File name:

playlist.m3u

Full analysis: https://app.any.run/tasks/a5ff43b0-8735-4664-8f50-31a3b12e6c6b
Verdict: Suspicious activity
Analysis date: July 26, 2020, 20:13:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
downloader
Indicators:
MIME: text/plain
File info: M3U playlist, UTF-8 Unicode text, with CRLF line terminators
MD5:

6F52E90D246DBF7148087334B4C905A1

SHA1:

1D204074816682666A7E819372537B9A520712ED

SHA256:

DDA51E3E3AE4A331405384E56D824FC0013847343BCA77930130A0C397ECBED7

SSDEEP:

48:CXs3XVXgyX0X2XkRXbXXXzXHIX/X9XNXg3XDXFXCNs3XNXo0X07lX0XFz3XhK3XU:GdAOCl6orSJ5CQ7qi699KRl5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • vlc.exe (PID: 1852)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.m3u | Extended M3U playlist (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vlc.exe

Process information

PID
CMD
Path
Indicators
Parent process
1852"C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\admin\AppData\Local\Temp\playlist.m3u"C:\Program Files\VideoLAN\VLC\vlc.exe
explorer.exe
User:
admin
Company:
VideoLAN
Integrity Level:
MEDIUM
Description:
VLC media player
Exit code:
0
Version:
2.2.6
Modules
Images
c:\program files\videolan\vlc\vlc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\videolan\vlc\libvlc.dll
c:\program files\videolan\vlc\libvlccore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
372
Read events
371
Write events
1
Delete events
0

Modification events

(PID) Process:(1852) vlc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
vlc.exe
Executable files
0
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC590D.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC5A18.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC5A19.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC5A1A.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC5A1B.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC5A2B.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Roaming\vlc\vlcrc.1852
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC6CCA.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC6CCB.tmp
MD5:
SHA256:
1852vlc.exeC:\Users\admin\AppData\Local\Temp\VLC6CCC.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
18
DNS requests
1
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1852
vlc.exe
GET
200
78.129.228.178:80
http://xlfr15wf.ottclub.xyz/iptv/FNHM9TMKAF77VV/5014/index.m3u
GB
text
403 b
suspicious
1852
vlc.exe
GET
93.189.62.194:80
http://93.189.62.194/iptv/FNHM9TMKAF77VV/5014/1595792297000.ts
DE
unknown
1852
vlc.exe
GET
78.129.228.178:80
http://xlfr15wf.ottclub.xyz/iptv/FNHM9TMKAF77VV/5014/index.m3u
GB
suspicious
1852
vlc.exe
GET
78.129.228.178:80
http://xlfr15wf.ottclub.xyz/iptv/FNHM9TMKAF77VV/5014/index.m3u
GB
suspicious
1852
vlc.exe
GET
206
93.189.62.194:80
http://93.189.62.194/iptv/FNHM9TMKAF77VV/5014/1595792292000.ts
DE
ts
7.54 Mb
unknown
1852
vlc.exe
GET
206
213.183.42.10:80
http://213.183.42.10/iptv/FNHM9TMKAF77VV/5014/1595792272000.ts
DE
ts
7.56 Mb
unknown
1852
vlc.exe
GET
78.129.228.178:80
http://xlfr15wf.ottclub.xyz/iptv/FNHM9TMKAF77VV/5014/index.m3u
GB
suspicious
1852
vlc.exe
GET
213.183.40.195:80
http://213.183.40.195/iptv/FNHM9TMKAF77VV/5014/1595792287000.ts
NL
unknown
1852
vlc.exe
GET
206
213.183.40.195:80
http://213.183.40.195/iptv/FNHM9TMKAF77VV/5014/1595792277000.ts
NL
ts
7.56 Mb
unknown
1852
vlc.exe
GET
206
213.183.42.10:80
http://213.183.42.10/iptv/FNHM9TMKAF77VV/5014/1595792282000.ts
DE
ts
7.39 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1852
vlc.exe
78.129.228.178:80
xlfr15wf.ottclub.xyz
iomart Cloud Services Limited.
GB
suspicious
213.183.42.10:80
Melbikomas UAB
DE
unknown
1852
vlc.exe
213.183.42.10:80
Melbikomas UAB
DE
unknown
1852
vlc.exe
213.183.40.195:80
Melbikomas UAB
NL
unknown
1852
vlc.exe
93.189.62.194:80
Melbikomas UAB
DE
unknown
1852
vlc.exe
93.189.62.122:80
Melbikomas UAB
DE
unknown

DNS requests

Domain
IP
Reputation
xlfr15wf.ottclub.xyz
  • 78.129.228.178
suspicious

Threats

PID
Process
Class
Message
1852
vlc.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
1852
vlc.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
1852
vlc.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
1852
vlc.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
Process
Message
vlc.exe
core libvlc: one instance mode ENABLED
vlc.exe
core libvlc: Running vlc with the default interface. Use 'cvlc' to use vlc without interface.
vlc.exe
core playlist: stopping playback
vlc.exe
httplive stream: HTTP Live Streaming (xlfr15wf.ottclub.xyz/iptv/FNHM9TMKAF77VV/5014/index.m3u)
vlc.exe
ts demux: MPEG-4 descriptor not found for pid 0x101 type 0xf
vlc.exe
packetizer_mpeg4audio packetizer: AAC channels: 2 samplerate: 48000
vlc.exe
direct3d vout display error: Could not read adapter capabilities. (hr=0x8876086A)
vlc.exe
direct3d vout display error: Direct3D could not be initialized
vlc.exe
avcodec decoder error: more than 5 seconds of late video -> dropping frame (computer too slow ?)
vlc.exe
avcodec decoder error: more than 5 seconds of late video -> dropping frame (computer too slow ?)