File name:

FiveM (1).exe

Full analysis: https://app.any.run/tasks/69762ff4-ad0c-473c-a310-806fa9ef40f7
Verdict: Malicious activity
Analysis date: July 07, 2024, 03:51:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

C397F272B00FF8221678E28CDF0F7E3A

SHA1:

721E8237EDA2F3EBA05307B50EDB49162B06D0DC

SHA256:

2A17EECCA2D73F4F148C81938F18463887561703CEA09565EBF85DC39E5B2C65

SSDEEP:

98304:Cs1u/BuMzTdCvx4JQfXBAk9XJrCmA1bjgy1klNPB0E+0lnJyKOaB05He/tzFEeeL:u1mL+MFe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
      • FiveM (1).exe (PID: 1120)
      • FiveM.exe (PID: 5264)
    • Actions looks like stealing of personal data

      • FiveM.exe (PID: 5264)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
      • FiveM.exe (PID: 5264)
      • GameBar.exe (PID: 5148)
    • Executable content was dropped or overwritten

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
      • FiveM.exe (PID: 5264)
      • FiveM (1).exe (PID: 1120)
    • Starts application with an unusual extension

      • FiveM (1).exe (PID: 1124)
    • Reads the date of Windows installation

      • CitizenFX.exe.new (PID: 4168)
    • Starts itself from another location

      • CitizenFX.exe.new (PID: 4168)
      • FiveM (1).exe (PID: 1120)
    • Creates a software uninstall entry

      • FiveM.exe (PID: 5264)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FiveM.exe (PID: 5264)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 5264)
  • INFO

    • Create files in a temporary directory

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
    • Reads the computer name

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
      • FiveM.exe (PID: 5264)
      • GameBar.exe (PID: 5148)
      • FiveM (1).exe (PID: 1120)
    • Checks supported languages

      • FiveM (1).exe (PID: 1124)
      • CitizenFX.exe.new (PID: 4168)
      • FiveM (1).exe (PID: 1120)
      • FiveM.exe (PID: 5264)
      • GameBar.exe (PID: 5148)
    • Process checks computer location settings

      • CitizenFX.exe.new (PID: 4168)
    • Creates files or folders in the user directory

      • FiveM.exe (PID: 5264)
      • FiveM (1).exe (PID: 1120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:06:25 16:09:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3393024
InitializedDataSize: 1921536
UninitializedDataSize: -
EntryPoint: 0x28e3b0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.8691
ProductVersionNumber: 2.0.0.8691
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.8691
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.8691
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem (1).exe citizenfx.exe.new fivem (1).exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1120"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
CitizenFX.exe.new
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1124"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3580"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
4168CitizenFX.exe.new -bootstrap "C:\Users\admin\AppData\Local\Temp\FiveM (1).exe"C:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new
FiveM (1).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\citizenfx.exe.new
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5148"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
5264"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM (1).exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
1073807364
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
31 377
Read events
31 349
Write events
28
Delete events
0

Modification events

(PID) Process:(1124) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(4168) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4168) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4168) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4168) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1120) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(5264) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(5264) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(5264) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(5264) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
Executable files
143
Suspicious files
9
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1124FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.newexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
4168CitizenFX.exe.newC:\Users\admin\AppData\Local\Temp\FiveM (1).exeexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
1120FiveM (1).exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
1120FiveM (1).exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnklnk
MD5:ACEA81A49529D9E08114A4A75E36BB97
SHA256:0638439674EB0BD0B2B250F617BD31BB6B4D6F279E9AB210BDE277F38FDF9833
5264FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.VisualElementsManifest.xmltext
MD5:B8180561E3C94A6371383B4541FFFFD0
SHA256:0B6FCF104FDF32515ADFFBF1633E0DF97F1C674884178848BACF981D9311D81F
5264FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:5F71253BCD2264B757075C86D19717CD
SHA256:DFBFE1BB0439EC4A621B2D0EF8A5846097D46EE8D62D7C292DAB0D9AC7886B00
5264FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dll.tmpexecutable
MD5:505456B61E71997CF377B168FB495BA6
SHA256:911B21E14E6E0D89A2367F8E7965381B72B85C02ED96E97DFBBCC5F63BF84BAA
1124FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new.tmpexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
4168CitizenFX.exe.newC:\Users\admin\AppData\Local\Temp\FiveM (1).exe.oldexecutable
MD5:C397F272B00FF8221678E28CDF0F7E3A
SHA256:2A17EECCA2D73F4F148C81938F18463887561703CEA09565EBF85DC39E5B2C65
5264FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1604_aslr.bin.tmpexecutable
MD5:F121B62255B2B3B9DE721181F0313136
SHA256:9ABD8C7BDCDBA024D91896F7C21F62CCFAA1D5363BAB2CF213612EA4CE00E5A9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
49
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
2448
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4016
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
4016
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
2448
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2448
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2868
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1972
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1124
FiveM (1).exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
4656
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
unknown
4656
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1120
FiveM (1).exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
4656
SearchApp.exe
204.79.197.222:443
fp.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
content.cfx.re
  • 104.18.34.171
  • 172.64.153.85
unknown
www.bing.com
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.139
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted
fp-vs.azureedge.net
  • 152.199.19.161
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.60
unknown
mcr-ring.msedge.net
  • 150.171.70.254
  • 150.171.69.254
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info