File name:

FortresVPN.exe

Full analysis: https://app.any.run/tasks/0915cb69-07ad-4db5-b5e1-1adc6a1039ac
Verdict: Malicious activity
Analysis date: December 02, 2023, 20:58:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

D5A234DBACC4BD50D3A04960397868CA

SHA1:

BDCE9C173DFE7C5486703705C61152A53B3F1B63

SHA256:

2226E845B4555852BB50945E70991C91E1AFBDAA964A0BD45978F31555459F3D

SSDEEP:

1572864:F193auyQW6KZnzATf0JUlMAT7VCkr/VGjfb32TY:T93aQfKza0JQMAT5pr/VUf0Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FortresVPN.exe (PID: 2200)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • FortresVPN.exe (PID: 2200)
    • The process creates files with name similar to system file names

      • FortresVPN.exe (PID: 2200)
    • Drops 7-zip archiver for unpacking

      • FortresVPN.exe (PID: 2200)
    • Process drops legitimate windows executable

      • FortresVPN.exe (PID: 2200)
  • INFO

    • Checks supported languages

      • FortresVPN.exe (PID: 2200)
    • Reads the computer name

      • FortresVPN.exe (PID: 2200)
    • Create files in a temporary directory

      • FortresVPN.exe (PID: 2200)
    • Creates files or folders in the user directory

      • FortresVPN.exe (PID: 2200)
    • Manual execution by a user

      • FortresVPN.exe (PID: 3028)
    • Reads the machine GUID from the registry

      • FortresVPN.exe (PID: 2200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 23:26:14+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: FortresVPN © 2023
FileVersion: 1.0.0
LegalCopyright: Copyright © 2023 FortresVPN
ProductName: FortresVPN
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fortresvpn.exe no specs fortresvpn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2200"C:\Users\admin\AppData\Local\Temp\FortresVPN.exe" C:\Users\admin\AppData\Local\Temp\FortresVPN.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
FortresVPN © 2023
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\fortresvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3028"C:\Users\admin\AppData\Local\Programs\FortresVPN\FortresVPN.exe" C:\Users\admin\AppData\Local\Programs\FortresVPN\FortresVPN.exeexplorer.exe
User:
admin
Company:
GitHub, Inc.
Integrity Level:
MEDIUM
Description:
FortresVPN
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\programs\fortresvpn\fortresvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\fortresvpn\ffmpeg.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
719
Read events
719
Write events
0
Delete events
0

Modification events

No data
Executable files
19
Suspicious files
120
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\app-64.7z
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\icudtl.dat
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\LICENSES.chromium.html
MD5:
SHA256:
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\LICENSE.electron.txttext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\locales\ca.pakbinary
MD5:2CDDD012546CAF0AED6775CDF5CFDEE9
SHA256:02D60B97F70C31F5C5003108321FC3AC3C79BF39A36392C3ADAF7735B9CC1C1D
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\SpiderBanner.dllexecutable
MD5:17309E33B596BA3A5693B4D3E85CF8D7
SHA256:996A259E53CA18B89EC36D038C40148957C978C0FD600A268497D4C92F882A93
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\locales\am.pakbinary
MD5:4CB4B30911E9FBFE6C1DE688CCA821AB
SHA256:685ECDFF01D4AE92BE1D900EF00FD8632616BC41F18A56E682528F312D4A5167
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\chrome_100_percent.pakbinary
MD5:443C58245EEB233D319ABF7150B99C31
SHA256:99CA6947D97DF212E45782BBD5D97BFB42112872E1C42BAB4209CEEDF66DC760
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\chrome_200_percent.pakbinary
MD5:81B5B74FE16C7C81870F539D5C263397
SHA256:CB4FD141A5C4D188A3ECB203E9D41A3AFCA648724160E212289ADCAC666FBFF4
2200FortresVPN.exeC:\Users\admin\AppData\Local\Temp\nsb53E8.tmp\7z-out\locales\af.pakbinary
MD5:B293CC5EA7DB02649BD7D386B8FA0624
SHA256:7BB75ADEF02D28819F1BD3B42FA46ED56D6DFBEAE072341997B09B8C1F52D8DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info