Source: vlc-3.0.20-win64.exe |
Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED |
Source: vlc-3.0.20-win64.exe |
Static PE information: certificate valid |
Source: vlc-3.0.20-win64.exe |
Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: vlc-3.0.20-win64.exe |
Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED |
Source: classification engine |
Classification label: clean1.winEXE@1/2@0/0 |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
File created: C:\Users\user\AppData\Local\Temp\nsj252D.tmp |
Source: vlc-3.0.20-win64.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
File read: C:\Users\desktop.ini |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
File read: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: userenv.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: apphelp.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: propsys.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: dwmapi.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: cryptbase.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: oleacc.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: version.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: shfolder.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: windows.storage.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: wldp.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: textinputframework.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Section loaded: textshaping.dll |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 |
Source: vlc-3.0.20-win64.exe |
Static PE information: certificate valid |
Source: vlc-3.0.20-win64.exe |
Static file information: File size 44420344 > 1048576 |
Source: vlc-3.0.20-win64.exe |
Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
File created: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\System.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
File created: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\LangDLL.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\System.dll |
Jump to dropped file |
Source: C:\Users\user\Desktop\vlc-3.0.20-win64.exe |
Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsz25DB.tmp\LangDLL.dll |
Jump to dropped file |