File name:

rbxfpsunlocker.exe

Full analysis: https://app.any.run/tasks/10b2da04-171e-40e9-9493-47cf24401378
Verdict: Malicious activity
Analysis date: October 29, 2023, 07:57:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

559E4B863C9736D6DD81B67A1C7C51E9

SHA1:

351CD63B60A1F570EFC1A4D662A8D22C3A4D3C0E

SHA256:

6314F6518CD5779E9BA758702432180DE55F69E2963601D77A57799569332FFB

SSDEEP:

98304:3jsVP1nzPnvEAEZGPBzJx7WQizOMAu8PHieEM1SBkyZiJYfpx7AHHWWmOOei8yRS:KOjcYfzPuB6ERaql+X7aCrMO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • rbxfpsunlocker.exe (PID: 1584)
    • Drops the executable file immediately after the start

      • rbxfpsunlocker.exe (PID: 2536)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • rbxfpsunlocker.exe (PID: 2536)
    • The process drops C-runtime libraries

      • rbxfpsunlocker.exe (PID: 2536)
    • Loads Python modules

      • rbxfpsunlocker.exe (PID: 1584)
    • Application launched itself

      • rbxfpsunlocker.exe (PID: 2536)
  • INFO

    • Create files in a temporary directory

      • rbxfpsunlocker.exe (PID: 2536)
    • Reads the computer name

      • rbxfpsunlocker.exe (PID: 2536)
    • Checks supported languages

      • rbxfpsunlocker.exe (PID: 2536)
      • rbxfpsunlocker.exe (PID: 1584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:09:10 07:15:27+02:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.32
CodeSize: 165888
InitializedDataSize: 154112
UninitializedDataSize: -
EntryPoint: 0xafa0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rbxfpsunlocker.exe no specs rbxfpsunlocker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1584"C:\Users\admin\AppData\Local\Temp\rbxfpsunlocker.exe" C:\Users\admin\AppData\Local\Temp\rbxfpsunlocker.exerbxfpsunlocker.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rbxfpsunlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2536"C:\Users\admin\AppData\Local\Temp\rbxfpsunlocker.exe" C:\Users\admin\AppData\Local\Temp\rbxfpsunlocker.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rbxfpsunlocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
14
Read events
14
Write events
0
Delete events
0

Modification events

No data
Executable files
89
Suspicious files
6
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_pkcs1_decode.pydexecutable
MD5:3EFFD59CD95B6706C1F2DD661AA943FC
SHA256:4C29950A9EDEDBBC24A813F8178723F049A529605EF6D35F16C7955768AACE9E
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_Salsa20.pydexecutable
MD5:E3AE69E44C4C82D83082BBB8C25AA8DD
SHA256:4229235814BBEE62311E3623C07898B03D3B22281CD4E5F1A87B86450B1B740F
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_arc2.pydexecutable
MD5:3F5FD606893B3DE6116D4A185E713CA3
SHA256:0898CDE5FCCFA86E2423CDF627A3745B1F59BB30DFEF0DD9423926D4167F9F82
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_ctr.pydexecutable
MD5:D67F83D1482D9600AC012868FB49D16E
SHA256:AA463CD4D0B4BBD4159650D66C11A699B23775BF92455FB58A2206B932A65FEC
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_cast.pydexecutable
MD5:243E336DEC71A28E7F61548A2425A2E1
SHA256:BF53063304119CF151F22809356B5B4E44799131BBAB5319736D0321F3012238
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_cbc.pydexecutable
MD5:FE44F698198190DE574DC193A0E1B967
SHA256:32FA416A29802EB0017A2C7360BF942EDB132D4671168DE26BD4C3E94D8DE919
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_cfb.pydexecutable
MD5:FF64FD41B794E0EF76A9EEAE1835863C
SHA256:5D2D1A5F79B44F36AC87D9C6D886404D9BE35D1667C4B2EB8AAB59FB77BF8BAC
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_des.pydexecutable
MD5:B0EEF5CEAE8BA5E2A04C17B2B6AE87B5
SHA256:C9BBA124BE36ADA4549276D984BB3812EE2207C7DBF646EC6DF9A968E83205FB
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_chacha20.pydexecutable
MD5:ED1BBDC7CC945DA2D1F5A914987EB885
SHA256:1EECE2F714DC1F520D0608F9F71E692F5B269930603F8AFC330118EA38F16005
2536rbxfpsunlocker.exeC:\Users\admin\AppData\Local\Temp\_MEI25362\Crypto\Cipher\_raw_aesni.pydexecutable
MD5:DCD2F68680E2FB83E9FEFA18C7B4B3E0
SHA256:D63F63985356B7D2E0E61E7968720FB72DC6B57D73BED4F337E372918078F946
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info