File name:

FlashFXP.5.4.0.Build.3970.rar

Full analysis: https://app.any.run/tasks/e56b74e5-c69d-4c35-8a73-3cceb6f6c0f9
Verdict: Malicious activity
Analysis date: February 17, 2024, 12:27:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

618DF102490DD1A85B8D439F5B67F79D

SHA1:

2540E3EA89420F080AAFCCD10539EC897A52AB01

SHA256:

A3CB788F23B299E95AFA9117CD3BEB731DC7A5E4F215CAD956B52C87E0DF512D

SSDEEP:

98304:U4GjVhgEcsGZZyqqqYKp2d64rTFU4r38/FpMYzjHhePQV+EXbnfBmGh1vml3Rl76:sbe4qH+oRKJhG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 3864)
      • WinRAR.exe (PID: 3460)
      • FlashFXP54_3970_Setup.exe (PID: 1860)
      • FlashFXP5_Setup.exe (PID: 1112)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3864)
      • patch.exe (PID: 956)
      • FlashFXP54_3970_Setup.exe (PID: 1860)
      • FlashFXP5_Setup.exe (PID: 1112)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • patch.exe (PID: 956)
      • FlashFXP54_3970_Setup.exe (PID: 1860)
      • FlashFXP5_Setup.exe (PID: 1112)
    • Process drops legitimate windows executable

      • FlashFXP54_3970_Setup.exe (PID: 1860)
    • Drops 7-zip archiver for unpacking

      • FlashFXP5_Setup.exe (PID: 1112)
    • Reads the Windows owner or organization settings

      • FlashFXP5_Setup.exe (PID: 1112)
    • The process drops C-runtime libraries

      • FlashFXP54_3970_Setup.exe (PID: 1860)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3864)
      • WinRAR.exe (PID: 3460)
    • Manual execution by a user

      • WinRAR.exe (PID: 3460)
      • patch.exe (PID: 2232)
      • patch.exe (PID: 956)
      • notepad.exe (PID: 2064)
      • FlashFXP54_3970_Setup.exe (PID: 848)
      • FlashFXP54_3970_Setup.exe (PID: 1860)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3460)
    • Create files in a temporary directory

      • patch.exe (PID: 956)
      • FlashFXP5_Setup.exe (PID: 1112)
    • Checks supported languages

      • patch.exe (PID: 956)
      • FlashFXP54_3970_Setup.exe (PID: 1860)
      • FlashFXP5_Setup.exe (PID: 1112)
    • Creates files in the program directory

      • FlashFXP54_3970_Setup.exe (PID: 1860)
    • Reads the computer name

      • FlashFXP5_Setup.exe (PID: 1112)
    • Creates files or folders in the user directory

      • FlashFXP5_Setup.exe (PID: 1112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 195931
UncompressedSize: 195862
OperatingSystem: Win32
ModifyDate: 2017:04:01 23:46:30
PackingMethod: Stored
ArchivedFileName: FlashFXP.5.4.0.Build.3970.KaranPC\Fixed.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe patch.exe no specs patch.exe notepad.exe no specs flashfxp54_3970_setup.exe no specs flashfxp54_3970_setup.exe flashfxp5_setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\FlashFXP54_3970_Setup.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\FlashFXP54_3970_Setup.exeexplorer.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
MEDIUM
Description:
FlashFXP Installation
Exit code:
3221226540
Version:
5.4.0.3970
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970.karanpc\flashfxp54_3970_setup.exe
c:\windows\system32\ntdll.dll
956"C:\Users\admin\Desktop\Fixed\patch.exe" C:\Users\admin\Desktop\Fixed\patch.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\fixed\patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1112.\FlashFXP5_Setup.exe /m="C:\Users\admin\Desktop\FLASHF~1.397\FLASHF~1.KAR\FLASHF~1.EXE" /k=""C:\ProgramData\mia73E3.tmp\FlashFXP5_Setup.exe
FlashFXP54_3970_Setup.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
HIGH
Description:
FlashFXP Installation
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\programdata\mia73e3.tmp\flashfxp5_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1860"C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\FlashFXP54_3970_Setup.exe" C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\FlashFXP54_3970_Setup.exe
explorer.exe
User:
admin
Company:
OpenSight Software LLC
Integrity Level:
HIGH
Description:
FlashFXP Installation
Exit code:
0
Version:
5.4.0.3970
Modules
Images
c:\users\admin\desktop\flashfxp.5.4.0.build.3970\flashfxp.5.4.0.build.3970.karanpc\flashfxp54_3970_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2064"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Fixed\ReadME.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2232"C:\Users\admin\Desktop\Fixed\patch.exe" C:\Users\admin\Desktop\Fixed\patch.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\fixed\patch.exe
c:\windows\system32\ntdll.dll
3460"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\Fixed.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3864"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FlashFXP.5.4.0.Build.3970.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
7 086
Read events
7 044
Write events
28
Delete events
14

Modification events

(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FlashFXP.5.4.0.Build.3970.rar
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
30
Suspicious files
14
Text files
39
Unknown types
0

Dropped files

PID
Process
Filename
Type
3864WinRAR.exeC:\Users\admin\Desktop\FlashFXP.5.4.0.Build.3970\FlashFXP.5.4.0.Build.3970.KaranPC\Fixed.rarcompressed
MD5:D6B79904248BFC30AEA93ECA967B0009
SHA256:F9094D0BC196DFEA1AD2CF35F4EAF152963C02B5A48A6183DACA7E5124B12881
1860FlashFXP54_3970_Setup.exeC:\ProgramData\mia73E3.tmp\FlashFXP5_Setup.exeexecutable
MD5:F7071E5890CA24E4A70BD464864F73C5
SHA256:F853F133A483FDA5066D376C84AC589D20A7748D4BDBCC3C7F4D1666CFF15F3C
3460WinRAR.exeC:\Users\admin\Desktop\Fixed\KEYGEN-FFF\FFF.NFOtext
MD5:EC5CB51A4B46BC62D6CC75A32DC23851
SHA256:AC10EF5DAEF3F2D581B328B9050228335EE7CBE18D34F8552E41A4C0D077E030
3460WinRAR.exeC:\Users\admin\Desktop\Fixed\ReadME.txttext
MD5:A88BE202F7B113B7F9787FEEC77B990A
SHA256:6242AEE9BDD973714D0D9E2921265AEE1C7323CC041BBA56CBBDF9891F5A6E53
3460WinRAR.exeC:\Users\admin\Desktop\Fixed\patch.exeexecutable
MD5:3FB257D56FA1BB87E01792B9BB342DF4
SHA256:9F14B237218E7A422ED1FF6BD1805F03ABF3E0B81AE83CF7C238799DCA6D1F2C
1860FlashFXP54_3970_Setup.exeC:\ProgramData\mia73E3.tmp\data\OFFLINE\DAD92799\68B78533\libssl-1_1.dllexecutable
MD5:613CF648BAD9BCEDD36B61B07DF73787
SHA256:0589A38B1C2B41CE9D2CB96F14EB16C39598C473A8A64D5280C6ADD1C3BF3B99
956patch.exeC:\Users\admin\AppData\Local\Temp\dUP4E0B.tmpexecutable
MD5:9CAB84E34E172F5592BD1C15072A51F7
SHA256:A5D3B52271D154A3DFC2138176096ABCE529494852B649F02E0513C31B9CD000
1860FlashFXP54_3970_Setup.exeC:\ProgramData\mia73E3.tmp\data\OFFLINE\3731CFF1\68B78533\FlashFXP.exeexecutable
MD5:872EFE0137CE33E5E2C5A77FAA49C7F8
SHA256:981D0E9432B837AC20E7E6C74CA4511AE59F1EF73DAB37A1930B9A5672058D41
1860FlashFXP54_3970_Setup.exeC:\ProgramData\mia73E3.tmp\data\OFFLINE\F5F53788\68B78533\IEFlash.dllexecutable
MD5:8A7F6277412DE46264D66AB7364D0DE8
SHA256:B52C800421C9CEB29816B29D76A69F71B5439BCFC442875AA94A1F1B19DFEFEE
1860FlashFXP54_3970_Setup.exeC:\ProgramData\mia73E3.tmp\data\OFFLINE\mIDEFunc.dll\mEXEFunc.dllexecutable
MD5:B94F4B9790F50FE13961F2ADDE9FD23B
SHA256:EB6C4A273B5C7A19172A90DF5271BBD3B91FB425E8182E3FC63934255E1680F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info