stream error: no suitable access module for `file:///C:/Users/admin/AppData/Local/Temp/ArtearHD-video=1344000.m3u8'
vlc.exe
filesystem access error: cannot open file C:\Users\admin\AppData\Local\Temp\ArtearHD-video=1972000.m3u8 (No such file or directory)
vlc.exe
core stream error: no suitable access module for `file:///C:/Users/admin/AppData/Local/Temp/ArtearHD-video=1972000.m3u8'
vlc.exe
filesystem access error: cannot open file C:\Users\admin\AppData\Local\Temp\ArtearHD-video=2740000.m3u8 (No such file or directory)