File name:

FirPE写入器.exe

Full analysis: https://app.any.run/tasks/7003fa73-6ece-4965-80e5-f95e28336497
Verdict: Suspicious activity
Analysis date: October 29, 2018, 07:52:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

016CDE6435AC39ED6770E77FCCE10EDB

SHA1:

F62FBD356A70DFF821B07820E318F27728D9E9B5

SHA256:

FC57A8945F6B88FB5F7B399432F8113831198BC3ACA766F1A11E1CF1E2158DCA

SSDEEP:

196608:BdQXPBGl/ba2JvL+w5DcNWZL+ws1DmgYfUt23QK8enZPaWRO8+C3jjwLfJEtac0m:XZjvL+wNcoHKiO23QK1MWAcj8JEAc05E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Fbinst.exe (PID: 2212)
      • 7z.exe (PID: 3936)
      • 7z.exe (PID: 1680)
    • Loads dropped or rewritten executable

      • 7z.exe (PID: 3936)
      • 7z.exe (PID: 1680)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • FirPE写入器.exe (PID: 2944)
    • Executable content was dropped or overwritten

      • FirPE写入器.exe (PID: 2944)
      • 7z.exe (PID: 3936)
      • 7z.exe (PID: 1680)
    • Low-level read access rights to disk partition

      • Fbinst.exe (PID: 2212)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (30.7)
.exe | UPX compressed Win32 Executable (30.1)
.exe | Win32 EXE Yoda's Crypter (29.5)
.exe | Win32 Executable (generic) (5)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:10:26 15:07:05+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 12124160
InitializedDataSize: 110592
UninitializedDataSize: 10563584
EntryPoint: 0x15a3150
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.1.2.0
ProductVersionNumber: 1.1.2.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 1.1.2.0
FileDescription: 维护利器 - FirPE维护系统
ProductName: FirPE 维护系统
ProductVersion: 1.1.2.0
CompanyName: FirPE 维护系统
LegalCopyright: (C) 2018 FirPE Team All Rights Reserved.
Comments: 维护利器 - FirPE维护系统

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 26-Oct-2018 13:07:05
Detected languages:
  • Chinese - PRC
  • Italian - Italy
FileVersion: 1.1.2.0
FileDescription: 维护利器 - FirPE维护系统
ProductName: FirPE 维护系统
ProductVersion: 1.1.2.0
CompanyName: FirPE 维护系统
LegalCopyright: (C) 2018 FirPE Team All Rights Reserved.
Comments: 维护利器 - FirPE维护系统

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 26-Oct-2018 13:07:05
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00A13000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00A14000
0x00B90000
0x00B8F400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.88799
.rsrc
0x015A4000
0x0001B000
0x0001A200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.1089

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.02094
697
Latin 1 / Western European
UNKNOWN
RT_MANIFEST
2
7.09186
296
Latin 1 / Western European
Chinese - PRC
RT_ICON
3
3.2115
67624
Latin 1 / Western European
UNKNOWN
RT_ICON
4
4.65204
16936
Latin 1 / Western European
UNKNOWN
RT_ICON
5
4.91674
9640
Latin 1 / Western European
UNKNOWN
RT_ICON
6
5.31231
4264
Latin 1 / Western European
UNKNOWN
RT_ICON
7
5.42148
2440
Latin 1 / Western European
UNKNOWN
RT_ICON
8
5.41191
1128
Latin 1 / Western European
UNKNOWN
RT_ICON
9
7.01515
308
Latin 1 / Western European
Chinese - PRC
RT_CURSOR
1032
4.22193
20
Latin 1 / Western European
Chinese - PRC
RT_GROUP_CURSOR

Imports

ADVAPI32.dll
AVIFIL32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.DLL
MSIMG32.dll
MSVFW32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start firpe写入器.exe cmd.exe no specs 7z.exe cmd.exe no specs 7z.exe cmd.exe no specs fbinst.exe no specs firpe写入器.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1680C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe x C:\Users\admin\AppData\Local\Temp\FirPE\PaCmd.7z -y -aos -o"C:\Users\admin\AppData\Local\Temp\FirPE\"C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\firpe\7z.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1772cmd.exe /c C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe x C:\Users\admin\AppData\Local\Temp\FirPE\PaCmd.7z -y -aos -o"C:\Users\admin\AppData\Local\Temp\FirPE\"C:\Windows\system32\cmd.exeFirPE写入器.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2212C:\Users\admin\AppData\Local\Temp\FirPE\Fbinst.exe --hdlist "" --USBC:\Users\admin\AppData\Local\Temp\FirPE\Fbinst.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\firpe\fbinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
2348cmd.exe /c C:\Users\admin\AppData\Local\Temp\FirPE\Fbinst.exe --hdlist "" --USBC:\Windows\system32\cmd.exeFirPE写入器.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2944"C:\Users\admin\Desktop\FirPE写入器.exe" C:\Users\admin\Desktop\FirPE写入器.exe
explorer.exe
User:
admin
Company:
FirPE 维护系统
Integrity Level:
HIGH
Description:
维护利器 - FirPE维护系统
Exit code:
0
Version:
1.1.2.0
Modules
Images
c:\users\admin\desktop\firpe写入器.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\user32.dll
3132cmd.exe /c C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe x C:\Users\admin\AppData\Local\Temp\FirPE\\Qemu.7z -y -aos -o"C:\Users\admin\AppData\Local\Temp\FirPE\"C:\Windows\system32\cmd.exeFirPE写入器.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3172"C:\Users\admin\Desktop\FirPE写入器.exe" C:\Users\admin\Desktop\FirPE写入器.exeexplorer.exe
User:
admin
Company:
FirPE 维护系统
Integrity Level:
MEDIUM
Description:
维护利器 - FirPE维护系统
Exit code:
3221226540
Version:
1.1.2.0
3936C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe x C:\Users\admin\AppData\Local\Temp\FirPE\\Qemu.7z -y -aos -o"C:\Users\admin\AppData\Local\Temp\FirPE\"C:\Users\admin\AppData\Local\Temp\FirPE\7z.exe
cmd.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\firpe\7z.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
18
Read events
18
Write events
0
Delete events
0

Modification events

No data
Executable files
27
Suspicious files
3
Text files
6
Unknown types
7

Dropped files

PID
Process
Filename
Type
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\Fbinst.exeexecutable
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\Gdisk32.exeexecutable
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\Etfsboot.combinary
MD5:D4BEFEBF3CEF129AC087422B9E912788
SHA256:F425E135AAC26B55E2BAC655E62E2CE0B16255226C583D9AB43B2E93E8A6D932
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\PaCmd.7zcompressed
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\Qemu.7zcompressed
MD5:
SHA256:
16807z.exeC:\Users\admin\AppData\Local\Temp\FirPE\PACMDforUSB\wnd.initext
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\UltraISO.exeexecutable
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\UD.fbavxd
MD5:
SHA256:
2944FirPE写入器.exeC:\Users\admin\AppData\Local\Temp\FirPE\7z.exeexecutable
MD5:A51D90F2F9394F5EA0A3ACAE3BD2B219
SHA256:AC9674FEB8F2FAD20C1E046DE67F899419276AE79A60E8CC021A4BF472AE044F
16807z.exeC:\Users\admin\AppData\Local\Temp\FirPE\PACMDforUSB\Microsoft.VC80.CRT.manifestxml
MD5:541423A06EFDCD4E4554C719061F82CF
SHA256:17AD1A64BA1C382ABF89341B40950F9B31F95015C6B0D3E25925BFEBC1B53EB5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info