File name:

FiveM.exe

Full analysis: https://app.any.run/tasks/699e7cdc-0db5-471e-a8c3-c0eda8f52f02
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 02, 2024, 18:42:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

E8C3FD1B35507FA301FAC9367F28757F

SHA1:

FD03919C9370248A62C9D540F6CD9FBECCAC09F6

SHA256:

05A99A0067DDDE35A8B6C92721FC8EE058FFE1CEE9A9DCEB2BAFB1A8E2D92368

SSDEEP:

98304:kP1CJqKCLt/w7rImQfbiHdj+Qu/3yTVMj9N36V2txB9ROtJgmgwd0ARKZdlXrlEh:6y5uOtOlq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 4128)
      • FiveM.exe (PID: 1640)
    • Executable content was dropped or overwritten

      • FiveM.exe (PID: 1640)
      • FiveM.exe (PID: 3848)
      • CitizenFX.exe.new (PID: 1696)
      • FiveM.exe (PID: 6556)
    • Starts itself from another location

      • FiveM.exe (PID: 3848)
      • CitizenFX.exe.new (PID: 1696)
      • FiveM.exe (PID: 6556)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 6556)
    • Starts application with an unusual extension

      • FiveM.exe (PID: 1640)
      • FiveM.exe (PID: 6556)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 6556)
  • INFO

    • Reads the computer name

      • FiveM.exe (PID: 1640)
      • GameBar.exe (PID: 4128)
    • Checks supported languages

      • GameBar.exe (PID: 4128)
      • FiveM.exe (PID: 1640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:10:09 08:56:51+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3383296
InitializedDataSize: 1909760
UninitializedDataSize: -
EntryPoint: 0x28cd20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.6775
ProductVersionNumber: 2.0.0.6775
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.6775
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.6775
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs gamebarpresencewriter.exe no specs citizenfx.exe.new fivem.exe fivem.exe gamebarpresencewriter.exe no specs fivem_b2699_dumpserver gamebarpresencewriter.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1640"C:\Users\admin\Desktop\FiveM.exe" C:\Users\admin\Desktop\FiveM.exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.6775
Modules
Images
c:\users\admin\desktop\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1696CitizenFX.exe.new -bootstrap "C:\Users\admin\Desktop\FiveM.exe"C:\Users\admin\Desktop\CitizenFX.exe.new
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.10011
Modules
Images
c:\users\admin\desktop\citizenfx.exe.new
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
3848"C:\Users\admin\Desktop\FiveM.exe" C:\Users\admin\Desktop\FiveM.exe
CitizenFX.exe.new
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.10011
Modules
Images
c:\users\admin\desktop\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
4128"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
5612"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
5656"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
6360"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
6556"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.10011
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\win32u.dll
6688"C:\Users\admin\AppData\Local\FiveM\FiveM.app\data\cache\subprocess\FiveM_b2699_DumpServer" -dumpserver:2060 -parentpid:6556C:\Users\admin\AppData\Local\FiveM\FiveM.app\data\cache\subprocess\FiveM_b2699_DumpServer
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.10011
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_b2699_dumpserver
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
7020"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
Total events
26 347
Read events
26 285
Write events
62
Delete events
0

Modification events

(PID) Process:(1640) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\Desktop\
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionMajor
Value:
02001A83C5DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionMinor
Value:
22001A83C5DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionBuild
Value:
616D1A83C5DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionRevision
Value:
00001A83C5DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:PreviousAppTerminationFromSuspended
Value:
001A83C5DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:CurrentDisplayMonitor
Value:
670061006D0065000000E8ADCCDBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:StartupTipIndex
Value:
0100000000000000C174D1DBFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionMajor
Value:
02005A0675DDFA14DB01
(PID) Process:(4128) GameBar.exeKey:\REGISTRY\A\{25ea3739-49e1-8a4e-7768-b8ecfa983ebd}\LocalState
Operation:writeName:InstalledVersionMinor
Value:
22005A0675DDFA14DB01
Executable files
416
Suspicious files
156
Text files
231
Unknown types
2

Dropped files

PID
Process
Filename
Type
1640FiveM.exeC:\Users\admin\Desktop\CitizenFX.exe.newexecutable
MD5:224E0E23FCD9128FEE27D7ADF59EBBFE
SHA256:389BFA7307679A9875AA41351B942724964BC0ED4763C442D1288FE693782066
3848FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:224E0E23FCD9128FEE27D7ADF59EBBFE
SHA256:389BFA7307679A9875AA41351B942724964BC0ED4763C442D1288FE693782066
1696CitizenFX.exe.newC:\Users\admin\Desktop\FiveM.exe.oldexecutable
MD5:E8C3FD1B35507FA301FAC9367F28757F
SHA256:05A99A0067DDDE35A8B6C92721FC8EE058FFE1CEE9A9DCEB2BAFB1A8E2D92368
3848FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnklnk
MD5:64E4EC6D9ED9D7ADD5CAF95118EC1F13
SHA256:F3316898C3D685F3FF16C2032B44D998C1A2BE80B009BC6CD0ED3AA1AC406A43
6556FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\desktop.initext
MD5:9D2F20E16EC4711FFD07D7BE13BAD063
SHA256:D6967B5C56EDD0A0D0340663EF91E4BD20981752977590B688B18060E7220682
3848FiveM.exeC:\Users\admin\Desktop\FiveM.lnklnk
MD5:AA865BD40D03B6607D75FCB9C9C5F35C
SHA256:4CC398CBF932E602F1C5D5CEEB31EFD05C5821BFF3BC0AC6C692B92D4D33E1B0
6556FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.VisualElementsManifest.xmltext
MD5:B8180561E3C94A6371383B4541FFFFD0
SHA256:0B6FCF104FDF32515ADFFBF1633E0DF97F1C674884178848BACF981D9311D81F
6556FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnkbinary
MD5:EAF48D806A2DD4D3639727CC4CF09E46
SHA256:E33A2EC4ECF2FE7CBE4BD9C1BDE100E9B105D814FF1149D4083CEB8455250A06
1696CitizenFX.exe.newC:\Users\admin\Desktop\FiveM.exeexecutable
MD5:224E0E23FCD9128FEE27D7ADF59EBBFE
SHA256:389BFA7307679A9875AA41351B942724964BC0ED4763C442D1288FE693782066
6556FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM - Cfx.re Development Kit (FxDK).lnkbinary
MD5:1F697E5348A914C559A5F4A3CD3837F2
SHA256:FCED1D637DA21FD8C04112AD57C6ACA5043F8590E5E26575C1C6CA5B8A49782A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
325
TCP/UDP connections
40
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3324
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
104.18.34.171:443
https://content.cfx.re/updates/22/f9/22f9e604cbe126cf7b68d644c64e625f91b55294f6af945f4c41afb5f4188181.xz
unknown
binary
746 Kb
unknown
GET
200
104.18.34.171:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1727894555
unknown
text
7 b
unknown
GET
200
104.18.34.171:443
https://content.cfx.re/updates/ab/f0/abf04d91a5c1e60ade3fda83c603457cbfcb0958dffa0a71b11d847968c73ee5.xz
unknown
binary
750 Kb
unknown
GET
200
172.64.153.85:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1727894564
unknown
text
7 b
unknown
GET
200
172.64.153.85:443
https://content.cfx.re/updates/38/9b/389bfa7307679a9875aa41351b942724964bc0ed4763c442d1288fe693782066.xz
unknown
binary
1.83 Mb
unknown
GET
200
104.18.34.171:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1727894563
unknown
text
7 b
unknown
GET
200
172.64.153.85:443
https://content.cfx.re/updates/65/4d/654d60def7da2aeb985a373a36ffb71efe0d1f88f68ec82c0ab35da762d8fc06
unknown
text
94.3 Kb
unknown
GET
200
104.18.34.171:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1727894566
unknown
text
7 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3324
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1640
FiveM.exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
2120
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3324
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3324
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 172.217.23.110
whitelisted
content.cfx.re
  • 104.18.34.171
  • 172.64.153.85
unknown
www.microsoft.com
  • 23.35.229.160
whitelisted
browser.pipe.aria.microsoft.com
  • 20.189.173.12
whitelisted
sentry.fivem.net
  • 172.64.148.97
  • 104.18.39.159
whitelisted

Threats

No threats detected
Process
Message
FiveM_b2699_DumpServer
DumpServer is active and waiting.