File name:

vlc-3.0.21-win64.exe

Full analysis: https://app.any.run/tasks/ed003704-66c0-4067-9eae-e1548af55721
Verdict: Malicious activity
Analysis date: September 27, 2024, 17:24:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A6F92AFFB6CE711F9F5048410CB4BC32

SHA1:

80D994FB95087EFCE34AEB4A98C8F4D7D2A035A6

SHA256:

9742689A50E96DDC04D80CEFF046B28DA2BEEFD617BE18166F8C5E715EC60C59

SSDEEP:

393216:60D8jG0ZIpp/kAuk6sQdyHhTCXw/GLbINLLPoD:Hw6sAZ6sQdJg/GLbINLLPoD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • vlc-3.0.21-win64.exe (PID: 2244)
  • SUSPICIOUS

    • Searches for installed software

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • vlc-3.0.21-win64.exe (PID: 2244)
    • The process creates files with name similar to system file names

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Executable content was dropped or overwritten

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 2036)
  • INFO

    • Checks supported languages

      • vlc-3.0.21-win64.exe (PID: 2244)
      • vlc-cache-gen.exe (PID: 3528)
    • Reads the computer name

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Creates files in the program directory

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Create files in a temporary directory

      • vlc-3.0.21-win64.exe (PID: 2244)
    • Sends debugging messages

      • vlc-cache-gen.exe (PID: 3528)
    • Reads the machine GUID from the registry

      • vlc-cache-gen.exe (PID: 3528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:29 12:07:21+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.42
CodeSize: 37888
InitializedDataSize: 61952
UninitializedDataSize: 129024
EntryPoint: 0x45a4
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
124
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc-3.0.21-win64.exe vlc-cache-gen.exe conhost.exe no specs regsvr32.exe no specs regsvr32.exe no specs explorer.exe no specs explorer.exe no specs vlc.exe vlc-3.0.21-win64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
488"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\VideoLAN\VLC\axvlc.dll"C:\Windows\SysWOW64\regsvr32.exevlc-3.0.21-win64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2020"C:\Program Files\VideoLAN\VLC\vlc.exe" C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Version:
3.0.21
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\program files\videolan\vlc\libvlc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\videolan\vlc\libvlccore.dll
2036"C:\WINDOWS\explorer.exe" "C:\Program Files\VideoLAN\VLC\vlc.exe"C:\Windows\explorer.exevlc-3.0.21-win64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
2244"C:\Users\admin\Desktop\vlc-3.0.21-win64.exe" C:\Users\admin\Desktop\vlc-3.0.21-win64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\vlc-3.0.21-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3528"C:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe" C:\Program Files\VideoLAN\VLC\pluginsC:\Program Files\VideoLAN\VLC\vlc-cache-gen.exe
vlc-3.0.21-win64.exe
User:
admin
Company:
VideoLAN
Integrity Level:
HIGH
Description:
VLC media player
Exit code:
0
Version:
3.0.21
Modules
Images
c:\program files\videolan\vlc\vlc-cache-gen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\program files\videolan\vlc\libvlc.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4892C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\twinapi.dll
c:\windows\system32\oleaut32.dll
5196"C:\Users\admin\Desktop\vlc-3.0.21-win64.exe" C:\Users\admin\Desktop\vlc-3.0.21-win64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\vlc-3.0.21-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5740 /s "C:\Program Files\VideoLAN\VLC\axvlc.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exevlc-cache-gen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
12 772
Read events
11 666
Write events
992
Delete events
114

Modification events

(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\vlc.exe
Operation:writeName:FriendlyAppName
Value:
VLC media player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.3ga\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\vlc.exe\SupportedTypes
Operation:writeName:10160232
Value:
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.669\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.a52\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.aac\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.ac3\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.adt\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.adts\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
(PID) Process:(2244) vlc-3.0.21-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VLC.aif\shell\Open
Operation:writeName:MultiSelectModel
Value:
Player
Executable files
378
Suspicious files
156
Text files
69
Unknown types
0

Dropped files

PID
Process
Filename
Type
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\plugins\access\libaccess_concat_plugin.dllexecutable
MD5:3129A88916039FB124F4856C4DCD299D
SHA256:6F6F559EF8D2159307D0AE995994240137CC3CE57C0F92EAE2E523AA59E552D3
2244vlc-3.0.21-win64.exeC:\Users\admin\AppData\Local\Temp\nsu92F8.tmp\nsDialogs.dllexecutable
MD5:8B11196DC49C4DF98C6F97457C97E590
SHA256:47A1976B7736371B9B2E073EF0DD49DB3BDBE604EC9EE77E50621E5F19D9AE7B
2244vlc-3.0.21-win64.exeC:\Users\admin\AppData\Local\Temp\nsu92F8.tmp\nsProcess.dllexecutable
MD5:391F1B7C2BA6CC753CC300EB0B3C522F
SHA256:72D4EC8A496C7057F676BB6C0D3AE872F22FA88EFE2AACED163EE1F429534DDE
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\libvlccore.dllexecutable
MD5:C62C3EF5753AF6E0980F38EEBC196B1C
SHA256:2DDB85B36650F85B5A09724C5B17428B1B1B76BD3E3DD85B643933659D5E333D
2244vlc-3.0.21-win64.exeC:\Users\admin\AppData\Local\Temp\nsu92F8.tmp\modern-wizard.bmpimage
MD5:62C83E308015E087AFC979EC4CE88AF6
SHA256:D13427F81EC2D123845CEE7CFE2F6C5663709444CB90713CB474E7898AE645E4
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\axvlc.dllexecutable
MD5:76C37511EF2E97250CFB0142A114954F
SHA256:EE55B5CA4494DAE67E5328128587829E1417E732D0F76858B473C834D5306419
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\libvlc.dllexecutable
MD5:264A9E0194DBD3C0540D67B156ECAABA
SHA256:095D164633AF53AC015DCD76540E8523744F57D506DB111F19B3FDD9D6180833
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\npvlc.dllexecutable
MD5:4CF84CD0AB10F53129BEC2A500A24F85
SHA256:ABB6C380AD7E4CA3ADEC507B7721BC6A98064BBD3B2DB6C3455F7E65B4098912
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\AUTHORS.txttext
MD5:83804040C2ADC7A7FF0610DDB80823C1
SHA256:003189E0271BDCFC593B5CDC66B4022565384D6A5BD4A1C42BECC6321F128E29
2244vlc-3.0.21-win64.exeC:\Program Files\VideoLAN\VLC\NEWS.txttext
MD5:D29D2C41DB4100DC1E21C7A29F7BF0D8
SHA256:310A9CCB2FF5DFC4F9BF7D5E971708B8D7AF93D7C864FEDEDFA104A4C97BBC31
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
27
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
20.50.73.9:443
https://browser.pipe.aria.microsoft.com/Collector/3.0/?qsp=true&content-type=application%2Fbond-compact-binary&client-id=NO_AUTH&sdk-version=AWT-Web-CJS-1.2.0&x-apikey=33d70a864599496b982a39f036f71122-2064703e-3a9d-4d90-8362-eec08dffe8e8-7176
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
8
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5336
SearchApp.exe
20.50.73.9:443
browser.pipe.aria.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
browser.pipe.aria.microsoft.com
  • 20.50.73.9
whitelisted

Threats

No threats detected
Process
Message
vlc-cache-gen.exe
main libvlc debug: VLC media player - 3.0.21 Vetinari
vlc-cache-gen.exe
main libvlc debug: Copyright © 1996-2024 the VideoLAN team
vlc-cache-gen.exe
main libvlc debug: revision 3.0.21-1-0-g9c4768291e
vlc-cache-gen.exe
main libvlc debug: configured with /builds/videolan/vlc/extras/package/win32/../../../configure '--enable-update-check' '--enable-lua' '--enable-faad' '--enable-flac' '--enable-theora' '--enable-avcodec' '--enable-merge-ffmpeg' '--enable-dca' '--enable-mpc' '--enable-libass' '--enable-schroedinger' '--enable-realrtsp' '--enable-live555' '--enable-shout' '--enable-goom' '--enable-sse' '--enable-mmx' '--enable-libcddb' '--enable-zvbi' '--disable-telx' '--enable-nls' '--host=x86_64-w64-mingw32' '--with-contrib=../contrib/x86_64-w64-mingw32' '--with-breakpad=https://win.crashes.videolan.org' '--enable-qt' '--enable-skins2' '--enable-dvdread' '--enable-caca' 'host_alias=x86_64-w64-mingw32' 'CFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'CXXFLAGS= -D_WIN32_WINNT=0x0502 -DWINVER=0x502 -D__MSVCRT_VERSION__=0x700 ' 'PKG_CONFIG=pkg-config' 'PKG_CONFIG_LIBDIR=/usr/x86_64-w64-mingw32/lib/pkgconfig:/usr/lib/x86_64-w64-mingw32/pkgconfig'
vlc-cache-gen.exe
main libvlc debug: using multimedia timers as clock source
vlc-cache-gen.exe
main libvlc debug: min period: 1 ms, max period: 1000000 ms
vlc-cache-gen.exe
main libvlc debug: searching plug-in modules
vlc-cache-gen.exe
main libvlc debug: ignoring plugins cache file
vlc-cache-gen.exe
main libvlc debug: recursively browsing `C:\Program Files\VideoLAN\VLC\plugins'
vlc-cache-gen.exe
main libvlc debug: saving plugins cache C:\Program Files\VideoLAN\VLC\plugins\plugins.dat