Analysis

  • max time kernel
    140s
  • max time network
    120s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:29

General

  • Target

    bin/Background.mp4

  • Size

    4.6MB

  • MD5

    9782180eb68f73030fe24ef6a1735932

  • SHA1

    589827fe098ba048c9f871a28db8eae3e3537ff4

  • SHA256

    3a1cbb800f8f25c2ab703ba8bfdb01e938e4143c3bc0fea8ca734fb5ba779ba7

  • SHA512

    dc768638bae2d6d47d8910252ae64a656d8a6fd88efdf24165ddce51b7afdb4acb3fddd41dfe788737a2cab4fab66174db2f0d2f48bc8669af76d1656bca8be1

  • SSDEEP

    98304:xs/6Ldccul3Wn48btjNEkPSFTaIwJ0Mt6KNY:xs/Gul3EvEmFItMkb

Score
1/10

Malware Config

Signatures

  • Suspicious behavior: AddClipboardFormatListener 1 IoCs
  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of AdjustPrivilegeToken 2 IoCs
  • Suspicious use of FindShellTrayWindow 27 IoCs
  • Suspicious use of SendNotifyMessage 8 IoCs
  • Suspicious use of SetWindowsHookEx 1 IoCs

Processes

  • C:\Program Files\VideoLAN\VLC\vlc.exe
    "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "C:\Users\Admin\AppData\Local\Temp\bin\Background.mp4"
    1⤵
    • Suspicious behavior: AddClipboardFormatListener
    • Suspicious behavior: GetForegroundWindowSpam
    • Suspicious use of AdjustPrivilegeToken
    • Suspicious use of FindShellTrayWindow
    • Suspicious use of SendNotifyMessage
    • Suspicious use of SetWindowsHookEx
    PID:2436

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/2436-5-0x000000013F460000-0x000000013F558000-memory.dmp
    Filesize

    992KB

  • memory/2436-6-0x000007FEF7890000-0x000007FEF78C4000-memory.dmp
    Filesize

    208KB

  • memory/2436-8-0x000007FEFB550000-0x000007FEFB568000-memory.dmp
    Filesize

    96KB

  • memory/2436-13-0x000007FEF6A20000-0x000007FEF6A3D000-memory.dmp
    Filesize

    116KB

  • memory/2436-14-0x000007FEF6A00000-0x000007FEF6A11000-memory.dmp
    Filesize

    68KB

  • memory/2436-7-0x000007FEF5EC0000-0x000007FEF6176000-memory.dmp
    Filesize

    2.7MB

  • memory/2436-12-0x000007FEF6A40000-0x000007FEF6A51000-memory.dmp
    Filesize

    68KB

  • memory/2436-11-0x000007FEF75F0000-0x000007FEF7607000-memory.dmp
    Filesize

    92KB

  • memory/2436-10-0x000007FEF7610000-0x000007FEF7621000-memory.dmp
    Filesize

    68KB

  • memory/2436-9-0x000007FEFA7D0000-0x000007FEFA7E7000-memory.dmp
    Filesize

    92KB

  • memory/2436-15-0x000007FEF5CB0000-0x000007FEF5EBB000-memory.dmp
    Filesize

    2.0MB

  • memory/2436-27-0x000007FEF4B40000-0x000007FEF4BA7000-memory.dmp
    Filesize

    412KB

  • memory/2436-26-0x000007FEF4BB0000-0x000007FEF4BE0000-memory.dmp
    Filesize

    192KB

  • memory/2436-30-0x000007FEF4A40000-0x000007FEF4A97000-memory.dmp
    Filesize

    348KB

  • memory/2436-16-0x000007FEF4C00000-0x000007FEF5CB0000-memory.dmp
    Filesize

    16.7MB

  • memory/2436-32-0x000007FEF48A0000-0x000007FEF48B7000-memory.dmp
    Filesize

    92KB

  • memory/2436-31-0x000007FEF48C0000-0x000007FEF4A40000-memory.dmp
    Filesize

    1.5MB

  • memory/2436-29-0x000007FEF4AA0000-0x000007FEF4AB1000-memory.dmp
    Filesize

    68KB

  • memory/2436-28-0x000007FEF4AC0000-0x000007FEF4B3C000-memory.dmp
    Filesize

    496KB

  • memory/2436-25-0x000007FEF4BE0000-0x000007FEF4BF8000-memory.dmp
    Filesize

    96KB

  • memory/2436-24-0x000007FEF64F0000-0x000007FEF6501000-memory.dmp
    Filesize

    68KB

  • memory/2436-23-0x000007FEF6510000-0x000007FEF652B000-memory.dmp
    Filesize

    108KB

  • memory/2436-22-0x000007FEF6530000-0x000007FEF6541000-memory.dmp
    Filesize

    68KB

  • memory/2436-21-0x000007FEF6550000-0x000007FEF6561000-memory.dmp
    Filesize

    68KB

  • memory/2436-20-0x000007FEF6570000-0x000007FEF6581000-memory.dmp
    Filesize

    68KB

  • memory/2436-19-0x000007FEF6590000-0x000007FEF65A8000-memory.dmp
    Filesize

    96KB

  • memory/2436-18-0x000007FEF69D0000-0x000007FEF69F1000-memory.dmp
    Filesize

    132KB

  • memory/2436-17-0x000007FEF65B0000-0x000007FEF65F1000-memory.dmp
    Filesize

    260KB

  • memory/2436-35-0x000007FEF2E00000-0x000007FEF2E12000-memory.dmp
    Filesize

    72KB

  • memory/2436-34-0x000007FEF2E20000-0x000007FEF3026000-memory.dmp
    Filesize

    2.0MB

  • memory/2436-37-0x000007FEF2D60000-0x000007FEF2DAD000-memory.dmp
    Filesize

    308KB

  • memory/2436-39-0x000007FEF2B90000-0x000007FEF2BE7000-memory.dmp
    Filesize

    348KB

  • memory/2436-38-0x000007FEF2BF0000-0x000007FEF2D5B000-memory.dmp
    Filesize

    1.4MB

  • memory/2436-33-0x000007FEF3030000-0x000007FEF489F000-memory.dmp
    Filesize

    24.4MB

  • memory/2436-47-0x000007FEF2740000-0x000007FEF27A2000-memory.dmp
    Filesize

    392KB

  • memory/2436-49-0x000007FEF2620000-0x000007FEF2635000-memory.dmp
    Filesize

    84KB

  • memory/2436-48-0x000007FEF26D0000-0x000007FEF273D000-memory.dmp
    Filesize

    436KB

  • memory/2436-51-0x000007FEF2350000-0x000007FEF2365000-memory.dmp
    Filesize

    84KB

  • memory/2436-53-0x000007FEF22E0000-0x000007FEF22F3000-memory.dmp
    Filesize

    76KB

  • memory/2436-55-0x000007FEF1DF0000-0x000007FEF1E01000-memory.dmp
    Filesize

    68KB

  • memory/2436-56-0x000007FEF1D80000-0x000007FEF1DE1000-memory.dmp
    Filesize

    388KB

  • memory/2436-57-0x000007FEF1D30000-0x000007FEF1D77000-memory.dmp
    Filesize

    284KB

  • memory/2436-60-0x000007FEF14F0000-0x000007FEF153E000-memory.dmp
    Filesize

    312KB

  • memory/2436-62-0x000007FEEFC80000-0x000007FEEFCB4000-memory.dmp
    Filesize

    208KB

  • memory/2436-61-0x000007FEEFCC0000-0x000007FEEFD17000-memory.dmp
    Filesize

    348KB

  • memory/2436-59-0x000007FEF1B40000-0x000007FEF1B51000-memory.dmp
    Filesize

    68KB

  • memory/2436-58-0x000007FEF1CB0000-0x000007FEF1D24000-memory.dmp
    Filesize

    464KB

  • memory/2436-54-0x000007FEF21D0000-0x000007FEF22D6000-memory.dmp
    Filesize

    1.0MB

  • memory/2436-52-0x000007FEF2300000-0x000007FEF2323000-memory.dmp
    Filesize

    140KB

  • memory/2436-50-0x000007FEF2370000-0x000007FEF2620000-memory.dmp
    Filesize

    2.7MB

  • memory/2436-46-0x000007FEF27B0000-0x000007FEF27F2000-memory.dmp
    Filesize

    264KB

  • memory/2436-45-0x000007FEF2800000-0x000007FEF28C5000-memory.dmp
    Filesize

    788KB

  • memory/2436-44-0x000007FEF28D0000-0x000007FEF28E6000-memory.dmp
    Filesize

    88KB

  • memory/2436-43-0x000007FEF28F0000-0x000007FEF2901000-memory.dmp
    Filesize

    68KB

  • memory/2436-42-0x000007FEF2910000-0x000007FEF293F000-memory.dmp
    Filesize

    188KB

  • memory/2436-41-0x000007FEFA7C0000-0x000007FEFA7D0000-memory.dmp
    Filesize

    64KB

  • memory/2436-40-0x000007FEF2940000-0x000007FEF2B81000-memory.dmp
    Filesize

    2.3MB

  • memory/2436-36-0x000007FEF2DB0000-0x000007FEF2DF2000-memory.dmp
    Filesize

    264KB

  • memory/2436-65-0x000007FEF5EC0000-0x000007FEF6176000-memory.dmp
    Filesize

    2.7MB