File name:

fodhelper.exe

Full analysis: https://app.any.run/tasks/be2e424f-cb9e-41d1-9c81-e2e35d353454
Verdict: Malicious activity
Analysis date: May 03, 2024, 04:18:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
raccoonclipper
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

D3CAD18B786A20196C2DD96141225A35

SHA1:

78A9702746779E4C6675E46379405C0FDF98A92F

SHA256:

57D3D5D5B3F8E4AA80FC43D107A3D73DD203FD15524266AAF62873E11691AFFF

SSDEEP:

24576:TCcI6kVhM/D9p4Q0a1KMyRGlemKAEm6MaP:TC/6kVhM/D9p4Q11KMyRGlemKAEhMaP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fodhelper.exe (PID: 3980)
      • fodhelper.exe (PID: 4040)
    • RACCOONCLIPPER has been detected (YARA)

      • fodhelper.exe (PID: 2108)
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • fodhelper.exe (PID: 1200)
      • fodhelper.exe (PID: 336)
      • fodhelper.exe (PID: 1580)
    • Application launched itself

      • fodhelper.exe (PID: 3980)
      • fodhelper.exe (PID: 1200)
      • fodhelper.exe (PID: 336)
      • fodhelper.exe (PID: 1580)
    • Executable content was dropped or overwritten

      • fodhelper.exe (PID: 4040)
  • INFO

    • Checks supported languages

      • fodhelper.exe (PID: 3980)
      • fodhelper.exe (PID: 1200)
      • fodhelper.exe (PID: 4040)
      • fodhelper.exe (PID: 2108)
      • fodhelper.exe (PID: 336)
      • fodhelper.exe (PID: 1112)
      • fodhelper.exe (PID: 1580)
      • fodhelper.exe (PID: 660)
    • Reads the computer name

      • fodhelper.exe (PID: 1200)
      • fodhelper.exe (PID: 3980)
      • fodhelper.exe (PID: 336)
      • fodhelper.exe (PID: 1580)
    • Reads the machine GUID from the registry

      • fodhelper.exe (PID: 3980)
      • fodhelper.exe (PID: 1200)
      • fodhelper.exe (PID: 336)
      • fodhelper.exe (PID: 1580)
    • Creates files or folders in the user directory

      • fodhelper.exe (PID: 4040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

RaccoonClipper

(PID) Process(2108) fodhelper.exe
Wallets (18)Ae2tdPwUPEZKFp3DNd7g57oc3vWeZ6N2fA1uA5KqJ9qyQTyC2D2YEaGEYzL
bc1qnl5vwuzw57rtm98wg2jh6mu0p597892q0pss27
Adu5K93Evg5jsQGdwMA69onB4dJ74L87GX
bnb1gjp5822en66dsh7k0v00q0hxzwuus3c0m2v74w
t1Upr9Q3VMFLC8sz6spautGumgDqdSvdgsq
88ULP41eYUCWzYVGPXuBUEJR9j8Lu17zPKvkLqyXQMt3BjKZijVqiq6786u3bveEHnemGXR78uGj28ELXmDTURC2PJYRuTH
Z1BspfXbHj1R5RcShF31KNpBW79h9zBej5J
TXQXx2nJnd1PpUVkZvfh7LbffUisurwd43
LKTWnwuM4eZgXdUNh5RpV3ETxNRbbbPDFT
ltc1qvfghx46z8v9fyawar6qgdhj5wtrslvvx2kn438
YWAMDRGWA6TMDAVJV5XP6CQZZMO46NLC4TK555FRDCTPLUMST5YENA4VIE
cosmos1k6y3w45ralwcaarlgt7zcgm5htk2rw9jq5jxce
DB84kZEkPqBUVh1KvEcN7f3KSEEhPVMNPS
BXgs2AAWD7gF2WUNhva7byzkpR4QbvM3YHoCJzrGebnb
0xB78aD0c44964c978c763cCa142C8D3f30B711e3c
addr1q90kzt7nhxjkhm5e40nadh5ym57p24aswumdy0aggyk8mmjlvyha8wd9d0hfn2l86m0gfhfuz4tmqaek6gl6ssfv0hhqe6akq0
1BspfXbHj1R5RcShF31KNpBW79h9zBej5J
49XPrw6TrHAVvw2pPGhdifGdfYc3iHftvSwQvmy74drQMpU4bmE3syc6mV9uSKDhbQB54Egan4AL1NMzAvYRY3jHHZdYUcm
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:27 19:42:24+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 655360
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0xa1ebe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: -
FileVersion: 1.0.0.0
InternalName: Odhcjivd.exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: Odhcjivd.exe
ProductName: -
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
10
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start fodhelper.exe no specs fodhelper.exe schtasks.exe no specs fodhelper.exe no specs #RACCOONCLIPPER fodhelper.exe no specs schtasks.exe no specs fodhelper.exe no specs fodhelper.exe no specs fodhelper.exe no specs fodhelper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
336C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
660C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exeC:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exefodhelper.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1036/C /create /F /sc minute /mo 1 /tn "Telemetry Logging" /tr "C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe"C:\Windows\System32\schtasks.exefodhelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1112C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exeC:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exefodhelper.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1200C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1580C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2108C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exeC:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe
fodhelper.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\telemetryservices\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
RaccoonClipper
(PID) Process(2108) fodhelper.exe
Wallets (18)Ae2tdPwUPEZKFp3DNd7g57oc3vWeZ6N2fA1uA5KqJ9qyQTyC2D2YEaGEYzL
bc1qnl5vwuzw57rtm98wg2jh6mu0p597892q0pss27
Adu5K93Evg5jsQGdwMA69onB4dJ74L87GX
bnb1gjp5822en66dsh7k0v00q0hxzwuus3c0m2v74w
t1Upr9Q3VMFLC8sz6spautGumgDqdSvdgsq
88ULP41eYUCWzYVGPXuBUEJR9j8Lu17zPKvkLqyXQMt3BjKZijVqiq6786u3bveEHnemGXR78uGj28ELXmDTURC2PJYRuTH
Z1BspfXbHj1R5RcShF31KNpBW79h9zBej5J
TXQXx2nJnd1PpUVkZvfh7LbffUisurwd43
LKTWnwuM4eZgXdUNh5RpV3ETxNRbbbPDFT
ltc1qvfghx46z8v9fyawar6qgdhj5wtrslvvx2kn438
YWAMDRGWA6TMDAVJV5XP6CQZZMO46NLC4TK555FRDCTPLUMST5YENA4VIE
cosmos1k6y3w45ralwcaarlgt7zcgm5htk2rw9jq5jxce
DB84kZEkPqBUVh1KvEcN7f3KSEEhPVMNPS
BXgs2AAWD7gF2WUNhva7byzkpR4QbvM3YHoCJzrGebnb
0xB78aD0c44964c978c763cCa142C8D3f30B711e3c
addr1q90kzt7nhxjkhm5e40nadh5ym57p24aswumdy0aggyk8mmjlvyha8wd9d0hfn2l86m0gfhfuz4tmqaek6gl6ssfv0hhqe6akq0
1BspfXbHj1R5RcShF31KNpBW79h9zBej5J
49XPrw6TrHAVvw2pPGhdifGdfYc3iHftvSwQvmy74drQMpU4bmE3syc6mV9uSKDhbQB54Egan4AL1NMzAvYRY3jHHZdYUcm
3980"C:\Users\admin\Desktop\fodhelper.exe" C:\Users\admin\Desktop\fodhelper.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4040C:\Users\admin\Desktop\fodhelper.exeC:\Users\admin\Desktop\fodhelper.exe
fodhelper.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\fodhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4052/C /create /F /sc minute /mo 1 /tn "Telemetry Logging" /tr "C:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe"C:\Windows\System32\schtasks.exefodhelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
535
Read events
535
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4040fodhelper.exeC:\Users\admin\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exeexecutable
MD5:D3CAD18B786A20196C2DD96141225A35
SHA256:57D3D5D5B3F8E4AA80FC43D107A3D73DD203FD15524266AAF62873E11691AFFF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info