File name:

FiveM.exe

Full analysis: https://app.any.run/tasks/e7650e16-7831-4ed5-801d-55bd7772789a
Verdict: Malicious activity
Analysis date: November 26, 2024, 22:26:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

16BE58978B46F7DB7EEC9B32D7E0639A

SHA1:

3E7170478582D67041687A97D35B1FFE1E01EA6D

SHA256:

621C965F296D1AB062DEFB429AAA1BA688E4F561236A4E76B3C7F3D5A6716280

SSDEEP:

98304:a+1A/oykHycaMNarQfpfgujEJRA2EyrSsebzcxaw01RBhcCFN8RKHWyywkAAgnAx:bF05un0V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
    • Starts itself from another location

      • FiveM.exe (PID: 2436)
    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 3552)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 3220)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 3220)
  • INFO

    • Creates files or folders in the user directory

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
    • Checks supported languages

      • FiveM.exe (PID: 2436)
      • FiveM.exe (PID: 3220)
      • GameBar.exe (PID: 3552)
    • Reads the computer name

      • FiveM.exe (PID: 3220)
      • FiveM.exe (PID: 2436)
      • GameBar.exe (PID: 3552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:11:26 14:00:18+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3398656
InitializedDataSize: 1918464
UninitializedDataSize: -
EntryPoint: 0x28d010
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.11538
ProductVersionNumber: 2.0.0.11538
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.11538
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.11538
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem.exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2436"C:\Users\admin\AppData\Local\Temp\FiveM.exe" C:\Users\admin\AppData\Local\Temp\FiveM.exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.11538
Modules
Images
c:\users\admin\appdata\local\temp\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3220"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.11538
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3552"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
3724"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
Total events
16 265
Read events
16 247
Write events
18
Delete events
0

Modification events

(PID) Process:(2436) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\FiveM
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:Publisher
Value:
Cfx.re
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\FiveM\FiveM.exe" -uninstall app
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:URLInfoAbout
Value:
https://cfx.re/
(PID) Process:(3220) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:NoModify
Value:
1
Executable files
337
Suspicious files
157
Text files
220
Unknown types
13

Dropped files

PID
Process
Filename
Type
2436FiveM.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnkbinary
MD5:88A9D038C4850F10D7F5DD65FDC68BF1
SHA256:B4BD3AC63D0A8CFBA3171B530B71D84BF015CA5D87C432EA6D85E3C1E7A5F260
2436FiveM.exeC:\Users\admin\Desktop\FiveM.lnkbinary
MD5:0172D8B2423EB2553FE2EE52C94D86CB
SHA256:D52846C2CBC6642AC340C73596A47A085166B3D527F327EB908C4B98DA48CEBB
2436FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:16BE58978B46F7DB7EEC9B32D7E0639A
SHA256:621C965F296D1AB062DEFB429AAA1BA688E4F561236A4E76B3C7F3D5A6716280
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.VisualElementsManifest.xmltext
MD5:B8180561E3C94A6371383B4541FFFFD0
SHA256:0B6FCF104FDF32515ADFFBF1633E0DF97F1C674884178848BACF981D9311D81F
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2372_aslr.bin.tmpexecutable
MD5:233D3AFC35CBB9425DFF5727F1864F07
SHA256:4D7FBB0D98A83E35D8F30101FDA10B88489CF4F0930EF8E3829091EE5C45773D
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1_aslr.binexecutable
MD5:490C5FA129E4C52B6342A72C4C7E9AE7
SHA256:43C873E8D376FA64A5EDE4FF3F99EF6CAF067344438708588EAE9D2897A72617
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1604_aslr.bin.tmpexecutable
MD5:893F56F47128660DE09BA557F26002AB
SHA256:A59CF3ED94F75E9B939E65827C2E6FE3387F70A997FA6B97E1050DC4A4E4D04A
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2060_aslr.bin.tmpexecutable
MD5:9213D4742A2A273FC92FD5A5CE3A6625
SHA256:CC896030BD17A5A17B40279EAD77BD5AD80F1649D4FD52BE630C1388423CB207
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2060_aslr.binexecutable
MD5:9213D4742A2A273FC92FD5A5CE3A6625
SHA256:CC896030BD17A5A17B40279EAD77BD5AD80F1649D4FD52BE630C1388423CB207
3220FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2189_aslr.binexecutable
MD5:7DBF56DA6075E45D6C02359579347D74
SHA256:2DF659BF2B8481B15C9DB10A3CA0DFC728C79DA75622CCCEE25B3DC86521BA28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
49
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7092
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5448
svchost.exe
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.72.205.209:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2436
FiveM.exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
3220
FiveM.exe
104.18.34.171:443
content.cfx.re
CLOUDFLARENET
unknown
5064
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.72.205.209
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 95.101.149.131
whitelisted
content.cfx.re
  • 104.18.34.171
  • 172.64.153.85
unknown
www.bing.com
  • 2.23.209.187
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.182
  • 23.212.110.144
  • 23.212.110.152
  • 23.212.110.146
  • 23.212.110.160
  • 23.212.110.154
  • 23.212.110.153
  • 23.212.110.145
  • 23.212.110.155
  • 23.212.110.147
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
r.bing.com
  • 23.212.110.144
  • 23.212.110.152
  • 23.212.110.146
  • 23.212.110.160
  • 23.212.110.154
  • 23.212.110.153
  • 23.212.110.145
  • 23.212.110.155
  • 23.212.110.147
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info