File name:

OpenCodecSetup64.exe

Full analysis: https://app.any.run/tasks/e0eed1b2-e956-4491-b32c-758aaea6ed45
Verdict: Malicious activity
Analysis date: April 20, 2024, 17:07:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

602AAAB31B2FFE97AF601E647AF5EB3E

SHA1:

EF5716B66B2E98C81270750D3E829674DCFF7B3D

SHA256:

CB8F4ED286F7A6B87ED56C69C17E0D5757F179146864A227C34037D5FFDD9441

SSDEEP:

98304:bv2LjAVGfvqozlXPSnwcVwJPl5NWuJoR0+jy3BW+c2kEUWcUOg00quW+j3HYg60Z:syT4/z/ZIa5Yb5V+H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OpenCodecSetup64.exe (PID: 3592)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • OpenCodecSetup64.exe (PID: 3592)
    • Executable content was dropped or overwritten

      • OpenCodecSetup64.exe (PID: 3592)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • OpenCodecSetup64.exe (PID: 3592)
  • INFO

    • Checks supported languages

      • OpenCodecSetup64.exe (PID: 3592)
    • Reads the computer name

      • OpenCodecSetup64.exe (PID: 3592)
    • Create files in a temporary directory

      • OpenCodecSetup64.exe (PID: 3592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:43+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x3645
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start opencodecsetup64.exe opencodecsetup64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3416"C:\Users\admin\Desktop\OpenCodecSetup64.exe" C:\Users\admin\Desktop\OpenCodecSetup64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\opencodecsetup64.exe
c:\windows\system32\ntdll.dll
3592"C:\Users\admin\Desktop\OpenCodecSetup64.exe" C:\Users\admin\Desktop\OpenCodecSetup64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\users\admin\desktop\opencodecsetup64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
151
Read events
151
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3592OpenCodecSetup64.exeC:\Users\admin\AppData\Local\Temp\nsuE983.tmp
MD5:
SHA256:
3592OpenCodecSetup64.exeC:\Users\admin\AppData\Local\Temp\nsjE993.tmp\System.dllexecutable
MD5:4ADD245D4BA34B04F213409BFE504C07
SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info