File name:

vlc-3.0.21-win64.exe

Full analysis: https://app.any.run/tasks/c0149eb4-b5c6-4df6-bb5f-e4c9342819c6
Verdict: Malicious activity
Analysis date: October 20, 2024, 10:40:44
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A6F92AFFB6CE711F9F5048410CB4BC32

SHA1:

80D994FB95087EFCE34AEB4A98C8F4D7D2A035A6

SHA256:

9742689A50E96DDC04D80CEFF046B28DA2BEEFD617BE18166F8C5E715EC60C59

SSDEEP:

393216:60D8jG0ZIpp/kAuk6sQdyHhTCXw/GLbINLLPoD:Hw6sAZ6sQdJg/GLbINLLPoD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • vlc-3.0.21-win64.exe (PID: 1196)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • vlc-3.0.21-win64.exe (PID: 1196)
    • Searches for installed software

      • vlc-3.0.21-win64.exe (PID: 1196)
    • Executable content was dropped or overwritten

      • vlc-3.0.21-win64.exe (PID: 1196)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2652)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 6216)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • vlc-3.0.21-win64.exe (PID: 1196)
    • Creates a software uninstall entry

      • vlc-3.0.21-win64.exe (PID: 1196)
  • INFO

    • Checks supported languages

      • vlc-3.0.21-win64.exe (PID: 1196)
      • vlc-cache-gen.exe (PID: 4032)
      • vlc.exe (PID: 5068)
    • Creates files in the program directory

      • vlc-3.0.21-win64.exe (PID: 1196)
      • vlc-cache-gen.exe (PID: 4032)
    • Reads the machine GUID from the registry

      • vlc-cache-gen.exe (PID: 4032)
    • Sends debugging messages

      • vlc-cache-gen.exe (PID: 4032)
      • vlc.exe (PID: 5068)
    • Create files in a temporary directory

      • vlc-3.0.21-win64.exe (PID: 1196)
    • Reads the computer name

      • vlc-3.0.21-win64.exe (PID: 1196)
      • vlc.exe (PID: 5068)
    • The process uses the downloaded file

      • explorer.exe (PID: 6132)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 6132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:29 12:07:21+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.42
CodeSize: 37888
InitializedDataSize: 61952
UninitializedDataSize: 129024
EntryPoint: 0x45a4
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
123
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc-3.0.21-win64.exe vlc-cache-gen.exe conhost.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe no specs explorer.exe no specs vlc.exe vlc-3.0.21-win64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1196"C:\Users\admin\Desktop\vlc-3.0.21-win64.exe" C:\Users\admin\Desktop\vlc-3.0.21-win64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\vlc-3.0.21-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2652 /s "C:\Program Files\VideoLAN\VLC\axvlc.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3944\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exevlc-cache-gen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4032"C:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe" C:\Program Files\VideoLAN\VLC\pluginsC:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe
vlc-3.0.21-win64.exe
User:
admin
Company:
VideoLAN
Integrity Level:
HIGH
Description:
VLC media player
Exit code:
0
Version:
3.0.21
Modules
Images
c:\program files\videolan\vlc\vlc-cache-gen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files\videolan\vlc\libvlc.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5068"C:\Program Files\VideoLAN\VLC\vlc.exe" C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Version:
3.0.21
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\videolan\vlc\libvlc.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\videolan\vlc\libvlccore.dll
6132C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
6136"C:\Users\admin\Desktop\vlc-3.0.21-win64.exe" C:\Users\admin\Desktop\vlc-3.0.21-win64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\vlc-3.0.21-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6152"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\VideoLAN\VLC\axvlc.dll"C:\Windows\SysWOW64\regsvr32.exevlc-3.0.21-win64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6216"C:\WINDOWS\explorer.exe" "C:\Program Files\VideoLAN\VLC\vlc.exe"C:\Windows\explorer.exevlc-3.0.21-win64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
12 770
Read events
11 665
Write events
991
Delete events
114

Modification events

(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\vlc.exe
Operation:writeName:FriendlyAppName
Value:
VLC media player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.3ga\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\vlc.exe\SupportedTypes
Operation:writeName:9054456
Value:
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.669\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.a52\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.aac\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.ac3\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.adt\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.adts\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(1196) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.aif\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
Executable files
378
Suspicious files
154
Text files
71
Unknown types
0

Dropped files

PID
Process
Filename
Type
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\vlc.exeexecutable
MD5:F9538485432D3EC640F89096BA2D4D00
SHA256:5D695D8A0BB1D919CC77A2AA2488A61797BFA065238160278EE458120630AAF9
1196vlc-3.0.21-win64.exeC:\Users\admin\AppData\Local\Temp\nsjEBE1.tmp\nsProcess.dllexecutable
MD5:391F1B7C2BA6CC753CC300EB0B3C522F
SHA256:72D4EC8A496C7057F676BB6C0D3AE872F22FA88EFE2AACED163EE1F429534DDE
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\libvlc.dllexecutable
MD5:264A9E0194DBD3C0540D67B156ECAABA
SHA256:095D164633AF53AC015DCD76540E8523744F57D506DB111F19B3FDD9D6180833
1196vlc-3.0.21-win64.exeC:\Users\admin\AppData\Local\Temp\nsjEBE1.tmp\System.dllexecutable
MD5:4A82832A6209CDC3A2447AB2DE137542
SHA256:B07A12C5CED6A1ECE5E7DC4103F8B3E15BF77F5EDB70DAEF115B9A77BCF55885
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\vlc-cache-gen.exeexecutable
MD5:4DCB6D17F683D4DA04CCB245012E70D0
SHA256:CE6AFF142D300CE7CAEBD91A87A09A1752A56CFA324CCAAC2BD2D66AD36288FE
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\libvlccore.dllexecutable
MD5:C62C3EF5753AF6E0980F38EEBC196B1C
SHA256:2DDB85B36650F85B5A09724C5B17428B1B1B76BD3E3DD85B643933659D5E333D
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\COPYING.txttext
MD5:FFA10F40B98BE2C2BC9608F56827ED23
SHA256:189B1AF95D661151E054CEA10C91B3D754E4DE4D3FECFB074C1FB29476F7167B
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\AUTHORS.txttext
MD5:83804040C2ADC7A7FF0610DDB80823C1
SHA256:003189E0271BDCFC593B5CDC66B4022565384D6A5BD4A1C42BECC6321F128E29
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\README.txttext
MD5:A843F0E99AFB4FA6D987563043FFE3F2
SHA256:56951348F503A7CD9A635C36E0EA4FF8DF3DDA3FBEC41512885D5671ECF5C64A
1196vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\npvlc.dllexecutable
MD5:4CF84CD0AB10F53129BEC2A500A24F85
SHA256:ABB6C380AD7E4CA3ADEC507B7721BC6A98064BBD3B2DB6C3455F7E65B4098912
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
25
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
204
104.126.37.186:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.209.189:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5488
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.209.189
  • 2.23.209.185
  • 2.23.209.193
  • 2.23.209.182
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.148
  • 2.23.209.133
  • 2.23.209.130
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
self.events.data.microsoft.com
  • 20.42.73.30
whitelisted

Threats

No threats detected
Process
Message
vlc-cache-gen.exe
main libvlc debug: VLC media player - 3.0.21 Vetinari
vlc-cache-gen.exe
main libvlc debug: Copyright © 1996-2024 the VideoLAN team
vlc-cache-gen.exe
main libvlc debug: revision 3.0.21-1-0-g9c4768291e
vlc-cache-gen.exe
main libvlc debug: configured with /builds/videolan/vlc/extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-shout' '--enable-goom' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=x86_64-w64-mingw32' '--with-contrib=../contrib/x86_64-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' '--enable-qt' '--enable-skins2' '--enable-dvdread' '--enable-caca' 'host_alias=x86_64-w64-mingw32' 'CFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'CXXFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'PKG_CONFIG=pkg-config' 'PKG_CONFIG_LIBDIR=/usr/x86_64-w64-mingw32/lib/pkgconfig:/usr/lib/x86_64-w64-mingw32/pkgconfig'
vlc-cache-gen.exe
main libvlc debug: using multimedia timers as clock source
vlc-cache-gen.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc-cache-gen.exe
main libvlc debug: searching plug-in modules
vlc-cache-gen.exe
main libvlc debug: ignoring plugins cache file
vlc-cache-gen.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc-cache-gen.exe
main libvlc debug: saving plugins cache C:\Program Files\VideoLAN\VLC\plugins\plugins.dat