| File name: | fgdump.exe |
| Full analysis: | https://app.any.run/tasks/c3644f63-ecfd-4b80-adb4-fc94b04e95cd |
| Verdict: | No threats detected |
| Analysis date: | January 07, 2020, 13:18:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 0762764E298C369A2DE8AFAEC5174ED9 |
| SHA1: | EC932D26A059A188AF6320B8CA76CE6E609F4878 |
| SHA256: | A6CAD2D0F8DC05246846D2A9618FC93B7D97681331D5826F8353E7C3A3206E86 |
| SSDEEP: | 12288:ED7lxIXgij3qi3MAxGQ3BdOukFfY+F1ldsui3hBTo:EEXjj3qgPGQ3BVkpY+F1ldsui37To |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:05:02 00:38:49+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 7.1 |
| CodeSize: | 90112 |
| InitializedDataSize: | 888832 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xdd80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows command line |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Foofus Networking (www.foofus.net) |
| FileDescription: | fgdump |
| FileVersion: | 1, 0, 0, 0 |
| InternalName: | fgdump |
| LegalCopyright: | Copyright (C) 2008 Foofus Networking (www.foofus.net) |
| LegalTrademarks: | Licensed under the GPL - see COPYING for more information |
| OriginalFileName: | fgdump.exe |
| ProductName: | fgdump 1.x |
| ProductVersion: | 1, 0, 0, 0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_CUI |
| Compilation Date: | 01-May-2008 22:38:49 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Foofus Networking (www.foofus.net) |
| FileDescription: | fgdump |
| FileVersion: | 1, 0, 0, 0 |
| InternalName: | fgdump |
| LegalCopyright: | Copyright (C) 2008 Foofus Networking (www.foofus.net) |
| LegalTrademarks: | Licensed under the GPL - see COPYING for more information |
| OriginalFilename: | fgdump.exe |
| ProductName: | fgdump 1.x |
| ProductVersion: | 1, 0, 0, 0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 4 |
| Time date stamp: | 01-May-2008 22:38:49 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000157D9 | 0x00016000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48027 |
.rdata | 0x00017000 | 0x0000734E | 0x00008000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.935 |
.data | 0x0001F000 | 0x00002818 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.76777 |
.rsrc | 0x00022000 | 0x000CD9F8 | 0x000CE000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.18884 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 3.41546 | 964 | UNKNOWN | English - United States | RT_VERSION |
130 | 5.94976 | 57344 | UNKNOWN | English - United States | BIN |
149 | 5.3728 | 49152 | UNKNOWN | English - United States | BIN |
174 | 6.24311 | 174080 | UNKNOWN | English - United States | BIN |
175 | 6.42295 | 126976 | UNKNOWN | English - United States | BIN |
176 | 6.1769 | 80896 | UNKNOWN | English - United States | BIN |
177 | 5.74017 | 77824 | UNKNOWN | English - United States | BIN |
178 | 6.25097 | 147456 | UNKNOWN | English - United States | BIN |
179 | 5.9317 | 69632 | UNKNOWN | English - United States | BIN |
180 | 5.9629 | 57344 | UNKNOWN | English - United States | BIN |
ADVAPI32.dll |
KERNEL32.dll |
MPR.dll |
NETAPI32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 504 | "C:\Users\admin\AppData\Local\Temp\fgdump.exe" | C:\Users\admin\AppData\Local\Temp\fgdump.exe | explorer.exe | ||||||||||||
User: admin Company: Foofus Networking (www.foofus.net) Integrity Level: MEDIUM Description: fgdump Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 2952 | -o "C:\Users\admin\AppData\Local\Temp\127.0.0.1.pwdump" -u "(null)" -p "(null)" 127.0.0.1 | C:\Users\admin\AppData\Local\Temp\pwdump.exe | — | fgdump.exe | |||||||||||
User: admin Company: Foofus Networking Integrity Level: MEDIUM Exit code: 0 Version: 1, 7, 0, 0 Modules
| |||||||||||||||
| 4008 | -v | C:\Users\admin\AppData\Local\Temp\cachedump.exe | — | fgdump.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 5 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\2020-01-07-13-18-51.fgdump-log | text | |
MD5:— | SHA256:— | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\fgexec.exe | executable | |
MD5:A761BEA93C900044B9E67364F3C7B06F | SHA256:8697897BEE415F213CE7BC24F22C14002D660B8AAFFAB807490DDBF4F3F20249 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\lsremora.dll | executable | |
MD5:618E588A8CCFA331DAB8279A82A3E2D9 | SHA256:E0327C1218FD3723E20ACC780E20135F41ABCA35C35E0F97F7ECCAC265F4F44E | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\cachedump.exe | executable | |
MD5:9DE5B79050879AF333D8A0EC555D6B57 | SHA256:CF58CA5BF8C4F87BB67E6A4E1FB9E8BADA50157DACBD08A92A4A779E40D569C4 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\servpw.exe | executable | |
MD5:3D7C06D9A0151E6C1433D61988CBE9F2 | SHA256:0F340B471EF34C69F5413540ACD3095C829FFC4DF38764E703345EB5E5020301 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\servpw64.exe | executable | |
MD5:981E82F907D1943F3EE06E05AECF7C31 | SHA256:97B39AC28794A7610ED83AD65E28C605397EA7BE878109C35228C126D43E2F46 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\pwdump.exe | executable | |
MD5:F959F07A120D759DDD1AE4AA9FF32C75 | SHA256:3C796092F42A948018C3954F837B4047899105845019FCE75A6E82BC99317982 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\pstgdump.exe | executable | |
MD5:9DFB61C0601EB935872D9A0639C44110 | SHA256:368C10795DE10E988381B5DE5C7CD8B2D4B9718DCD4E5590ADC2556CBE9D13C1 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\lsremora64.dll | executable | |
MD5:3FED6DC4BA33DF1EADCBC50D88DCEF7A | SHA256:EFA66F6391EC471CA52CD053159C8A8778F11F921DA14E6DAF76387F8C9AFCD5 | |||
| 504 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\cachedump64.exe | executable | |
MD5:1D7742B936475548F8CB20C9DB8C7A93 | SHA256:E38EDAC8C838A043D0D9D28C71A96FE8F7B7F61C5EDF69F1CE0C13E141BE281F | |||