| File name: | Patch-Proteus-3.15-SP1-34318.0.exe |
| Full analysis: | https://app.any.run/tasks/67d34e7f-c8ec-4049-9076-714aa16c6934 |
| Verdict: | Malicious activity |
| Analysis date: | October 24, 2023, 05:58:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 95037214B3E4A95138199C79F678BFD9 |
| SHA1: | A3F7BFC54ECDB067B0D5DBCFEFD1EDA7486E787B |
| SHA256: | 28D09D5DD7121B92B42FE3457E304B8B5CB8BE1D57F527C47F0C65AF8E23C221 |
| SSDEEP: | 24576:F86RuyvBXm2ygmhJ0Qbwtzq1aQNQ4nhORX3ftION1uZDp+RZu/jc91BoQ9uZUR+o:hE0BXcRJ02DaQ64hOZmQ1DX1pV9u1O |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 15:27:46+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | My Company |
| FileDescription: | Patch for Proteus |
| FileVersion: | 1.0.0.0 |
| LegalCopyright: | Deoptim (Dmytro) |
| ProductName: | Proteus |
| ProductVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1440 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\OnStartupCode.bat"" | C:\Windows\System32\cmd.exe | — | Patch-Proteus-3.15-SP1-34318.0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1764 | "C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe" | C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe | — | explorer.exe | |||||||||||
User: admin Company: My Company Integrity Level: MEDIUM Description: Patch for Proteus Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2356 | "C:\Users\admin\AppData\Local\Temp\is-MF8ED.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp" /SL5="$B01D0,1210369,121344,C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe" /SPAWNWND=$140220 /NOTIFYWND=$5035E | C:\Users\admin\AppData\Local\Temp\is-MF8ED.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp | — | Patch-Proteus-3.15-SP1-34318.0.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2696 | "C:\Users\admin\AppData\Local\Temp\is-976CR.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp" /SL5="$5035E,1210369,121344,C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe" | C:\Users\admin\AppData\Local\Temp\is-976CR.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp | — | Patch-Proteus-3.15-SP1-34318.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2960 | "C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe" /SPAWNWND=$140220 /NOTIFYWND=$5035E | C:\Users\admin\AppData\Local\Temp\Patch-Proteus-3.15-SP1-34318.0.exe | Patch-Proteus-3.15-SP1-34318.0.tmp | ||||||||||||
User: admin Company: My Company Integrity Level: HIGH Description: Patch for Proteus Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\OnStartupCode.bat | — | |
MD5:— | SHA256:— | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\OnBeforeCode.bat | — | |
MD5:— | SHA256:— | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\OnFinishCode.bat | — | |
MD5:— | SHA256:— | |||
| 1764 | Patch-Proteus-3.15-SP1-34318.0.exe | C:\Users\admin\AppData\Local\Temp\is-976CR.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\lang\German.ini | text | |
MD5:B35BC657CCBFF642E13DDE3A7664C758 | SHA256:95C7895FE10FA03D4A0A47D9F37BE6020E72582819B22AAE60B07D524E33DBB7 | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\innocallback.dll | executable | |
MD5:1C55AE5EF9980E3B1028447DA6105C75 | SHA256:6AFA2D104BE6EFE3D9A2AB96DBB75DB31565DAD64DD0B791E402ECC25529809F | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\isproc.dll | executable | |
MD5:4BAFB0739C5FCD96BE991F2A3CC9AC2F | SHA256:7F74F1C445BF5E9456AAE6FAE695A8CA60E1D0EB5A2F44AC2CF0239A71F1A8A1 | |||
| 2960 | Patch-Proteus-3.15-SP1-34318.0.exe | C:\Users\admin\AppData\Local\Temp\is-MF8ED.tmp\Patch-Proteus-3.15-SP1-34318.0.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\wintb.dll | executable | |
MD5:9436DF49E08C83BAD8DDC906478C2041 | SHA256:1910537AA95684142250CA0C7426A0B5F082E39F6FBDBDBA649AECB179541435 | |||
| 2356 | Patch-Proteus-3.15-SP1-34318.0.tmp | C:\Users\admin\AppData\Local\Temp\is-FQBJB.tmp\lang\Italian.ini | text | |
MD5:92CCEED7990382F4F34A7A15E66B96E3 | SHA256:60C0823A9D451868DD60A472849DFE9C2A557B4CC62FE40BACF4074C89514970 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |