| File name: | DSD+2.395 FL_START_FIX_DMR.zip |
| Full analysis: | https://app.any.run/tasks/95e32a38-25cc-47cd-b753-dcad64482528 |
| Verdict: | Malicious activity |
| Analysis date: | August 26, 2024, 05:27:26 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | F8EE3DCA542028AD3BE2B6E5E6E5D028 |
| SHA1: | F94BEEF75AA05C5FB1C9A53861B788827B380A95 |
| SHA256: | C5A62DAB1105DEEB60685950357FD48E940777F44F41160B3FAD5A7FE6943517 |
| SSDEEP: | 98304:Tnn3naYw4cqvazbV7Mofzqo2mbrlVRx1zxOT05+Qx7rk0eeu2eZTgxjnunIQQHUe:d+GX/Sot/PiAX/K |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:09:04 10:45:28 |
| ZipCRC: | 0x6d88006a |
| ZipCompressedSize: | 173 |
| ZipUncompressedSize: | 6148 |
| ZipFileName: | DSD+2.395 FL/.DS_Store |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2068 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | FMPP.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2092 | "C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\Executables\FMPA.exe" | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\Executables\FMPA.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2524 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | FMPA.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3236 | "C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\Executables\FMPP.exe" | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\Executables\FMPP.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 6220 | "C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMPA.exe" | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMPA.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 6308 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | FMPA.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6364 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | FMP24.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6368 | "C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMP24.exe" | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMP24.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 6500 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6532 | "C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMP-Map.EXE" | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\FMP-Map.EXE | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR.zip | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR | |||
| (PID) Process: | (6708) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\.DS_Store | binary | |
MD5:194577A7E20BDCC7AFBB718F502C134C | SHA256:D65165279105CA6773180500688DF4BDC69A2C7B771752F0A46EF120B7FD8EC3 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\BatchFiles\FMPP-CC.bat | text | |
MD5:CEE6FDF079A8153313070D8095AE5EF0 | SHA256:EDA3D418971ED4D3AF7EDB8B6836235277E1771868F2BC97F8863C44F54BB017 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\BatchFiles\CC.bat | text | |
MD5:1C4FF2D70B18D7ACF8B69DB7E7CF90AE | SHA256:88F987BC13B8CE4A98760CB7007FAFF001604BB628EECFE1818DE06BF100874A | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\BatchFiles\FMPP-VC.bat | text | |
MD5:91A338B30B2F6FACDFFA28F834627E62 | SHA256:1F3B896ABBDD205198112332E890E910CC480DD269C4241D5FA5E79D9C526708 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DMRFL.bat | text | |
MD5:9FC907D0AAB30614F3BE7858AB142237 | SHA256:C23785F4B5EC1CC339686EA100ED4B98E4898B10D5EF0E6EC7CEE1356E0E09C7 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\ConfigurationFiles\FMPA.cfg | text | |
MD5:02D802D48A92C9F8B48EE355A4234510 | SHA256:35299BAA2D4C79275850698B12A9E7BF6F1B394C653DCA9456F62B586CEA6BDA | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\1R.bat | text | |
MD5:C0789B5ACD8A94EC93032BD2C3766253 | SHA256:3891A2F9C0F940D9311271585A8A3C0B8814D58A4A4D0675A408EAC44664FBC5 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\BatchFiles\1R.bat | text | |
MD5:C0789B5ACD8A94EC93032BD2C3766253 | SHA256:3891A2F9C0F940D9311271585A8A3C0B8814D58A4A4D0675A408EAC44664FBC5 | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\DSDPlus Base Files\BatchFiles\FMPA-VC.bat | text | |
MD5:64D5A2ACC603E9E88289F8F855950340 | SHA256:6A9B7693FBD7356C795E962B1A165334D0D0334736680656EE5CDA22A8FE6F7A | |||
| 6708 | WinRAR.exe | C:\Users\admin\Downloads\DSD+2.395 FL_START_FIX_DMR\DSD+2.395 FL\airspy.dll | executable | |
MD5:DBBAC0A53D598C48AE622F6A11AE6705 | SHA256:061CDA302E13D5CFD4DE55FFB42EB58DB25A764AD2BEEF10DB4C084415CC35B5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6532 | FMP-Map.EXE | GET | 200 | 151.101.65.91:80 | http://tile.openstreetmap.org/1/1/1.png | unknown | — | — | whitelisted |
6620 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6620 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6532 | FMP-Map.EXE | GET | 200 | 151.101.65.91:80 | http://tile.openstreetmap.org/1/0/1.png | unknown | — | — | whitelisted |
5904 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6532 | FMP-Map.EXE | GET | 200 | 151.101.65.91:80 | http://tile.openstreetmap.org/1/1/0.png | unknown | — | — | whitelisted |
6532 | FMP-Map.EXE | GET | 200 | 151.101.65.91:80 | http://tile.openstreetmap.org/1/0/0.png | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3992 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
1492 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3992 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6620 | SIHClient.exe | 20.12.23.50:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6620 | SIHClient.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
tile.openstreetmap.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
6532 | FMP-Map.EXE | Potentially Bad Traffic | ET USER_AGENTS User-Agent (Internet Explorer) |
6532 | FMP-Map.EXE | Potentially Bad Traffic | ET USER_AGENTS User-Agent (Internet Explorer) |
6532 | FMP-Map.EXE | Potentially Bad Traffic | ET USER_AGENTS User-Agent (Internet Explorer) |
6532 | FMP-Map.EXE | Potentially Bad Traffic | ET USER_AGENTS User-Agent (Internet Explorer) |