File name:

[FTUApps.com] - FL Studio Producer Edition v24.1.2.zip

Full analysis: https://app.any.run/tasks/bcf9647d-79aa-4f0b-a216-44d1a6d8fc3d
Verdict: Malicious activity
Analysis date: December 02, 2024, 05:58:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

713F4D5F9F792D94D5B42B5D27886BF4

SHA1:

66D63652B3A839BDACCC42FAC8366820CA13E14A

SHA256:

9ED04A28E9EA9AE623D880B2FFDF0F9349B422D5DB87A9491BDC7FA132E3E2FD

SSDEEP:

49152:77HeQqhlQ6NY3f04ulih/On1tEaLI5IrziAiDcazIV+Lcrp4+B8+JHfPh2FdDo0e:H+QqZ8fVOteSf04WRLWpBz01hbbOGlbA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6412)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6412)
      • FL.Studio.v24.1.2.4394.tmp (PID: 6900)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7152)
    • Executable content was dropped or overwritten

      • FL.Studio.v24.1.2.4394.exe (PID: 6880)
      • FL.Studio.v24.1.2.4394.exe (PID: 6976)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.exe (PID: 7132)
      • FL.Studio.v24.1.2.4394.exe (PID: 2424)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
    • Reads the Windows owner or organization settings

      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 6412)
  • INFO

    • Create files in a temporary directory

      • FL.Studio.v24.1.2.4394.exe (PID: 6880)
      • FL.Studio.v24.1.2.4394.exe (PID: 6976)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.exe (PID: 7132)
      • FL.Studio.v24.1.2.4394.exe (PID: 2424)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
    • Checks supported languages

      • FL.Studio.v24.1.2.4394.exe (PID: 6880)
      • FL.Studio.v24.1.2.4394.tmp (PID: 6900)
      • FL.Studio.v24.1.2.4394.exe (PID: 6976)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.exe (PID: 7132)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7152)
      • FL.Studio.v24.1.2.4394.exe (PID: 2424)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
    • Reads the computer name

      • FL.Studio.v24.1.2.4394.tmp (PID: 6900)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7152)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6412)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6412)
    • Process checks computer location settings

      • FL.Studio.v24.1.2.4394.tmp (PID: 6900)
      • FL.Studio.v24.1.2.4394.tmp (PID: 7152)
    • Creates files or folders in the user directory

      • FL.Studio.v24.1.2.4394.tmp (PID: 7000)
      • FL.Studio.v24.1.2.4394.tmp (PID: 3608)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7088)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 6412)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:12:01 07:09:20
ZipCRC: 0xe085332b
ZipCompressedSize: 239
ZipUncompressedSize: 239
ZipFileName: FTUApps.com - Download Paids Apps Free.url
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
10
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe fl.studio.v24.1.2.4394.exe fl.studio.v24.1.2.4394.tmp no specs fl.studio.v24.1.2.4394.exe fl.studio.v24.1.2.4394.tmp notepad.exe no specs fl.studio.v24.1.2.4394.exe fl.studio.v24.1.2.4394.tmp no specs fl.studio.v24.1.2.4394.exe fl.studio.v24.1.2.4394.tmp

Process information

PID
CMD
Path
Indicators
Parent process
2424"C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe" /SPAWNWND=$90306 /NOTIFYWND=$D022A C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe
FL.Studio.v24.1.2.4394.tmp
User:
admin
Company:
Image Line Software
Integrity Level:
HIGH
Description:
FL Studio
Version:
24.1.2.439.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6412.49749\fl.studio.v24.1.2.4394.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3608"C:\Users\admin\AppData\Local\Temp\is-LJF9G.tmp\FL.Studio.v24.1.2.4394.tmp" /SL5="$E01F2,876544,0,C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe" /SPAWNWND=$90306 /NOTIFYWND=$D022A C:\Users\admin\AppData\Local\Temp\is-LJF9G.tmp\FL.Studio.v24.1.2.4394.tmp
FL.Studio.v24.1.2.4394.exe
User:
admin
Company:
Image Line Software
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ljf9g.tmp\fl.studio.v24.1.2.4394.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\mpr.dll
6412"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\[FTUApps.com] - FL Studio Producer Edition v24.1.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6880"C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe
WinRAR.exe
User:
admin
Company:
Image Line Software
Integrity Level:
MEDIUM
Description:
FL Studio
Exit code:
5
Version:
24.1.2.439.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6412.45536\fl.studio.v24.1.2.4394.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6900"C:\Users\admin\AppData\Local\Temp\is-EVKLF.tmp\FL.Studio.v24.1.2.4394.tmp" /SL5="$602A6,876544,0,C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe" C:\Users\admin\AppData\Local\Temp\is-EVKLF.tmp\FL.Studio.v24.1.2.4394.tmpFL.Studio.v24.1.2.4394.exe
User:
admin
Company:
Image Line Software
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
5
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-evklf.tmp\fl.studio.v24.1.2.4394.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
6976"C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe" /SPAWNWND=$6030A /NOTIFYWND=$602A6 C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe
FL.Studio.v24.1.2.4394.tmp
User:
admin
Company:
Image Line Software
Integrity Level:
HIGH
Description:
FL Studio
Exit code:
5
Version:
24.1.2.439.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6412.45536\fl.studio.v24.1.2.4394.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7000"C:\Users\admin\AppData\Local\Temp\is-G6GD1.tmp\FL.Studio.v24.1.2.4394.tmp" /SL5="$80356,876544,0,C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exe" /SPAWNWND=$6030A /NOTIFYWND=$602A6 C:\Users\admin\AppData\Local\Temp\is-G6GD1.tmp\FL.Studio.v24.1.2.4394.tmp
FL.Studio.v24.1.2.4394.exe
User:
admin
Company:
Image Line Software
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
5
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-g6gd1.tmp\fl.studio.v24.1.2.4394.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
7088"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa6412.48656\Readme.txtC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
7132"C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe
WinRAR.exe
User:
admin
Company:
Image Line Software
Integrity Level:
MEDIUM
Description:
FL Studio
Version:
24.1.2.439.4
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6412.49749\fl.studio.v24.1.2.4394.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7152"C:\Users\admin\AppData\Local\Temp\is-HMSKS.tmp\FL.Studio.v24.1.2.4394.tmp" /SL5="$D022A,876544,0,C:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exe" C:\Users\admin\AppData\Local\Temp\is-HMSKS.tmp\FL.Studio.v24.1.2.4394.tmpFL.Studio.v24.1.2.4394.exe
User:
admin
Company:
Image Line Software
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-hmsks.tmp\fl.studio.v24.1.2.4394.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
Total events
2 925
Read events
2 916
Write events
9
Delete events
0

Modification events

(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\[FTUApps.com] - FL Studio Producer Edition v24.1.2.zip
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6412) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
Executable files
12
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
6412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\Join Our Telegram.txttext
MD5:987526EF99B0B0626E47914A278B9059
SHA256:C619DE0B50A8DF02BDD1033E342BCFED1150D01A78A471FC62A56A1F0F958F8C
6412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\FL.Studio.v24.1.2.4394.exeexecutable
MD5:78C43F73484B4F54982424446F9EEB9A
SHA256:2492D5EF655E6CBE0FA6AF364F329E4A7EA9F805BE84636661D994A12F41EF5D
6412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6412.45536\Readme.txttext
MD5:FDFBFCCB1E091776439567EE49FDF9BA
SHA256:DBF7A51DFA234368935129CFFE396DD21759BF104D768C60EDC31AA8ACF69D81
6976FL.Studio.v24.1.2.4394.exeC:\Users\admin\AppData\Local\Temp\is-G6GD1.tmp\FL.Studio.v24.1.2.4394.tmpexecutable
MD5:745FC509050BDB38CC7C56CC22049ECB
SHA256:6426B5D1F308D2B888D46C47C71DA0961737EDF98DD6E693FCCDDD5C66648849
6412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FTUApps.com - Download Paids Apps Free.urlurl
MD5:708A581C8010D315C99C5ED36512CA2C
SHA256:0F5746A7B0CD0A4904117B92F1330FBBA1981BFFF6AA8913C6EC19C0FF7F65B6
7000FL.Studio.v24.1.2.4394.tmpC:\Users\admin\AppData\Local\is-2TBNA.tmpexecutable
MD5:9C5C27AC197D05E766D9A98832E3757F
SHA256:EF3BE42E23143EEE1EA570353C0DF9E301EEDFF8DB4A89B9C603E66576E78682
7000FL.Studio.v24.1.2.4394.tmpC:\Users\admin\AppData\Local\unins000.exeexecutable
MD5:9C5C27AC197D05E766D9A98832E3757F
SHA256:EF3BE42E23143EEE1EA570353C0DF9E301EEDFF8DB4A89B9C603E66576E78682
6880FL.Studio.v24.1.2.4394.exeC:\Users\admin\AppData\Local\Temp\is-EVKLF.tmp\FL.Studio.v24.1.2.4394.tmpexecutable
MD5:745FC509050BDB38CC7C56CC22049ECB
SHA256:6426B5D1F308D2B888D46C47C71DA0961737EDF98DD6E693FCCDDD5C66648849
6412WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6412.49749\FL.Studio.v24.1.2.4394.exeexecutable
MD5:78C43F73484B4F54982424446F9EEB9A
SHA256:2492D5EF655E6CBE0FA6AF364F329E4A7EA9F805BE84636661D994A12F41EF5D
3608FL.Studio.v24.1.2.4394.tmpC:\Users\admin\AppData\Local\Temp\is-12BG0.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
23
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3976
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5340
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.238
whitelisted

Threats

No threats detected
No debug info