| File name: | flux-setup4-134.exe |
| Full analysis: | https://app.any.run/tasks/54c9bcc1-7770-47ba-8db0-5e4224ecf64a |
| Verdict: | Malicious activity |
| Analysis date: | February 06, 2025, 23:35:31 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | EBF5B897E0E4B90143764FC39E0C5A21 |
| SHA1: | 244EB29A512F1CC980BCFDC3BDA2C62E1954C6D7 |
| SHA256: | B53390DBA0E0C227341F3C688BE3AEF91455C4F926E6527AF6CE1E4ACF74A7B3 |
| SSDEEP: | 24576:F5sHdXD15A20DShVQog3j4FY5i/iZposemU5HJZkANLmBz3CLnTAWtQD24fCxS17:F5MdXD15A20ShVQ5j4FY5iKZposemU54 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:02 03:20:05+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 120320 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30fb |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6340 | "C:\Users\admin\AppData\Local\Temp\flux-setup4-134.exe" | C:\Users\admin\AppData\Local\Temp\flux-setup4-134.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6464 | "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" /unlockwingamma | C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe | — | flux-setup4-134.exe | |||||||||||
User: admin Company: f.lux Software LLC Integrity Level: MEDIUM Description: f.lux Exit code: 0 Version: 4, 134, 0, 0 Modules
| |||||||||||||||
| 6588 | "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" /unlockwingamma | C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe | flux.exe | ||||||||||||
User: admin Company: f.lux Software LLC Integrity Level: HIGH Description: f.lux Exit code: 0 Version: 4, 134, 0, 0 Modules
| |||||||||||||||
| 6640 | "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" /writeinstallversion | C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe | — | flux-setup4-134.exe | |||||||||||
User: admin Company: f.lux Software LLC Integrity Level: MEDIUM Description: f.lux Exit code: 0 Version: 4, 134, 0, 0 Modules
| |||||||||||||||
| 6660 | "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" | C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe | flux-setup4-134.exe | ||||||||||||
User: admin Company: f.lux Software LLC Integrity Level: MEDIUM Description: f.lux Version: 4, 134, 0, 0 Modules
| |||||||||||||||
| (PID) Process: | (6588) flux.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM |
| Operation: | write | Name: | GdiICMGammaRange |
Value: 256 | |||
| (PID) Process: | (6588) flux.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM |
| Operation: | write | Name: | GdiICMGammaRange |
Value: 256 | |||
| (PID) Process: | (6640) flux.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | DisplayVersion |
Value: 4.134 | |||
| (PID) Process: | (6660) flux.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\default$windows.data.bluelightreduction.settings\windows.data.bluelightreduction.settings |
| Operation: | write | Name: | Data |
Value: 434201000A0201002A06CE8E95BD062A2B0E2143420100CA140E1500CA1E0E0700CF28C435CA320E132E1100CA3C0E062E260000000000 | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | f.lux |
Value: "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | DisplayName |
Value: f.lux | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | Publisher |
Value: f.lux Software LLC | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Local\FluxSoftware\Flux\flux.exe" | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\FluxSoftware\Flux\uninstall.exe" | |||
| (PID) Process: | (6340) flux-setup4-134.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Flux |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Users\admin\AppData\Local\FluxSoftware\Flux\uninstall.exe" /S | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6340 | flux-setup4-134.exe | C:\Users\admin\AppData\Local\Temp\nsn6A38.tmp\nsProcess.dll | executable | |
MD5:FAA7F034B38E729A983965C04CC70FC1 | SHA256:579A034FF5AB9B732A318B1636C2902840F604E8E664F5B93C07A99253B3C9CF | |||
| 6660 | flux.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:BEB6F7FA24C8100F160EC7DBF0AF01D9 | SHA256:69B62037D21DCD3B7DE379A954C7CE03986BCEF49B44806149A913A7CA0CA205 | |||
| 6660 | flux.exe | C:\Users\admin\AppData\Local\FluxSoftware\Flux\font\Segoe UI-19-700-0.ytf | binary | |
MD5:49FDB31F35F1BD50A22E40D96C4B64F4 | SHA256:5BF22EC58884D9D26540BD7C758D65627BE4243B337C83ED53114E894DDE688F | |||
| 6660 | flux.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:258AD31FC90D3A344BF3483E2E03ED31 | SHA256:A2C024AFC933898F56A41EDC89F144D2CAB6955EDA55AA4999EADC3A09E008A3 | |||
| 6660 | flux.exe | C:\Users\admin\AppData\Local\FluxSoftware\Flux\font\Calibri-13-400-0.ytf | binary | |
MD5:FAD467D43E7DD4CD1C13404ED897B14D | SHA256:B1134DAFE29DC765259468DAC4A4DB79A135002F7FFF9D9009A9CA68134CD7A8 | |||
| 6660 | flux.exe | C:\Users\admin\AppData\Local\FluxSoftware\Flux\font\Calibri-29-400-0.ytf | binary | |
MD5:4EFCA15728E47A36CE03DA27E5A72C8F | SHA256:6F908DDE9AB0E97E8A190350D177C476A329322C4E73AC9C0AAE043674913C2E | |||
| 6660 | flux.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\65E4E5D32C2481BB44383D7FBD7C5144 | binary | |
MD5:E61AED1F6736ED578F3F9E6CEBFB13DD | SHA256:F3028A6FC2CEB78A0A95B2E7BF1ED66BA0198E48344A2F9BB1F7D4CF3EB8B672 | |||
| 6660 | flux.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:C97A718CE8586F84A7E896BFBD5FACCA | SHA256:3798F30E7960C127A8EB0C9F00C48A9E6D808BE3270D371154E85D19935E60EE | |||
| 6660 | flux.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:52C1BFFC83B3F8A89DFF522EC96765EB | SHA256:0052EE3317EBB90F870BFD316319D72BCAF40DB5101CD7A3E6CC6E4252ACD223 | |||
| 6660 | flux.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\preset[1].json | text | |
MD5:6D68E518B810046C3F49F9F1A0C81F40 | SHA256:97688AE8230AAC5070866EB90A981D228B7B6E58D204985AFC142AAFDF103A3F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.11:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6660 | flux.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
6660 | flux.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
6660 | flux.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQCKAhou7VlnPBmXQ6zNyu89 | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1448 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
4264 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4264 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.48.23.11:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 92.123.104.33:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1176 | svchost.exe | 20.190.159.128:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1076 | svchost.exe | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
6660 | flux.exe | 216.176.200.22:443 | justgetflux.com | VPLS-GLOBAL | US | unknown |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
justgetflux.com |
| unknown |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
Process | Message |
|---|---|
flux-setup4-134.exe | ExecShellAsUser: DLL_PROCESS_ATTACH |
flux-setup4-134.exe | ExecShellAsUser: process is not elevated, will fallback to ShellExecute |
flux-setup4-134.exe | ExecShellAsUser: DLL_PROCESS_DETACH |