File name:

SFVipPlayer.exe

Full analysis: https://app.any.run/tasks/3391d4a5-385f-4ce8-a410-b68cb5576db9
Verdict: No threats detected
Analysis date: December 09, 2024, 11:01:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

55DC954E10EBB2AE56558D90750674FC

SHA1:

402CDE435FCA213D36C52DD398354B83E3A9EE02

SHA256:

AD7F6AFEDCE28AABF41C5627BF057D45142CC59B43BC71DAC482105D76835714

SSDEEP:

12288:JXtNAU5FrzAmj3t8Uj4XbkTHF2HMqi8E65:J9u+vjd8Uj4rkTHF2sqi8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • SFVipPlayer.exe (PID: 1668)
  • INFO

    • Reads the computer name

      • SFVipPlayer.exe (PID: 1668)
    • Checks supported languages

      • SFVipPlayer.exe (PID: 1668)
    • Reads the machine GUID from the registry

      • SFVipPlayer.exe (PID: 1668)
    • Checks proxy server information

      • WerFault.exe (PID: 6416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2104:01:01 22:55:07+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 819712
InitializedDataSize: 79360
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.2.7.90
ProductVersionNumber: 1.2.7.90
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: SFVipPlayer
FileVersion: 1.2.7.90
InternalName: SFVipPlayer.exe
LegalCopyright: Copyright © salezli 2024
LegalTrademarks: -
OriginalFileName: SFVipPlayer.exe
ProductName: SFVipPlayer
ProductVersion: 1.2.7.90
AssemblyVersion: 1.2.7.90
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sfvipplayer.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1668"C:\Users\admin\AppData\Local\Temp\SFVipPlayer.exe" C:\Users\admin\AppData\Local\Temp\SFVipPlayer.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SFVipPlayer
Exit code:
3762504530
Version:
1.2.7.90
Modules
Images
c:\users\admin\appdata\local\temp\sfvipplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6416C:\WINDOWS\system32\WerFault.exe -u -p 1668 -s 1008C:\Windows\System32\WerFault.exe
SFVipPlayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
3 788
Read events
3 788
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_SFVipPlayer.exe_b8ec1618a5d1a6778e9a21ed37628349d22dfdb6_276542ff_65b62e2d-f274-4b78-a8cd-b18994c41da1\Report.wer
MD5:
SHA256:
6416WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\SFVipPlayer.exe.1668.dmp
MD5:
SHA256:
6416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5C6C.tmp.WERInternalMetadata.xmlxml
MD5:4F9C8B3F53B4A05A82F52EF90D1FAFE7
SHA256:D3EB87A2A57F25D9C9AA440456C699052958025617BAD0FDF3C6D6B0A93AE547
6416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5CAC.tmp.xmlxml
MD5:6AD78FF7789652108EF1CB681C98A060
SHA256:159F8A60B606ED8E42C0AEBC14B0D14D696FFAA49E03C8456959EAD4D5FB4BCE
6416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5A58.tmp.dmpdmp
MD5:1CC148A7BA1C3C2BA0B386A48236DDEE
SHA256:DDA31702F2ACFF14BA54F49C656131818D52A36F28FDA824105618EFDDF33F1D
6416WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:F0CF5B1794ECA7CD73F9C020DAAB8EF2
SHA256:2AF00EDCE7EF3266897E52DC81E8DE3B7A079028C0F1F96EAFF9E38AD342F617
6416WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:98B41AFC2E632BB192DCA8100600457B
SHA256:9D5A9BB1E012D1E13E43D2087A3B7132AA21DB77608AB32C29CC0144B616B0D1
6416WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:469BD96AADE9648A4F0B54CAD49CD64B
SHA256:5A70453E4220B7943AD4F8B29DD670A562DBF05B50C4D6E78A352E4026CA098E
6416WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:F6F53CD09A41E968C363419B279D3112
SHA256:6D2BB01CC7A9BADE2113B219CAC1BDA86B2733196B7E1BD0C807CE1E396B1892
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
36
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6416
WerFault.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6416
WerFault.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7048
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
104.126.37.176:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
google.com
  • 142.250.186.110
whitelisted
www.bing.com
  • 104.126.37.176
  • 104.126.37.137
  • 104.126.37.138
  • 104.126.37.186
  • 104.126.37.136
  • 104.126.37.130
  • 104.126.37.184
  • 104.126.37.128
  • 104.126.37.131
whitelisted
login.live.com
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.136
  • 40.126.32.138
  • 40.126.32.133
  • 40.126.32.68
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
watson.events.data.microsoft.com
  • 20.189.173.20
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info