File name:

Fluency.Direct.Full.Install.Downloader.exe

Full analysis: https://app.any.run/tasks/33eedfc4-66a2-406d-9513-f790c2353848
Verdict: Malicious activity
Analysis date: October 23, 2023, 15:00:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

1BF4FD00B2C0F7E967241B64B8A16E32

SHA1:

FBF59FFB3E40974C70D0C00B466F378E53B4E0FD

SHA256:

280BBEC37189DC21FBFAA0C070AF9959D4C4C0F63908EE07C861F4B5761156C5

SSDEEP:

98304:dammKzpnfvSgsKPaJTSNybHCcj2Ta6fHv2ZPO3Dqy44R3rvAQi6J1+yCpAXj9lJH:C0Vr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Fluency.Direct.Full.Install.Downloader.exe (PID: 2160)
    • Application was dropped or rewritten from another process

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
    • Loads dropped or rewritten executable

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Fluency.Direct.Full.Install.Downloader.exe (PID: 2160)
    • Reads the Internet Settings

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
    • Reads Internet Explorer settings

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
  • INFO

    • Create files in a temporary directory

      • Fluency.Direct.Full.Install.Downloader.exe (PID: 2160)
    • Checks supported languages

      • Fluency.Direct.Full.Install.Downloader.exe (PID: 2160)
      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
    • Reads the computer name

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
    • Reads Environment values

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
    • Reads the machine GUID from the registry

      • Fluency.Direct.Downloader.Setup.exe (PID: 3800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2001:03:20 07:35:57+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Aggressive working-set trim, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 4096
UninitializedDataSize: 77824
EntryPoint: 0x19200
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start fluency.direct.full.install.downloader.exe fluency.direct.downloader.setup.exe fluency.direct.full.install.downloader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2160"C:\Users\admin\Downloads\Fluency.Direct.Full.Install.Downloader.exe" C:\Users\admin\Downloads\Fluency.Direct.Full.Install.Downloader.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\fluency.direct.full.install.downloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2464"C:\Users\admin\Downloads\Fluency.Direct.Full.Install.Downloader.exe" C:\Users\admin\Downloads\Fluency.Direct.Full.Install.Downloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\fluency.direct.full.install.downloader.exe
c:\windows\system32\ntdll.dll
3800Fluency.Direct.Downloader.Setup.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\Fluency.Direct.Downloader.Setup.exe
Fluency.Direct.Full.Install.Downloader.exe
User:
admin
Company:
M*Modal
Integrity Level:
HIGH
Description:
M*Modal Fluency Direct Download
Exit code:
0
Version:
8.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\fluency.direct.full.install.downloader\fluency.direct.downloader.setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
387
Read events
387
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\cpuBenchmarks.csvbinary
MD5:47214FDB397AA51306206B7E372A545F
SHA256:89F41348FC6291408F34A3BD517D06BD1BCA8423694ADB6C1AD1C64140426715
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\FED02F.tmptext
MD5:CD621C352799BC3EAB0D763679E0484E
SHA256:66407942980B3E3DD5D7F246A18D2D89929A749B0EC1FA2E29A800BB958A4301
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\custom_settings.inibinary
MD5:8F6056741DB02B9BBA635E048C3A1F7F
SHA256:7ED1EE8C0D7C29BD4B77F65B9B274C99042F093CE68F4A6AD2272980CA746331
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\Ionic.Zip.dllexecutable
MD5:58398593E580F8A503D87A9A8DB94EA5
SHA256:67EDD34F274345C78DFFAC7BBB2511CBEA433E0D69CD13261DA9562B9F4C0D35
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\read.me.txttext
MD5:C076A9F960AB67E0A0A56B9469127221
SHA256:67230A110DE73A382B57D3F6C07CC945D477EF29D31749A23D667F8D0AACA9B4
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\runasexe.battext
MD5:A2633FBD42F2C6AFD38C87DE44189621
SHA256:E2AD12FAFDCEE30D05383C584AF25EF166DB72E4A81FD5109E74487DD869C162
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\ndp48-web.exeexecutable
MD5:40604BAF5A025F4B23CBE463239B68CB
SHA256:B9821F28FACFD6B11FFBF3703FF3F218CC3C31B85D6503D5C20570751FF08876
3800Fluency.Direct.Downloader.Setup.exeC:\Users\admin\Downloads\DownloadList.en-ca.initext
MD5:5E50DCAA635AFE289A6EC8E59B6480E2
SHA256:4B1799E4324088B1E11A8DE520E917A384B8A0D70A1637989ED5539A993FBA96
2160Fluency.Direct.Full.Install.Downloader.exeC:\Users\admin\AppData\Local\Temp\Fluency.Direct.Full.Install.Downloader\Fluency.Direct.Downloader.Setup.exeexecutable
MD5:D6BF2B71B8464F3156A221F62DF7A01F
SHA256:6886F62D88448643142FBAA76579F5DFDEDE382EC91295717AD32775FEF8BB77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3800
Fluency.Direct.Downloader.Setup.exe
GET
404
52.217.197.145:80
http://fluencydirect-distro.s3.amazonaws.com/releases/Fluency.Direct.12.1.43.7.en-ca.zip
unknown
xml
314 b
unknown
3800
Fluency.Direct.Downloader.Setup.exe
GET
200
52.217.197.145:80
http://fluencydirect-distro.s3.amazonaws.com/releases/DownloadList.ini
unknown
text
17.4 Kb
unknown
3800
Fluency.Direct.Downloader.Setup.exe
GET
404
52.217.197.145:80
http://fluencydirect-distro.s3.amazonaws.com/releases/Fluency.Direct.12.1.43.7.en-ca.zip
unknown
xml
314 b
unknown
3800
Fluency.Direct.Downloader.Setup.exe
GET
404
52.217.197.145:80
http://fluencydirect-distro.s3.amazonaws.com/releases/Fluency.Direct.12.1.43.7.en-ca.zip
unknown
xml
314 b
unknown
3800
Fluency.Direct.Downloader.Setup.exe
GET
404
52.217.197.145:80
http://fluencydirect-distro.s3.amazonaws.com/releases/Fluency.Direct.12.1.43.7.Client.en-ca.zip
unknown
xml
321 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3800
Fluency.Direct.Downloader.Setup.exe
52.217.197.145:80
fluencydirect-distro.s3.amazonaws.com
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
fluencydirect-distro.s3.amazonaws.com
  • 52.217.197.145
  • 52.217.87.156
  • 52.217.125.17
  • 54.231.223.57
  • 52.217.72.108
  • 3.5.29.254
  • 3.5.6.160
  • 54.231.198.113
unknown

Threats

No threats detected
No debug info