File name:

PcAppStore.exe

Full analysis: https://app.any.run/tasks/09e62ded-1947-4243-9afa-fa78a994c59c
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: February 21, 2025, 14:08:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
pcappstore
adware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

1D7B2E853186125A599F5E2476D28E6B

SHA1:

D22BEEA6D19A5D7CA03E2E2F24E648F4A75F806A

SHA256:

6FB23DCB8AE019046B8C09FE164E8D49D8D541C3604122AC640EA5A33EDE3B13

SSDEEP:

49152:5NQmRpvFK7K6wq9S5Ue61wbKJtn7ZLCApf6IC6rM5ZWqyrSkqtYd8QLzGxNfulFL:5NQmRC7NgB0PLCApDMXWqylqEzAq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PCAPPSTORE mutex has been found

      • PcAppStore.exe (PID: 1876)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • PcAppStore.exe (PID: 1876)
  • INFO

    • The sample compiled with english language support

      • PcAppStore.exe (PID: 1876)
    • Reads the computer name

      • PcAppStore.exe (PID: 1876)
    • Checks supported languages

      • PcAppStore.exe (PID: 1876)
    • Reads Environment values

      • PcAppStore.exe (PID: 1876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:20 15:32:01+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 2787840
InitializedDataSize: 784384
UninitializedDataSize: -
EntryPoint: 0x25d3b8
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.2009
ProductVersionNumber: 1.0.0.2009
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Fast Corporation LTD
FileDescription: PC App Store Runtime
FileVersion: 1.0.0.2009
InternalName: fa_rss.exe
LegalCopyright: Fast Corporation LTD
OriginalFileName: PCAppStore.exe
ProductName: PC App Store
ProductVersion: 1.0.0.2009
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
115
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT pcappstore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1876"C:\Users\admin\PcAppStore.exe" C:\Users\admin\PcAppStore.exe
explorer.exe
User:
admin
Company:
Fast Corporation LTD
Integrity Level:
MEDIUM
Description:
PC App Store Runtime
Exit code:
4294967295
Version:
1.0.0.2009
Modules
Images
c:\users\admin\pcappstore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
256
Read events
256
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
23
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4504
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.238
whitelisted

Threats

No threats detected
No debug info