File name:

F.C.E. 365 Firmware Manager X (v32).zip

Full analysis: https://app.any.run/tasks/1335ffdf-06b7-49f0-8d89-87a1b58acb64
Verdict: Malicious activity
Analysis date: August 16, 2020, 00:42:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

775F8EB1AA93E378DD3B46E780510C48

SHA1:

E05A96DAB3E2D58E7E061D524EE53F8AF12A804C

SHA256:

5C232CC2BD7B3BD78547031B443B1472B855755E40D52380C900D76A815D8BD4

SSDEEP:

393216:nT2JKseatsRZImHYjHcL1NzjYxh/C2MlfiGlE+nOarx1:qKRZ5A5C2aiGi+OO1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Detects Cygwin installation

      • WinRAR.exe (PID: 3208)
    • Loads dropped or rewritten executable

      • F.C.E. 365 Firmware Manager X.exe (PID: 3980)
      • SearchProtocolHost.exe (PID: 3856)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3208)
  • INFO

    • Manual execution by user

      • F.C.E. 365 Firmware Manager X.exe (PID: 3980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2017:03:11 00:47:16
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: F.C.E. 365 Firmware Manager X (v32)/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe f.c.e. 365 firmware manager x.exe no specs searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3208"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\F.C.E. 365 Firmware Manager X (v32).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3856"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3980"C:\Users\admin\Desktop\F.C.E. 365 Firmware Manager X (v32)\F.C.E. 365 Firmware Manager X.exe" C:\Users\admin\Desktop\F.C.E. 365 Firmware Manager X (v32)\F.C.E. 365 Firmware Manager X.exeexplorer.exe
User:
admin
Company:
F.C.E. 365 TV
Integrity Level:
MEDIUM
Description:
F.C.E. 365 Firmware Manager X
Exit code:
0
Version:
32.0.0.0
Modules
Images
c:\users\admin\desktop\f.c.e. 365 firmware manager x (v32)\f.c.e. 365 firmware manager x.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
791
Read events
765
Write events
26
Delete events
0

Modification events

(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3208) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3208) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\F.C.E. 365 Firmware Manager X (v32).zip
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3208) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
52
Suspicious files
0
Text files
6
Unknown types
1

Dropped files

PID
Process
Filename
Type
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\.DS_Storeds_store
MD5:
SHA256:
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\7z.exeexecutable
MD5:D8FDD24BA6F295F96F03CA25669D02AF
SHA256:6E6C7EFF13A01EF23B56396630CF4205FC4552ABD4425BEB304AD4554903D01A
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Be.Windows.Forms.HexBox.dllexecutable
MD5:50791F7918621726ED56F11A7837C85E
SHA256:A32CACF1E339FC99F22029503BC07458BCBFFBBBF0F33B5BBABFA6EF84484D3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\curl.txttext
MD5:
SHA256:
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\cygz.dllexecutable
MD5:
SHA256:
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\Be.Windows.Forms.HexBox.dllexecutable
MD5:50791F7918621726ED56F11A7837C85E
SHA256:A32CACF1E339FC99F22029503BC07458BCBFFBBBF0F33B5BBABFA6EF84484D3D
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\idevicebackup2.exeexecutable
MD5:BEF6B88F3AB1E447C11E008C2DE23860
SHA256:1EC20FBA2BC7D06D2FAF14D3C7F9A9610AA710578CA14ED1695B5EF42848955B
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\cygwin1.dllexecutable
MD5:
SHA256:
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\7za.exeexecutable
MD5:42BADC1D2F03A8B1E4875740D3D49336
SHA256:C136B1467D669A725478A6110EBAAAB3CB88A3D389DFA688E06173C066B76FCF
3208WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3208.40401\F.C.E. 365 Firmware Manager X (v32)\Data\bspatch.exeexecutable
MD5:2E7543A4DEEC9620C101771CA9B45D85
SHA256:32A4664E367A5C6BC7316D2213E60086D2813C21DB3D407350E4ACA61C1B16A1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info