File name:

hfsexplorer-2021.10.9-setup.exe

Full analysis: https://app.any.run/tasks/fbdba86c-4a26-4fb3-ac0d-6b315e59d00a
Verdict: Malicious activity
Analysis date: May 20, 2025, 18:27:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

844EB78E1B04545DBDC3B805699F89B5

SHA1:

B54A09C01493E4B0AB8B536A5A16FC4B119A6B08

SHA256:

F4F55575D3E91FCCE05DD994EBC6BABCEC317A4B27EE986E8A9A37F936EA2D44

SSDEEP:

49152:nhwTEIOHQNlNDMGoTM9E820b9gA+XreDAfOaOnaH5Fmbufg4U:nNXHQRDMGHE82WmkIEQ58q2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates a software uninstall entry

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Executable content was dropped or overwritten

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • There is functionality for taking screenshot (YARA)

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • The process creates files with name similar to system file names

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Starts itself from another location

      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Searches for installed software

      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Reads security settings of Internet Explorer

      • hfsexplorer.exe (PID: 4068)
      • javaw.exe (PID: 5556)
    • Application launched itself

      • hfsexplorer.exe (PID: 4068)
    • Checks for Java to be installed

      • javaw.exe (PID: 5556)
  • INFO

    • Creates files in the program directory

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • javaw.exe (PID: 5556)
    • Reads the computer name

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • uninst.exe (PID: 3888)
      • hfsexplorer.exe (PID: 4068)
      • javaw.exe (PID: 5556)
    • Create files in a temporary directory

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • javaw.exe (PID: 5556)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
    • Checks supported languages

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • hfsexplorer.exe (PID: 5260)
      • hfsexplorer.exe (PID: 4068)
      • uninst.exe (PID: 3888)
    • The sample compiled with english language support

      • hfsexplorer-2021.10.9-setup.exe (PID: 6264)
    • Manual execution by a user

      • hfsexplorer-2021.10.9-setup.exe (PID: 6512)
      • hfsexplorer-2021.10.9-setup.exe (PID: 3008)
      • hfsexplorer.exe (PID: 4068)
    • Process checks computer location settings

      • hfsexplorer.exe (PID: 4068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:53:44+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 3805696
UninitializedDataSize: 2048
EntryPoint: 0x350a
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hfsexplorer-2021.10.9-setup.exe sppextcomobj.exe no specs slui.exe no specs hfsexplorer-2021.10.9-setup.exe no specs hfsexplorer-2021.10.9-setup.exe uninst.exe no specs hfsexplorer.exe no specs hfsexplorer.exe javaw.exe no specs icacls.exe no specs conhost.exe no specs hfsexplorer-2021.10.9-setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2140C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
2656C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3008"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3888"C:\Program Files (x86)\HFSExplorer\uninst.exe" _?=C:\Program Files (x86)\HFSExplorerC:\Program Files (x86)\HFSExplorer\uninst.exehfsexplorer-2021.10.9-setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\program files (x86)\hfsexplorer\uninst.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4068"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe" C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exeexplorer.exe
User:
admin
Company:
Catacombae Software
Integrity Level:
MEDIUM
Description:
HFSExplorer
Exit code:
0
Version:
2021, 10, 9, 0
Modules
Images
c:\program files (x86)\hfsexplorer\bin\hfsexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5260"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe" "-invokeduac"C:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exe
hfsexplorer.exe
User:
admin
Company:
Catacombae Software
Integrity Level:
HIGH
Description:
HFSExplorer
Version:
2021, 10, 9, 0
Modules
Images
c:\program files (x86)\hfsexplorer\bin\hfsexplorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5556javaw.exe -classpath ..\lib\hfsx.jar;..\lib\swing-layout-1.0.4.jar;..\lib\hfsx_dmglib.jar;..\lib\apache-ant-1.7.0-bzip2.jar;..\lib\iharder-base64.jar org.catacombae.hfsexplorer.FileSystemBrowserWindow "-dbgconsole"C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_2989500\javaw.exehfsexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files (x86)\common files\oracle\java\javapath_target_2989500\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6028"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6132"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6264"C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe" C:\Users\admin\Desktop\hfsexplorer-2021.10.9-setup.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\hfsexplorer-2021.10.9-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
2 653
Read events
2 646
Write events
7
Delete events
0

Modification events

(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:NSIS:StartMenuDir
Value:
HFSExplorer
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:DisplayName
Value:
HFSExplorer 2021.10.9
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\HFSExplorer\uninst.exe
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:DisplayVersion
Value:
2021.10.9
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:URLInfoAbout
Value:
https://www.catacombae.org/
(PID) Process:(6264) hfsexplorer-2021.10.9-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HFSExplorer
Operation:writeName:Publisher
Value:
Catacombae Software
Executable files
18
Suspicious files
6
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\resviewtext
MD5:D9B2546DCB321311674501540FE678C1
SHA256:D6C464E861A3EA166DAA1CE4E53EE7C4AE5FE92859A514CE94EB97564D9D8683
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsexplorertext
MD5:F2DA9BD473616187D29749C7975CFB94
SHA256:41F6A57D275D616B066CEE4C6B969E279F2E7BDCD344C79D46C73422608623C7
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsexplorer.exeexecutable
MD5:0EB9FF6944D9658D967AA202F16CBC28
SHA256:3ABF9A85609335BA3E27BC79DEED76229CD5256599304FAF82E71EC70D032418
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\unhfs.battext
MD5:FBE9C94A2AA1AB29228025737DE90070
SHA256:01D258088FFAECE6CA0290522715433D179892342CF983884CECCA42CBFAD222
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsexplorer_vista.vbstext
MD5:853975571CA02610167C2DE5E9FB64A1
SHA256:2599BC161954294E41E00B714EE0D3E199CB559C13B8962E46A1E5C90E3FD023
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\hfsx.battext
MD5:7E4405F833126FA95118F3B5D1E88CC8
SHA256:BE10629635DB60280364014451615D5B3979D121EED72BB68B9DAE86E0CC72DA
6264hfsexplorer-2021.10.9-setup.exeC:\Users\admin\AppData\Local\Temp\nssC92F.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\resview.battext
MD5:0D6C68E932252F56B123D74312E72EFB
SHA256:7C39EFD14C3674CF60F897BC8E8925A4EDC7E6D89BC0A4F80A59A34F06F21072
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\unhfstext
MD5:1362E17F9C40B85A595D3BB3DD02494B
SHA256:96F003E20F43D794768F38D01DF987CCAEAFCD338CBE71B395F66DB9D84A376A
6264hfsexplorer-2021.10.9-setup.exeC:\Program Files (x86)\HFSExplorer\bin\dumpfsdata.battext
MD5:88DA4A496A8DEB538E08738A035236DD
SHA256:FF3CF8D7135640AF412D85E1E0AA36476B006A8AF13DE49CE9E5A1DDCB3839E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
24
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
680
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
680
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
680
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.169
  • 23.48.23.176
  • 23.48.23.147
  • 23.48.23.158
  • 23.48.23.193
  • 23.48.23.180
  • 23.48.23.141
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.131
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted

Threats

No threats detected
No debug info