File name:

faststone-capture-10-6.exe

Full analysis: https://app.any.run/tasks/69682af5-9af8-4be8-b155-07ab2ec1453d
Verdict: Malicious activity
Analysis date: August 19, 2024, 18:52:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

53EC562F7A9D90E01FC6BD62D2F7C55C

SHA1:

190306B8EA1BF037C4712F7C1063763AB4E0EF87

SHA256:

C8DA7C2F2C78D6E6592E75D155E1B754935604FC796D4AA329B9CE36E68BD379

SSDEEP:

98304:5J8u8un1sljw81HpYDDv5dDw620+m2EcDMngqr6MMu8N6pNsuLojU4sde2HOD7Dx:5b5Vd4WiU8GzGJa8akYx8H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • faststone-capture-10-6.exe (PID: 6896)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • faststone-capture-10-6.exe (PID: 6896)
    • Executable content was dropped or overwritten

      • faststone-capture-10-6.exe (PID: 6896)
    • Creates a software uninstall entry

      • faststone-capture-10-6.exe (PID: 6896)
    • The process creates files with name similar to system file names

      • faststone-capture-10-6.exe (PID: 6896)
  • INFO

    • Creates files in the program directory

      • faststone-capture-10-6.exe (PID: 6896)
    • Checks supported languages

      • faststone-capture-10-6.exe (PID: 6896)
      • FSCapture.exe (PID: 5504)
    • Reads the computer name

      • faststone-capture-10-6.exe (PID: 6896)
      • FSCapture.exe (PID: 5504)
    • Manual execution by a user

      • FSCapture.exe (PID: 5504)
    • Create files in a temporary directory

      • faststone-capture-10-6.exe (PID: 6896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.6.0.0
ProductVersionNumber: 10.6.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: FastStone Capture 10.6
CompanyName: FastStone Corporation
FileDescription: FastStone Capture 10.6 Setup
FileVersion: 10.6.0.0
LegalCopyright: Copyright (C) 2024 by FastStone Corporation
LegalTrademarks: -
ProductName: FastStone Capture
ProductVersion: 10.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start faststone-capture-10-6.exe fscapture.exe no specs faststone-capture-10-6.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5504"C:\Program Files (x86)\FastStone Capture\FSCapture.exe" C:\Program Files (x86)\FastStone Capture\FSCapture.exeexplorer.exe
User:
admin
Company:
FastStone Corporation
Integrity Level:
MEDIUM
Description:
FastStone Capture
Version:
10.6.0.0
Modules
Images
c:\program files (x86)\faststone capture\fscapture.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6820"C:\Users\admin\AppData\Local\Temp\faststone-capture-10-6.exe" C:\Users\admin\AppData\Local\Temp\faststone-capture-10-6.exeexplorer.exe
User:
admin
Company:
FastStone Corporation
Integrity Level:
MEDIUM
Description:
FastStone Capture 10.6 Setup
Exit code:
3221226540
Version:
10.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\faststone-capture-10-6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6896"C:\Users\admin\AppData\Local\Temp\faststone-capture-10-6.exe" C:\Users\admin\AppData\Local\Temp\faststone-capture-10-6.exe
explorer.exe
User:
admin
Company:
FastStone Corporation
Integrity Level:
HIGH
Description:
FastStone Capture 10.6 Setup
Exit code:
0
Version:
10.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\faststone-capture-10-6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
3 884
Read events
3 873
Write events
11
Delete events
0

Modification events

(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fsc\OpenWithProgids
Operation:writeName:FastStone.fsc
Value:
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\FastStone Capture\Capabilities
Operation:writeName:ApplicationDescription
Value:
FastStone Capture
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\FastStone Capture\Capabilities\FileAssociations
Operation:writeName:.fsc
Value:
FastStone.fsc
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
Operation:writeName:FastStone-Capture
Value:
Software\FastStone Capture\Capabilities
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:DisplayName
Value:
FastStone Capture 10.6
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\FastStone Capture\uninst.exe
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\FastStone Capture\FSCapture.exe
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:DisplayVersion
Value:
10.6
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:URLInfoAbout
Value:
http://www.faststone.org
(PID) Process:(6896) faststone-capture-10-6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FastStone Capture
Operation:writeName:Publisher
Value:
FastStone Corporation
Executable files
19
Suspicious files
25
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCPlugin03.dllexecutable
MD5:FC610B497818BCB5249E72410AED5162
SHA256:FB8C862B1E2C2F423DDE036B9D77F241951674DC5E6EE51954F2B37E19BCA378
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCapture.exeexecutable
MD5:BCA0559E2AFA8882803F5D4B90A44846
SHA256:A2A36B50807B47C0FAD6F176C8FACE92011E9CCE7F16B6068D0547290D1FFE38
6896faststone-capture-10-6.exeC:\Users\admin\AppData\Local\Temp\nsoF1A2.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCPlugin02.dllexecutable
MD5:A3101ADDC099361A751198614972D5FA
SHA256:4EF58566D20EAE8ED18177DA8FCABBC55A5585CC5CC51806EF86E136291AC1F1
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSFocus.exeexecutable
MD5:97AA518D2A3B2AD63573128C7E10E6C5
SHA256:493B2B08ECADD1895C4FCFE0FFD9C7B2B4F5B276CCD494846E0CB35DE004AD91
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSRecorder.exeexecutable
MD5:7CC74657FA2F0E970A6A1209A2CDC821
SHA256:ED4CCAB9609EA12A3D8DF8DA3843CF45191709FA51E6F1FDA28EED8FBE7F7C42
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCPlugin01.dllexecutable
MD5:F421919DA3CB7C44B086210D4D797D7A
SHA256:CF66F927D6D3EBC77D93567C25C9577803E5FB64201755D7773257C4C3ED5D2B
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCrossHair.exeexecutable
MD5:EFFB23AB4ECE53D5E07C8C0437D86BBE
SHA256:C0BCB458D844158F42F8BE4DA7187008115F849FF25D85AA00FA8637869EDE2F
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCPlugin04.dllexecutable
MD5:3D936F0507E9BE6F4AEDE56BF440F42C
SHA256:99C55D9B65D38C22DD84FC96DE55A29008E564B92AE97D9B3B31BBDD31D78A01
6896faststone-capture-10-6.exeC:\Program Files (x86)\FastStone Capture\FSCPlugin07.exeexecutable
MD5:E3EF14ED122068DAE0AEEF89DB996513
SHA256:FE43D2A447EACBDA956728AD75B85C4743D406389C0354F3D81BBB0DFB4A7D44
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
28
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
788
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6476
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6948
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
1292
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
788
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
788
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6948
backgroundTaskHost.exe
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6948
backgroundTaskHost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6476
SIHClient.exe
40.127.169.103:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.31.67
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.2
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.43
whitelisted

Threats

No threats detected
Process
Message
faststone-capture-10-6.exe
ExecShellAsUser: got desktop
faststone-capture-10-6.exe
ExecShellAsUser: elevated process detected
faststone-capture-10-6.exe
ExecShellAsUser: thread finished
faststone-capture-10-6.exe
ExecShellAsUser: DLL_PROCESS_DETACH