File name:

Calculadoras Casio FX-ES PLUS [Software PRO].rar

Full analysis: https://app.any.run/tasks/e4d1162e-3fa1-4b1b-80ac-d284564165b6
Verdict: Malicious activity
Analysis date: December 29, 2020, 09:27:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

09554D2F5EBFBBC66B9B281F55317B30

SHA1:

C43D425FCD91FA2ABE49C4817D381B38139FBABC

SHA256:

A8879AD89BA76E6491743E5C032835FC8A0E98DF23AEBFF29AD6BAAFD1AEB6F9

SSDEEP:

196608:b2oXuw0OTCURBtLZVf4TCOQDTxAuY9ONkchM+ncIyneMwneWEA/cIHvp9hVt6D3M:qcZei3Z+TCZTXyqv++ncIynel7EApHRt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • fx-570LA X_991LA X Emulator.exe (PID: 3276)
      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
      • fx-85ES PLUS Emulator.exe (PID: 3588)
      • fx-991ES PLUS C Emulator.exe (PID: 2812)
    • Loads dropped or rewritten executable

      • fx-570LA X_991LA X Emulator.exe (PID: 3276)
      • fx-85ES PLUS Emulator.exe (PID: 3588)
      • fx-991ES PLUS C Emulator.exe (PID: 2812)
    • Drops executable file immediately after starts

      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
    • Drops a file that was compiled in debug mode

      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
  • INFO

    • Manual execution by user

      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
7
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs casio classwiz fx 991 lax.exe fx-570la x_991la x emulator.exe casio fx 85es plus.exe fx-85es plus emulator.exe no specs casio fx 991es plus c.exe fx-991es plus c emulator.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe" C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio fx 85es plus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2812"C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exeCasio FX 991ES PLUS C.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
fx-ES PLUS Emulator
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx2\fx-991es plus c emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx2\fxesplus_p16.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2872"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3128"C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe" C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio fx 991es plus c.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3276"C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe
Casio Classwiz FX 991 LAX.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
ClassWiz Emulator
Exit code:
0
Version:
2.0.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\fx-570la x_991la x emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx0\simu8.dll
c:\users\admin\appdata\local\temp\rarsfx0\simu8engine.dll
c:\windows\system32\mfc100.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3588"C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exeCasio FX 85ES PLUS.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
fx-ES PLUS Emulator
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx1\fx-85es plus emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx1\fxesplus_p1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3988"C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe" C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio classwiz fx 991 lax.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 574
Read events
1 503
Write events
71
Delete events
0

Modification events

(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2872) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
19
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio Classwiz FX 991 LAX.exe
MD5:
SHA256:
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio FX 85ES PLUS.exe
MD5:
SHA256:
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40731\Casio FX 991ES PLUS C.exe
MD5:
SHA256:
292Casio FX 85ES PLUS.exeC:\Users\admin\AppData\Local\Temp\RarSFX1\fxESPLUS_P1.dllexecutable
MD5:
SHA256:
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\opencv_highgui2410.dllexecutable
MD5:67CD5063A8E1A6843906FED6B2F4CD78
SHA256:33E1867AA2502409E19531940F47D464FBC82C9D512F417ECC5D46432D91DDFD
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\opencv_imgproc2410.dllexecutable
MD5:4EACF36B9DA3053A9AC2BDA5E5147745
SHA256:7A48136BD2B09A6C5530390E4F5123A2CEBE92EC30779B482CC4B8AAC603E8F5
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8engine.dllexecutable
MD5:9A20D708A346868A162F750FC4B19FD6
SHA256:B2D9BA345A0DBBED569C1E4A67CDFBF066FCA7E1BBCC1B6AEB53AD22371D5105
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exeexecutable
MD5:0DF801B5BA7ED603761ECA879D7429B2
SHA256:1DF70EA44E6603A46ED4A40BE51350B9A65D000E8BA28E94A7C847902CF0F8EB
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.lictext
MD5:B5079698754ED5228FFDD030D10D2349
SHA256:7AD701A07921C77A4C203800BADE620ECB6A1ED76089ED2D0AB7DD637A24A0F4
292Casio FX 85ES PLUS.exeC:\Users\admin\AppData\Local\Temp\RarSFX1\License.rtftext
MD5:2DB15A6A31EFED9423199C91C648D4F2
SHA256:959CD047936E26A0C04E0A8AAA5895C98DBD2CD1C987FB5034924D7ADEE00B6B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3276
fx-570LA X_991LA X Emulator.exe
52.193.252.34:443
edu.casio.com
Amazon.com, Inc.
JP
unknown

DNS requests

Domain
IP
Reputation
edu.casio.com
  • 52.193.252.34
  • 3.115.124.100
unknown

Threats

No threats detected
No debug info