File name:

PortableApps.com_Platform_Setup_29.1.1.paf.exe

Full analysis: https://app.any.run/tasks/4aeaf2a7-5c0b-445f-af1e-3ba88ca6b793
Verdict: Malicious activity
Analysis date: March 06, 2024, 22:42:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

AF0156724850BEB194FDC946188BCA9F

SHA1:

1F52F910AE3C5FC591F4A7C054179762FB89DE78

SHA256:

2B85994335CF367F15744C63E56379F8B904AC418F084827A40EF0E9247FC5A8

SSDEEP:

98304:oaX47hP0/Fo/AP2jjQDocnpwvGAbBjgz7458bpTWNshTMgTFVcm55rmgJaqkhvjU:rm+5CgViEf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
    • Create files in the Startup directory

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
    • The process creates files with name similar to system file names

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
    • Write to the desktop.ini file (may be used to cloak folders)

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
    • Executable content was dropped or overwritten

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
    • Drops 7-zip archiver for unpacking

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
    • Checks for Java to be installed

      • PortableAppsPlatform.exe (PID: 3708)
    • Reads the Internet Settings

      • PortableAppsPlatform.exe (PID: 3708)
      • PortableAppsUpdater.exe (PID: 1776)
    • Reads security settings of Internet Explorer

      • PortableAppsPlatform.exe (PID: 3708)
      • PortableAppsUpdater.exe (PID: 1776)
    • Reads settings of System Certificates

      • PortableAppsUpdater.exe (PID: 1776)
    • Checks Windows Trust Settings

      • PortableAppsUpdater.exe (PID: 1776)
    • Starts application with an unusual extension

      • PortableAppsUpdater.exe (PID: 1776)
  • INFO

    • Checks supported languages

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsPlatform.exe (PID: 3708)
      • PortableAppsUpdater.exe (PID: 1776)
      • 7za.exe (PID: 2856)
      • ns532C.tmp (PID: 1696)
    • Reads the computer name

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsPlatform.exe (PID: 3708)
      • PortableAppsUpdater.exe (PID: 1776)
      • 7za.exe (PID: 2856)
    • Create files in a temporary directory

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
      • 7za.exe (PID: 2856)
    • Reads the machine GUID from the registry

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
      • PortableAppsPlatform.exe (PID: 3708)
    • Creates files or folders in the user directory

      • PortableApps.com_Platform_Setup_29.1.1.paf.exe (PID: 3864)
      • PortableAppsUpdater.exe (PID: 1776)
    • Checks proxy server information

      • PortableAppsUpdater.exe (PID: 1776)
    • Reads the software policy settings

      • PortableAppsUpdater.exe (PID: 1776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:10:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3645
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 29.1.1.0
ProductVersionNumber: 29.1.1.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: PortableApps.com Platform
FileVersion: 29.1.1.0
InternalName: PortableApps.com Platform
LegalCopyright: PortableApps.com
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: PortableApps.com_Platform_Setup_29.1.1.paf.exe
PortableAppscomAppID: PortableApps.com
PortableAppscomFormatVersion: 3.8.0.0
PortableAppscomInstallerVersion: 3.8.3.0
ProductName: PortableApps.com Platform
ProductVersion: 29.1.1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start portableapps.com_platform_setup_29.1.1.paf.exe portableappsplatform.exe no specs portableappsupdater.exe ns532c.tmp no specs 7za.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1696"C:\Users\admin\AppData\Local\Temp\nsw35FC.tmp\ns532C.tmp" "C:\PortableApps\PortableApps.com\App\7-Zip\7za.exe" x "C:\Users\admin\AppData\Local\Temp\nsw35FC.tmp\update.7z" -o"C:\Users\admin\AppData\Local\Temp\nsw35FC.tmp" -aoaC:\Users\admin\AppData\Local\Temp\nsw35FC.tmp\ns532C.tmpPortableAppsUpdater.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsw35fc.tmp\ns532c.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1776"C:\PortableApps\PortableApps.com\PortableAppsUpdater.exe" /MODE=ADD /SHOWFREEWARE=all /KEYBOARDFRIENDLY=false /ADVANCED=false /SHOWINSTALLEDAPPS=false /HIDEPORTABLE=true /BETA=false /HIDE64BIT=true /INSTALL32BITDUALMODE=always /CONNECTION=AutomaticC:\PortableApps\PortableApps.com\PortableAppsUpdater.exe
PortableAppsPlatform.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Updater
Exit code:
0
Version:
29.1.1.0
Modules
Images
c:\portableapps\portableapps.com\portableappsupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2856"C:\PortableApps\PortableApps.com\App\7-Zip\7za.exe" x "C:\Users\admin\AppData\Local\Temp\nsw35FC.tmp\update.7z" -o"C:\Users\admin\AppData\Local\Temp\nsw35FC.tmp" -aoaC:\PortableApps\PortableApps.com\App\7-Zip\7za.exens532C.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Console
Exit code:
0
Version:
23.01
Modules
Images
c:\portableapps\portableapps.com\app\7-zip\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3708C:\PortableApps\PortableApps.com\PortableAppsPlatform.exeC:\PortableApps\PortableApps.com\PortableAppsPlatform.exePortableApps.com_Platform_Setup_29.1.1.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Exit code:
0
Version:
29.1.1.0
Modules
Images
c:\portableapps\portableapps.com\portableappsplatform.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3864"C:\Users\admin\AppData\Local\Temp\PortableApps.com_Platform_Setup_29.1.1.paf.exe" C:\Users\admin\AppData\Local\Temp\PortableApps.com_Platform_Setup_29.1.1.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Exit code:
0
Version:
29.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\portableapps.com_platform_setup_29.1.1.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
10 805
Read events
10 757
Write events
42
Delete events
6

Modification events

(PID) Process:(3708) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3708) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3708) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3708) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(1776) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
37
Suspicious files
10
Text files
953
Unknown types
2

Dropped files

PID
Process
Filename
Type
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallTypeNew.icoimage
MD5:5BF124D896DFB5B6430EA011EE0B1501
SHA256:8A25F3B78E5EF376A25B7A4831B1179D734AF99F08FCB2C459CA4F1B9FE9A6F5
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\System.dllexecutable
MD5:4ADD245D4BA34B04F213409BFE504C07
SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallLocationCustom.icoimage
MD5:F83DC55D453732C387FB866CCE6A6DEC
SHA256:CD57E5E8CFC9D5570DCBB944F9FD8676F3132C8F9497659EB148A0EC77B92C8C
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallTypeLocal.icoimage
MD5:A8676F0BDFE1EE2547B87CFC6CED01DB
SHA256:1011AA4843604F7B5D6EB59A8E41B27F83007DFEC67AEF6F63FA6DFD54399E74
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallTypeCloud.icoimage
MD5:FD20C8F4A900EF2763FD620B4EF7F3DA
SHA256:09DA891CC747228824450065D905D8DAA59AE51AA9370FDB068A83E25FEC2CD9
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallCloudDropbox.icoimage
MD5:C057C8276F42ED3EA043FAFFEFD2184E
SHA256:F51EA28292105EE4209BB1CD80536D57D23B18259E313A3A6424E6F6F62800CA
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallTypeLocalAllUsers.icoimage
MD5:CE880C8089E8DB48164E5A25D7DA7BB7
SHA256:76838E210EA7A131C97D329F603FBB80C4419C4C7748F682FF6B4BAB23EED715
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallCloudBox.icoimage
MD5:8230E343310B8AD58A3642466FFC0CA0
SHA256:4FE8A7B7618E0DDE72117437A6583BB14B5A0E0B9215DBEEABDE6CC404977821
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallCloudGoogleDrive.icoimage
MD5:8F8E5010A8B7DB88F0DDF093B726053F
SHA256:43CCCB5BF1E5BAF646B419F33E461D2DC265EA758C4C8FF70F1AC5AA17B0DDD4
3864PortableApps.com_Platform_Setup_29.1.1.paf.exeC:\Users\admin\AppData\Local\Temp\nss79E.tmp\InstallCloudOneDrive.icoimage
MD5:314ED4E313894FAD9EF7AF45D71F2D11
SHA256:1FEE7F9360E24F5C3DDD4E05AAF5368749FC60B3AB24E1AF5B86B2A8FB170612
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
13
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1776
PortableAppsUpdater.exe
GET
304
87.248.204.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?bfc5340f4a80f724
unknown
unknown
1776
PortableAppsUpdater.exe
GET
200
87.248.204.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0ccd5e715b3eca47
unknown
compressed
67.5 Kb
unknown
1776
PortableAppsUpdater.exe
GET
200
72.246.169.163:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1080
svchost.exe
GET
304
87.248.204.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1b8fee253118cbef
unknown
unknown
1776
PortableAppsUpdater.exe
GET
200
184.25.51.75:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgNVErg9QJxCrE2X5gl2wUB11g%3D%3D
unknown
binary
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1776
PortableAppsUpdater.exe
3.69.213.60:443
portableapps.com
AMAZON-02
DE
unknown
1776
PortableAppsUpdater.exe
87.248.204.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
1776
PortableAppsUpdater.exe
72.246.169.163:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
1776
PortableAppsUpdater.exe
184.25.51.75:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
1080
svchost.exe
87.248.204.0:80
ctldl.windowsupdate.com
LLNW
US
unknown

DNS requests

Domain
IP
Reputation
portableapps.com
  • 3.69.213.60
unknown
ctldl.windowsupdate.com
  • 87.248.204.0
whitelisted
x1.c.lencr.org
  • 72.246.169.163
whitelisted
r3.o.lencr.org
  • 184.25.51.75
shared

Threats

No threats detected
No debug info