File name:

MLG GREEN SCREEN.mp4

Full analysis: https://app.any.run/tasks/b43b53bb-878a-4e92-8161-faf274bd29e2
Verdict: Suspicious activity
Analysis date: August 10, 2019, 10:18:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: video/mp4
File info: ISO Media, MP4 v2 [ISO 14496-14]
MD5:

6F349EC648618EC3870A91CF377C8C03

SHA1:

B1E1582D46846A9B4BA709E93D3569D529E1C9E3

SHA256:

D4EEC8141A9E0F41697E6ED3714CDDE5FF4364E39692A2342AA4E2B41B252F73

SSDEEP:

24576:8ufg6av5vMszHKMaKJbLVx/lOjULw9ZsB+iABypMm9l6J33AF1LLPSwSS2s9qrqA:ZgpasTKnEbLVujULkN+Myl6h4DSwS4Sx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • DllHost.exe (PID: 3084)
    • Creates files in the user directory

      • vlc.exe (PID: 1504)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.m4v | MPEG-4 Video (36.5)
.m4r | iPhone Ringtone (32.8)
.3g2 | 3GPP2 multimedia audio/video (25.3)
.mov | QuickTime Movie (2.6)
.mp4 | Generic MP4 container (1.5)

EXIF

QuickTime

MajorBrand: MP4 v2 [ISO 14496-14]
MinorVersion: 0.0.0
CompatibleBrands:
  • isom
  • mp42
MovieHeaderVersion: -
CreateDate: 2015:03:17 13:28:04
ModifyDate: 2015:03:17 13:28:04
TimeScale: 600
Duration: 5.08 s
PreferredRate: 1
PreferredVolume: 100.00%
PreviewTime: 0 s
PreviewDuration: 0 s
PosterTime: 0 s
SelectionTime: 0 s
SelectionDuration: 0 s
CurrentTime: 0 s
NextTrackID: 3
TrackHeaderVersion: -
TrackCreateDate: 0000:00:00 00:00:00
TrackModifyDate: 2015:03:17 13:28:04
TrackID: 1
TrackDuration: 5.04 s
TrackLayer: -
TrackVolume: 0.00%
ImageWidth: 640
ImageHeight: 360
GraphicsMode: srcCopy
OpColor: 0 0 0
CompressorID: avc1
SourceImageWidth: 640
SourceImageHeight: 360
XResolution: 72
YResolution: 72
BitDepth: 24
BufferSize: 15653
MaxBitrate: 2480768
AverageBitrate: 2390032
VideoFrameRate: 29.97
MatrixStructure: 1 0 0 0 1 0 0 0 1
MediaHeaderVersion: -
MediaCreateDate: 2015:03:17 13:28:04
MediaModifyDate: 2015:03:17 13:28:04
MediaTimeScale: 44100
MediaDuration: 5.09 s
MediaLanguageCode: und
HandlerType: Audio Track
HandlerDescription: IsoMedia File Produced by Google, 5-11-2011
Balance: -
AudioFormat: mp4a
AudioChannels: 2
AudioBitsPerSample: 16
AudioSampleRate: 44100
MovieDataSize: 1566412
MovieDataOffset: 2843

Composite

AvgBitrate: 2.46 Mbps
ImageSize: 640x360
Megapixels: 0.23
Rotation: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc.exe PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
1504"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\AppData\Local\Temp\MLG GREEN SCREEN.mp4"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
0
Version:
2.2.6
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3084C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
407
Read events
405
Write events
2
Delete events
0

Modification events

(PID) Process:(1504) vlc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
vlc.exe
(PID) Process:(3084) DllHost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
DllHost.exe
Executable files
0
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD24D.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD386.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD387.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD388.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD389.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD38A.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD38B.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD38C.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD38D.tmp
MD5:
SHA256:
1504vlc.exeC:\Users\admin\AppData\Local\Temp\VLCD38E.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
vlc.exe
core libvlc: one instance mode ENABLED
vlc.exe
core libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
vlc.exe
direct3d vout display error: Direct3D could not be initialized
vlc.exe
direct3d vout display error: Direct3D could not be initialized