File name:

fdmftsetup.exe

Full analysis: https://app.any.run/tasks/3b44f18b-05d7-47dd-a5d6-e123710c1934
Verdict: Malicious activity
Analysis date: January 12, 2024, 13:02:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E76E0C6984311CF12820BBD6E6F3057

SHA1:

C4652FF057D31DA5EBDE1E389B813D1D58C29944

SHA256:

A5F9660307EB21CAA05CEA8A405930A4283825947DE4F8DDE6088EEAC692A68F

SSDEEP:

98304:kzEIuJ3PT+nz4TryfltuoQer6cHjyxGsMJ/RcOctjjzXgWYWDmJMHdTu8ZL9ZejR:8rJ00HZ8Bb2f7/nKRPej

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • ftsetup.exe (PID: 1780)
      • ftsetup.tmp (PID: 1972)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
    • Actions looks like stealing of personal data

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • unzip.exe (PID: 696)
    • Steals credentials from Web Browsers

      • fdm.exe (PID: 1652)
    • Creates a writable file in the system directory

      • WombatUpdater.exe (PID: 1844)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • ftsetup.exe (PID: 1780)
      • updater_setup.exe (PID: 1796)
      • fastesttube_1.3.7.exe (PID: 1808)
      • ftsetup.tmp (PID: 1972)
    • Starts application with an unusual extension

      • fdmftsetup.exe (PID: 2268)
    • Process drops legitimate windows executable

      • fdm134.tmp (PID: 2016)
      • ftsetup.tmp (PID: 1972)
    • Reads the Windows owner or organization settings

      • fdm134.tmp (PID: 2016)
      • ftsetup.tmp (PID: 1972)
    • The process drops C-runtime libraries

      • fdm134.tmp (PID: 2016)
    • Drops 7-zip archiver for unpacking

      • fdm134.tmp (PID: 2016)
    • Reads the Internet Settings

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
    • Searches for installed software

      • ftsetup.tmp (PID: 1972)
    • The process executes via Task Scheduler

      • WombatUpdater.exe (PID: 1844)
  • INFO

    • Create files in a temporary directory

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2016)
      • fdm134.tmp (PID: 2024)
      • ftsetup.exe (PID: 1780)
      • ftsetup.tmp (PID: 1972)
      • updater_setup.exe (PID: 1796)
    • Checks supported languages

      • fdm134.tmp (PID: 2024)
      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2016)
      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • ftsetup.exe (PID: 1780)
      • unzip.exe (PID: 696)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • WombatUpdater.exe (PID: 1844)
      • WombatUpdater.exe (PID: 2172)
    • Reads the computer name

      • fdm134.tmp (PID: 2016)
      • ftsetup.tmp (PID: 1972)
      • fdm.exe (PID: 1652)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • WombatUpdater.exe (PID: 1844)
      • WombatUpdater.exe (PID: 2172)
    • Creates files in the program directory

      • fdm134.tmp (PID: 2016)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • ftsetup.tmp (PID: 1972)
    • Creates files or folders in the user directory

      • fdm134.tmp (PID: 2016)
      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • unzip.exe (PID: 696)
    • Checks proxy server information

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
    • Reads the machine GUID from the registry

      • ftsetup.tmp (PID: 1972)
      • WombatUpdater.exe (PID: 1844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (52.5)
.scr | Windows screen saver (22)
.dll | Win32 Dynamic Link Library (generic) (11)
.exe | Win32 Executable (generic) (7.5)
.exe | Generic Win/DOS Executable (3.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:02:18 02:29:55+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 40960
UninitializedDataSize: -
EntryPoint: 0x1eca
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start fdmftsetup.exe fdm134.tmp fdm134.tmp fdm.exe ftsetup.exe ftsetup.tmp unzip.exe fastesttube_1.3.7.exe updater_setup.exe wombatupdater.exe no specs wombatupdater.exe fdmftsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\fdmftsetup.exe" C:\Users\admin\AppData\Local\Temp\fdmftsetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\fdmftsetup.exe
c:\windows\system32\ntdll.dll
696"C:\Users\admin\AppData\Local\FastestTube\unzip.exe" -o -qq "C:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.xpi" -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default\extensions\{6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}"C:\Users\admin\AppData\Local\FastestTube\unzip.exe
ftsetup.tmp
User:
admin
Company:
Info-Zip <www.info-zip.org>
Integrity Level:
HIGH
Description:
UnZip SPECS UnZip: list, test and extract compressed files in a ZIP archive
Exit code:
0
Version:
5.51.1871.34282
Modules
Images
c:\users\admin\appdata\local\fastesttube\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1652"C:\Program Files\Free Download Manager\fdm.exe" -regserverC:\Program Files\Free Download Manager\fdm.exe
fdm134.tmp
User:
admin
Company:
FreeDownloadManager.ORG
Integrity Level:
HIGH
Description:
Free Download Manager
Exit code:
0
Version:
3, 0, 852, 0
Modules
Images
c:\program files\free download manager\fdm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1780"C:\Program Files\Free Download Manager\ftsetup.exe" /VERYSILENT /NORESTART /SUPPRESSMSGBOXESC:\Program Files\Free Download Manager\ftsetup.exe
fdm134.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
FastestTube Setup
Exit code:
0
Version:
1.3.7.0
Modules
Images
c:\program files\free download manager\ftsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1796updater_setup.exe /SC:\Program Files\FastestTube\1.3.7\updater_setup.exe
fastesttube_1.3.7.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\fastesttube\1.3.7\updater_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1808"C:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.exe" /S /noitemC:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.exe
ftsetup.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\fastesttube\fastesttube_1.3.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1844C:\ProgramData\WombatUpdater\WombatUpdater.exe C:\ProgramData\WombatUpdater\WombatUpdater.exe
taskeng.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\programdata\wombatupdater\wombatupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1972"C:\Users\admin\AppData\Local\Temp\is-38K57.tmp\ftsetup.tmp" /SL5="$20136,636300,140800,C:\Program Files\Free Download Manager\ftsetup.exe" /VERYSILENT /NORESTART /SUPPRESSMSGBOXESC:\Users\admin\AppData\Local\Temp\is-38K57.tmp\ftsetup.tmp
ftsetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-38k57.tmp\ftsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2016"C:\Users\admin\AppData\Local\Temp\is-BL1KE.tmp\fdm134.tmp" /SL5="$30128,6733168,54272,C:\Users\admin\AppData\Local\Temp\fdm134.tmp" C:\Users\admin\AppData\Local\Temp\is-BL1KE.tmp\fdm134.tmp
fdm134.tmp
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-bl1ke.tmp\fdm134.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2024"C:\Users\admin\AppData\Local\Temp\fdm134.tmp"C:\Users\admin\AppData\Local\Temp\fdm134.tmp
fdmftsetup.exe
User:
admin
Company:
FreeDownloadManager.ORG
Integrity Level:
HIGH
Description:
Free Download Manager Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\fdm134.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
2 846
Read events
2 803
Write events
37
Delete events
6

Modification events

(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:SwitchToOpinions
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:CheckIfMalBeforeDlding
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:DisplayOpinionsAtDlding
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Network\Bittorrent
Operation:writeName:Enable
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\LocalServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\ProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\Programmable
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\TypeLib
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\VersionIndependentProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}
Operation:delete keyName:(default)
Value:
Executable files
63
Suspicious files
89
Text files
215
Unknown types
0

Dropped files

PID
Process
Filename
Type
2268fdmftsetup.exeC:\Users\admin\AppData\Local\Temp\fdm134.tmpexecutable
MD5:895ED79F6A08F68DD975161854472A09
SHA256:3D4D421659D985F1A415DC024A51F3173B8892ABF3A4037D6B8B77025E2358EA
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\alb.lngtext
MD5:356D87A0000D7A56813446F594A05194
SHA256:B6286EB99DB92C6D5E4429182FA4B2C9E7446376710264AADCEF1966891094FE
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-M5EB6.tmptext
MD5:48CA3E512307684C80F40C7CD25E7B8F
SHA256:5B7591E12BB8DB91838B12F6339F26A50BE5BEFC264D28BE898126AC6D229DDE
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-NKQ7M.tmptext
MD5:356D87A0000D7A56813446F594A05194
SHA256:B6286EB99DB92C6D5E4429182FA4B2C9E7446376710264AADCEF1966891094FE
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-3R8QJ.tmptext
MD5:B507BF22531E8B1B6EA1376A2B284641
SHA256:A1A3E8FBA3635FC8472ADAB9B0B3FD80111FC96A354D7C04B24B5B83EC2EA48A
2016fdm134.tmpC:\Program Files\Free Download Manager\unins000.exeexecutable
MD5:82488F7F7B142C9CDE4DB28D36943436
SHA256:6A395958AD8AEB1076F0055262D2176F4BFE0912B3BA2298B7EC05E41F11DC05
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\arb.lngtext
MD5:B507BF22531E8B1B6EA1376A2B284641
SHA256:A1A3E8FBA3635FC8472ADAB9B0B3FD80111FC96A354D7C04B24B5B83EC2EA48A
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-M4KIF.tmptext
MD5:B4D0912E3973D90CCB25F77D301C019D
SHA256:84A8F86DCDF4E4A6FD2ACFB21B9BE5A752AD91E2F96ACE777EB5FE922295CC23
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\cat.lngtext
MD5:8F048AC9448DBA481E3662C0A5A6FA64
SHA256:30BA34C9673AEDDC32E429387C2CC8C70CACBE089D94EA0BC20C147856B4C624
2016fdm134.tmpC:\Users\admin\AppData\Local\Temp\is-95LRR.tmp\ftsshot.bmpimage
MD5:8B95CC604BCC3B32CDED6C965AE1CF6A
SHA256:1C25F2503379DF5CA3444203921AC39C7995AB0912E165FCE30BE5E06E4CAAE6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1972
ftsetup.tmp
GET
172.67.209.141:80
http://stat.adlesse.com/log.php?id=819&r=2982
unknown
unknown
1844
WombatUpdater.exe
GET
200
204.155.156.137:80
http://kwizzu.com/fastesttube/ie/update.xml
unknown
xml
139 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1972
ftsetup.tmp
172.67.209.141:80
stat.adlesse.com
CLOUDFLARENET
US
unknown
1844
WombatUpdater.exe
204.155.156.137:80
kwizzu.com
WZCOM
US
unknown
1844
WombatUpdater.exe
204.155.156.137:443
kwizzu.com
WZCOM
US
unknown

DNS requests

Domain
IP
Reputation
stat.adlesse.com
  • 172.67.209.141
  • 104.21.85.192
unknown
kwizzu.com
  • 204.155.156.137
unknown

Threats

No threats detected
No debug info