| File name: | Xvid-1.3.7-20191228.exe |
| Full analysis: | https://app.any.run/tasks/7dd752b5-2460-492f-98f8-c78187e7b641 |
| Verdict: | Malicious activity |
| Analysis date: | February 04, 2024, 08:12:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
| MD5: | 0A2F190C7B8E2744733944822BD317F3 |
| SHA1: | C2F2C0726ECB8230EBA1953C3120DDD24F16745B |
| SHA256: | 7997CB88DB3331191042EEF5238FBF2EBA44B9D244F43554A712996EBA2FFF49 |
| SSDEEP: | 196608:b/k/IXN+BupbShmbuR7HY4QIA6TC6otdn3gY3QIA6TP:NChG6xo3e6P |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:04:10 17:42:38+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 2.22 |
| CodeSize: | 905216 |
| InitializedDataSize: | 77824 |
| UninitializedDataSize: | 1994752 |
| EntryPoint: | 0x2c4190 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.7.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| ProductName: | Xvid Video Codec |
| LegalTrademarks: | - |
| FileDescription: | - |
| InternalName: | - |
| CompanyName: | Xvid Team |
| FileVersion: | 1.3.7.0 |
| LegalCopyright: | Copyright Xvid Team |
| OriginalFileName: | Xvid-1.3.7-windows.exe |
| Comments: | - |
| ProductVersion: | 1.3.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 572 | "C:\Users\admin\AppData\Local\Temp\Xvid-1.3.7-20191228.exe" | C:\Users\admin\AppData\Local\Temp\Xvid-1.3.7-20191228.exe | — | explorer.exe | |||||||||||
User: admin Company: Xvid Team Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.3.7.0 Modules
| |||||||||||||||
| 908 | C:\Users\admin\AppData\Local\Temp\xvid_x86\SETPRI~1.EXE | C:\Users\admin\AppData\Local\Temp\xvid_x86\setpriv32.exe | Xvid-1.3.7-20191228.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2204 | "C:\Users\admin\AppData\Local\Temp\Xvid-1.3.7-20191228.exe" | C:\Users\admin\AppData\Local\Temp\Xvid-1.3.7-20191228.exe | explorer.exe | ||||||||||||
User: admin Company: Xvid Team Integrity Level: HIGH Exit code: 0 Version: 1.3.7.0 Modules
| |||||||||||||||
| 2776 | "C:\Windows\System32\grpconv.exe" -o | C:\Windows\System32\grpconv.exe | — | runonce.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Progman Group Converter Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3048 | C:\Windows\System32\regsvr32.exe /s C:\Windows\system32/xvid.ax | C:\Windows\System32\regsvr32.exe | — | Xvid-1.3.7-20191228.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3136 | "C:\Windows\system32\runonce.exe" -r | C:\Windows\System32\runonce.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Run Once Wrapper Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3416 | C:\Windows\System32\rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 0 C:\Users\admin\AppData\Local\Temp/xvid_x86/xvid.inf | C:\Windows\System32\rundll32.exe | Xvid-1.3.7-20191228.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3452 | C:\Users\admin\AppData\Local\Temp\xvid_x86\setavi32.exe | C:\Users\admin\AppData\Local\Temp\xvid_x86\setavi32.exe | Xvid-1.3.7-20191228.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (2204) Xvid-1.3.7-20191228.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | delete value | Name: | BitRock |
Value: 1 | |||
| (PID) Process: | (3136) runonce.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | GrpConv |
Value: grpconv -o | |||
| (PID) Process: | (3136) runonce.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3136) runonce.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3136) runonce.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3136) runonce.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3416) rundll32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 115 | |||
| (PID) Process: | (2204) Xvid-1.3.7-20191228.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 |
| Operation: | write | Name: | msacm.l3acm |
Value: C:\Windows\System32\l3codeca.acm | |||
| (PID) Process: | (2204) Xvid-1.3.7-20191228.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\drivers.desc |
| Operation: | delete value | Name: | C:\Windows\System32\l3codeca.acm |
Value: Fraunhofer IIS MPEG Layer-3 Codec | |||
| (PID) Process: | (2204) Xvid-1.3.7-20191228.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectShow\Preferred |
| Operation: | write | Name: | {44495658-0000-0010-8000-00AA00389B71} |
Value: {2A11BAE2-FE6E-4249-864B-9E9ED6E8DBC2} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3EC9.tmp | executable | |
MD5:B226B75915B944BF20F96ADDFD6E4F87 | SHA256:91910BF7A630D272D5389AA6DAFC4E71F32298731B4F44D39B6A0B0D34BD1A3B | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3946.tmp | executable | |
MD5:A210F1AC135E5331C314CE5F394FB5A5 | SHA256:65B32EA2982078FB9A18E88FEEC238CB76ED2AE6C2BB4DDB0F6A9C4F57B1D62B | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3995.tmp | executable | |
MD5:08AD4CD2A940379F1DCDBDB9884A1375 | SHA256:78827E2B1EF0AAD4F8B1B42D0964064819AA22BFCD537EBAACB30D817EDC06D8 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Program Files\Xvid\xvidw.ico | image | |
MD5:5C9E6AE81C94213B01037C3AB4465D4E | SHA256:6379E90C8602C4BF575A4BCCD73607FF5DD451552303812A228EE6BC5004690E | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3A15.tmp | executable | |
MD5:C04970B55BCF614F24CA75B1DE641AE2 | SHA256:5DDEE4AAB3CF33E505F52199D64809125B26DE04FB9970CA589CD8619C859D80 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR39D5.tmp | executable | |
MD5:027491B39A7B16B116E780F55ABC288E | SHA256:EEF69D005BF1C0B715C8D6205400D4755C261DD38DDFBBFE918E6EE91F21F1F0 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3EEA.tmp | executable | |
MD5:5BBF62FAF1E96DEA7752DC930AE150AD | SHA256:39CA391D58EC87F407227C5129194D747CC690BAC514BBE735346C23DB0A5462 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3F1A.tmp | executable | |
MD5:4CF27E0747E5719A5478AA2624F6B996 | SHA256:E69A9D06F2C17CC021EBF9B62CA110548FACDC147B67DEA4846E09865043D2D9 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Users\admin\AppData\Local\Temp\BR3EDA.tmp | executable | |
MD5:924B90C3D9E645DFAD53F61EA4E91942 | SHA256:41788435F245133EC5511111E2C5D52F7515E359876180067E0B5BA85C729322 | |||
| 2204 | Xvid-1.3.7-20191228.exe | C:\Program Files\Xvid\xvid_encraw.exe | executable | |
MD5:EC3AFBA956C2F319B62A054ADB85A7EE | SHA256:6EE53C74B915FDAFC14297B60800F898B72153196147DB578A4DFFF3C23F7EBB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
setpriv32.exe | Successfully changed DACL
|
setpriv32.exe | Successfully changed DACL
|
setavi32.exe | Successfully changed DACL
|