File name:

Shark Tool FRP 0.5.exe

Full analysis: https://app.any.run/tasks/4fd4f808-6388-424b-a89c-d4bd034087c3
Verdict: Malicious activity
Analysis date: January 05, 2024, 15:35:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F3CE51FE0FE3681AA288A1E41D59C667

SHA1:

D8E61EDE1C6EDFEF1E10BFCE7AD78C47E4F01FA6

SHA256:

9FF8A4AC1B2217FB033D5D260C4C51447BB637823C86FE547ABF47CCD105E194

SSDEEP:

98304:zXPNM5NwCDx4Xbsd6dS3THTS9dtUm/s7OO5xDL374KOfgXAiKsKiw8HJYdyhWiFP:rulK+SVMa/5ukdboISvt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Reads settings of System Certificates

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Reads the Internet Settings

      • Shark Tool FRP 0.5.exe (PID: 2208)
  • INFO

    • Checks supported languages

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Drops the executable file immediately after the start

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Reads the computer name

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Process checks are UAC notifies on

      • Shark Tool FRP 0.5.exe (PID: 2208)
    • Reads the machine GUID from the registry

      • Shark Tool FRP 0.5.exe (PID: 2208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:25 20:43:29+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 4211200
InitializedDataSize: 780288
UninitializedDataSize: -
EntryPoint: 0x1173108
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.5
ProductVersionNumber: 0.0.0.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: Shark Tool
FileVersion: 0.0.0.5
LegalCopyright: Copyright (c) Sark Tool
ProgramID: Shark Team
ProductName: Shark Tool
ProductVersion: 0.0.0.5
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start shark tool frp 0.5.exe shark tool frp 0.5.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Users\admin\AppData\Local\Temp\Shark Tool FRP 0.5.exe" C:\Users\admin\AppData\Local\Temp\Shark Tool FRP 0.5.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Shark Tool
Exit code:
3221226540
Version:
0.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\shark tool frp 0.5.exe
c:\windows\system32\ntdll.dll
2208"C:\Users\admin\AppData\Local\Temp\Shark Tool FRP 0.5.exe" C:\Users\admin\AppData\Local\Temp\Shark Tool FRP 0.5.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Shark Tool
Exit code:
0
Version:
0.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\shark tool frp 0.5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 609
Read events
3 595
Write events
14
Delete events
0

Modification events

(PID) Process:(2208) Shark Tool FRP 0.5.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2208
Shark Tool FRP 0.5.exe
172.67.69.125:443
api.shark-tool.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
api.shark-tool.com
  • 172.67.69.125
  • 104.26.15.185
  • 104.26.14.185
unknown

Threats

No threats detected
No debug info