MyVideoTab by MyWay

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: January 29, 2022
Last Seen: January 29, 2022
OS(es) Affected: Windows

The MyVideoTab by MyWay software that you can find on h[tt]p://install.myvideotab[.]com/?pid=11111 and h[tt]ps://chrome.google[.]com/webstore/detail/myvideotab/bgahknbpjmchggbdoehhmbcgmmbafimh is promoted as a customized new tab, which helps you find movies easily. The MyVideoTab by MyWay software is developed by APN, LLC., and it can be installed free of charge. The program at hand is known to modify your browser settings so that you are redirected to a personalized version of Search.myway.com that you can load by navigating to h[tt]p://hp.mysearch[.]com/mvt-vcn/b2bms/index.html. You don't need to have the MyVideoTab by MyWay extension installed if you intend to use its new tab functionality. There is a catch though. The MyVideoTab by MyWay program is an ad-supported app, which requires the following privileges:

  • Read and change all your data on the websites you visit.
  • Replace the page you see when opening a new tab.
  • Read and change your browsing history.
  • Manage your downloads.
  • Manage your apps, extensions and themes.

Not running the app means that APN, LLC. is not going to have access to your extensions, themes, browsing history and all data exchanged online. That way it is likely to be hard for APN, LLC. to monetize the traffic on h[tt]p://hp.mysearch[.]com/mvt-vcn/b2bms/index.html but they will be able to record your IP, browser type and search terms. PC security experts note that MyVideoTab by MyWay is a free program that is monetized through targeted advertisements. Considering there are many users who may not be fond of ad-supported apps they may have a thing or two against how APN, LLC. collects data from MyVideoTab users. The MyVideoTab by MyWay extension may add links to Netflix, IMDB, and RottenTomatoes to your new tab page, as well as a custom search by Search.myway.com. The MyVideoTab app is perceived as a Potentially Unwanted Program (PUP) that you may consider for removal.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.DGC
Signature status: No Signature

Known Samples

MD5: 2d8b481844219e8195b119c69fe6de8c
SHA1: 69190aa4d5b7f96029837213fef0b7c9fe963cdd
SHA256: 616E5E0196D3E92240D87F73F315E4F273CCC968BC01954956593A99A7DED377
File Size: 323.07 KB, 323072 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.4.5.0
File Description JClient
File Version 1.4.5.0
Internal Name JClient.exe
Legal Copyright Copyright © 2018
Original Filename JClient.exe
Product Name JClient
Product Version 1.4.5.0

File Traits

  • .NET
  • SmartAssembly
  • x86

Block Information

Total Blocks: 646
Potentially Malicious Blocks: 243
Whitelisted Blocks: 287
Unknown Blocks: 116

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x x x x x x x x x 0 x x x x 0 x x x x ? x x x 0 ? x x x 0 x x x x 0 0 0 0 0 0 ? 0 0 0 0 0 x x 0 x 0 x 0 ? ? ? x ? ? ? x x x x ? x x x ? x 0 x x x x 0 x 0 x 0 0 0 x 0 ? ? 0 0 0 x 0 x 0 x x x 0 x 0 0 x ? 0 0 x x ? 0 0 0 0 x 0 x 0 0 0 ? 0 x x x 0 ? 0 0 x ? x ? x 0 x ? 0 0 ? x x ? x 0 x ? ? ? x x x x 0 x 0 0 ? ? 0 0 x x 0 x ? ? ? 0 x x x x ? x x 0 x ? ? ? ? x x ? 0 0 0 x ? 0 0 x ? x 0 0 x ? ? x ? x x ? x ? x ? ? 0 0 ? x x ? x ? x ? x ? x 0 x x x 0 0 x ? x x x x x ? 0 0 x x x ? x x ? ? ? 0 x ? 0 ? x ? 0 0 ? ? x x 0 x ? x 0 0 0 x 0 x ? 0 ? x ? x ? x x x 0 0 ? x ? 0 ? 0 0 x 0 x 0 0 0 0 x x 0 x 0 x x x 0 x 0 x 0 ? 0 ? 0 x ? 0 ? x x 0 ? 0 x ? ? 0 x ? 0 x 0 0 0 ? x ? 0 x x 0 0 x x 0 x x 0 ? 0 x x ? x ? 0 ? x x 0 x 0 ? x x ? ? x x 0 x x x 0 ? 0 ? 0 0 0 x x 0 ? x x x 0 x 0 0 0 x 0 ? ? x 0 ? 0 x 0 ? x ? x x x 0 ? 0 0 ? 0 x ? x x ? ? ? 0 x ? x x ? ? x x 0 x ? x ? x 0 0 x x 0 x 0 x 0 0 0 x ? 0 x x x x ? x x ? x 0 0 0 0 0 0 0 0 0 x 0 0 x ? ? x 0 0 0 x 0 ? ? x x x x x ? x x x x x x x ? 0 0 0 0 0 0 0 x x x x x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.DGC

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • inet_addr
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Keyboard Access
  • GetKeyState