| File name: | leru.exe |
| Full analysis: | https://app.any.run/tasks/11a3a924-f126-4853-ba52-ddeefc356a26 |
| Verdict: | Malicious activity |
| Threats: | RisePro, an information-stealing malware, targets a wide range of sensitive data, including credit cards, passwords, and cryptocurrency wallets. By compromising infected devices, RisePro can steal valuable information and potentially cause significant financial and personal losses for victims. |
| Analysis date: | January 13, 2024, 14:01:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | risepro |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7EDC7839432AA6801008C4E71ADF7D2E |
| SHA1: | 8DC506BECA3EF89B9220F621157319FB0E5AD216 |
| SHA256: | 37EDD92328E327016C691F2E0A5F83FC4BA03E0F6BC35BF7217CFE816590F2F3 |
| SSDEEP: | 49152:+Ojq279bMRZlwUWq3INtmtxLaU8YZBdVcQasgLXsdLoMRVsf4gmGcIOqyE:+Ojq279bMRZlwUWqYNtmje6VcQhgL8Ro |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:01:06 15:44:07+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.34 |
| CodeSize: | 1230848 |
| InitializedDataSize: | 283648 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xfb48b |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.0.10.8379 |
| ProductVersionNumber: | 7.0.10.27307 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Pre-release |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Oracle |
| FileDescription: | VirtualBox ExtPack Helper |
| FileVersion: | 7.0.10.8379 |
| InternalName: | VBoxExtPackHelperApp.exe |
| LegalCopyright: | Copyright (C) 2009-2023 Oracle |
| OriginalFileName: | VBoxExtPackHelperApp |
| ProductName: | Oracle VM VirtualBox |
| ProductVersion: | 7.0.10.27307 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\AppData\Local\Temp\leru.exe" | C:\Users\admin\AppData\Local\Temp\leru.exe | explorer.exe | ||||||||||||
User: admin Company: Oracle Integrity Level: MEDIUM Description: VirtualBox ExtPack Helper Exit code: 0 Version: 7.0.10.8379 Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
