| File name: | MediaInfo_GUI_24.12_Windows.exe |
| Full analysis: | https://app.any.run/tasks/40ec79f9-2996-491a-8084-ce9c7ce4b45a |
| Verdict: | Malicious activity |
| Analysis date: | December 23, 2024, 11:43:01 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 8644818749031AAE77B66462BFC1CD97 |
| SHA1: | BC1F9C08C165F8EC64B7C85BD14434FC391C7048 |
| SHA256: | 7DE8C5D7B7654ACCEB54AA4484014C6FA0D470CDC5A2130E6DFB7B2E2AA15F8F |
| SSDEEP: | 196608:eVqoQvtR+kXXziAeoJjV1EVek26mgUjjT0OvEpvnVP:/oytgkXXzleoFVsVmjjjT0OvEVP |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:03:30 16:55:19+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 139776 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x3665 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.12.0.0 |
| ProductVersionNumber: | 24.12.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Cyrillic |
| CompanyName: | MediaArea.net |
| FileDescription: | All about your audio and video files |
| FileVersion: | 24.12.0.0 |
| LegalCopyright: | MediaArea.net |
| OriginalFileName: | MediaInfo_GUI_24.12_Windows.exe |
| ProductName: | MediaInfo |
| ProductVersion: | 24.12.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6524 | "C:\Users\admin\Desktop\MediaInfo_GUI_24.12_Windows.exe" | C:\Users\admin\Desktop\MediaInfo_GUI_24.12_Windows.exe | — | explorer.exe | |||||||||||
User: admin Company: MediaArea.net Integrity Level: MEDIUM Description: All about your audio and video files Exit code: 3221226540 Version: 24.12.0.0 Modules
| |||||||||||||||
| 6676 | "C:\Users\admin\Desktop\MediaInfo_GUI_24.12_Windows.exe" | C:\Users\admin\Desktop\MediaInfo_GUI_24.12_Windows.exe | explorer.exe | ||||||||||||
User: admin Company: MediaArea.net Integrity Level: HIGH Description: All about your audio and video files Exit code: 0 Version: 24.12.0.0 Modules
| |||||||||||||||
| 6872 | "C:\WINDOWS\system32\regsvr32.exe" "C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll" /s | C:\Windows\SysWOW64\regsvr32.exe | — | MediaInfo_GUI_24.12_Windows.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 5 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6884 | "C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll" /s | C:\Windows\System32\regsvr32.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 5 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7052 | "C:\WINDOWS\explorer.exe" "C:\Program Files\MediaInfo\MediaInfo.exe" | C:\Windows\explorer.exe | — | MediaInfo_GUI_24.12_Windows.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7100 | C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7140 | "C:\Program Files\MediaInfo\MediaInfo.exe" | C:\Program Files\MediaInfo\MediaInfo.exe | — | explorer.exe | |||||||||||
User: admin Company: MediaArea.net Integrity Level: MEDIUM Description: MediaInfo Version: 24.12.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\MediaArea\MediaInfo |
| Operation: | write | Name: | InstallCount |
Value: 1 | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | DisplayName |
Value: MediaInfo 24.12 | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | Publisher |
Value: MediaArea.net | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\MediaInfo\uninst.exe | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\MediaInfo\MediaInfo.exe | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | DisplayVersion |
Value: 24.12 | |||
| (PID) Process: | (6676) MediaInfo_GUI_24.12_Windows.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaInfo |
| Operation: | write | Name: | URLInfoAbout |
Value: http://MediaArea.net/MediaInfo | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Users\admin\AppData\Local\Temp\nsf9679.tmp\System.dll | executable | |
MD5:192639861E3DC2DC5C08BB8F8C7260D5 | SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Users\admin\AppData\Local\Temp\nsf9679.tmp\INetC.dll | executable | |
MD5:40D7ECA32B2F4D29DB98715DD45BFAC5 | SHA256:85E03805F90F72257DD41BFDAA186237218BBB0EC410AD3B6576A88EA11DCCB9 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk | binary | |
MD5:06C48BF7F8E2CC95363A58EAD846C0F9 | SHA256:226C66CDFA22A5333B1435CD86CAD40A0FD82227794B1D78C12F92A99FE10433 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Program Files\MediaInfo\MediaInfo.exe | executable | |
MD5:FE81E47578CAC10D2B287765DDDE40CF | SHA256:E55A809DCDE7E073117451F6CFB953167C84B88BD5F77FBAD371076C0BB5329C | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Program Files\MediaInfo\Plugin\Custom\Example.csv | text | |
MD5:3D10242A6FB504C9FBEB9B56B9E33198 | SHA256:A785697B761AEA39467134EC4E0FBD39218685B295553773EF5E5D707B025AB9 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Program Files\MediaInfo\MediaInfo.dll | executable | |
MD5:97DB94B8BD4748767F273F0E572754B8 | SHA256:E2C364FB046826787D6EB32A11F2C4741D52CA204E2C1021361C8CBEA4B1A8B6 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Program Files\MediaInfo\LIBCURL.DLL | executable | |
MD5:AD257F17355AF93B8D706C4FFAD68E55 | SHA256:22B972F008AB8BB5BC225889A8BE60683B2BF7546B8E0D699B5B4186BDBB7CC1 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Program Files\MediaInfo\Plugin\Custom\Table by fields, short (HTML).csv | html | |
MD5:2FDDA620B24C981F004A60532BE7C95A | SHA256:D213026162C0610F833B4C72760E8AA0B3630FCF52D96A118068ECB8A3C51908 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Users\admin\AppData\Local\Temp\nsf9679.tmp\temp.txt | text | |
MD5:1CE7A409B6B5FE83A917E8774587F4A2 | SHA256:DBEA19FE105F3B1221259B70038C30704FA19EA2735D2B4966DD04740271FD19 | |||
| 6676 | MediaInfo_GUI_24.12_Windows.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\24.12.0[1].0 | text | |
MD5:1CE7A409B6B5FE83A917E8774587F4A2 | SHA256:DBEA19FE105F3B1221259B70038C30704FA19EA2735D2B4966DD04740271FD19 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5160 | svchost.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5160 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 51.75.207.234:443 | https://mediaarea.net/install/MediaInfo/24.12.0.0 | unknown | text | 9 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 104.126.37.171:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5160 | svchost.exe | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5160 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
mediaarea.net |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |