| File name: | fgdump-2.1.0-exeonly.zip |
| Full analysis: | https://app.any.run/tasks/6c12ad22-5e33-48ef-a1f7-cdee9a5bbb90 |
| Verdict: | Malicious activity |
| Analysis date: | March 08, 2021, 03:15:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | A6057C3321471B8F4149E4E30200F69B |
| SHA1: | 445673B8F9C3794ED05C6AA2CB167BF0E4510868 |
| SHA256: | F4D0DA680BED0859E03659EED678C9503F166D20293BC263291D18A3337409FA |
| SSDEEP: | 12288:k1xSWgCcTziE4FeONHmhlWWTYFSKEycFsoS8l:axVgCc6EfOtmhlpm5cFt |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2008:05:01 17:38:25 |
| ZipCRC: | 0xfac7a561 |
| ZipCompressedSize: | 471084 |
| ZipUncompressedSize: | 974848 |
| ZipFileName: | fgdump.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 488 | C:\Windows\system32\lsass.exe | C:\Windows\System32\lsass.exe | wininit.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Local Security Authority Process Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1384 | -v | C:\Users\admin\AppData\Local\Temp\cachedump.exe | — | fgdump.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1440 | "C:\Users\admin\Desktop\fgdump.exe" | C:\Users\admin\Desktop\fgdump.exe | explorer.exe | ||||||||||||
User: admin Company: Foofus Networking (www.foofus.net) Integrity Level: MEDIUM Description: fgdump Exit code: 3221225786 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 1716 | "C:\Users\admin\Desktop\fgdump.exe" | C:\Users\admin\Desktop\fgdump.exe | explorer.exe | ||||||||||||
User: admin Company: Foofus Networking (www.foofus.net) Integrity Level: HIGH Description: fgdump Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 2248 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\127.0.0.1.pwdump | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2396 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\fgdump-2.1.0-exeonly.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2484 | -o "C:\Users\admin\Desktop\127.0.0.1.pwdump" -u "(null)" -p "(null)" 127.0.0.1 | C:\Users\admin\AppData\Local\Temp\pwdump.exe | — | fgdump.exe | |||||||||||
User: admin Company: Foofus Networking Integrity Level: MEDIUM Exit code: 0 Version: 1, 7, 0, 0 Modules
| |||||||||||||||
| 2800 | -o "C:\Users\admin\Desktop\127.0.0.1.pwdump" -u "(null)" -p "(null)" 127.0.0.1 | C:\Users\admin\AppData\Local\Temp\pwdump.exe | — | fgdump.exe | |||||||||||
User: admin Company: Foofus Networking Integrity Level: HIGH Exit code: 0 Version: 1, 7, 0, 0 Modules
| |||||||||||||||
| 2864 | -v | C:\Users\admin\AppData\Local\Temp\cachedump.exe | — | fgdump.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 5 Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\AppData\Local\Temp\cachedump.exe" -s | C:\Users\admin\AppData\Local\Temp\cachedump.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\fgdump-2.1.0-exeonly.zip | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2396) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1716 | fgdump.exe | C:\Users\admin\Desktop\127.0.0.1.cachedump | text | |
MD5:— | SHA256:— | |||
| 2396 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2396.17053\fgdump.exe | executable | |
MD5:0762764E298C369A2DE8AFAEC5174ED9 | SHA256:A6CAD2D0F8DC05246846D2A9618FC93B7D97681331D5826F8353E7C3A3206E86 | |||
| 1440 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\fgexec.exe | executable | |
MD5:A761BEA93C900044B9E67364F3C7B06F | SHA256:8697897BEE415F213CE7BC24F22C14002D660B8AAFFAB807490DDBF4F3F20249 | |||
| 2800 | pwdump.exe | C:\Users\admin\Desktop\127.0.0.1.pwdump | text | |
MD5:— | SHA256:— | |||
| 1440 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\cachedump.exe | executable | |
MD5:9DE5B79050879AF333D8A0EC555D6B57 | SHA256:CF58CA5BF8C4F87BB67E6A4E1FB9E8BADA50157DACBD08A92A4A779E40D569C4 | |||
| 1440 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\pwdump.exe | executable | |
MD5:F959F07A120D759DDD1AE4AA9FF32C75 | SHA256:3C796092F42A948018C3954F837B4047899105845019FCE75A6E82BC99317982 | |||
| 1440 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\lsremora64.dll | executable | |
MD5:3FED6DC4BA33DF1EADCBC50D88DCEF7A | SHA256:EFA66F6391EC471CA52CD053159C8A8778F11F921DA14E6DAF76387F8C9AFCD5 | |||
| 1440 | fgdump.exe | C:\Users\admin\Desktop\2021-03-08-03-15-45.fgdump-log | text | |
MD5:— | SHA256:— | |||
| 1716 | fgdump.exe | C:\Users\admin\Desktop\2021-03-08-03-16-07.fgdump-log | text | |
MD5:— | SHA256:— | |||
| 1440 | fgdump.exe | C:\Users\admin\AppData\Local\Temp\lsremora.dll | executable | |
MD5:618E588A8CCFA331DAB8279A82A3E2D9 | SHA256:E0327C1218FD3723E20ACC780E20135F41ABCA35C35E0F97F7ECCAC265F4F44E | |||