File name:

FastCopy5.8.0_installer.exe

Full analysis: https://app.any.run/tasks/2a581ad8-d2ea-484d-90d6-458e07aeb243
Verdict: Malicious activity
Analysis date: October 17, 2024, 09:32:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

19D18DB1F75F1EB81DA1275B88E4D233

SHA1:

5B9417C755AC08DB99914CFA89301C5351982751

SHA256:

5374571A36FC6012FF56FCC4871CD960D32C9840237CFB1B4E0A5C03E9324AEC

SSDEEP:

98304:IFvtn6lTf2P3lGrpTnZBwJ0H06f9OKh8QgYU3leHoSGqSy1Xc/m2LBtWVc6Vdm3U:LvC/QMzGF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FastCopy5.8.0_installer.exe (PID: 5264)
      • FastCopy.exe (PID: 6452)
    • Reads security settings of Internet Explorer

      • FastCopy5.8.0_installer.exe (PID: 5264)
    • Uses RUNDLL32.EXE to load library

      • FastCopy.exe (PID: 6452)
    • Creates a software uninstall entry

      • FastCopy5.8.0_installer.exe (PID: 5264)
    • Process drops legitimate windows executable

      • FastCopy.exe (PID: 6452)
    • The process drops C-runtime libraries

      • FastCopy.exe (PID: 6452)
  • INFO

    • Reads the computer name

      • FastCopy5.8.0_installer.exe (PID: 5264)
      • FastCopy.exe (PID: 6452)
    • Checks supported languages

      • FastCopy5.8.0_installer.exe (PID: 5264)
      • FastCopy.exe (PID: 6452)
    • Reads the machine GUID from the registry

      • FastCopy5.8.0_installer.exe (PID: 5264)
      • FastCopy.exe (PID: 6452)
    • Creates files or folders in the user directory

      • FastCopy5.8.0_installer.exe (PID: 5264)
    • Process checks whether UAC notifications are on

      • FastCopy.exe (PID: 6452)
    • The process uses the downloaded file

      • FastCopy5.8.0_installer.exe (PID: 5264)
    • Process checks computer location settings

      • FastCopy5.8.0_installer.exe (PID: 5264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:08 10:33:44+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 374784
InitializedDataSize: 271360
UninitializedDataSize: -
EntryPoint: 0x3d24b
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 5.8.0.0
ProductVersionNumber: 5.8.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Japanese
CharacterSet: Unicode
Comments: https://fastcopy.jp
CompanyName: FastCopy Lab, LLC.
FileDescription: FastCopy Installer
FileVersion: 5.8.0.0
InternalName: FastCopy Installer
LegalCopyright: Copyright (C) 2004-2024 SHIROUZU Hiroaki and FastCopy Lab, LLC. All rights reserved.
OriginalFileName: setup.exe
ProductName: FastCopy
ProductVersion: 5.8.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fastcopy5.8.0_installer.exe fastcopy.exe rundll32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
860"C:\Windows\System32\rundll32.exe" "C:\Users\admin\FastCopy\FastExt1.dll",DllRegisterServerUser 0C:\Windows\SysWOW64\rundll32.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5264"C:\Users\admin\AppData\Local\Temp\FastCopy5.8.0_installer.exe" C:\Users\admin\AppData\Local\Temp\FastCopy5.8.0_installer.exe
explorer.exe
User:
admin
Company:
FastCopy Lab, LLC.
Integrity Level:
MEDIUM
Description:
FastCopy Installer
Exit code:
0
Version:
5.8.0.0
Modules
Images
c:\users\admin\appdata\local\temp\fastcopy5.8.0_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6192"C:\Windows\System32\rundll32.exe" "C:\Users\admin\FastCopy\FastExt1.dll",DllRegisterServerUser 0C:\Windows\System32\rundll32.exeFastCopy.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
6452"C:\Users\admin\FastCopy\FastCopy.exe" /INSTALLC:\Users\admin\FastCopy\FastCopy.exe
FastCopy5.8.0_installer.exe
User:
admin
Company:
FastCopy Lab, LLC.
Integrity Level:
MEDIUM
Description:
FastCopy
Version:
5.8.0.0
Modules
Images
c:\users\admin\fastcopy\fastcopy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 754
Read events
9 501
Write events
242
Delete events
11

Modification events

(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:DisplayName
Value:
FastCopy
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:UninstallString
Value:
C:\Users\admin\FastCopy\setup.exe /r
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\FastCopy\FastCopy.exe
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:DisplayVersion
Value:
5.8.0
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:Publisher
Value:
H.Shirouzu & FastCopy Lab, LLC.
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:EstimatedSize
Value:
4100
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:HelpLink
Value:
https://fastcopy.jp/help/fastcopy.htm
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:URLUpdateInfo
Value:
https://fastcopy.jp
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:URLInfoAbout
Value:
https://github.com/FastCopyLab/FastCopy/issues
(PID) Process:(5264) FastCopy5.8.0_installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FastCopy
Operation:writeName:Comments
Value:
pub-setup@fastcopy.jp
Executable files
124
Suspicious files
103
Text files
282
Unknown types
2

Dropped files

PID
Process
Filename
Type
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\FastExt1.dllexecutable
MD5:42329F71F490015C39228F3CE7172751
SHA256:8B71DA700647FDDC1E289C883C7E17AB719DD0498B2E180A948FD66A7CFDE088
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\fcp.exeexecutable
MD5:9BDE6F182876CD0F93EA7D91F3427528
SHA256:26EDFADD5410069E6553BDC497D35BC1465CECA68CCF621EC93EEF1912196675
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\FastEx11.dllexecutable
MD5:265FA56E8EE9E2C1889DDCACF086FFBE
SHA256:789C034BA2B61B75F620053FB8E35868BEA15357EB078EF847A8E892C2A71928
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\msix\fastcopy2.msixcompressed
MD5:650723E87A7301BFFDB25524653D73AD
SHA256:9DAEA82452E4DA8377613882C1FD35B01F2A4040B92F7927FF5EACABB5855C9E
6452FastCopy.exeC:\Users\admin\Desktop\Adobe\Acrobat DC\Acrobat\Acrobat.dll
MD5:
SHA256:
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\setup.exeexecutable
MD5:24B89DF146AC50F54F578995CA3503AA
SHA256:EB73AE81DE032690F0415F95AA90103F6CF9385D37E4856C9433274F7ED840D0
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\FastCopy.exeexecutable
MD5:2F63050D651488230593C5B9DD8C92CA
SHA256:BC9876A889D2D1F724149CADD2EA63D7848D15BB7D582BFDBA9DBDCE02A320E3
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\doc\FastCopy.chmbinary
MD5:97471DC0571BFD29E112D9C1B5E2B4A2
SHA256:69357F6247D4E014DAE04DE2DFA0F95A8F87F7EA63D671916963F0C804C62464
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\doc\FastCopy_cn.chmbinary
MD5:12EC5392A56EFEC79381710D0A43FF95
SHA256:8B29DFEBFF6102304DAD820C26962FA73C11573980A0FD2DC8C4AE6AB624E328
5264FastCopy5.8.0_installer.exeC:\Users\admin\FastCopy\msix\fastcopy0.msixcompressed
MD5:FE7CF2623C8C8287D82D8796AB57DB9B
SHA256:91DA8B5E07E7E16AD9D29C5D24C3A49FF15CEEEEA73045875384FE5D8446C743
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
53
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.164.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7092
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5984
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5984
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4360
SearchApp.exe
2.23.209.130:443
www.bing.com
Akamai International B.V.
GB
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.81:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
2.16.164.81:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5488
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.23.209.130
  • 2.23.209.142
  • 2.23.209.140
  • 2.23.209.141
  • 2.23.209.135
  • 2.23.209.133
  • 2.23.209.193
  • 2.23.209.132
  • 2.23.209.131
  • 2.23.209.153
  • 2.23.209.154
  • 2.23.209.149
  • 2.23.209.158
  • 2.23.209.150
whitelisted
crl.microsoft.com
  • 2.16.164.81
  • 2.16.164.49
  • 2.16.164.40
  • 2.16.164.114
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.19.217.218
whitelisted
google.com
  • 142.250.186.142
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.68
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.76
whitelisted
th.bing.com
  • 2.23.209.179
  • 2.23.209.177
  • 2.23.209.185
  • 2.23.209.180
  • 2.23.209.186
  • 2.23.209.182
  • 2.23.209.183
  • 2.23.209.187
  • 2.23.209.178
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
Process
Message
FastCopy.exe
0226.21: [17e0]: minSize = 65536 (ntfs=65536 fat=131072)
FastCopy.exe
0226.21: [17e0]: RegisterRegFilter idx=0 depth=1 src=\\?\C:\Program Files\Adobe
FastCopy.exe
0226.21: [17e0]: srcSector=4096/512, dstSector=4096/512 memAlign=4096, wtrunc=1
FastCopy.exe
0226.21: [17e0]: RegisterRegFilter idx=1 depth=1 src=\\?\C:\Program Files\CCleaner
FastCopy.exe
0226.21: [17e0]: already reg2(00000297E056E850)
FastCopy.exe
0226.21: [17e0]: srcSector=4096/512, dstSector=4096/512 memAlign=4096, wtrunc=1
FastCopy.exe
0226.21: [17e0]: RegisterRegFilter idx=2 depth=1 src=\\?\C:\Program Files\FileZilla FTP Client
FastCopy.exe
0226.21: [17e0]: already reg2(00000297E056E850)
FastCopy.exe
0226.21: [17e0]: srcSector=4096/512, dstSector=4096/512 memAlign=4096, wtrunc=1
FastCopy.exe
0226.21: [17e0]: cpuAffinity 2 to 1