File name:

Filmora9 Fixer Tool.exe

Full analysis: https://app.any.run/tasks/6d963fe8-1258-4d42-883b-a1ab925706a2
Verdict: Malicious activity
Analysis date: August 09, 2020, 12:38:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

0A184F219E7D013491EDBF55D2F9A245

SHA1:

7C96915FFE155A1BEE8E6463BEF93F209D110F48

SHA256:

DAC31CFD4258A2BBB6C8124D184AC1EFDC2748D8BA5582ECCEF468D06E631EE8

SSDEEP:

6144:aBlkZvaF4NTBMiMpxBBAD13Y1DJZ++6ZyWS/wt/OzWhNbh+t:aoSWNTiiCfBZ1Dw4WS/cGYNbh+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 2484)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Filmora9 Fixer Tool.exe (PID: 3932)
    • Starts CMD.EXE for commands execution

      • Filmora9 Fixer Tool.exe (PID: 3932)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Filmora9 Fixer Tool.exe (PID: 3932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:07:30 10:52:45+02:00
PEType: PE32
LinkerVersion: 2.5
CodeSize: 70656
InitializedDataSize: 263168
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows command line
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Unknown (3409)
CharacterSet: Windows, Latin1
CompanyName: Thirdz-Key
FileDescription: Filmora9 Fixer Tool
FileVersion: 1.0.0.0
InternalName: Filmora9 Fixer Tool.exe
LegalCopyright: Thirdzky™ 2020
OriginalFileName: Filmora9 Fixer Tool.exe
ProductName: Filmora9 Fixer Tool
ProductVersion: 1.0.0.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date: 30-Jul-2019 08:52:45
Detected languages:
  • English - Philippines
CompanyName: Thirdz-Key
FileDescription: Filmora9 Fixer Tool
FileVersion: 1.0.0.0
InternalName: Filmora9 Fixer Tool.exe
LegalCopyright: Thirdzky™ 2020
OriginalFilename: Filmora9 Fixer Tool.exe
ProductName: Filmora9 Fixer Tool
ProductVersion: 1.0.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 30-Jul-2019 08:52:45
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.code
0x00001000
0x0000387E
0x00003A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.52922
.text
0x00005000
0x0000D962
0x0000DA00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.56249
.rdata
0x00013000
0x000033A5
0x00003400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.11184
.data
0x00017000
0x0000178C
0x00001200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.79585
.rsrc
0x00019000
0x0003BC08
0x0003BE00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.81523

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.08821
672
Latin 1 / Western European
English - Philippines
RT_MANIFEST
2
4.07097
16936
Latin 1 / Western European
English - Philippines
RT_ICON
3
4.38784
9640
Latin 1 / Western European
English - Philippines
RT_ICON
4
4.74382
4264
Latin 1 / Western European
English - Philippines
RT_ICON
5
5.57316
1128
Latin 1 / Western European
English - Philippines
RT_ICON
0ED35CA2D0DBB0A2FE9D1865AFC72BB6
4.77356
30
Latin 1 / Western European
English - Philippines
RT_RCDATA
1EB73D6A0F3B7202B9FC55A237F5AD2658DF746A
3.32193
10
Latin 1 / Western European
English - Philippines
RT_RCDATA
206E87F9F34756FBEC405A55D3423333
3.74899
21
Latin 1 / Western European
English - Philippines
RT_RCDATA
5BC574832E0EB11808CC4E69AEAAE501
7.06499
194
Latin 1 / Western European
English - Philippines
RT_RCDATA
60554DB5CCB62F5DD00C0E19649E388D87D73A28
7.99701
63110
Latin 1 / Western European
English - Philippines
RT_RCDATA

Imports

COMCTL32.DLL
GDI32.DLL
KERNEL32.DLL
MSVCRT.dll
OLE32.DLL
SHELL32.DLL
SHLWAPI.DLL
USER32.DLL
WINMM.DLL
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start filmora9 fixer tool.exe cmd.exe no specs mode.com no specs mode.com no specs mode.com no specs ping.exe no specs ping.exe no specs ping.exe no specs mode.com no specs filmora9 fixer tool.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020ping localhost -n 2 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1208ping localhost -n 3 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2420"C:\Users\admin\AppData\Local\Temp\Filmora9 Fixer Tool.exe" C:\Users\admin\AppData\Local\Temp\Filmora9 Fixer Tool.exeexplorer.exe
User:
admin
Company:
Thirdz-Key
Integrity Level:
MEDIUM
Description:
Filmora9 Fixer Tool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\filmora9 fixer tool.exe
2452mode con:cols=53 lines=16C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2484"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\E657.tmp\E658.tmp\E659.bat "C:\Users\admin\AppData\Local\Temp\Filmora9 Fixer Tool.exe""C:\Windows\system32\cmd.exeFilmora9 Fixer Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2792mode con:cols=53 lines=21C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3204mode con:cols=53 lines=24C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3684mode con:cols=53 lines=18C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3812ping localhost -n 2 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3932"C:\Users\admin\AppData\Local\Temp\Filmora9 Fixer Tool.exe" C:\Users\admin\AppData\Local\Temp\Filmora9 Fixer Tool.exe
explorer.exe
User:
admin
Company:
Thirdz-Key
Integrity Level:
HIGH
Description:
Filmora9 Fixer Tool
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\filmora9 fixer tool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
27
Read events
27
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3932Filmora9 Fixer Tool.exeC:\Users\admin\AppData\Local\Temp\E657.tmp\Authorization.jsontext
MD5:7E259F0BC6FFE546A9812C0FE855E34D
SHA256:41E2A3203AE9CAC1123BFBE63EBA96A3EC0D841F86F6E43E2FFCEBB8251D3409
3932Filmora9 Fixer Tool.exeC:\Users\admin\AppData\Local\Temp\E657.tmp\WSHelper.exeexecutable
MD5:35AFE275396F40125A89FF1E7F26D084
SHA256:B98A6155E5132D8164DC0193B03D449A511A112AC460DCF049F2D7333A4CCCB7
3932Filmora9 Fixer Tool.exeC:\Users\admin\AppData\Local\Temp\E657.tmp\E658.tmp\E659.battext
MD5:8403F7A40E53E78694B11378E3B0F28B
SHA256:187D12D5865B8A4801F47361283E13D2E3EAE2D3F479BAEEF3215D23AC72D08E
3932Filmora9 Fixer Tool.exeC:\Users\admin\AppData\Local\Temp\E657.tmp\WF9Tool.battext
MD5:2C5C8C22DA00EA40CCBA757C09B1AA6C
SHA256:CC1AF715D92DD5D4EE7BB0F8D9E78FEB756EB495C1A96F3D4D23BA769BBD71A0
3932Filmora9 Fixer Tool.exeC:\Users\admin\AppData\Local\Temp\E657.tmp\Config.jsontext
MD5:EF4C655095A28E7349A322561B676636
SHA256:99E16A5A38DB59BA9405ADDCDAE8B8CC2CC6F01D32CF415A1F077D8727929CAD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info