File name:

fdmftsetup.exe

Full analysis: https://app.any.run/tasks/3b44f18b-05d7-47dd-a5d6-e123710c1934
Verdict: Malicious activity
Analysis date: January 12, 2024, 13:02:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E76E0C6984311CF12820BBD6E6F3057

SHA1:

C4652FF057D31DA5EBDE1E389B813D1D58C29944

SHA256:

A5F9660307EB21CAA05CEA8A405930A4283825947DE4F8DDE6088EEAC692A68F

SSDEEP:

98304:kzEIuJ3PT+nz4TryfltuoQer6cHjyxGsMJ/RcOctjjzXgWYWDmJMHdTu8ZL9ZejR:8rJ00HZ8Bb2f7/nKRPej

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • ftsetup.exe (PID: 1780)
      • ftsetup.tmp (PID: 1972)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
    • Actions looks like stealing of personal data

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • unzip.exe (PID: 696)
    • Steals credentials from Web Browsers

      • fdm.exe (PID: 1652)
    • Creates a writable file in the system directory

      • WombatUpdater.exe (PID: 1844)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • ftsetup.exe (PID: 1780)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • ftsetup.tmp (PID: 1972)
    • Drops 7-zip archiver for unpacking

      • fdm134.tmp (PID: 2016)
    • Reads the Windows owner or organization settings

      • fdm134.tmp (PID: 2016)
      • ftsetup.tmp (PID: 1972)
    • Process drops legitimate windows executable

      • fdm134.tmp (PID: 2016)
      • ftsetup.tmp (PID: 1972)
    • The process drops C-runtime libraries

      • fdm134.tmp (PID: 2016)
    • Starts application with an unusual extension

      • fdmftsetup.exe (PID: 2268)
    • Reads the Internet Settings

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
    • The process executes via Task Scheduler

      • WombatUpdater.exe (PID: 1844)
    • Searches for installed software

      • ftsetup.tmp (PID: 1972)
  • INFO

    • Create files in a temporary directory

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • ftsetup.exe (PID: 1780)
      • ftsetup.tmp (PID: 1972)
      • updater_setup.exe (PID: 1796)
    • Checks supported languages

      • fdmftsetup.exe (PID: 2268)
      • fdm134.tmp (PID: 2024)
      • fdm134.tmp (PID: 2016)
      • fdm.exe (PID: 1652)
      • ftsetup.exe (PID: 1780)
      • ftsetup.tmp (PID: 1972)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • WombatUpdater.exe (PID: 2172)
      • unzip.exe (PID: 696)
      • WombatUpdater.exe (PID: 1844)
    • Reads the computer name

      • fdm134.tmp (PID: 2016)
      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • fastesttube_1.3.7.exe (PID: 1808)
      • updater_setup.exe (PID: 1796)
      • WombatUpdater.exe (PID: 2172)
      • WombatUpdater.exe (PID: 1844)
    • Creates files or folders in the user directory

      • fdm134.tmp (PID: 2016)
      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
      • unzip.exe (PID: 696)
    • Creates files in the program directory

      • fdm134.tmp (PID: 2016)
      • updater_setup.exe (PID: 1796)
      • fastesttube_1.3.7.exe (PID: 1808)
      • ftsetup.tmp (PID: 1972)
    • Checks proxy server information

      • fdm.exe (PID: 1652)
      • ftsetup.tmp (PID: 1972)
    • Reads the machine GUID from the registry

      • ftsetup.tmp (PID: 1972)
      • WombatUpdater.exe (PID: 1844)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (52.5)
.scr | Windows screen saver (22)
.dll | Win32 Dynamic Link Library (generic) (11)
.exe | Win32 Executable (generic) (7.5)
.exe | Generic Win/DOS Executable (3.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:02:18 02:29:55+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 40960
UninitializedDataSize: -
EntryPoint: 0x1eca
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start fdmftsetup.exe fdm134.tmp fdm134.tmp fdm.exe ftsetup.exe ftsetup.tmp unzip.exe fastesttube_1.3.7.exe updater_setup.exe wombatupdater.exe no specs wombatupdater.exe fdmftsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\fdmftsetup.exe" C:\Users\admin\AppData\Local\Temp\fdmftsetup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\fdmftsetup.exe
c:\windows\system32\ntdll.dll
696"C:\Users\admin\AppData\Local\FastestTube\unzip.exe" -o -qq "C:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.xpi" -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default\extensions\{6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}"C:\Users\admin\AppData\Local\FastestTube\unzip.exe
ftsetup.tmp
User:
admin
Company:
Info-Zip <www.info-zip.org>
Integrity Level:
HIGH
Description:
UnZip SPECS UnZip: list, test and extract compressed files in a ZIP archive
Exit code:
0
Version:
5.51.1871.34282
Modules
Images
c:\users\admin\appdata\local\fastesttube\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1652"C:\Program Files\Free Download Manager\fdm.exe" -regserverC:\Program Files\Free Download Manager\fdm.exe
fdm134.tmp
User:
admin
Company:
FreeDownloadManager.ORG
Integrity Level:
HIGH
Description:
Free Download Manager
Exit code:
0
Version:
3, 0, 852, 0
Modules
Images
c:\program files\free download manager\fdm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1780"C:\Program Files\Free Download Manager\ftsetup.exe" /VERYSILENT /NORESTART /SUPPRESSMSGBOXESC:\Program Files\Free Download Manager\ftsetup.exe
fdm134.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
FastestTube Setup
Exit code:
0
Version:
1.3.7.0
Modules
Images
c:\program files\free download manager\ftsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1796updater_setup.exe /SC:\Program Files\FastestTube\1.3.7\updater_setup.exe
fastesttube_1.3.7.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\fastesttube\1.3.7\updater_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1808"C:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.exe" /S /noitemC:\Users\admin\AppData\Local\FastestTube\fastesttube_1.3.7.exe
ftsetup.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\fastesttube\fastesttube_1.3.7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1844C:\ProgramData\WombatUpdater\WombatUpdater.exe C:\ProgramData\WombatUpdater\WombatUpdater.exe
taskeng.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\programdata\wombatupdater\wombatupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1972"C:\Users\admin\AppData\Local\Temp\is-38K57.tmp\ftsetup.tmp" /SL5="$20136,636300,140800,C:\Program Files\Free Download Manager\ftsetup.exe" /VERYSILENT /NORESTART /SUPPRESSMSGBOXESC:\Users\admin\AppData\Local\Temp\is-38K57.tmp\ftsetup.tmp
ftsetup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-38k57.tmp\ftsetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2016"C:\Users\admin\AppData\Local\Temp\is-BL1KE.tmp\fdm134.tmp" /SL5="$30128,6733168,54272,C:\Users\admin\AppData\Local\Temp\fdm134.tmp" C:\Users\admin\AppData\Local\Temp\is-BL1KE.tmp\fdm134.tmp
fdm134.tmp
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-bl1ke.tmp\fdm134.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2024"C:\Users\admin\AppData\Local\Temp\fdm134.tmp"C:\Users\admin\AppData\Local\Temp\fdm134.tmp
fdmftsetup.exe
User:
admin
Company:
FreeDownloadManager.ORG
Integrity Level:
HIGH
Description:
Free Download Manager Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\fdm134.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
2 846
Read events
2 803
Write events
37
Delete events
6

Modification events

(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:SwitchToOpinions
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:CheckIfMalBeforeDlding
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Community
Operation:writeName:DisplayOpinionsAtDlding
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FreeDownloadManager.ORG\Free Download Manager\Settings\Network\Bittorrent
Operation:writeName:Enable
Value:
1
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\LocalServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\ProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\Programmable
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\TypeLib
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}\VersionIndependentProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(1652) fdm.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01483019-D8C9-47D8-8E93-AF032EBFADA6}
Operation:delete keyName:(default)
Value:
Executable files
63
Suspicious files
89
Text files
215
Unknown types
0

Dropped files

PID
Process
Filename
Type
2268fdmftsetup.exeC:\Users\admin\AppData\Local\Temp\fdm134.tmpexecutable
MD5:895ED79F6A08F68DD975161854472A09
SHA256:3D4D421659D985F1A415DC024A51F3173B8892ABF3A4037D6B8B77025E2358EA
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\alb.lngtext
MD5:356D87A0000D7A56813446F594A05194
SHA256:B6286EB99DB92C6D5E4429182FA4B2C9E7446376710264AADCEF1966891094FE
2016fdm134.tmpC:\Users\admin\AppData\Local\Temp\is-95LRR.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
2016fdm134.tmpC:\Users\admin\AppData\Local\Temp\is-95LRR.tmp\fdminno.dllexecutable
MD5:440FFCAB7B04ED29A44D4092221AB088
SHA256:E486A34FFF3F5E9D7FD12A2AC9FC82E323BBAE2D3BAC9667595C8580A019B116
2016fdm134.tmpC:\Users\admin\AppData\Local\Temp\is-95LRR.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2016fdm134.tmpC:\Program Files\Free Download Manager\unins000.exeexecutable
MD5:82488F7F7B142C9CDE4DB28D36943436
SHA256:6A395958AD8AEB1076F0055262D2176F4BFE0912B3BA2298B7EC05E41F11DC05
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\cht.lngtext
MD5:065D2ACA7CBA306D2D934992FABAC98A
SHA256:E1088F174F72B6F161EEA2A62D66163C09B6B8E110ACB7AAB74529F5CEEC3CD7
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-M5EB6.tmptext
MD5:48CA3E512307684C80F40C7CD25E7B8F
SHA256:5B7591E12BB8DB91838B12F6339F26A50BE5BEFC264D28BE898126AC6D229DDE
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-M4KIF.tmptext
MD5:B4D0912E3973D90CCB25F77D301C019D
SHA256:84A8F86DCDF4E4A6FD2ACFB21B9BE5A752AD91E2F96ACE777EB5FE922295CC23
2016fdm134.tmpC:\Program Files\Free Download Manager\Language\is-O3GF4.tmptext
MD5:065D2ACA7CBA306D2D934992FABAC98A
SHA256:E1088F174F72B6F161EEA2A62D66163C09B6B8E110ACB7AAB74529F5CEEC3CD7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1972
ftsetup.tmp
GET
172.67.209.141:80
http://stat.adlesse.com/log.php?id=819&r=2982
unknown
unknown
1844
WombatUpdater.exe
GET
200
204.155.156.137:80
http://kwizzu.com/fastesttube/ie/update.xml
unknown
xml
139 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1972
ftsetup.tmp
172.67.209.141:80
stat.adlesse.com
CLOUDFLARENET
US
unknown
1844
WombatUpdater.exe
204.155.156.137:80
kwizzu.com
WZCOM
US
unknown
1844
WombatUpdater.exe
204.155.156.137:443
kwizzu.com
WZCOM
US
unknown

DNS requests

Domain
IP
Reputation
stat.adlesse.com
  • 172.67.209.141
  • 104.21.85.192
unknown
kwizzu.com
  • 204.155.156.137
unknown

Threats

No threats detected
No debug info