File name:

hfsexplorer-2021.10.9-setup.exe

Full analysis: https://app.any.run/tasks/fbdba86c-4a26-4fb3-ac0d-6b315e59d00a
Verdict: Malicious activity
Analysis date: May 20, 2025, 18:27:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

844EB78E1B04545DBDC3B805699F89B5

SHA1:

B54A09C01493E4B0AB8B536A5A16FC4B119A6B08

SHA256:

F4F55575D3E91FCCE05DD994EBC6BABCEC317A4B27EE986E8A9A37F936EA2D44

SSDEEP:

49152:nhwTEIOHQNlNDMGoTM9E820b9gA+XreDAfOaOnaH5Fmbufg4U:nNXHQRDMGHE82WmkIEQ58q2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Creates a software uninstall entry

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • There is functionality for taking screenshot (YARA)

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • The process creates files with name similar to system file names

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Searches for installed software

      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Starts itself from another location

      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Reads security settings of Internet Explorer

      • hfsexplorer.exe (PID: 4068)
      • javaw.exe (PID: 5556)
    • Application launched itself

      • hfsexplorer.exe (PID: 4068)
    • Checks for Java to be installed

      • javaw.exe (PID: 5556)
  • INFO

    • Checks supported languages

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • uninst.exe (PID: 3888)
      • hfsexplorer.exe (PID: 4068)
      • hfsexplorer.exe (PID: 5260)
    • Creates files in the program directory

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • javaw.exe (PID: 5556)
    • Reads the computer name

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • uninst.exe (PID: 3888)
      • hfsexplorer.exe (PID: 4068)
      • javaw.exe (PID: 5556)
    • The sample compiled with english language support

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Create files in a temporary directory

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • javaw.exe (PID: 5556)
    • Manual execution by a user

      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • hfsexplorer-2021.10.9-setup.exe (PID: 6512)
      • hfsexplorer.exe (PID: 4068)
    • Process checks computer location settings

      • hfsexplorer.exe (PID: 4068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:53:44+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 3805696
UninitializedDataSize: 2048
EntryPoint: 0x350a
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hfsexplorer-2021.10.9-setup.exe sppextcomobj.exe no specs slui.exe no specs hfsexplorer-2021.10.9-setup.exe no specs hfsexplorer-2021.10.9-setup.exe uninst.exe no specs hfsexplorer.exe no specs hfsexplorer.exe javaw.exe no specs icacls.exe no specs conhost.exe no specs hfsexplorer-2021.10.9-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2140C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2656C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3008"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3888"C:\Program Files (x86)\HFSExplorer\uninst.exe" _?=C:\Program Files (x86)\HFSExplorerC:\Program Files (x86)\HFSExplorer\uninst.exehfsexplorer-2021.10.9-setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\program files (x86)\hfsexplorer\uninst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4068"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe" C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exeexplorer.exe
User:
admin
Company:
Catacombae Software
Integrity Level:
MEDIUM
Description:
HFSExplorer
Exit code:
0
Version:
2021, 10, 9, 0
Modules
Images
c:\program files (x86)\hfsexplorer\bin\hfsexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5260"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe" "-invokeduac"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe
hfsexplorer.exe
User:
admin
Company:
Catacombae Software
Integrity Level:
HIGH
Description:
HFSExplorer
Version:
2021, 10, 9, 0
Modules
Images
c:\program files (x86)\hfsexplorer\bin\hfsexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5556javaw.exe -classpath ..\lib\hfsx.jar;..\lib\swing-layout-1.0.4.jar;..\lib\hfsx_dmglib.jar;..\lib\apache-ant-1.7.0-bzip2.jar;..\lib\iharder-base64.jar org.catacombae.hfsexplorer.FileSystemBrowserWindow "-dbgconsole"C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_2989500\javaw.exehfsexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files (x86)\common files\oracle\java\javapath_target_2989500\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6028"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6132"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6264"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
2 653
Read events
2 646
Write events
7
Delete events
0

Modification events

(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:NSIS:StartMenuDir
Value:
HFSExplorer
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:DisplayName
Value:
HFSExplorer 2021.10.9
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\HFSExplorer\uninst.exe
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:DisplayVersion
Value:
2021.10.9
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:URLInfoAbout
Value:
https://www.catacombae.org/
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:Publisher
Value:
Catacombae Software
Executable files
18
Suspicious files
6
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
6264hfsexplorer-2021.10.9-setup.exeC:\Users\admin\AppData\Local\Temp\nssC92F.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
6264hfsexplorer-2021.10.9-setup.exeC:\Users\admin\AppData\Local\Temp\nssC92F.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6264hfsexplorer-2021.10.9-setup.exeC:\Users\admin\AppData\Local\Temp\nssC92F.tmp\StartMenu.dllexecutable
MD5:D070F3275DF715BF3708BEFF2C6C307D
SHA256:42DD4DDA3249A94E32E20F76EAFFAE784A5475ED00C60EF0197C8A2C1CCD2FB7
6264hfsexplorer-2021.10.9-setup.exeC:\Users\admin\AppData\Local\Temp\nssC92F.tmp\InstallOptions.dllexecutable
MD5:ECE25721125D55AA26CDFE019C871476
SHA256:C7FEF6457989D97FECC0616A69947927DA9D8C493F7905DC8475C748F044F3CF
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\lib\csframework.jarjava
MD5:CA343E720CA8C4A9142D776A9250DD13
SHA256:D7F351BCEC81E90BA094368584EB3D11148392BD8CD19322A43AE0103938BF28
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsxtext
MD5:90601B2C7BE7BBBF9B40314522EDE50B
SHA256:F2E19C392209F9DD411137D2C7E5D7662450B067236E985F73A06762F633B4A6
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\resviewtext
MD5:D9B2546DCB321311674501540FE678C1
SHA256:D6C464E861A3EA166DAA1CE4E53EE7C4AE5FE92859A514CE94EB97564D9D8683
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\unhfstext
MD5:1362E17F9C40B85A595D3BB3DD02494B
SHA256:96F003E20F43D794768F38D01DF987CCAEAFCD338CBE71B395F66DB9D84A376A
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\resview.battext
MD5:0D6C68E932252F56B123D74312E72EFB
SHA256:7C39EFD14C3674CF60F897BC8E8925A4EDC7E6D89BC0A4F80A59A34F06F21072
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsx.battext
MD5:7E4405F833126FA95118F3B5D1E88CC8
SHA256:BE10629635DB60280364014451615D5B3979D121EED72BB68B9DAE86E0CC72DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
24
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
680
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
680
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
680
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.169
  • 23.48.23.176
  • 23.48.23.147
  • 23.48.23.158
  • 23.48.23.193
  • 23.48.23.180
  • 23.48.23.141
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.131
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted

Threats

No threats detected
No debug info