File name:

cfosspeed-v1300-build3000.exe

Full analysis: https://app.any.run/tasks/6e7d0a32-76a5-4657-9efd-27dfaa61fe8c
Verdict: Malicious activity
Analysis date: February 26, 2024, 15:08:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
MD5:

1C7C0C9E1B0D3EB69BFB916706E549CA

SHA1:

A05B55B4C73436CE1CEDC6C4384CE03A8BACC297

SHA256:

14907BE46280AEA0162AE96DC841F5321216B2EAD63A88AEE5E0F9C2F98E607F

SSDEEP:

98304:lAfmctp5yQ0LacESM9WbdLiKOy8kbD9/wwqjGmZvwM1ZLJmP4ieOFTvcL/YfxPID:zh4Y8Z7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cfosspeed-v1300-build3000.exe (PID: 1776)
      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2148)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • cfosspeed-v1300-build3000.exe (PID: 1776)
      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Reads the Windows owner or organization settings

      • setup.exe (PID: 1492)
    • Executable content was dropped or overwritten

      • cfosspeed-v1300-build3000.exe (PID: 1776)
      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Suspicious use of NETSH.EXE

      • setup.exe (PID: 1492)
    • Reads the Internet Settings

      • setup.exe (PID: 1492)
    • Creates a software uninstall entry

      • setup.exe (PID: 1492)
    • Creates or modifies Windows services

      • setup.exe (PID: 1492)
    • Adds/modifies Windows certificates

      • setup.exe (PID: 1492)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2148)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2148)
  • INFO

    • Create files in a temporary directory

      • cfosspeed-v1300-build3000.exe (PID: 1776)
      • setup.exe (PID: 1492)
    • Checks supported languages

      • cfosspeed-v1300-build3000.exe (PID: 1776)
      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Reads the computer name

      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Reads product name

      • setup.exe (PID: 1492)
    • Reads Environment values

      • setup.exe (PID: 1492)
    • Reads Windows Product ID

      • setup.exe (PID: 1492)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 1492)
      • drvinst.exe (PID: 2148)
    • Process checks computer location settings

      • setup.exe (PID: 1492)
    • Creates files in the program directory

      • setup.exe (PID: 1492)
    • Reads the software policy settings

      • drvinst.exe (PID: 2148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:07 09:43:21+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 56832
InitializedDataSize: 142336
UninitializedDataSize: -
EntryPoint: 0x27d9
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cfosspeed-v1300-build3000.exe setup.exe netsh.exe no specs drvinst.exe rundll32.exe no specs cfosspeed-v1300-build3000.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 10 Global\{549da1df-2a90-20af-83fd-d76b8254782f} Global\{144af8fc-2c7e-6ad0-7555-c92be4acff3c} C:\Windows\System32\DriverStore\Temp\{2a274c41-5cc5-68c6-d8de-5c7d044e3a67}\speed6.inf C:\Windows\System32\DriverStore\Temp\{2a274c41-5cc5-68c6-d8de-5c7d044e3a67}\speed.catC:\Windows\System32\rundll32.exedrvinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1492"C:\Users\admin\AppData\Local\Temp\$cfsfx.0\setup.exe" -parentdir:"C:\Users\admin\Desktop\"C:\Users\admin\AppData\Local\Temp\$cfsfx.0\setup.exe
cfosspeed-v1300-build3000.exe
User:
admin
Company:
Atlas Tech Solutions SM PC
Integrity Level:
HIGH
Description:
cFosSpeed Installer
Exit code:
0
Version:
13.00.3000
Modules
Images
c:\users\admin\appdata\local\temp\$cfsfx.0\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1776"C:\Users\admin\Desktop\cfosspeed-v1300-build3000.exe" C:\Users\admin\Desktop\cfosspeed-v1300-build3000.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\cfosspeed-v1300-build3000.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
2148DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{7e0c4b27-dc93-6564-26b5-6a73a4144862}\speed6.inf" "0" "67da035fb" "000005C8" "WinSta0\Default" "000004B0" "208" "C:\Program Files\cFosSpeed"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2304netsh int tcp show globalC:\Windows\System32\netsh.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3700"C:\Users\admin\Desktop\cfosspeed-v1300-build3000.exe" C:\Users\admin\Desktop\cfosspeed-v1300-build3000.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\cfosspeed-v1300-build3000.exe
c:\windows\system32\ntdll.dll
Total events
6 416
Read events
6 290
Write events
122
Delete events
4

Modification events

(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dhcpqec.dll,-100
Value:
DHCP Quarantine Enforcement Client
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dhcpqec.dll,-101
Value:
Provides DHCP based enforcement for NAP
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dhcpqec.dll,-103
Value:
1.0
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dhcpqec.dll,-102
Value:
Microsoft Corporation
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\napipsec.dll,-1
Value:
IPsec Relying Party
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\napipsec.dll,-2
Value:
Provides IPsec based enforcement for Network Access Protection
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\napipsec.dll,-4
Value:
1.0
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\napipsec.dll,-3
Value:
Microsoft Corporation
(PID) Process:(2304) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:@%SystemRoot%\system32\tsgqec.dll,-100
Value:
RD Gateway Quarantine Enforcement Client
Executable files
88
Suspicious files
135
Text files
1 026
Unknown types
400

Dropped files

PID
Process
Filename
Type
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\cfosspeed32.cabcompressed
MD5:337DC207C41B61A60E2C2FB78CBC2D78
SHA256:59612D39BB32919A03303597696C8D154BC61A4B911BA1F863B49D2343A8CB67
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\cfosspeedsh.cabcompressed
MD5:86E3D7B7240D336F2B32E8025D01F745
SHA256:9FB380FAB5AD6A016A19E532BE655F74502CC51328D6DC584F5A871185B3289F
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\cfosspeed64.cabcompressed
MD5:E20404E76CFC8F9390E64308DE55AC98
SHA256:7925833E81A52C238E2CB5E651E0D5F3E77D9E761DE7A64BA58C5D3D14E99FA6
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\priority_tpl.htmhtml
MD5:A4A32219CD3E1B8ADDBFE6F08EFD41A9
SHA256:1CC5A5D849D04A8FBE57578DA936D05E79BEBD8D6BEA48635409950CEB0E4264
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\console_tpl.htmhtml
MD5:2B3CEC6042F36546857A07CF51C91FED
SHA256:46118C3E9E6557E364C985A0DF3A1D7A74587D64920D093702E5B8F42DC2543C
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\preferences_tpl.htmhtml
MD5:2A50363252F1CA4B16FCE767377E70B1
SHA256:3AB5AA2D72E87C99B8BC5F73C77A228424B88AE88A9C4F3CDC1020D6B9975491
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\pingstat_tpl.htmhtml
MD5:868D01A6F5E2D7B418D547E5FF2F3555
SHA256:E8DA00EEDB95A942F57D3BF171C301CD43358AED11462E64A4FF106649E627B1
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\bgraph_tpl.htmhtml
MD5:BC7DAEB0AD5F1F3DE0DD3D640F9D8ACC
SHA256:50377D5EC96EE30F2CE6E577BB24F299F5C5713C947B7C6CEEE0C2CF4C711BE3
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\programdata\pub\adapterinfo_tpl.htmxml
MD5:BBBAD469C318A11A25FCFC9EB39E6804
SHA256:B74D16380691FD36047053FAEF9F95E431F9ADE895FDB261BFE826A87E0C17A9
1776cfosspeed-v1300-build3000.exeC:\Users\admin\AppData\Local\Temp\$cfsfx.0\license.txttext
MD5:E74AFA713F690A850AB9872D2C50D1C6
SHA256:A79BF9D66765310904172B2F2DDDE19A019A9E7A62CFA2D14DD78BF5BFA80C8C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1492
setup.exe
GET
95.100.53.90:80
http://go.microsoft.com/fwlink/p/?LinkId=2124703
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1492
setup.exe
95.100.53.90:443
go.microsoft.com
AKAMAI-AS
CH
unknown
1492
setup.exe
95.100.53.90:80
go.microsoft.com
AKAMAI-AS
CH
unknown

DNS requests

Domain
IP
Reputation
atlas-cfosspeed.com
unknown
go.microsoft.com
  • 95.100.53.90
whitelisted

Threats

No threats detected
Process
Message
setup.exe
file 'C:\Program Files\cFosSpeed\cFosSpeed.ini' open error 3
setup.exe
file 'C:\Program Files\cFosSpeed\cFosSpeed.ini' open error 3
setup.exe
file 'C:\Program Files\cFosSpeed\cFosSpeed.ini' open error 3
setup.exe
file 'C:\Program Files\cFosSpeed\cFosSpeed.ini' open error 3
setup.exe
Unable to open device 'CFOSSPEED$D'.