File name:

Calculadoras Casio FX-ES PLUS [Software PRO].rar

Full analysis: https://app.any.run/tasks/e4d1162e-3fa1-4b1b-80ac-d284564165b6
Verdict: Malicious activity
Analysis date: December 29, 2020, 09:27:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

09554D2F5EBFBBC66B9B281F55317B30

SHA1:

C43D425FCD91FA2ABE49C4817D381B38139FBABC

SHA256:

A8879AD89BA76E6491743E5C032835FC8A0E98DF23AEBFF29AD6BAAFD1AEB6F9

SSDEEP:

196608:b2oXuw0OTCURBtLZVf4TCOQDTxAuY9ONkchM+ncIyneMwneWEA/cIHvp9hVt6D3M:qcZei3Z+TCZTXyqv++ncIynel7EApHRt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • fx-991ES PLUS C Emulator.exe (PID: 2812)
      • fx-570LA X_991LA X Emulator.exe (PID: 3276)
      • fx-85ES PLUS Emulator.exe (PID: 3588)
    • Application was dropped or rewritten from another process

      • fx-991ES PLUS C Emulator.exe (PID: 2812)
      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • fx-570LA X_991LA X Emulator.exe (PID: 3276)
      • fx-85ES PLUS Emulator.exe (PID: 3588)
      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
    • Drops executable file immediately after starts

      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • Casio FX 991ES PLUS C.exe (PID: 3128)
      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
    • Executable content was dropped or overwritten

      • Casio FX 991ES PLUS C.exe (PID: 3128)
      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 85ES PLUS.exe (PID: 292)
  • INFO

    • Manual execution by user

      • Casio Classwiz FX 991 LAX.exe (PID: 3988)
      • Casio FX 85ES PLUS.exe (PID: 292)
      • Casio FX 991ES PLUS C.exe (PID: 3128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
7
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs casio classwiz fx 991 lax.exe fx-570la x_991la x emulator.exe casio fx 85es plus.exe fx-85es plus emulator.exe no specs casio fx 991es plus c.exe fx-991es plus c emulator.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe" C:\Users\admin\Desktop\Casio FX 85ES PLUS.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio fx 85es plus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2812"C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX2\fx-991ES PLUS C Emulator.exeCasio FX 991ES PLUS C.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
fx-ES PLUS Emulator
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx2\fx-991es plus c emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx2\fxesplus_p16.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2872"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3128"C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe" C:\Users\admin\Desktop\Casio FX 991ES PLUS C.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio fx 991es plus c.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3276"C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.exe
Casio Classwiz FX 991 LAX.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
ClassWiz Emulator
Exit code:
0
Version:
2.0.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\fx-570la x_991la x emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx0\simu8.dll
c:\users\admin\appdata\local\temp\rarsfx0\simu8engine.dll
c:\windows\system32\mfc100.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3588"C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exe" C:\Users\admin\AppData\Local\Temp\RarSFX1\fx-85ES PLUS Emulator.exeCasio FX 85ES PLUS.exe
User:
admin
Company:
CASIO COMPUTER CO., LTD.
Integrity Level:
MEDIUM
Description:
fx-ES PLUS Emulator
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx1\fx-85es plus emulator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rarsfx1\fxesplus_p1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3988"C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe" C:\Users\admin\Desktop\Casio Classwiz FX 991 LAX.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\casio classwiz fx 991 lax.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 574
Read events
1 503
Write events
71
Delete events
0

Modification events

(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2872) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Calculadoras Casio FX-ES PLUS [Software PRO].rar
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
19
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio Classwiz FX 991 LAX.exe
MD5:
SHA256:
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40412\Casio FX 85ES PLUS.exe
MD5:
SHA256:
2872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2872.40731\Casio FX 991ES PLUS C.exe
MD5:
SHA256:
292Casio FX 85ES PLUS.exeC:\Users\admin\AppData\Local\Temp\RarSFX1\fxESPLUS_P1.dllexecutable
MD5:
SHA256:
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8engine.dllexecutable
MD5:9A20D708A346868A162F750FC4B19FD6
SHA256:B2D9BA345A0DBBED569C1E4A67CDFBF066FCA7E1BBCC1B6AEB53AD22371D5105
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\SimU8.dllexecutable
MD5:228C76037C2268F4954FF042D1C92AEA
SHA256:634051B2DD8F93663D618AC1A4370F5BDAEC8DE5F23D938C9915ABB429FF4CBF
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\libcurl.dllexecutable
MD5:70E2A0F0E403F097E9804D8ACFF5658E
SHA256:7E346863F3F157CA1CC60BF73109068BA5841BF719007F193C41D9DC7C0011DD
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\fx-570LA X_991LA X Emulator.lictext
MD5:B5079698754ED5228FFDD030D10D2349
SHA256:7AD701A07921C77A4C203800BADE620ECB6A1ED76089ED2D0AB7DD637A24A0F4
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\CLASSWIZ_P16.dllexecutable
MD5:B4FB3B8F14426435E415F3B610C95762
SHA256:92E3C7369B95A97C708E84A06B291496235A62E7D062E2939A5F9AF6C9FBDCB3
3988Casio Classwiz FX 991 LAX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\License.rtftext
MD5:B73E36C19CAC214A3CF7BEA059454464
SHA256:607421EBEF87CA0DAB08B7707F4DA3F49C4FEC12AB4C2017319A92825A72932E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3276
fx-570LA X_991LA X Emulator.exe
52.193.252.34:443
edu.casio.com
Amazon.com, Inc.
JP
unknown

DNS requests

Domain
IP
Reputation
edu.casio.com
  • 52.193.252.34
  • 3.115.124.100
unknown

Threats

No threats detected
No debug info