File name:

vpsetup.exe

Full analysis: https://app.any.run/tasks/355cdb6c-5831-4443-8ed4-64e97e8383a1
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 25, 2024, 08:47:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
opendir
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

668AECE25C236DAE50D2196E41AC8C0C

SHA1:

97480152AE6D355CCA7845A8CA8BB2FD89BCDF20

SHA256:

E9ABDA83472C89B778D7FBB5FC468F16B38F890D1E38698750D12E4495727EA1

SSDEEP:

98304:w9bjyPMYqMM03VA1deU7Qf2UhJak49Z4SV48s1JzlAFvZUiZGkdcbhdKeie26mU9:5PZmV1giAtYiS2Sz8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • mp3el2.exe (PID: 3212)
      • ffmpeg23.exe (PID: 3960)
    • Changes the autorun value in the registry

      • nchsetup.exe (PID: 3932)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • mp3el2.exe (PID: 3212)
      • ffmpeg23.exe (PID: 3960)
    • Reads the Internet Settings

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • videopad.exe (PID: 2892)
    • Reads security settings of Internet Explorer

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • videopad.exe (PID: 2892)
    • Starts itself from another location

      • nchsetup.exe (PID: 3932)
    • Creates a software uninstall entry

      • nchsetup.exe (PID: 3932)
    • Searches for installed software

      • nchsetup.exe (PID: 3932)
    • Process requests binary or script from the Internet

      • nchsetup.exe (PID: 3932)
  • INFO

    • Create files in a temporary directory

      • vpsetup.exe (PID: 3848)
      • mp3el2.exe (PID: 3212)
      • nchsetup.exe (PID: 3932)
      • ffmpeg23.exe (PID: 3960)
      • videopad.exe (PID: 2892)
    • Reads the computer name

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • videopad.exe (PID: 2892)
      • videopad.exe (PID: 2420)
    • Checks supported languages

      • vpsetup.exe (PID: 3848)
      • nchsetup.exe (PID: 3932)
      • mp3el2.exe (PID: 3212)
      • ffmpeg23.exe (PID: 3960)
      • videopad.exe (PID: 2892)
      • videopad.exe (PID: 2420)
    • Creates files in the program directory

      • nchsetup.exe (PID: 3932)
      • mp3el2.exe (PID: 3212)
      • ffmpeg23.exe (PID: 3960)
    • Reads the machine GUID from the registry

      • nchsetup.exe (PID: 3932)
      • videopad.exe (PID: 2892)
    • Process checks computer location settings

      • videopad.exe (PID: 2892)
    • Creates files or folders in the user directory

      • videopad.exe (PID: 2892)
      • nchsetup.exe (PID: 3932)
    • Reads CPU info

      • videopad.exe (PID: 2892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:21 05:45:58+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 2560
InitializedDataSize: 6136320
UninitializedDataSize: -
EntryPoint: 0x1286
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: NCH Software
FileDescription: VideoPad Video Editor
FileVersion: 16.08
ProductVersion: 16.08
ProductName: VideoPad
LegalCopyright: NCH Software
InternalName: VideoPad
OriginalFileName: VideoPad.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start vpsetup.exe nchsetup.exe mp3el2.exe ffmpeg23.exe videopad.exe no specs videopad.exe vpsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2420"C:\Program Files\NCH Software\VideoPad\videopad.exe" -installschedC:\Program Files\NCH Software\VideoPad\videopad.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
VideoPad Video Editor
Exit code:
0
Version:
16.08
Modules
Images
c:\program files\nch software\videopad\videopad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2892"C:\Program Files\NCH Software\VideoPad\videopad.exe"C:\Program Files\NCH Software\VideoPad\videopad.exe
nchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
VideoPad Video Editor
Exit code:
0
Version:
16.08
Modules
Images
c:\program files\nch software\videopad\videopad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3212"C:\Program Files\NCH Software\VideoPad\mp3el2.exe" -LQUIET -instby fiVideoPad -instsvar VIDEOPADRelatedprogramsfreeonC:\Program Files\NCH Software\VideoPad\mp3el2.exe
nchsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\nch software\videopad\mp3el2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3652"C:\Users\admin\AppData\Local\Temp\vpsetup.exe" C:\Users\admin\AppData\Local\Temp\vpsetup.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
VideoPad Video Editor
Exit code:
3221226540
Version:
16.08
Modules
Images
c:\users\admin\appdata\local\temp\vpsetup.exe
c:\windows\system32\ntdll.dll
3848"C:\Users\admin\AppData\Local\Temp\vpsetup.exe" C:\Users\admin\AppData\Local\Temp\vpsetup.exe
explorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
VideoPad Video Editor
Exit code:
0
Version:
16.08
Modules
Images
c:\users\admin\appdata\local\temp\vpsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3932"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\vpsetup.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
vpsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
VideoPad Video Editor
Exit code:
0
Version:
16.08
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3960"C:\Users\admin\AppData\Local\Temp\VideoPad-864-1\ffmpeg23.exe" -LQUIET -instby coVideoPad -instsvar VIDEOPADRelatedprogramsfreeonLLIBInstquickoffC:\Users\admin\AppData\Local\Temp\VideoPad-864-1\ffmpeg23.exe
nchsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\videopad-864-1\ffmpeg23.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
8 896
Read events
7 311
Write events
1 569
Delete events
16

Modification events

(PID) Process:(3848) vpsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3848) vpsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3848) vpsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3848) vpsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:VideoPadInstall
Value:
C:\Users\admin\AppData\Local\Temp\vpsetup.exe
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\VideoPad\Software
Operation:writeName:SVar
Value:
VIDEOPADRelatedprogramsfreeon
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\VideoPad\Settings
Operation:writeName:InstalledByAdmin
Value:
1
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\VideoPad\UsageStatsChoice
Operation:writeName:llinad
Value:
1
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3932) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
15
Suspicious files
38
Text files
634
Unknown types
7

Dropped files

PID
Process
Filename
Type
3848vpsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cab
MD5:
SHA256:
3932nchsetup.exeC:\Program Files\NCH Software\VideoPad\shellmenu.dllexecutable
MD5:55D4973F968D671383A5CCE9564DC09E
SHA256:5345EBFEA9A98A23F5D2E6F14E0E229310CBEC5C7A569A31578061BD949B66FE
3932nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\MovieObject.bdmvbinary
MD5:D09C378F8BF32DFA8980804907476390
SHA256:786153F704EC247566EF93F4C42C8D06BA8CA5D94DBF83913B909A9C7B821FB7
3932nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\multititle\MovieObject.bdmvbinary
MD5:8F2EF4FF0BECF711DABDF3B2C5FFEB04
SHA256:046BB32D9696D10199375330D7C4004FA58C4F550759310CF39923A28AE37342
3848vpsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.datexecutable
MD5:F2011A2248873C4DB8A0F7AD3AD7E184
SHA256:78253FA531AC1799DA288CD76373F599054AC63C7112655E34E4948E857CB6D2
3932nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\index.bdmvbinary
MD5:166EEDECAE3C417CEAC1C3D6745CEF3E
SHA256:BAD301EEDFF7B31EA2A9C59B14C313DC09642932D4C69B81E65B2BFF9E6BF160
3932nchsetup.exeC:\Program Files\NCH Software\VideoPad\shellmenub.msixcompressed
MD5:FC78D31F3ED680BD577879521D749AB7
SHA256:6CBAD1180DAB86EEF82B0FF1CFE27F7E08E2083465008D280CEE85A7080ED07C
3932nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\multititle\00000.jarjava
MD5:14F0215F660805E2FBDAA8E618AAF994
SHA256:65E98A9301AF0AE9FB3444600FC0FB0B4733059352AB61A47CB8D17F914BEE54
3932nchsetup.exeC:\ProgramData\NCH Software\VideoPad\bdmv\multititle\app.discroot.crtder
MD5:81D202825BD9A79F3B6FCCA0BD9EB12A
SHA256:51C52C886D2F95DD0F86D0B140B18D4AAA12427FD2CC2BAAE52AB98F666E0B1C
3848vpsetup.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:51A6B131BD3AB1C22F55260C60FE7FC1
SHA256:ECDBFB870867E922F648819DF74D57B6098C0713337E1B780B7CF6CA7D33BD7C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
2
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3932
nchsetup.exe
GET
200
66.39.83.117:80
http://audiochannel.net/components/ffmpeg23.exe
unknown
executable
3.16 Mb
unknown
2892
videopad.exe
GET
200
66.39.83.117:80
http://audiochannel.net/components/shared/dustscratch_textures.zip
unknown
compressed
1.33 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3932
nchsetup.exe
66.39.83.117:80
audiochannel.net
PAIR-NETWORKS
US
unknown
3932
nchsetup.exe
173.247.253.164:443
secure.nch.com.au
INMOTION
US
unknown
2892
videopad.exe
66.39.83.117:80
audiochannel.net
PAIR-NETWORKS
US
unknown

DNS requests

Domain
IP
Reputation
audiochannel.net
  • 66.39.83.117
  • 173.247.250.125
whitelisted
secure.nch.com.au
  • 173.247.253.164
unknown

Threats

PID
Process
Class
Message
3932
nchsetup.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3932
nchsetup.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3932
nchsetup.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info