| File name: | Bochs-2.5.pre1.exe |
| Full analysis: | https://app.any.run/tasks/6622186c-0e3d-4f76-842e-acd0bcfb9203 |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2024, 20:57:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 7FB2EECC2C09AB4D3EF66A2B5DA48F21 |
| SHA1: | 1E2C148F168F814A9B6A7A88B92FF2782355C087 |
| SHA256: | 5C8E6F1C28AA1F4D0813578525508C6B49D3B0B0826AB1B2981E49FEDBBAEAF8 |
| SSDEEP: | 98304:lldLn6FbTFRA/kj8/yMqoWBUHkCQld/8osb1LV2OLqLqOCZlMY7Ca7kosSnpsVwz:AUuBkjvyS7 |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:02:21 19:46:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30fa |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1688 | C:\Windows\System32\ctfmon.exe | C:\Windows\System32\ctfmon.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CTF Loader Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 1696 | ..\bochs -q -f bochsrc.bxrc | C:\Program Files\Bochs-2.5.pre1\bochs.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1073807364 Modules
| |||||||||||||||
| 1956 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | taskeng.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) | |||||||||||||||
| 2060 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 2072 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 2124 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Bochs-2.5.pre1\dlxlinux\run.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1073807364 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2444 | notepad.exe C:\Program Files\Bochs-2.5.pre1\CHANGES.TXT | C:\Windows\System32\notepad.exe | — | Bochs-2.5.pre1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3212 | notepad.exe C:\Program Files\Bochs-2.5.pre1\README.txt | C:\Windows\System32\notepad.exe | — | Bochs-2.5.pre1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" | C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" | C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayName |
Value: Bochs 2.5.pre1 (remove only) | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Bochs-2.5.pre1\bochs.ico,0 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayVersion |
Value: 2.5.pre1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | Publisher |
Value: The Bochs Project | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | URLInfoAbout |
Value: http://bochs.sourceforge.net | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | Readme |
Value: C:\Program Files\Bochs-2.5.pre1\Readme.txt | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Bochs-2.5.pre1\ | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\Bochs-2.5.pre1\Uninstall.exe" | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bochsdbg.exe | executable | |
MD5:711246E178655950C50A9890D0A38394 | SHA256:99BC58BA2BCBA5F6816309BB0210B0C8B70978802A5D2919FB6674764E99C37D | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\CHANGES.txt | text | |
MD5:FB5C6D9AEEC3D379C64A7EE5248F1807 | SHA256:8A9E963915484EC56FBED4FB7E850CB602C2B5F11FF46A8D1150AD4E20A02C7D | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\keymaps\sdl-pc-de.map | text | |
MD5:136EC8AADA36A12C00E2F92727987685 | SHA256:33A4BC929A048D81A2CDB7242717689A058B29B39E2ED7B7305E39D8FE340F86 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\README.txt | text | |
MD5:70CE54A08B1A883546ABE665C6211D65 | SHA256:05FC0770AEED080D4B1B262357BE65C2633D8F874433823B249873DFA12936D3 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bochs.ico | image | |
MD5:FC95A21F41CD84907D200C837F18E6DA | SHA256:3C64B4132FE2BCB7C7125E185C9A3B63132BE99494BF3278ADF6F864ADDB2BB3 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bxcommit.exe | executable | |
MD5:3BD700D04A99DAB2B5A65D3622C3247A | SHA256:C9C23380EEB4A3888C7B3631F821020A8587C4E8E692CBFA1E8C61CBA6C673F7 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\TODO.txt | text | |
MD5:3815DA3A639AF6904C4EEDC46961154E | SHA256:235345BE9183B3A8465FD331B296AA607616EE313935555CBEDD1DB4DB4D2D90 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\niclist.exe | executable | |
MD5:430DA2E1B1FE601F632E865A3D455F5A | SHA256:697AC35AF5F3AC6D4A3EBA849B10C67792E222A81BAE56A388C1765E3C4F9ECF | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\sb16ctrl.exe | executable | |
MD5:40266BA8B1AF90C51ABA1CAC50082F3A | SHA256:3AC7C6A957F660733705A2DFA5DE9654DEAF388954716C37A4A268CE024A8EA6 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\COPYING.txt | text | |
MD5:3101CD8F3A6E3A7666E0CF09D70E1A7C | SHA256:3C6750AD9E73219F202928CF03B946EA5792044F2B24F768A53BA70A43B24E3F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.50.98.211:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133538867506710000 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1112 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | sipnotify.exe | 23.50.98.211:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | CH | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |