| File name: | FSDCInstaller_20241128_r2844-1733447696861.exe |
| Full analysis: | https://app.any.run/tasks/4181b50d-5a2a-4c48-8de7-8b33ab57dd97 |
| Verdict: | Malicious activity |
| Analysis date: | December 06, 2024, 09:01:52 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | F3244A1763AE0B426541A88C4D734642 |
| SHA1: | 4C8448F89D1CC45222F3E4D8EFF1A22078F7B12A |
| SHA256: | 32B22826414329CF462225459CE497C4CF8DEB7721B612C04EA56E6B86D062BF |
| SSDEEP: | 98304:rTkYWuhv8nYg9b9Z7QHIbbfeNGj547SnxgUae8Fyq85mkxxUA/8w9R6lgdA8yaeT:TvqFMFbsf7eRd/q7UH31mn9 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:09:25 21:55:49+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x34f7 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | netsh advfirewall firewall set rule name = all protocol = TCP localport = 9528 new action = allow | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 556 | netsh advfirewall firewall set rule name = all protocol = UDP localport = 7089 new action = allow | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1140 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | netsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2212 | netsh advfirewall firewall delete rule name = "TCP 9527" | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2828 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | netsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3140 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | netsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3640 | netsh advfirewall firewall set rule name = all protocol = UDP localport = 7117 new action = allow | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3700 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | netsh.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3952 | netsh advfirewall firewall set rule name = all protocol = TCP localport = 9527 new action = allow | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4628 | netsh advfirewall firewall delete rule name = "UDP 7088" | C:\Windows\SysWOW64\netsh.exe | — | FSDCInstaller_20241128_r2844-1733447696861.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6896) FSDCInstaller_20241128_r2844-1733447696861.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Friendess\DataCenter |
| Operation: | write | Name: | LatestVersion |
Value: V2.7.1.1 | |||
| (PID) Process: | (5252) fsdc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Friendess\DataCenter |
| Operation: | write | Name: | HdInfoHash |
Value: 99226C807621B4853E3D4B5CA83E9DB1 | |||
| (PID) Process: | (5252) fsdc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Friendess\DataCenter |
| Operation: | write | Name: | WarnIntervalMins |
Value: 5 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\TaskClient\RunTaskClient.exe | executable | |
MD5:C82FC3110F1C999C1234E194399EE92E | SHA256:C4CC88D191169323EBDD20995CA8D8AE01B9F6F7F7D75B71407B289918687220 | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\RunFSDC.exe | executable | |
MD5:0E01F285864D82253A89AE13B8D9E449 | SHA256:139D34B8CC4D69D42B15DD2D56BF79CC2D4BE080C63AACE95D0BEA3BD08000CF | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Users\admin\AppData\Local\Temp\nsk64BA.tmp\System.dll | executable | |
MD5:CFF85C549D536F651D4FB8387F1976F2 | SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8 | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Users\admin\AppData\Local\Temp\nsp648A.tmp | executable | |
MD5:5DEF44160B85DA29BA629B00A273CEB1 | SHA256:C519BDEB3C783EDCDCFB68B976A12534674EA151D84AC27072C0ECF3CC205DFE | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\V2.7.1.1\7z.dll | executable | |
MD5:9954584250324791BEBDE54E8264A97C | SHA256:B5B25E9FB4A5175EF0D21C7C7F9D51D7D3F4000E147440571FF57FCB46DCAEA2 | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\FsdcSvc.exe | executable | |
MD5:6D95983A91455B884F0D41C6F8E66C37 | SHA256:2A4F71A1C3C750B4F1F230D28291E79DCCE831916E57D2390926E8FFEF2E837E | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\V2.7.1.1\RunFSDC.exe | executable | |
MD5:0E01F285864D82253A89AE13B8D9E449 | SHA256:139D34B8CC4D69D42B15DD2D56BF79CC2D4BE080C63AACE95D0BEA3BD08000CF | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\V2.7.1.1\fsdc.exe | executable | |
MD5:3007DA6B77CACC91AA22E9C67F9F4A3C | SHA256:860846DF9E27A5E60DC2495732591769610B42F7466469CF4C1B891F2039C2B1 | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\V2.7.1.1\ShareMemTool.exe | executable | |
MD5:3787B0E8C65037F32E33D3F4E89CFECB | SHA256:DF959CFD8414B101FBCFBBE9A8D505DB002447B30BA0AE01B615F6AA94361D9D | |||
| 6896 | FSDCInstaller_20241128_r2844-1733447696861.exe | C:\Program Files (x86)\Friendess\Share\fsdc\V2.7.1.1\TaskClient.exe | executable | |
MD5:EECEC5396F2B563B2830C13996E6D503 | SHA256:B48292B3195C1FDDD6C6FC6403A3CBE69981603064DDB11CC3E8A0ECDE38F708 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3208 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
2380 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2380 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5252 | fsdc.exe | GET | 200 | 163.181.92.234:80 | http://d.fscut.com/upgradeCenter/apps/TaskClient/2_0_4_5/TaskClient-1712467086715.zip | unknown | — | — | unknown |
5252 | fsdc.exe | POST | 200 | 8.211.6.3:80 | http://upd8.fscut.com/api/release/check/batch?gmid=647028 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 2.23.209.143:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5064 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3560 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 23.218.210.69:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
hdauth.fscut.com |
| unknown |
www.fscut.com |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
fsdc.exe | 12/6/2024 9:02:23 AM [SYSTEM] SysStart6752BDA0592 Procceed by THttpStartHandler |
fsdc.exe | 12/6/2024 9:02:24 AM [SYSTEM] SysStart6752BDA0592 Procceed by TDBInitHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [SYSTEM] SysStart6752BDA0592 Procceed by TFsdcInitHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [SYSTEM] SysStart6752BDA0592 Procceed by THttpInitHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [SYSTEM] SysInitialized6752BDA2552 Procceed by TEventBusStartHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [SYSTEM] SysInitialized6752BDA2552 Procceed by TTaskSchedulerStartHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [SYSTEM] SysInitialized6752BDA2552 Procceed by TAppEventHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [LOG] LOG6752BDA2526 Procceed by TLogHandler |
fsdc.exe | 12/6/2024 9:02:25 AM [LOG] LOG6752BDA2526 Procceed by TFsdcLogReporter |
fsdc.exe | TcpConnectThread |