File name:

FlashFXP.5.4.0.Build.3970.zip

Full analysis: https://app.any.run/tasks/a95b5394-9ec1-45ae-84ef-d525d1c47a8b
Verdict: Malicious activity
Analysis date: February 17, 2024, 12:22:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

1EA66C5182E7162E64932DA6839534FD

SHA1:

11CD98CC6F54DF66BD84D551BA0F6D70B228F690

SHA256:

732ED851D5E1871017AD2A1903362B4F9B4C7CB35DF36AEEF29C5FE2AF9D51BA

SSDEEP:

98304:0OE44jmfQPZ+SmhsKKHuTWyg/FeUGCoJ21+j2CblStlCHyyBz8Nvy7o/9AolFFwm:3La4lTH0h3G3I/UWJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 3864)
      • FlashFXP.5.4.0.Build.3970.exe (PID: 3932)
      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP.exe (PID: 3248)
      • Keygen.exe (PID: 3564)
      • patch.exe (PID: 2840)
      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3864)
      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
      • patch.exe (PID: 2840)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
      • patch.exe (PID: 2840)
    • Process drops legitimate windows executable

      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
    • The process drops C-runtime libraries

      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
    • Drops 7-zip archiver for unpacking

      • FlashFXP5_Setup.exe (PID: 3960)
    • Reads the Windows owner or organization settings

      • FlashFXP5_Setup.exe (PID: 3960)
    • Reads the Internet Settings

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Checks Windows Trust Settings

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Adds/modifies Windows certificates

      • FlashFXP5_Setup.exe (PID: 3960)
    • Reads security settings of Internet Explorer

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Reads settings of System Certificates

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Creates a software uninstall entry

      • FlashFXP5_Setup.exe (PID: 3960)
    • Application launched itself

      • FlashFXP.exe (PID: 2108)
  • INFO

    • Manual execution by a user

      • FlashFXP.5.4.0.Build.3970.exe (PID: 3932)
      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • Keygen.exe (PID: 3564)
      • patch.exe (PID: 3860)
      • patch.exe (PID: 2840)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3864)
    • Creates files in the program directory

      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
    • Checks supported languages

      • FlashFXP.5.4.0.Build.3970.exe (PID: 2648)
      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • Keygen.exe (PID: 3564)
      • FlashFXP.exe (PID: 3248)
      • patch.exe (PID: 2840)
    • Reads the computer name

      • FlashFXP5_Setup.exe (PID: 3960)
      • Keygen.exe (PID: 3564)
      • FlashFXP.exe (PID: 3248)
      • FlashFXP.exe (PID: 2108)
    • Creates files or folders in the user directory

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
    • Checks proxy server information

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Reads the machine GUID from the registry

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Reads the software policy settings

      • FlashFXP5_Setup.exe (PID: 3960)
      • FlashFXP.exe (PID: 2108)
      • FlashFXP.exe (PID: 3248)
    • Create files in a temporary directory

      • FlashFXP5_Setup.exe (PID: 3960)
      • patch.exe (PID: 2840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:07:27 00:17:02
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: FlashFXP.5.4.0.Build.3970/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
9
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe flashfxp.5.4.0.build.3970.exe flashfxp.5.4.0.build.3970.exe flashfxp5_setup.exe flashfxp.exe keygen.exe flashfxp.exe patch.exe no specs patch.exe

Process information

PID
CMD
Path
Indicators
Parent process
2108"C:\Program Files\FlashFXP 5\FlashFXP.exe" C:\Program Files\FlashFXP 5\FlashFXP.exe
FlashFXP5_Setup.exe
User:
admin
Company:
OpenSight Software, LLC
Integrity Level:
MEDIUM
Description:
FlashFXP
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\program files\flashfxp 5\flashfxp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2648"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.exe
explorer.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
HIGH
Description:
FlashFXP Installation
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2840"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Patch\patch.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Patch\patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970\patch\patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3248"C:\Program Files\FlashFXP 5\FlashFXP.exe" C:\Program Files\FlashFXP 5\FlashFXP.exe
FlashFXP.exe
User:
admin
Company:
OpenSight Software, LLC
Integrity Level:
MEDIUM
Description:
FlashFXP
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\program files\flashfxp 5\flashfxp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3564"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\KeyGen\Keygen.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\KeyGen\Keygen.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225547
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970\keygen\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3860"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Patch\patch.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Patch\patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970\patch\patch.exe
c:\windows\system32\ntdll.dll
3864"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FlashFXP.5.4.0.Build.3970.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3932"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.exe
explorer.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
MEDIUM
Description:
FlashFXP Installation
Exit code:
3221226540
Version:
5.4.0.3970
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970.exe
c:\windows\system32\ntdll.dll
3960.\FlashFXP5_Setup.exe /m="C:\Users\admin\Desktop\FLASHF~1.397\FLASHF~1.397\FLASHF~1.EXE" /k=""C:\ProgramData\mia43EA.tmp\FlashFXP5_Setup.exe
FlashFXP.5.4.0.Build.3970.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
HIGH
Description:
FlashFXP Installation
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\programdata\mia43ea.tmp\flashfxp5_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
32 511
Read events
32 245
Write events
235
Delete events
31

Modification events

(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FlashFXP.5.4.0.Build.3970.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
54
Suspicious files
25
Text files
71
Unknown types
7

Dropped files

PID
Process
Filename
Type
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.exeexecutable
MD5:8CD4B351244B15C40194185B2C804154
SHA256:631AE7074649A665D62AC6FC940D203EFF715C88B4B57EE46865286607909231
2648FlashFXP.5.4.0.Build.3970.exeC:\ProgramData\mia43EA.tmp\data\OFFLINE\FF2DB651\68B78533\flashfxp.chmchm
MD5:62B822DAEBDAA8D825756872A9C8F7B2
SHA256:AC2301CB25568D6A432F3AEF2C8CBA6547424F18B8EA41514E3D3CE053FEDBAE
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Patch\patch.exeexecutable
MD5:3FB257D56FA1BB87E01792B9BB342DF4
SHA256:9F14B237218E7A422ED1FF6BD1805F03ABF3E0B81AE83CF7C238799DCA6D1F2C
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\KeyGen\Keygen.exeexecutable
MD5:25D30D13C66368C6E264631CD4D9F665
SHA256:3B0110B7FDD79ED3821FB96E7F8EAAC27DB893272D46EDAA3A8DD0F24B8E45D8
2648FlashFXP.5.4.0.Build.3970.exeC:\ProgramData\mia43EA.tmp\data\OFFLINE\AF05CD28\68B78533\libcrypto-1_1.dllexecutable
MD5:9FD7C07BE92476F8E925F51E03CCE20C
SHA256:57E1E17D63EFC7B46D051D0267F8A01B52B9A649684BCF9C2809E18F98F7A473
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\KeyGen\FFF.NFOtext
MD5:EC5CB51A4B46BC62D6CC75A32DC23851
SHA256:AC10EF5DAEF3F2D581B328B9050228335EE7CBE18D34F8552E41A4C0D077E030
2648FlashFXP.5.4.0.Build.3970.exeC:\ProgramData\mia43EA.tmp\FlashFXP5_Setup.exeexecutable
MD5:F7071E5890CA24E4A70BD464864F73C5
SHA256:F853F133A483FDA5066D376C84AC589D20A7748D4BDBCC3C7F4D1666CFF15F3C
2648FlashFXP.5.4.0.Build.3970.exeC:\ProgramData\mia43EA.tmp\data\OFFLINE\F5F53788\68B78533\IEFlash.dllexecutable
MD5:8A7F6277412DE46264D66AB7364D0DE8
SHA256:B52C800421C9CEB29816B29D76A69F71B5439BCFC442875AA94A1F1B19DFEFEE
2648FlashFXP.5.4.0.Build.3970.exeC:\ProgramData\mia43EA.tmp\data\OFFLINE\567099BD\68B78533\libeay32.dllexecutable
MD5:EC378CBB7E8A2BCF317A2280AF3ED16A
SHA256:17989AD9AC232405870502A4F81C66F8D845729960D2A056E112C884B53A69E9
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970\Readme.txttext
MD5:666D606831FF1D25584B7E773C396B92
SHA256:8700E068102CDCE988CE02DE81665F76F459779FE50DBF09EFEE051158233C2F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
13
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3960
FlashFXP5_Setup.exe
GET
304
23.32.238.235:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a65c765d39622c71
unknown
unknown
3960
FlashFXP5_Setup.exe
GET
200
23.32.238.235:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8bbac7a3b9c97ce5
unknown
compressed
65.2 Kb
unknown
3960
FlashFXP5_Setup.exe
GET
200
23.192.153.142:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
3960
FlashFXP5_Setup.exe
GET
200
23.192.153.142:80
http://x2.c.lencr.org/
unknown
binary
299 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3960
FlashFXP5_Setup.exe
104.21.5.173:443
app.flashfxp.com
CLOUDFLARENET
unknown
3960
FlashFXP5_Setup.exe
23.32.238.235:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3960
FlashFXP5_Setup.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown
2108
FlashFXP.exe
104.21.5.173:443
app.flashfxp.com
CLOUDFLARENET
unknown
3248
FlashFXP.exe
104.21.5.173:443
app.flashfxp.com
CLOUDFLARENET
unknown
3248
FlashFXP.exe
172.67.133.170:443
app.flashfxp.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
app.flashfxp.com
  • 104.21.5.173
  • 172.67.133.170
unknown
ctldl.windowsupdate.com
  • 23.32.238.235
  • 23.32.238.217
  • 23.32.238.243
  • 23.32.238.210
  • 23.32.238.224
  • 23.32.238.219
  • 23.32.238.232
  • 23.32.238.242
  • 23.32.238.240
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
x2.c.lencr.org
  • 23.192.153.142
whitelisted

Threats

No threats detected
No debug info