| File name: | RServer.exe |
| Full analysis: | https://app.any.run/tasks/1ea1a190-4bb5-41ae-ab2d-db86b4fc9fa3 |
| Verdict: | Malicious activity |
| Analysis date: | May 12, 2025, 14:48:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | 94DF301A9842D3E1A42B6FAE69359B70 |
| SHA1: | 2139D1924EE9F5362727A7F18275FF2A9A01C4A1 |
| SHA256: | F5F2B3FFFFD401895B66C2254703425A800B4E288FFCDF9A3C34A9E953621696 |
| SSDEEP: | 98304:MfeGPE+mYjHS9dry54DP9+gAQdaCnnLt2kC0FiOwYQ7U0D6w7edEDaF0o5+ZVvhj:wKAS |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 107520 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1a238 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| FileVersion: | 1.0.0.0 |
| FileDescription: | Radmin Server install |
| ProductName: | Radmin Server install |
| ProductVersion: | 1.0.0.0 |
| CompanyName: | Bluefish |
| LegalCopyright: | Bluefish QQ10531348 |
| Comments: | Radmin服务端静默安装器 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\@°²×°.bat" " | C:\Windows\System32\cmd.exe | Radmin Server install.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 676 | reg import C:\Windows\System32\rserver30\install.reg /reg:32 | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1336 | "C:\Users\admin\AppData\Local\Temp\RServer.exe" | C:\Users\admin\AppData\Local\Temp\RServer.exe | explorer.exe | ||||||||||||
User: admin Company: Bluefish Integrity Level: HIGH Description: Radmin Server install Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1964 | "C:\Users\admin\AppData\Local\Temp\RServer.exe" | C:\Users\admin\AppData\Local\Temp\RServer.exe | — | explorer.exe | |||||||||||
User: admin Company: Bluefish Integrity Level: MEDIUM Description: Radmin Server install Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1980 | C:\Windows\System32\rserver30\rsetup.exe /start | C:\Windows\System32\rserver30\rsetup.exe | — | cmd.exe | |||||||||||
User: admin Company: Famatech Corp. Integrity Level: HIGH Description: Radmin Setup Helper Exit code: 1 Version: 3, 5, 0, 0 Modules
| |||||||||||||||
| 2528 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{3b126f26-d831-678a-a1e9-e12f38b96a1d}\mirrorv3.inf" "0" "60bbf019f" "00000404" "WinSta0\Default" "00000560" "208" "c:\windows\system32\rserver30" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2588 | "C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\Radmin Server install.exe" | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\Radmin Server install.exe | — | RServer.exe | |||||||||||
User: admin Company: Bluefish Integrity Level: HIGH Description: Radmin Server install Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2832 | C:\Windows\system32\cmd.exe /S /D /c" ver" | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2872 | "C:\Windows\System32\rserver30\RServer3.exe" /service | C:\Windows\System32\rserver30\rserver3.exe | services.exe | ||||||||||||
User: SYSTEM Company: Famatech Corp. Integrity Level: SYSTEM Description: Radmin Server Version: 3, 5, 0, 0 Modules
| |||||||||||||||
| 2944 | findstr "6\.[0-9]\.[0-9][0-9]*" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2588) Radmin Server install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2588) Radmin Server install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2588) Radmin Server install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2588) Radmin Server install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1336) RServer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1336) RServer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1336) RServer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1336) RServer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1336) RServer.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\@Ð¶ÔØ.bat | |||
| (PID) Process: | (3116) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\install.reg | text | |
MD5:1A4FAF0CF38750C9B38EA8D2959379A8 | SHA256:CC364495CDD75E2C4DE86A0F45E2BF9DCAD1753AD1C18FF7E8BE99133D05F096 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\@Ð¶ÔØ.bat | text | |
MD5:358E854E2C5A9A8F0CDF40B4C21EB525 | SHA256:FCB91E8B635B1954F8C9713E7F7F866468FA05C91E91922AA93402283572EABA | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\rchatx.dll | executable | |
MD5:4BD29908E0CA2831CB74D5128F29F59A | SHA256:C4AA2789BE22FB8F49D63126169070072ED46D88A628E745AE2CA7A6E21FEAC8 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\FirewallInstallHelper.dll | executable | |
MD5:FB1B13C20766630A858591C00FFA3DE2 | SHA256:3928266D66790991D2DDBB31A955AC503254413EBC82D29439E0ADA95F45BBBF | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\R_sui.dll | executable | |
MD5:F0C41DBD12D9D78A17302692541E931F | SHA256:6F70032F0B83D6083310C579BDFE4AD18FD7D60A11A1450CF25BF30A746DCB26 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\raudiox.dll | executable | |
MD5:E4B19ABF75D0ED279AB4D8856109B169 | SHA256:80CCD620D5C46797078DB9AB2E8DD94CB03324C42D34E811C1203729D6B6FDB6 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\vcintcx.dll | executable | |
MD5:F0A907C1E49BC449886A1726AED7D8E3 | SHA256:532867F1D4B640C05DEDC3446888641BAA1B9183CAE2E2E2D28D7C70FE0F2767 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\RCursor.dll | executable | |
MD5:A8A3C98D50F6CB33F95416E459641D43 | SHA256:56BB6BAC6B5456F6A2EA5B5B8DF09D6ED9CD4FA0461471685668509BCFB13EB2 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\FamItrfc.Exe | executable | |
MD5:D97153B43EA9E9C3F5D9FB467E6B101D | SHA256:54F7CE751B2B4BEA492076F7B8E3172A14A343F8CDD59E3BAB1981D5FE04F0F6 | |||
| 1336 | RServer.exe | C:\Users\admin\AppData\Local\Temp\~sfx004CB0CB55\rserver30\rsaudiox.dll | executable | |
MD5:8AB91356DAC90ADBAB17A6D1926E369C | SHA256:AF08B325C3C5642219F0420D79BBD1CE1BC20382415CE199CE9007C3D8AEE6E1 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
Process | Message |
|---|---|
rserver3.exe | %n%n%n%n%n%n%n%n%n |