File name:

FCBU喜马拉雅音频批量下载器v27.exe

Full analysis: https://app.any.run/tasks/c161c20c-266f-45ae-aec9-5a4df7686f76
Verdict: Malicious activity
Analysis date: September 14, 2024, 11:13:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
upx
antivm
ip-check
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C5CC0A2A6282653393E428397FF23E04

SHA1:

12919F4A0BEB2482299338F4A038C786F1FA9B1F

SHA256:

D4376F564E9C0DA97F9BC4733A007C3BBBEBF74ADA406E80F4BC8727F4BF99A5

SSDEEP:

98304:n3nx26H/Z/maWNeJMjVZvo80WQBFGxCSdMObveZY2CfW4vgk8KHa9AdAPIC/q2R9:UCEFzT6MsJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Accesses name of a computer manufacturer via WMI (SCRIPT)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
  • SUSPICIOUS

    • Accesses WMI object caption (SCRIPT)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Accesses Windows installation date via WMI (SCRIPT)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Accesses WMI object, sets custom ImpersonationLevel (SCRIPT)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Access Product Name via WMI (SCRIPT)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Reads security settings of Internet Explorer

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • There is functionality for VM detection (VirtualBox)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • There is functionality for capture public ip (YARA)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • There is functionality for taking screenshot (YARA)

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
  • INFO

    • Reads the computer name

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Reads the machine GUID from the registry

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Checks supported languages

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Create files in a temporary directory

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Checks proxy server information

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • Creates files or folders in the user directory

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
    • UPX packer has been detected

      • FCBU喜马拉雅音频批量下载器v27.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:22 10:00:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7.1
CodeSize: 884736
InitializedDataSize: 1781760
UninitializedDataSize: -
EntryPoint: 0xc8f5d0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.2.4
ProductVersionNumber: 2.0.2.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 2.0.2.4
FileDescription: 简单易用批量下载喜马拉雅专辑所有音频的工具
ProductName: FCBU喜马拉雅音频批量下载工具
ProductVersion: 2.0.2.4
CompanyName: 苏刻
LegalCopyright: (C) 2024 苏刻
Comments: download xmly Audio.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
126
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT fcbu喜马拉雅音频批量下载器v27.exe

Process information

PID
CMD
Path
Indicators
Parent process
3784"C:\Users\admin\AppData\Local\Temp\FCBU喜马拉雅音频批量下载器v27.exe" C:\Users\admin\AppData\Local\Temp\FCBU喜马拉雅音频批量下载器v27.exe
explorer.exe
User:
admin
Company:
苏刻
Integrity Level:
MEDIUM
Description:
简单易用批量下载喜马拉雅专辑所有音频的工具
Exit code:
4294967295
Version:
2.0.2.4
Modules
Images
c:\users\admin\appdata\local\temp\fcbu喜马拉雅音频批量下载器v27.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
682
Read events
676
Write events
6
Delete events
0

Modification events

(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Multimedia\DrawDib
Operation:writeName: 1280x720x32(BGR 0)
Value:
31,31,31,31
(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings
Operation:writeName:JITDebug
Value:
0
(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\FCBU.com\FCBUsoft\DownXimalaya\Url
Operation:writeName:Startkey
Value:
E2,B2,45,89,BA,BB,BB,93,91,8C,3C,48,4D,D8,17,6A,1C,15,DB,21,05,F5,67,09,11,93,FC,62,C5,AD,69,85,24,0A,C0,4E,F0,94,A0,E1,65,D9,11,9A,44,7D,F6,9A,8E,9E,EB,6E,A6,67,05,FE,8C,0A,B1,A8,AF,1B,2F,07,55,C7,82,F3,3A,13,BB,1E,AE,E9,E2,D4,79,8E,03,D5,B2,43,51,73,87,9F,XY1726283645YX169CAD7F611
(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3784) FCBU喜马拉雅音频批量下载器v27.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
1
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3784FCBU喜马拉雅音频批量下载器v27.exeC:\Users\admin\AppData\Local\Temp\tempcfec7w27\Solesourceofincome.dllimage
MD5:A622163EDFF9285AA5CF12B503759125
SHA256:9E5CB271F82C4BD51BCC7EBA4A82F2533027E853D8DBC6CABA31125426F64ADC
3784FCBU喜马拉雅音频批量下载器v27.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\wxfk[1].pngimage
MD5:A622163EDFF9285AA5CF12B503759125
SHA256:9E5CB271F82C4BD51BCC7EBA4A82F2533027E853D8DBC6CABA31125426F64ADC
3784FCBU喜马拉雅音频批量下载器v27.exeC:\Users\admin\AppData\Local\Temp\tempcfec7w27\audiodl.exeexecutable
MD5:ED25F59A5FD007D5798C791CE2B3EA9F
SHA256:77A0BF0CAEAFE991AF06D1722D4B9D68E447D504C3EF844716821CB3D06DF1B4
3784FCBU喜马拉雅音频批量下载器v27.exeC:\Users\admin\AppData\Local\Temp\tempcfec7w27\tempx.datcompressed
MD5:754C8AD783FDD63A9860119388430696
SHA256:6F045AD242AD29DD65239064475A068C7FB968C25AA6384DEAAE9FD6C2D9D94F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7072
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
3784
FCBU喜马拉雅音频批量下载器v27.exe
GET
200
118.24.8.68:80
http://api.dngz.net/SoftApi/downximalaya.xml?20240914
CN
text
1.59 Kb
unknown
3784
FCBU喜马拉雅音频批量下载器v27.exe
GET
200
118.24.8.68:80
http://api.dngz.net/SoftApi/wxfk.png?20240914
CN
image
11.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1356
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7072
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7072
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7072
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3784
FCBU喜马拉雅音频批量下载器v27.exe
118.24.8.68:80
api.dngz.net
Shenzhen Tencent Computer Systems Company Limited
CN
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.124.78.146
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
api.dngz.net
  • 118.24.8.68
unknown

Threats

No threats detected
No debug info