File name:

VbsToExePortable_3.2_Dev_Test_1.paf.exe

Full analysis: https://app.any.run/tasks/29beb81b-3f06-443e-8f60-dcd4ef2ae394
Verdict: Malicious activity
Analysis date: December 02, 2023, 12:26:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

ED9776CDE2D5CBEFE7A9694FB6764CDD

SHA1:

D0D06013E017291F5EA2DBBA652DD133B2CA55F5

SHA256:

470887F40264DCECD818DED225970338D2C84CBC3B7D0A3169BDA7582D83633B

SSDEEP:

98304:1aXNOJY5KMlZA0Tkffj8kmI3OB3l6hOlWApuOlEuXve4OM9kIOhIxOsshp1nqgML:vIo4FsLLMUY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
  • INFO

    • Reads the computer name

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
    • Checks supported languages

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
    • Create files in a temporary directory

      • VbsToExePortable_3.2_Dev_Test_1.paf.exe (PID: 564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 23:26:01+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 428544
UninitializedDataSize: 16384
EntryPoint: 0x34a5
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.1.99.1
ProductVersionNumber: 3.1.99.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: VbsToExe Portable
FileVersion: 3.1.99.1
InternalName: VbsToExe Portable
LegalCopyright: 2007-2019 PortableApps.com, PortableApps.com Installer 3.5.14.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: VbsToExePortable_3.2_Dev_Test_1.paf.exe
PortableAppscomAppID: VbsToExePortable
PortableAppscomFormatVersion: 3.5.14
PortableAppscomInstallerVersion: 3.5.14.0
ProductName: VbsToExe Portable
ProductVersion: 3.1.99.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start vbstoexeportable_3.2_dev_test_1.paf.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564"C:\Users\admin\AppData\Local\Temp\VbsToExePortable_3.2_Dev_Test_1.paf.exe" C:\Users\admin\AppData\Local\Temp\VbsToExePortable_3.2_Dev_Test_1.paf.exeexplorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
VbsToExe Portable
Exit code:
0
Version:
3.1.99.1
Modules
Images
c:\users\admin\appdata\local\temp\vbstoexeportable_3.2_dev_test_1.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 181
Read events
1 171
Write events
10
Delete events
0

Modification events

(PID) Process:(564) VbsToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(564) VbsToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(564) VbsToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
Executable files
3
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
564VbsToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nsa63E0.tmp\modern-wizard.bmpimage
MD5:4DF53EFCAA2C52F39618B2AAD77BB552
SHA256:EE13539F3D66CC0592942EA1A4C35D8FD9AF67B1A7F272D0D791931E6E9CE4EB
564VbsToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nsa63E0.tmp\LangDLL.dllexecutable
MD5:AB1DB56369412FE8476FEFFFD11E4CC0
SHA256:6F14C8F01F50A30743DAC68C5AC813451463DFB427EB4E35FCDFE2410E1A913B
564VbsToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nsa63E0.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
564VbsToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nsa63E0.tmp\modern-header.bmpimage
MD5:B38AB57798D466422DFD9146A5DE37A9
SHA256:F11C32AC449E53052B607374B92E5C9B52D6145C9092C7F029023ADC61FD4AC7
564VbsToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nsa63E0.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info