File name:

FileZilla_3.69.0_win64-setup.exe

Full analysis: https://app.any.run/tasks/123a6c47-38dd-4571-841f-050e90864cf0
Verdict: Malicious activity
Analysis date: April 21, 2025, 19:02:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

59BBBA435DACBF04935C5254EB59E410

SHA1:

E23322EAF26160C037A8DF8BEC8DE7E80FECC97C

SHA256:

FFBA5C9D8B6550DF595E3767D4A36856D739F54E4182721A1EA754DDEBC1FCAD

SSDEEP:

98304:G0s2wvAl1kGp5EQ4jY/C/aty8cLVEhGIMQ1kq4hmtKENasLF+l8LRNA/vWWQ6TMS:fL1aerDDiLbU0IIokek

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
    • Registers / Runs the DLL via REGSVR32.EXE

      • uninstall.exe (PID: 5344)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
    • Reads security settings of Internet Explorer

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • filezilla.exe (PID: 1568)
    • Executable content was dropped or overwritten

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
    • Application launched itself

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
    • There is functionality for taking screenshot (YARA)

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 4068)
  • INFO

    • The sample compiled with english language support

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
    • Reads the computer name

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
      • filezilla.exe (PID: 1568)
    • Create files in a temporary directory

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
    • Process checks computer location settings

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
    • Checks supported languages

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
      • uninstall.exe (PID: 5344)
      • filezilla.exe (PID: 1568)
    • FileZilla executable

      • FileZilla_3.69.0_win64-setup.exe (PID: 3676)
      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
    • Creates files in the program directory

      • FileZilla_3.69.0_win64-setup.exe (PID: 5024)
    • Creates files or folders in the user directory

      • filezilla.exe (PID: 1568)
    • FileZilla mutex has been found

      • filezilla.exe (PID: 1568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:08 23:05:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x369f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.69.0.0
ProductVersionNumber: 3.69.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Tim Kosse
FileDescription: FileZilla FTP Client
FileVersion: 3.69.0
LegalCopyright: Tim Kosse
OriginalFileName: FileZilla_3.69.0_win32-setup.exe
ProductName: FileZilla
ProductVersion: 3.69.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start filezilla_3.69.0_win64-setup.exe filezilla_3.69.0_win64-setup.exe sppextcomobj.exe no specs slui.exe no specs uninstall.exe regsvr32.exe no specs regsvr32.exe no specs filezilla.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516"C:\WINDOWS\system32\regsvr32.exe" /s /u "C:\Program Files\FileZilla FTP Client\fzshellext_64.dll"C:\Windows\System32\regsvr32.exeuninstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1568"C:\Program Files\FileZilla FTP Client\filezilla.exe" C:\Program Files\FileZilla FTP Client\filezilla.exeFileZilla_3.69.0_win64-setup.exe
User:
admin
Company:
FileZilla Project
Integrity Level:
MEDIUM
Description:
FileZilla FTP Client
Version:
3, 69, 0, 0
Modules
Images
c:\program files\filezilla ftp client\filezilla.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\program files\filezilla ftp client\libfzclient-commonui-private-3-69-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
2800C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3676"C:\Users\admin\Downloads\FileZilla_3.69.0_win64-setup.exe" C:\Users\admin\Downloads\FileZilla_3.69.0_win64-setup.exe
explorer.exe
User:
admin
Company:
Tim Kosse
Integrity Level:
MEDIUM
Description:
FileZilla FTP Client
Exit code:
0
Version:
3.69.0
Modules
Images
c:\users\admin\downloads\filezilla_3.69.0_win64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4068"C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\FileZilla FTP Client\fzshellext_64.dll"C:\Windows\System32\regsvr32.exeFileZilla_3.69.0_win64-setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5024"C:\Users\admin\Downloads\FileZilla_3.69.0_win64-setup.exe" /UAC:4034A /NCRC C:\Users\admin\Downloads\FileZilla_3.69.0_win64-setup.exe
FileZilla_3.69.0_win64-setup.exe
User:
admin
Company:
Tim Kosse
Integrity Level:
HIGH
Description:
FileZilla FTP Client
Exit code:
0
Version:
3.69.0
Modules
Images
c:\users\admin\downloads\filezilla_3.69.0_win64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5344"C:\Program Files\FileZilla FTP Client\uninstall.exe" /frominstall /keepstartmenudir _?=C:\Program Files\FileZilla FTP ClientC:\Program Files\FileZilla FTP Client\uninstall.exe
FileZilla_3.69.0_win64-setup.exe
User:
admin
Company:
Tim Kosse
Integrity Level:
HIGH
Description:
FileZilla FTP Client
Exit code:
0
Version:
3.65.0
Modules
Images
c:\program files\filezilla ftp client\uninstall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6132"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 390
Read events
3 355
Write events
20
Delete events
15

Modification events

(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook
Operation:delete keyName:(default)
Value:
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}\InProcServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB70412E-EEC9-479C-BBA9-BE36BFDDA41B}
Operation:delete keyName:(default)
Value:
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla 3\fzshellext
Operation:delete valueName:Enable
Value:

(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla 3\fzshellext
Operation:delete keyName:(default)
Value:
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\FileZilla 3
Operation:delete keyName:(default)
Value:
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
18
(PID) Process:(516) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
19
(PID) Process:(5344) uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\filezilla.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(5344) uninstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\filezilla.exe
Operation:delete valueName:DumpType
Value:

Executable files
35
Suspicious files
122
Text files
713
Unknown types
0

Dropped files

PID
Process
Filename
Type
5024FileZilla_3.69.0_win64-setup.exeC:\Users\admin\AppData\Local\Temp\nsvC557.tmp\System.dllexecutable
MD5:9B38A1B07A0EBC5C7E59E63346ECC2DB
SHA256:C881253DAFCF1322A771139B1A429EC1E78C507CA81A218A20DC1A4B25ABBFE7
5024FileZilla_3.69.0_win64-setup.exeC:\Program Files\FileZilla FTP Client\fzputtygen.exeexecutable
MD5:E838151DC7A982C051C38EA5DFDA0C6C
SHA256:7B0456785CD692407F4788A2D618CB2ED42654B5A750EB944FACC76D33BA0FF3
5344uninstall.exeC:\Users\admin\AppData\Local\Temp\nsiEFF1.tmpbinary
MD5:C7E474CA3901FC9AE5FD124308FF74E4
SHA256:4AAE673DFCC1FC8A4B90D0E0DB2BEB6769CED86AD23F3816B9533B2BDA2E2C50
5024FileZilla_3.69.0_win64-setup.exeC:\Program Files\FileZilla FTP Client\filezilla.exeexecutable
MD5:206218A54271D5B451C45D437C9F7A53
SHA256:A630C6807001B13578A51C56A342607BA0014BA6466EA2B14C84B78E7E0DE7D2
5024FileZilla_3.69.0_win64-setup.exeC:\Program Files\FileZilla FTP Client\fzsftp.exeexecutable
MD5:3E68E99FC575D3E5C6B23B181AEE69C1
SHA256:94CBA97AD220F6735F9EE4CF7E9A84FC8609B2A60F8522E123A5D2A8D6DC9504
3676FileZilla_3.69.0_win64-setup.exeC:\Users\admin\AppData\Local\Temp\nsyBFF8.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
5344uninstall.exeC:\Users\admin\AppData\Local\Temp\nsxF001.tmp\System.dllexecutable
MD5:564BB0373067E1785CBA7E4C24AAB4BF
SHA256:7A9DDEE34562CD3703F1502B5C70E99CD5BBA15DE2B6845A3555033D7F6CB2A5
5344uninstall.exeC:\Users\admin\AppData\Local\Temp\nsxF001.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
5024FileZilla_3.69.0_win64-setup.exeC:\Program Files\FileZilla FTP Client\fzstorj.exeexecutable
MD5:BA8BBD2D1C8766B72256CFBB46F32D6E
SHA256:67ABAA9C211CEF3E6B19C0DBDAE4C9E619C7C477139616425936E01D6EE5ECA7
5024FileZilla_3.69.0_win64-setup.exeC:\Users\admin\AppData\Local\Temp\nsvC557.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4212
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4212
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4212
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.137
  • 23.48.23.138
  • 23.48.23.139
  • 23.48.23.140
  • 23.48.23.193
  • 23.48.23.158
  • 23.48.23.194
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.73
  • 40.126.31.1
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.130
  • 20.190.159.128
  • 20.190.159.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info