File name:

R1Soft-HyperV-Explorer-3.6.1.exe

Full analysis: https://app.any.run/tasks/03d27b5a-d77e-4854-aea6-b35fdd4cc4ac
Verdict: Malicious activity
Analysis date: January 24, 2024, 09:48:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

455041ED81F78C7D6A3EA7E6FB6F8852

SHA1:

E6B2E62BFC36AC712DAF98E70F54D8D1B6603AC6

SHA256:

31CCBA4AB94D068C603C62F1C35E46E69E3B6BA6CF2AC0DBA16E6926E6EA2E73

SSDEEP:

49152:mBZPVkBnwsMgMHObvaKdBG+IQrkVuIp5LITwqRgbbEai8fKJ8g39lC9ugxTYGhYR:mBtVkBnzO2aIOuIp5uwWgbZKb39lyYGs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • R1Soft-HyperV-Explorer-3.6.1.exe (PID: 1880)
      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • R1Soft-HyperV-Explorer-3.6.1.exe (PID: 1880)
      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
    • Reads the Internet Settings

      • setup.exe (PID: 2828)
    • The process creates files with name similar to system file names

      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
    • Starts CMD.EXE for commands execution

      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Executing commands from a ".bat" file

      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Executes as Windows Service

      • vds.exe (PID: 1408)
    • Searches for installed software

      • R1Soft Hyper-V VHD Console.exe (PID: 2016)
  • INFO

    • Checks supported languages

      • R1Soft-HyperV-Explorer-3.6.1.exe (PID: 1880)
      • install.exe (PID: 2240)
      • setup.exe (PID: 2828)
      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
      • R1Soft Hyper-V VHD Console.exe (PID: 2016)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Reads the computer name

      • R1Soft-HyperV-Explorer-3.6.1.exe (PID: 1880)
      • setup.exe (PID: 2828)
      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Create files in a temporary directory

      • R1Soft-HyperV-Explorer-3.6.1.exe (PID: 1880)
      • setup.exe (PID: 2828)
      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 2828)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Reads Environment values

      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Creates files in the program directory

      • R1soft-VHD-Explorer--1.0.1.exe (PID: 2672)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
    • Manual execution by a user

      • R1Soft Hyper-V VHD Explorer.exe (PID: 3616)
      • R1Soft Hyper-V VHD Explorer.exe (PID: 3068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:05:03 16:08:47+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30e3
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start r1soft-hyperv-explorer-3.6.1.exe install.exe no specs setup.exe no specs r1soft-vhd-explorer--1.0.1.exe r1soft hyper-v vhd console.exe no specs r1soft hyper-v vhd explorer.exe no specs r1soft hyper-v vhd explorer.exe cmd.exe no specs diskpart.exe no specs vdsldr.exe no specs vds.exe no specs r1soft-hyperv-explorer-3.6.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
984"C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe" C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\r1soft-hyperv-explorer-3.6.1.exe
c:\windows\system32\ntdll.dll
1408C:\Windows\System32\vds.exeC:\Windows\System32\vds.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Virtual Disk Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vds.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
1880"C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe" C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\r1soft-hyperv-explorer-3.6.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2016"C:\Program Files\R1Soft Hyperv Explorer\R1Soft Hyper-V VHD Console.exe" -rC:\Program Files\R1Soft Hyperv Explorer\R1Soft Hyper-V VHD Console.exeR1soft-VHD-Explorer--1.0.1.exe
User:
admin
Company:
R1Soft
Integrity Level:
HIGH
Description:
Hyper-V VHD Console
Exit code:
0
Version:
1.0.3741.5669
Modules
Images
c:\program files\r1soft hyperv explorer\r1soft hyper-v vhd console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2240C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exeR1Soft-HyperV-Explorer-3.6.1.exe
User:
admin
Company:
R1Soft
Integrity Level:
HIGH
Description:
R1Soft Install Wrapper
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\3.6.1\r1soft\hyperv\install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2672"C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exe" /D=C:\Program Files\R1Soft Hyperv Explorer C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exe
setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\3.6.1\r1soft\hyperv\r1soft-vhd-explorer--1.0.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2820"cmd.exe" /C "C:\ProgramData\zth5abzv.bat"C:\Windows\System32\cmd.exeR1Soft Hyper-V VHD Explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2828.\setup.exe -setupxml conf\hyperv-explorer.xmlC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\setup.exeinstall.exe
User:
admin
Integrity Level:
HIGH
Description:
setup
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3.6.1\r1soft\hyperv\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3020C:\Windows\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
3048diskpart /s "C:\ProgramData\vraelsnq.txt"C:\Windows\System32\diskpart.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
DiskPart
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\diskpart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
2 994
Read events
2 986
Write events
8
Delete events
0

Modification events

(PID) Process:(2828) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2828) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2828) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2828) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
10
Suspicious files
2
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\hyperv-explorer.xmltext
MD5:BC7B9E93645443905A8789A081C9CFE4
SHA256:D8905DB56C92F714F553329751EF7754DDB82C5791CFB66404BC5A2D8E1AB058
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\Interop.ActiveDs.dllexecutable
MD5:22C3B6BB108FE58040D73781F7F025A4
SHA256:DCA5F1D45F825531EE30E5F0CCA98F4B6C878FBA8DF3D5ACBEF04BB8BE8CB3AC
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exeexecutable
MD5:8B83436DE6294AFAE14DF13C63EE14DB
SHA256:C48E0028886B09C3C47C66D437BCDD6DEA451E672B974EFDA012E6E1A34B931E
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\hyperv-libraries.htmlhtml
MD5:E526F8EB59AC5AD06147A675AFD0DA74
SHA256:CB107C96176E7E455DF6CE8D13C465CAD360BE51E0A8252D1335EF7E1B8567C2
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exeexecutable
MD5:C631DCB096540009947E36D4EA9CFE92
SHA256:2EA4DA2C7D81DF3B194AD4E19BAE4B90338E4200E3E44C86EE37C0D201131FDD
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\license.txttext
MD5:7AB0CB56946A890C26C0183376AD2C6E
SHA256:0B4B466D61511DBF2D5A130166D69B1EA0C73F78320AB6A55DFA903717E6D8B8
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\language.xmltext
MD5:8815107D81D2C2079B4C6AB4CAB31B48
SHA256:C43CDC21376F7C38A136C16B51CE2258A711E27C6EFE8835F671752EC8AE7434
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\incompatible.htmlhtml
MD5:650A5B353A8B6703E4775F63CA2E4A2B
SHA256:46FCDDE70817D3A09362585624A21F0C8777A7C8681677986CB5A9DB92BCD1ED
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\setup.exeexecutable
MD5:D15298129A32C341B05D07A42E06F5B5
SHA256:6C281FF1EE539FAD5A8FB3A563EC54D7E0645788D1962E147845B8A7D887B9B3
1880R1Soft-HyperV-Explorer-3.6.1.exeC:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\installer_header_r3_c1.jpgimage
MD5:3BBB1B2B66942E136D59D1DB5B447982
SHA256:D86818A52E67FE6E7DEA4620780D8FF996ECC68CC3CEB5BA1342512873B1EAC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info