| File name: | R1Soft-HyperV-Explorer-3.6.1.exe |
| Full analysis: | https://app.any.run/tasks/03d27b5a-d77e-4854-aea6-b35fdd4cc4ac |
| Verdict: | Malicious activity |
| Analysis date: | January 24, 2024, 09:48:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 455041ED81F78C7D6A3EA7E6FB6F8852 |
| SHA1: | E6B2E62BFC36AC712DAF98E70F54D8D1B6603AC6 |
| SHA256: | 31CCBA4AB94D068C603C62F1C35E46E69E3B6BA6CF2AC0DBA16E6926E6EA2E73 |
| SSDEEP: | 49152:mBZPVkBnwsMgMHObvaKdBG+IQrkVuIp5LITwqRgbbEai8fKJ8g39lC9ugxTYGhYR:mBtVkBnzO2aIOuIp5uwWgbZKb39lyYGs |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2008:05:03 16:08:47+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30e3 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 984 | "C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe" | C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1408 | C:\Windows\System32\vds.exe | C:\Windows\System32\vds.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Virtual Disk Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1880 | "C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe" | C:\Users\admin\AppData\Local\Temp\R1Soft-HyperV-Explorer-3.6.1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2016 | "C:\Program Files\R1Soft Hyperv Explorer\R1Soft Hyper-V VHD Console.exe" -r | C:\Program Files\R1Soft Hyperv Explorer\R1Soft Hyper-V VHD Console.exe | — | R1soft-VHD-Explorer--1.0.1.exe | |||||||||||
User: admin Company: R1Soft Integrity Level: HIGH Description: Hyper-V VHD Console Exit code: 0 Version: 1.0.3741.5669 Modules
| |||||||||||||||
| 2240 | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exe | — | R1Soft-HyperV-Explorer-3.6.1.exe | |||||||||||
User: admin Company: R1Soft Integrity Level: HIGH Description: R1Soft Install Wrapper Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2672 | "C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exe" /D=C:\Program Files\R1Soft Hyperv Explorer | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exe | setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2820 | "cmd.exe" /C "C:\ProgramData\zth5abzv.bat" | C:\Windows\System32\cmd.exe | — | R1Soft Hyper-V VHD Explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2828 | .\setup.exe -setupxml conf\hyperv-explorer.xml | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\setup.exe | — | install.exe | |||||||||||
User: admin Integrity Level: HIGH Description: setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3020 | C:\Windows\System32\vdsldr.exe -Embedding | C:\Windows\System32\vdsldr.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Virtual Disk Service Loader Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3048 | diskpart /s "C:\ProgramData\vraelsnq.txt" | C:\Windows\System32\diskpart.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DiskPart Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2828) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2828) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2828) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2828) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\hyperv-explorer.xml | text | |
MD5:BC7B9E93645443905A8789A081C9CFE4 | SHA256:D8905DB56C92F714F553329751EF7754DDB82C5791CFB66404BC5A2D8E1AB058 | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\Interop.ActiveDs.dll | executable | |
MD5:22C3B6BB108FE58040D73781F7F025A4 | SHA256:DCA5F1D45F825531EE30E5F0CCA98F4B6C878FBA8DF3D5ACBEF04BB8BE8CB3AC | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\R1soft-VHD-Explorer--1.0.1.exe | executable | |
MD5:8B83436DE6294AFAE14DF13C63EE14DB | SHA256:C48E0028886B09C3C47C66D437BCDD6DEA451E672B974EFDA012E6E1A34B931E | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\hyperv-libraries.html | html | |
MD5:E526F8EB59AC5AD06147A675AFD0DA74 | SHA256:CB107C96176E7E455DF6CE8D13C465CAD360BE51E0A8252D1335EF7E1B8567C2 | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\install.exe | executable | |
MD5:C631DCB096540009947E36D4EA9CFE92 | SHA256:2EA4DA2C7D81DF3B194AD4E19BAE4B90338E4200E3E44C86EE37C0D201131FDD | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\license.txt | text | |
MD5:7AB0CB56946A890C26C0183376AD2C6E | SHA256:0B4B466D61511DBF2D5A130166D69B1EA0C73F78320AB6A55DFA903717E6D8B8 | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\conf\language.xml | text | |
MD5:8815107D81D2C2079B4C6AB4CAB31B48 | SHA256:C43CDC21376F7C38A136C16B51CE2258A711E27C6EFE8835F671752EC8AE7434 | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\incompatible.html | html | |
MD5:650A5B353A8B6703E4775F63CA2E4A2B | SHA256:46FCDDE70817D3A09362585624A21F0C8777A7C8681677986CB5A9DB92BCD1ED | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\setup.exe | executable | |
MD5:D15298129A32C341B05D07A42E06F5B5 | SHA256:6C281FF1EE539FAD5A8FB3A563EC54D7E0645788D1962E147845B8A7D887B9B3 | |||
| 1880 | R1Soft-HyperV-Explorer-3.6.1.exe | C:\Users\admin\AppData\Local\Temp\3.6.1\r1soft\hyperv\pages\english\installer_header_r3_c1.jpg | image | |
MD5:3BBB1B2B66942E136D59D1DB5B447982 | SHA256:D86818A52E67FE6E7DEA4620780D8FF996ECC68CC3CEB5BA1342512873B1EAC9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |