File name:

FortresVPN.exe

Full analysis: https://app.any.run/tasks/0915cb69-07ad-4db5-b5e1-1adc6a1039ac
Verdict: Malicious activity
Analysis date: December 02, 2023, 20:58:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

D5A234DBACC4BD50D3A04960397868CA

SHA1:

BDCE9C173DFE7C5486703705C61152A53B3F1B63

SHA256:

2226E845B4555852BB50945E70991C91E1AFBDAA964A0BD45978F31555459F3D

SSDEEP:

1572864:F193auyQW6KZnzATf0JUlMAT7VCkr/VGjfb32TY:T93aQfKza0JQMAT5pr/VUf0Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FortresVPN.exe (PID: 2200)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • FortresVPN.exe (PID: 2200)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FortresVPN.exe (PID: 2200)
    • Drops 7-zip archiver for unpacking

      • FortresVPN.exe (PID: 2200)
    • Process drops legitimate windows executable

      • FortresVPN.exe (PID: 2200)
  • INFO

    • Checks supported languages

      • FortresVPN.exe (PID: 2200)
    • Reads the computer name

      • FortresVPN.exe (PID: 2200)
    • Create files in a temporary directory

      • FortresVPN.exe (PID: 2200)
    • Creates files or folders in the user directory

      • FortresVPN.exe (PID: 2200)
    • Reads the machine GUID from the registry

      • FortresVPN.exe (PID: 2200)
    • Manual execution by a user

      • FortresVPN.exe (PID: 3028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 23:26:14+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: FortresVPN © 2023
FileVersion: 1.0.0
LegalCopyright: Copyright © 2023 FortresVPN
ProductName: FortresVPN
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fortresvpn.exe no specs fortresvpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2200"C:\Users\admin\AppData\Local\Temp\FortresVPN.exe" C:\Users\admin\AppData\Local\Temp\FortresVPN.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
FortresVPN © 2023
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\fortresvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3028"C:\Users\admin\AppData\Local\Programs\FortresVPN\FortresVPN.exe" C:\Users\admin\AppData\Local\Programs\FortresVPN\FortresVPN.exeexplorer.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
MEDIUM
Description:
FortresVPN
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\programs\fortresvpn\fortresvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\fortresvpn\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
719
Read events
719
Write events
0
Delete events
0

Modification events

No data
Executable files
19
Suspicious files
120
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\app-64.7z
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\icudtl.dat
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\LICENSES.chromium.html
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\chrome_100_percent.pakbinary
MD5:443C58245EEB233D319ABF7150B99C31
SHA256:99CA6947D97DF212E45782BBD5D97BFB42112872E1C42BAB4209CEEDF66DC760
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\LICENSE.electron.txttext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\chrome_200_percent.pakbinary
MD5:81B5B74FE16C7C81870F539D5C263397
SHA256:CB4FD141A5C4D188A3ECB203E9D41A3AFCA648724160E212289ADCAC666FBFF4
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\nsis7z.dllexecutable
MD5:80E44CE4895304C6A3A831310FBF8CD0
SHA256:B393F05E8FF919EF071181050E1873C9A776E1A0AE8329AEFFF7007D0CADF592
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\installerHeaderico.icoimage
MD5:0E8D6A0503159E79700DCA57869BB657
SHA256:6B69FA073C3E7FDBCB22C727E6935453A0AA3407E302C2D917F9A8666B8ABD1A
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\SpiderBanner.dllexecutable
MD5:17309E33B596BA3A5693B4D3E85CF8D7
SHA256:996A259E53CA18B89EC36D038C40148957C978C0FD600A268497D4C92F882A93
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info