File name:

FiveM.exe

Full analysis: https://app.any.run/tasks/e7650e16-7831-4ed5-801d-55bd7772789a
Verdict: Malicious activity
Analysis date: November 26, 2024, 22:26:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

16BE58978B46F7DB7EEC9B32D7E0639A

SHA1:

3E7170478582D67041687A97D35B1FFE1E01EA6D

SHA256:

621C965F296D1AB062DEFB429AAA1BA688E4F561236A4E76B3C7F3D5A6716280

SSDEEP:

98304:a+1A/oykHycaMNarQfpfgujEJRA2EyrSsebzcxaw01RBhcCFN8RKHWyywkAAgnAx:bF05un0V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
    • Starts itself from another location

      • FiveM.exe (PID: 2436)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 3220)
    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 3552)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 3220)
  • INFO

    • Creates files or folders in the user directory

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
    • Checks supported languages

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
      • GameBar.exe (PID: 3552)
    • Reads the computer name

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
      • GameBar.exe (PID: 3552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:26 14:00:18+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3398656
InitializedDataSize: 1918464
UninitializedDataSize: -
EntryPoint: 0x28d010
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.11538
ProductVersionNumber: 2.0.0.11538
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.11538
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.11538
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem.exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2436"C:\Users\admin\AppData\Local\Temp\FiveM.exe" C:\Users\admin\AppData\Local\Temp\FiveM.exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.11538
Modules
Images
c:\users\admin\appdata\local\temp\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3220"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.11538
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3552"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
3724"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
Total events
16 265
Read events
16 247
Write events
18
Delete events
0

Modification events

(PID) Process:(2436) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\FiveM
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:Publisher
Value:
Cfx.re
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\FiveM\FiveM.exe" -uninstall app
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:URLInfoAbout
Value:
https://cfx.re/
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:NoModify
Value:
1
Executable files
337
Suspicious files
157
Text files
220
Unknown types
13

Dropped files

PID
Process
Filename
Type
2436FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnkbinary
MD5:88A9D038C4850F10D7F5DD65FDC68BF1
SHA256:B4BD3AC63D0A8CFBA3171B530B71D84BF015CA5D87C432EA6D85E3C1E7A5F260
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2189_aslr.bin.tmpexecutable
MD5:7DBF56DA6075E45D6C02359579347D74
SHA256:2DF659BF2B8481B15C9DB10A3CA0DFC728C79DA75622CCCEE25B3DC86521BA28
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_chrome.binexecutable
MD5:989DB0C4C634214EE13BD8384FAC5B76
SHA256:D545F30113F931167C333DEC644B4D3E83F4A25167F6CE348818AB3BCCB92087
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dll.tmpexecutable
MD5:D698EA9237C4F1532775FC4080CF025C
SHA256:50EF3F4F654A94D7BCCD26A377207C9D16320DF751CA8B5968B8F213DDB86E53
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_chrome.bin.tmpexecutable
MD5:989DB0C4C634214EE13BD8384FAC5B76
SHA256:D545F30113F931167C333DEC644B4D3E83F4A25167F6CE348818AB3BCCB92087
2436FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:16BE58978B46F7DB7EEC9B32D7E0639A
SHA256:621C965F296D1AB062DEFB429AAA1BA688E4F561236A4E76B3C7F3D5A6716280
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:0C18A5DD5B5311216D6B5AEBD091F647
SHA256:E897EA86B47ED51FC3793DB2703D8AD7A9A6430E0F71236CE396114085EBD9B8
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2060_aslr.bin.tmpexecutable
MD5:9213D4742A2A273FC92FD5A5CE3A6625
SHA256:CC896030BD17A5A17B40279EAD77BD5AD80F1649D4FD52BE630C1388423CB207
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1_aslr.bin.tmpexecutable
MD5:490C5FA129E4C52B6342A72C4C7E9AE7
SHA256:43C873E8D376FA64A5EDE4FF3F99EF6CAF067344438708588EAE9D2897A72617
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2189_aslr.binexecutable
MD5:7DBF56DA6075E45D6C02359579347D74
SHA256:2DF659BF2B8481B15C9DB10A3CA0DFC728C79DA75622CCCEE25B3DC86521BA28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
49
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5448
svchost.exe
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2436
FiveM.exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
3220
FiveM.exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
5064
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.72.205.209
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 95.101.149.131
whitelisted
content.cfx.re
  • 104.18.34.171
  • 172.64.153.85
unknown
www.bing.com
  • 2.23.209.187
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.182
  • 23.212.110.144
  • 23.212.110.152
  • 23.212.110.146
  • 23.212.110.160
  • 23.212.110.154
  • 23.212.110.153
  • 23.212.110.145
  • 23.212.110.155
  • 23.212.110.147
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
r.bing.com
  • 23.212.110.144
  • 23.212.110.152
  • 23.212.110.146
  • 23.212.110.160
  • 23.212.110.154
  • 23.212.110.153
  • 23.212.110.145
  • 23.212.110.155
  • 23.212.110.147
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info