Windows Analysis Report
vlc-3.0.20-win64.exe

Overview

General Information

Sample name: vlc-3.0.20-win64.exe
Analysis ID: 1431704
MD5: 3d63e3a94c39a18f4da866b896b41e80
SHA1: c9520268936bfa6d060c8603cdee753db214d0ce
SHA256: d8055b6643651ca5b9ad58c438692a481483657f3f31624cdfa68b92e8394a57
Infos:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Drops PE files
Found dropped PE file which has not been started or loaded
Uses 32bit PE files

Classification

Source: vlc-3.0.20-win64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: vlc-3.0.20-win64.exe Static PE information: certificate valid
Source: vlc-3.0.20-win64.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: vlc-3.0.20-win64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: classification engine Classification label: clean1.winEXE@1/2@0/0
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe File created: C:\Users\user\AppData\Local\Temp\nsj252D.tmp
Source: vlc-3.0.20-win64.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe File read: C:\Users\desktop.ini
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe File read: C:\Users\user\Desktop\vlc-3.0.20-win64.exe
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: oleacc.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: shfolder.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32
Source: vlc-3.0.20-win64.exe Static PE information: certificate valid
Source: vlc-3.0.20-win64.exe Static file information: File size 44420344 > 1048576
Source: vlc-3.0.20-win64.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe File created: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe File created: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\LangDLL.dll Jump to dropped file
⊘No contacted IP infos