File name:

FiveM.exe

Full analysis: https://app.any.run/tasks/219bb84f-79bd-4bd7-adf7-30f4e720f030
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 09, 2024, 09:01:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

3A013C0764489F527D04A4E04C4BAF97

SHA1:

ECA776AAFF56D08A1E5B7366FAD851507DB15ADC

SHA256:

18E292D57E4BE3E979E0619E88CFA48F8EBD2FF997349FEA2075942403180298

SSDEEP:

98304:HI1Vcg8O5Ou/Z1zqQfKPL3BIHU5y2Zk6kHlM6CCHaBCtDjL7Zut/5O3JOAoIWlAE:EnZ2jqDBWJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • FiveM.exe (PID: 6208)
  • SUSPICIOUS

    • Starts itself from another location

      • FiveM.exe (PID: 6160)
    • Drops the executable file immediately after the start

      • FiveM.exe (PID: 6160)
      • FiveM.exe (PID: 6208)
    • Executable content was dropped or overwritten

      • FiveM.exe (PID: 6160)
      • FiveM.exe (PID: 6208)
    • Creates a software uninstall entry

      • FiveM.exe (PID: 6208)
    • The process creates files with name similar to system file names

      • FiveM.exe (PID: 6208)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FiveM.exe (PID: 6208)
    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 6368)
      • FiveM.exe (PID: 6208)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 6208)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 6208)
  • INFO

    • Checks supported languages

      • FiveM.exe (PID: 6160)
      • FiveM.exe (PID: 6208)
      • GameBar.exe (PID: 6368)
    • Creates files or folders in the user directory

      • FiveM.exe (PID: 6160)
      • FiveM.exe (PID: 6208)
    • Reads the computer name

      • FiveM.exe (PID: 6160)
      • FiveM.exe (PID: 6208)
      • GameBar.exe (PID: 6368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:07:29 13:48:19+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3403776
InitializedDataSize: 1926656
UninitializedDataSize: -
EntryPoint: 0x2906a0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.9143
ProductVersionNumber: 2.0.0.9143
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.9143
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.9143
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem.exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6160"C:\Users\admin\AppData\Local\Temp\FiveM.exe" C:\Users\admin\AppData\Local\Temp\FiveM.exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.9143
Modules
Images
c:\users\admin\appdata\local\temp\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6208"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.9143
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6288"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
6368"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
Total events
23 819
Read events
23 801
Write events
18
Delete events
0

Modification events

(PID) Process:(6160) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\FiveM
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:Publisher
Value:
Cfx.re
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\FiveM\FiveM.exe" -uninstall app
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:URLInfoAbout
Value:
https://cfx.re/
(PID) Process:(6208) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:NoModify
Value:
1
Executable files
297
Suspicious files
77
Text files
70
Unknown types
19

Dropped files

PID
Process
Filename
Type
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnkbinary
MD5:6A3CDD7E92802C66593711079B28DA1F
SHA256:1297A78E76844DA9309371CE634EC5615FDA311465C290AB16D96E947B56A46F
6160FiveM.exeC:\Users\admin\Desktop\FiveM.lnkbinary
MD5:D62542D6B46F7403F76A1D40D3CEC244
SHA256:3287C3994959FBE9C87FF9D0151E267F728509B16D9610936A733D179BC82230
6160FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:3A013C0764489F527D04A4E04C4BAF97
SHA256:18E292D57E4BE3E979E0619E88CFA48F8EBD2FF997349FEA2075942403180298
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dll.tmpexecutable
MD5:5A6D73DCD0B102C00FB233A5A1003355
SHA256:31D4F0405F9552436B8917BAE05590F50ED0293CD8FCA4E46822C1A0CCDB239A
6208FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM - Cfx.re Development Kit (FxDK).lnkbinary
MD5:63B30348D45A36A58EBF938B6BED439C
SHA256:4F863B0EDEA4550B50C93E6721B1BF37621DB81ACC3E9291E8BAC725E05E3322
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.VisualElementsManifest.xmltext
MD5:B8180561E3C94A6371383B4541FFFFD0
SHA256:0B6FCF104FDF32515ADFFBF1633E0DF97F1C674884178848BACF981D9311D81F
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dllexecutable
MD5:5A6D73DCD0B102C00FB233A5A1003355
SHA256:31D4F0405F9552436B8917BAE05590F50ED0293CD8FCA4E46822C1A0CCDB239A
6160FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnkbinary
MD5:0B2253EFB30758D9E50075D01BD64C11
SHA256:85BB850A7C33C66AC5CC44FDD3AB1226ADACA0A74EDA062F2CFF22A019A2A5F5
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2189_aslr.bin.tmpexecutable
MD5:F4FFB9C49B03FF9362EDF6E6FE904D1B
SHA256:458284AFECE15FFD9F63C33C450241B31A324A41ACBBA0A9614DAE8427D821CA
6208FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_chrome.binexecutable
MD5:4BF2A4493DDBB65E242207270BF4FCFB
SHA256:04C9DA9D1EDE3DB137864A624A617C782BA93DBFC4FFD68318862EF95795E400
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
33
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4604
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5388
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2340
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6160
FiveM.exe
104.18.9.193:443
content.cfx.re
CLOUDFLARENET
unknown
6208
FiveM.exe
104.18.9.193:443
content.cfx.re
CLOUDFLARENET
unknown
2340
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
content.cfx.re
  • 104.18.9.193
  • 104.18.8.193
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.74
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 92.123.104.26
  • 92.123.104.33
  • 92.123.104.28
  • 92.123.104.29
  • 92.123.104.27
  • 92.123.104.30
  • 92.123.104.34
  • 92.123.104.22
  • 92.123.104.31
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info