General Info

File name

FileZilla_3.42.0_win64_sponsored-setup.exe

Full analysis
https://app.any.run/tasks/5adeaf57-612f-40e5-ac92-d469768594e0
Verdict
Malicious activity
Analysis date
7/11/2019, 21:25:45
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

trojan

adware

installcore

pup

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

10c83aa0529f3ccdfebadf33c115ce2e

SHA1

0c0f55f1f838a91205b0c2174298990e0724845c

SHA256

e5c73bc5806d0bf479d5ccc3399c8d62b48ed65183c25c92f3e5257d505a4af8

SSDEEP

196608:LuFVotvBWmqkQhFl7LTWrch3DnJS7FA58Obr:Lu+WcQhFZ/h3LiU8On

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • uninstall.exe (PID: 3496)
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 3408)
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Changes settings of System certificates
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Connects to CnC server
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
INSTALLCORE was detected
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Adds / modifies Windows certificates
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Reads the machine GUID from the registry
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Reads Environment values
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Executable content was dropped or overwritten
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
  • uninstall.exe (PID: 3496)
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 3408)
Reads internet explorer settings
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Reads CPU info
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Creates files in the program directory
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
  • uninstall.exe (PID: 3496)
Reads Windows Product ID
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 2868)
Application launched itself
  • FileZilla_3.42.0_win64_sponsored-setup.exe (PID: 3408)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:12:11 22:50:48+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
25088
InitializedDataSize:
141824
UninitializedDataSize:
2048
EntryPoint:
0x344a
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
3.42.0.0
ProductVersionNumber:
3.42.0.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Tim Kosse
FileDescription:
FileZilla FTP Client
FileVersion:
3.42.0
LegalCopyright:
Tim Kosse
OriginalFileName:
FileZilla_3.42.0_win32-setup.exe
ProductName:
FileZilla
ProductVersion:
3.42.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
11-Dec-2016 21:50:48
Detected languages
English - United States
CompanyName:
Tim Kosse
FileDescription:
FileZilla FTP Client
FileVersion:
3.42.0
LegalCopyright:
Tim Kosse
OriginalFilename:
FileZilla_3.42.0_win32-setup.exe
ProductName:
FileZilla
ProductVersion:
3.42.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
11-Dec-2016 21:50:48
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000061F1 0x00006200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.47707
.rdata 0x00008000 0x000013A4 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.163
.data 0x0000A000 0x00020338 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.97456
.ndata 0x0002B000 0x0003F000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x0006A000 0x0000A3A0 0x0000A400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.573
Resources
1

2

3

4

5

102

103

104

105

106

107

110

111

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

+
start filezilla_3.42.0_win64_sponsored-setup.exe #INSTALLCORE filezilla_3.42.0_win64_sponsored-setup.exe uninstall.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3408
CMD
"C:\Users\admin\AppData\Local\Temp\FileZilla_3.42.0_win64_sponsored-setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\FileZilla_3.42.0_win64_sponsored-setup.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Tim Kosse
Description
FileZilla FTP Client
Version
3.42.0
Modules
Image
c:\users\admin\appdata\local\temp\filezilla_3.42.0_win64_sponsored-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsz4477.tmp\system.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\nsz4477.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
2868
CMD
"C:\Users\admin\AppData\Local\Temp\FileZilla_3.42.0_win64_sponsored-setup.exe" /UAC:B01E8 /NCRC
Path
C:\Users\admin\AppData\Local\Temp\FileZilla_3.42.0_win64_sponsored-setup.exe
Indicators
Parent process
FileZilla_3.42.0_win64_sponsored-setup.exe
User
admin
Integrity Level
HIGH
Version:
Company
Tim Kosse
Description
FileZilla FTP Client
Version
3.42.0
Modules
Image
c:\users\admin\appdata\local\temp\filezilla_3.42.0_win64_sponsored-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\system.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\userinfo.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\inetc.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\imcznmtbf.dll
c:\windows\system32\mpr.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\dhcpcsvc.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\imagehlp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\sxs.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\nsm7e34.tmp\math.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\program files\filezilla ftp client\uninstall.exe

PID
3496
CMD
"C:\Program Files\FileZilla FTP Client\uninstall.exe" /frominstall /keepstartmenudir _?=C:\Program Files\FileZilla FTP Client
Path
C:\Program Files\FileZilla FTP Client\uninstall.exe
Indicators
Parent process
FileZilla_3.42.0_win64_sponsored-setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Tim Kosse
Description
FileZilla FTP Client
Version
3.36.0
Modules
Image
c:\program files\filezilla ftp client\uninstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsxab5.tmp\userinfo.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nsxab5.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsxab5.tmp\system.dll
c:\program files\filezilla ftp client\fzshellext.dll

Registry activity

Total events
1163
Read events
1125
Write events
26
Delete events
12

Modification events

PID
Process
Operation
Key
Name
Value
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13
Blob
040000000100000010000000410352DC0FF7501B16F0028EBA6F45C50F00000001000000140000005BCAA1C2780F0BCB5A90770451D96F38963F012D090000000100000042000000304006082B0601050507030406082B0601050507030106082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C6200000001000000200000000687260331A72403D909F105E69BCF0D32E1BD2493FFC6D9206D11BCD67707390B000000010000001E000000440053005400200052006F006F0074002000430041002000580033000000140000000100000014000000C4A7B1A47B2C71FADBE14B9075FFC415608589101D00000001000000100000004558D512EECB27464920897DE7B66053030000000100000014000000DAC9024F54D8F6DF94935FB1732638CA6AD77C131900000001000000100000006CF252FEC3E8F20996DE5D4DD9AEF42420000000010000004E0300003082034A30820232A003020102021044AFB080D6A327BA893039862EF8406B300D06092A864886F70D0101050500303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F74204341205833301E170D3030303933303231313231395A170D3231303933303134303131355A303F31243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311730150603550403130E44535420526F6F7420434120583330820122300D06092A864886F70D01010105000382010F003082010A0282010100DFAFE99750088357B4CC6265F69082ECC7D32C6B30CA5BECD9C37DC740C118148BE0E83376492AE33F214993AC4E0EAF3E48CB65EEFCD3210F65D22AD9328F8CE5F777B0127BB595C089A3A9BAED732E7A0C063283A27E8A1430CD11A0E12A38B9790A31FD50BD8065DFB7516383C8E28861EA4B6181EC526BB9A2E24B1A289F48A39E0CDA098E3E172E1EDD20DF5BC62A8AAB2EBD70ADC50B1A25907472C57B6AAB34D63089FFE568137B540BC8D6AEEC5A9C921E3D64B38CC6DFBFC94170EC1672D526EC38553943D0FCFD185C40F197EBD59A9B8D1DBADA25B9C6D8DFC115023AABDA6EF13E2EF55C089C3CD68369E4109B192AB62957E3E53D9B9FF0025D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C4A7B1A47B2C71FADBE14B9075FFC41560858910300D06092A864886F70D01010505000382010100A31A2C9B17005CA91EEE2866373ABF83C73F4BC309A095205DE3D95944D23E0D3EBD8A4BA0741FCE10829C741A1D7E981ADDCB134BB32044E491E9CCFC7DA5DB6AE5FEE6FDE04EDDB7003AB57049AFF2E5EB02F1D1028B19CB943A5E48C4181E58195F1E025AF00CF1B1ADA9DC59868B6EE991F586CAFAB96633AA595BCEE2A7167347CB2BCC99B03748CFE3564BF5CF0F0C723287C6F044BB53726D43F526489A5267B758ABFE67767178DB0DA256141339243185A2A8025A3047E1DD5007BC02099000EB6463609B16BC88C912E6D27D918BF93D328D65B4E97CB15776EAC5B62839BF15651CC8F677966A0A8D770BD8910B048E07DB29B60AEE9D82353510
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Name
FileZilla_3.42.0_win64_sponsored-setup.exe
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
ID
1481493048
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}\InProcServer32
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla 3\fzshellext
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla 3
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla Client
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileZilla Client
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\filezilla.exe
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\fzsftp.exe
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\fzputtygen.exe
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\fzstorj.exe
3496
uninstall.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\filezilla.exe
3496
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
62
3496
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
63
3496
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
64
3496
uninstall.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Program Files\FileZilla FTP Client\fzshellext.dll
3496
uninstall.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
65

Files activity

Executable files
12
Suspicious files
0
Text files
83
Unknown types
0

Dropped files

PID
Process
Filename
Type
3408
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsz4477.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
3496
uninstall.exe
C:\Users\admin\AppData\Local\Temp\nsxAB5.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\imCZNmtbF.dll
executable
MD5: 9e25e3b758cdca8225ba94031c0c02f0
SHA256: 7551f7e17ac6f0b6cb62e7f25fd4a340d4905a4c463bd0be678fe74470ab10ab
3496
uninstall.exe
C:\Users\admin\AppData\Local\Temp\nsxAB5.tmp\UserInfo.dll
executable
MD5: 1b446b36f5b4022d50ffdc0cf567b24a
SHA256: 2862c7bc7f11715cebdea003564a0d70bf42b73451e2b672110e1392ec392922
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\nsDialogs.dll
executable
MD5: 42b064366f780c1f298fa3cb3aeae260
SHA256: c13104552b8b553159f50f6e2ca45114493397a6fa4bf2cbb960c4a2bbd349ab
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\Math.dll
executable
MD5: 4d0580b254afd8d0e898d1b4fecbda98
SHA256: c6cef985757fedba46cc004907913113859c4049dfbe8c3b39df52d60a27f5bc
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\UAC.dll
executable
MD5: adb29e6b186daa765dc750128649b63d
SHA256: 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
3408
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsz4477.tmp\UAC.dll
executable
MD5: adb29e6b186daa765dc750128649b63d
SHA256: 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\INetC.dll
executable
MD5: 640bff73a5f8e37b202d911e4749b2e9
SHA256: c1e568e25ec111184deb1b87cfda4bfec529b1abeab39b66539d998012f33502
3496
uninstall.exe
C:\Users\admin\AppData\Local\Temp\nsxAB5.tmp\UAC.dll
executable
MD5: adb29e6b186daa765dc750128649b63d
SHA256: 2f7f8fc05dc4fd0d5cda501b47e4433357e887bbfed7292c028d99c73b52dc08
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\UserInfo.dll
executable
MD5: 1b446b36f5b4022d50ffdc0cf567b24a
SHA256: 2862c7bc7f11715cebdea003564a0d70bf42b73451e2b672110e1392ec392922
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\VI.locale
text
MD5: 1c68a0b054e91821a6ee5fcc95a8f370
SHA256: 949be3edb5994b200e83ca062b6badcffdac4c177ce1a77b2976ede622797399
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ZH.locale
text
MD5: f87a44df4ee66271fcb7cb8909be2c2e
SHA256: f212cbeb0355b860a19969bf9a685b6aae5e8cd1b50ca97ec59880bdbaac24ad
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\YO.locale
text
MD5: 28cadcc5482ef94c3dd399966efce474
SHA256: 18350d0b95fea022fe7f65b2c21748423ad96ac9f4a87e833395873d45130dad
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ZU.locale
text
MD5: e0fe6b07557ceadb3cdee5cd6bf1553c
SHA256: 9a5f171619d63344771d0af667662cc3672222166fc7d5368724b818d4508b24
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\UR.locale
text
MD5: f98806a6c51ad09ab464191f95320bba
SHA256: 5e7131784e1de61479c8dc8bfcf8de40ed07f4d0ffdd4a29c42be6f298ad169f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\TR.locale
text
MD5: 9456c52aed7848fb1ff6d05de42e8391
SHA256: dd4e1cbeabc982697c1d4227f4c8cd18413351a279962a40041cafe3e427b036
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\UZ.locale
text
MD5: d7bb18debd6ae4b95ca1128a01550970
SHA256: 816b2817affbeb1d634235c0d901bdf45504da18527b5cce6895b4cf8cf8e7ba
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\TL.locale
text
MD5: 4685406c7549ce5fcb79fae49c013dec
SHA256: 107c995c36d3412886613b05e62bf27c8941b106912c2ed9e9ac54b7240f7524
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\UK.locale
text
MD5: 805b4a7d627d697d81889e90b5dc26f1
SHA256: 63148079e733a889e2531b21e0234c1ba7f1c981f9c1d025e539a5a3b420e065
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\SR.locale
text
MD5: af688f29d4745ac3d641017da91ef575
SHA256: bb47f7a85af70aedbb61c86c7ed7199aafb823350b185722468f7a6d492b2632
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\TH.locale
text
MD5: 02b331449294adfdbbafa59074e4984c
SHA256: c53cf743d7169e2d17433d5f123ac45a672d415484fed6af4cbe0f8441b88515
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\SL.locale
text
MD5: 84cc837239842449c8ff335b165c07e6
SHA256: bbe36fcc8d9404395a3e85f76479a6f4f4ec67106e53ad93a3d70747e5157a3d
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\SV.locale
text
MD5: d9fd720403c7b8c786224b693c6331ad
SHA256: f7361ffcba975398338a814f1f061720064d58fd838d2b8879f1b3e6dc5138aa
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\SQ.locale
text
MD5: 393bf5a36c36bd97b7f206a13d602827
SHA256: a6b643c1d26d2a9d13c94c147ba35a520b749c40af3e729910fa99eb636fc63b
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\TE.locale
text
MD5: 4c04155e36f1c718a97bcf3f4ba20697
SHA256: a85fdcd0a5fbc7b09f1401a343f2c7d334caac8d7dfbd0d3bfca20a9fd76d7ec
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\SK.locale
text
MD5: 405b3c6f0e68d2db60d1585385896623
SHA256: ee1ce5e2bfe867f5600c4a15c47b9d319e23046de25bee4c21b1171bb21a9623
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\TA.locale
text
MD5: 0357e9121095334fb270b19d2e847368
SHA256: 009f1c6bfbb1f39d8a59e9a8fc589f4dc8a978b4150c283fb2f3f1dfca7a4b87
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\RU.locale
text
MD5: 84c7cb5b39f47ab1cd80ce1f0c25921e
SHA256: 8012719a70324556c482dd3598ba2ed2f959d5dec8a6db44faa421ef672becca
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\NE.locale
text
MD5: 5d79e5cec4f95a3ca6a202970ced6d6e
SHA256: 54f1ddd4b34f705ee10714210e71f59ee51b8931a07b190920bbba2e03950c09
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\PA.locale
text
MD5: ab30b346b4c737c4a9c3ba9b49f2ba83
SHA256: f57cb5d5f9225c52dce26ef9ba742a36b5958f927eec5cd6c898f4f7ea3c3b9c
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\NL.locale
text
MD5: ade4560acaaf360f9dc5e590419abe83
SHA256: 23d3afc51acc6f786f6fcb46aeb0cf74af9f430a0aa539916f68c6be8a7add48
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\RO.locale
text
MD5: 44652248cbb99cea6dd8f5613b874cfa
SHA256: 57a1b5998c567221f90bfd66f42161273ddd60f52418de1fc939e9c86a51cef9
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\NO.locale
text
MD5: 2febd73097d15772b1c90a4e12278018
SHA256: 8585251a7a33f40b2cebb310f57ac0f80dff863bffec69874eb20923eb98adbf
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\PT.locale
text
MD5: 49b6cd7b7b3df73b1de5bb76c4f22e2f
SHA256: bdb75d81031c2e2c588d4be0ad4c303141259dd88e19b3ae9d77580224037998
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\PS.locale
text
MD5: 06efce2d687d52bcb57a48e8b0b726b4
SHA256: 45a64d28eb92e02855f2ba2c1999cb217ff84f4bc9abc89e49c974cfc884a847
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\PL.locale
text
MD5: fb48165b230ae752119d6f89bd7699ee
SHA256: 6c83b789070f2f9f193aaac52e6f610e6766007352bebb7ee9f6113439ccae48
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\MS.locale
text
MD5: e333713949b150ee82345f922e0040ec
SHA256: 44d77861ff9fc61c13bc1408e2e8d43c32673844c7f0b04e17f075232e4ba7de
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\LT.locale
text
MD5: ed29292834140f8500e4548bf3dffbf2
SHA256: 278889852149473c3f2795593f25a1e544e367a07297573f01e712dde175fee8
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ML.locale
text
MD5: 119243b7f2c19e278e4684d266de18e6
SHA256: 5db2b398c16f0c95f1caa5d268be5b6fa2da37072bf3522b9d911a7cbe7e19d8
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\LV.locale
text
MD5: 5db26fee22efa33110cdc356002e82ae
SHA256: a925bc583d473136f561fbc2893685ad0112cd578d7fec9ced53cab8a8bf4681
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\MR.locale
text
MD5: bbaf39e1500f3851ad4ea9a0f8d8e3fd
SHA256: 988c7d261cab45a65b09cb485405da216f34c75d228c7e934c309999d3fbf8dd
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\MK.locale
text
MD5: 9766f19ce1168c26a4ba2ab95e177759
SHA256: a4968d3d8bed8e9ea59f980fc5b31b27bf81911036d70f9305956ede2d92f28f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\LO.locale
text
MD5: 08a83d5e6c8683249c5c3b195a33a007
SHA256: 7dd5d3b863ae1c4fce0a3342646639cc8dac2423b2addcc14bcc585a7b8dd83f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\KK.locale
text
MD5: 27cadfd9aa0fe98538ea44e91c149070
SHA256: f4ba3b56a35e18371e059ba3b9e9711c3cd99d04295ba51ae826767c12aa38e9
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\IS.locale
text
MD5: e43741977970f32159950e862a2e51ca
SHA256: f6706486f6928bc7f56e5ba9269cb57780a1a3db1cf08ccbf477418579e2b421
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\KU.locale
text
MD5: 1b0984c7b45d39fb72f200c72c1d00bd
SHA256: 6ee56f9f35e3c11102221ea9fd6bb083e75826c9dad46fc9fd5705363b191e40
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\KO.locale
text
MD5: dbf7f7864e99ee24bee3a2acdb534766
SHA256: 9039e23765337dcfff2cf9eefbb33a6394c5fe402843209298ef0f31db3cb494
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\KA.locale
text
MD5: 1a4abc33ce6e481942ecc7de68ca8d9c
SHA256: 70a39de6f6c425e362bafb70401e762fd724be0aa208748378d199ac4aab3072
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\JA.locale
text
MD5: 6bc9980050aed56c2eab3b378bd2ca7c
SHA256: 330e2fcef32fdf2acc2e0ca307436926ffb03532af10bea54ea6c1d66ef9e32f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\IT.locale
text
MD5: 5beb8094b02db5fe5acb113ea615b428
SHA256: 046a44dbd7f96007576ae6e193d308b16dd409f24b3434b2f97bc9e32d03ebec
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HE.locale
text
MD5: d1aea6c331c1db405a2a991346533477
SHA256: f71341df3639a6017693333d8bcce3131ca51f428adea6e940e21d2475342b79
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HU.locale
text
MD5: 7cce69e942d9e14a1cf10280499a2667
SHA256: 83001fce7998f3de063073587f905a13c7649f45ffd3139e8f589978e8fdaf7f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ID.locale
text
MD5: e871501287a24ef0d6802d62cd27b46c
SHA256: 0f2899ee236e8d53022ab9f18202114e1567e6c8c93a3fdd128f38bb80355931
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HY.locale
text
MD5: ab8b9b0e16b5ef75e0357a8b3f490e05
SHA256: 480570dada38e88b723aa39ac7d79eac7915eb72550b96157022ee0324406804
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HR.locale
text
MD5: 0df1fbe32d5c0037c39d94981f56e186
SHA256: 9078de8455c43a85408108abe2181be496897dc0bcbf533b15098fcddd4ebce1
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\FI.locale
text
MD5: aa02a7f1269174618543687ea202f385
SHA256: b891b31e69071351a1669b93f35c434f094973931572dfe36b3c24e648a0d12b
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HT.locale
text
MD5: 642c180660f79cd3cc7d841614b57365
SHA256: 045aa565e48add4ccbeab74bf38248733e0c4d8becaefab19a6746213ba17762
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\HI.locale
text
MD5: 791e420383be8d190644640fe7a10ab6
SHA256: 38c96d6da4f0b00a61cfc0f3734b80a37cf79d92cb583428e23e8381746081ca
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\FR.locale
text
MD5: 227c91a86f898c3b565180646141d680
SHA256: 5109297aaf2b41406b4b210c1da7cfe462c195af1b2bf1b60225477903919bc2
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\GU.locale
text
MD5: d58f240e4f4d700b8523cd8ecb3a83e2
SHA256: 25f31b56585cc3a34b59b9e72e8eff6a654d911fe1c7fb18feeb8dc62d4e0331
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\FA.locale
text
MD5: 9dbb5724b5a1526b1bfad362d67854f2
SHA256: b154cb9b33a3f2d3390b201025a027c0dee848f98118d601a5710988e95e33b3
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ET.locale
text
MD5: 31adb5d5e61e0a2e7fa200340df57102
SHA256: de026d2a590398259e6f34200aceb16ffca75c7b8479930b9c2d5524869cce15
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\EN.locale
text
MD5: 4459c311642a67b43941afcf798d7791
SHA256: d27e381c436210ac3d8c5ba9a2954cc050619b353c99c5978bb775759cd5f3b0
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\DA.locale
text
MD5: 7b1312c0dea89488087e56d35651e472
SHA256: e2f6b6a141164fd442aeaa79a261f2e9799a0c7700c928df701702468b902a8c
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\EL.locale
text
MD5: 71035ad0232f4d8dc0e837d5865e8834
SHA256: 3aea8bcfd2855028b3c77db0b53627e8884cd9c1d9481a8d83731a9d2b1e5d9f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\ES.locale
text
MD5: 53755996be49144a3a83890c026b4049
SHA256: d8cd03140dc31d4d08b2c7cb8067a77ca46ad3c58347988e6625cf15c6c8a4e2
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\EU.locale
text
MD5: 49c617241f6bfd93bc5b4b0573bd8b26
SHA256: 6c7241993651cb8414a78afc817b4a40dbbe3a359e7a8ce1f5e31ac1c6f78171
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\DE.locale
text
MD5: ac99de234c1c7dff173e1be6507d2b50
SHA256: 5f5f05b25b6f44af38ae2fabb99b1bb3f4cc9413e2275b2998b0d3771286737f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\CS.locale
text
MD5: 0af631d42063eef22d6bfcf3b1780254
SHA256: 8290556e9ad37befee2ccff5b65aab1dd44ac7f45292220a33ab30282e6b9d3a
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\BG.locale
text
MD5: c77a1f22bc00991db483daad060c21b9
SHA256: f3cfc4b300d6ac056cd21934c9a4cefbfde6531905323f08bf1985f9f3867da9
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\images\progress-bg.png
image
MD5: e9f12f92a9eeb8ebe911080721446687
SHA256: c1cf449536bc2778e27348e45f0f53d04c284109199fb7a9af7a61016b91f8bc
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\images\progress-bg2.png
image
MD5: b582d9a67bfe77d523ba825fd0b9dae3
SHA256: ab4eeb3ea1eef4e84cb61eccb0ba0998b32108d70b3902df3619f4d9393f74c3
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\AF.locale
text
MD5: 85683d68fac960fd7887669059b18113
SHA256: 6578baf8fab1dce694229303df0bac1be2bca437d05f3391d9939d9610028fe1
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\BE.locale
text
MD5: 411748400cd72340bcf29e34f539340a
SHA256: 2c9e5a82c1edabe537c04c330a87332faa1188a4ba3394084e756e9ab2f0066a
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\BS.locale
text
MD5: ff9188bbc0c3a5c14658db0627b28585
SHA256: add647d223c183f6d56a1aa9a22d2b0436f18c9f972da7bc8705cccf867d74dd
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\AZ.locale
text
MD5: 90a482ef6f51d900b5f3fbbfdeeedd8b
SHA256: 254679039a064418809eb8c9187c0d6588a0f2e44c671b77f79c82806c900750
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\images\Loader.gif
image
MD5: 57ca1a2085d82f0574e3ef740b9a5ead
SHA256: 476a7b1085cc64de1c0eb74a6776fa8385d57eb18774f199df83fc4d7bbcc24e
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\locale\CA.locale
text
MD5: 18dd92b6bfcf4b2d04ec752f2bbed37e
SHA256: acd3d339fc4c4978bd6942e95f451da49d10e8861d8d89022c9edc62748039f3
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\main.css
text
MD5: 9b27e2a266fe15a3aabfe635c29e8923
SHA256: 166aa42bc5216c5791388847ae114ec0671a0d97b9952d14f29419b8be3fb23f
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\button.css
text
MD5: 37e1ff96e084ec201f0d95feef4d5e94
SHA256: 8e806f5b94fc294e918503c8053ef1284e4f4b1e02c7da4f4635e33ec33e0534
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\browse.css
text
MD5: 6009d6e864f60aea980a9df94c1f7e1c
SHA256: 5ef48a8c8c3771b4f233314d50dd3b5afdcd99dd4b74a9745c8fe7b22207056d
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\checkbox.css
text
MD5: 64773c6b0e3413c81aebc46cce8c9318
SHA256: b09504c1bf0486d3ec46500592b178a3a6c39284672af8815c3687cc3d29560d
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\images\button-bg.png
image
MD5: 98b1de48dfa64dc2aa1e52facfbee3b0
SHA256: 2693930c474fe640e2fe8d6ef98abe2ecd303d2392c3d8b2e006e8942ba8f534
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\images\progress-bg-corner.png
image
MD5: 608f1f20cd6ca9936eaa7e8c14f366be
SHA256: 86b6e6826bcde2955d64d4600a4e01693522c1fddf156ce31c4ba45b3653a7bd
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\sdk-ui\progress-bar.css
text
MD5: 5335f1c12201b5f7cf5f8b4f5692e3d1
SHA256: 974cd89e64bdaa85bf36ed2a50af266d245d781a8139f5b45d7c55a0b0841dda
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\csshover3.htc
html
MD5: 52fa0da50bf4b27ee625c80d36c67941
SHA256: e37e99ddfc73ac7ba774e23736b2ef429d9a0cb8c906453c75b14c029bdd5493
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\css\ie6_main.css
text
MD5: 74f08d5a243ae79f1de64dffdaf846cb
SHA256: 15590060bfd227f656e569031113a080e0d45621a5c944dfc352f869eadafef2
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\0015A9B7.log
––
MD5:  ––
SHA256:  ––
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\EN[1].jpg
image
MD5: 486eb7ee86ab193bb6b3c5635da0aeaa
SHA256: 1187e1b0875a611f2279bcab132491bba547bde98d3a21ff8ed6706e30fd7806
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\logo_comp[1].png
image
MD5: 61505efafa51406086b32ac885d37807
SHA256: 2eda136d8645862194ef932b7a06714b9c49fc7b884424aa7758358d704b0e97
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\bg_comp[1].png
image
MD5: 965619ea661d15494bcabac08d1761f5
SHA256: 8bfc99d5cc3d9cddb44d77160d3c09a3a5ec629cde7bb7d64bd86a023dcbdb73
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsm7E34.tmp\modern-wizard.bmp
image
MD5: cbe40fd2b1ec96daedc65da172d90022
SHA256: 3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
3496
uninstall.exe
C:\Users\admin\AppData\Local\Temp\nshAA4.tmp
––
MD5:  ––
SHA256:  ––
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Program Files\0015ACE3.log
––
MD5:  ––
SHA256:  ––
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\nsd141970317131\bootstrap_36644.html
html
MD5: 1ea9e5b417811379e874ad4870d5c51a
SHA256: f076773a6e3ae0f1cee3c69232779a1aaaf05202db472040c0c8ea4a70af173a
2868
FileZilla_3.42.0_win64_sponsored-setup.exe
C:\Users\admin\AppData\Local\Temp\0015AAEF.log
––
MD5:  ––
SHA256:  ––
3496
uninstall.exe
C:\Users\admin\AppData\Local\Temp\nsxAB5.tmp\modern-wizard.bmp
image
MD5: cbe40fd2b1ec96daedc65da172d90022
SHA256: 3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
17
TCP/UDP connections
8
DNS requests
4
Threats
17

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2868 FileZilla_3.42.0_win64_sponsored-setup.exe GET 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.51.129.59:80 http://os.tourtodaylaboratory.com/FusionFileZilla/ IE
binary
binary
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe GET 200 146.185.27.45:80 http://img.tourtodaylaboratory.com/img/Tavasat/15Feb17/v2_fs/EN.jpg GB
image
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe GET 200 146.185.27.45:80 http://img.tourtodaylaboratory.com/img/Sibarasawi/bg_comp.png GB
image
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe GET 200 146.185.27.45:80 http://img.tourtodaylaboratory.com/img/Sibarasawi/logo_comp.png GB
image
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe POST 200 52.214.73.247:80 http://rp.tourtodaylaboratory.com/ IE
binary
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2868 FileZilla_3.42.0_win64_sponsored-setup.exe 136.243.154.86:443 Hetzner Online GmbH DE unknown
2868 FileZilla_3.42.0_win64_sponsored-setup.exe 52.214.73.247:80 Amazon.com, Inc. IE malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe 52.51.129.59:80 Amazon.com, Inc. IE malicious
2868 FileZilla_3.42.0_win64_sponsored-setup.exe 146.185.27.45:80 UK-2 Limited GB malicious

DNS requests

Domain IP Reputation
offers.filezilla-project.org 136.243.154.86
whitelisted
rp.tourtodaylaboratory.com 52.214.73.247
54.194.149.175
malicious
os.tourtodaylaboratory.com 52.51.129.59
52.50.98.206
34.247.72.148
malicious
img.tourtodaylaboratory.com 146.185.27.45
malicious

Threats

PID Process Class Message
2868 FileZilla_3.42.0_win64_sponsored-setup.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
2868 FileZilla_3.42.0_win64_sponsored-setup.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
2868 FileZilla_3.42.0_win64_sponsored-setup.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3
2868 FileZilla_3.42.0_win64_sponsored-setup.exe Misc activity ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4

13 ETPRO signatures available at the full report

Debug output strings

No debug info.