| File name: | Bochs-2.5.pre1.exe |
| Full analysis: | https://app.any.run/tasks/6622186c-0e3d-4f76-842e-acd0bcfb9203 |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2024, 20:57:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 7FB2EECC2C09AB4D3EF66A2B5DA48F21 |
| SHA1: | 1E2C148F168F814A9B6A7A88B92FF2782355C087 |
| SHA256: | 5C8E6F1C28AA1F4D0813578525508C6B49D3B0B0826AB1B2981E49FEDBBAEAF8 |
| SSDEEP: | 98304:lldLn6FbTFRA/kj8/yMqoWBUHkCQld/8osb1LV2OLqLqOCZlMY7Ca7kosSnpsVwz:AUuBkjvyS7 |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:02:21 19:46:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30fa |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1688 | C:\Windows\System32\ctfmon.exe | C:\Windows\System32\ctfmon.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CTF Loader Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 1696 | ..\bochs -q -f bochsrc.bxrc | C:\Program Files\Bochs-2.5.pre1\bochs.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1073807364 Modules
| |||||||||||||||
| 1956 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | taskeng.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) | |||||||||||||||
| 2060 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 2072 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 2124 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Bochs-2.5.pre1\dlxlinux\run.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1073807364 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2444 | notepad.exe C:\Program Files\Bochs-2.5.pre1\CHANGES.TXT | C:\Windows\System32\notepad.exe | — | Bochs-2.5.pre1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3212 | notepad.exe C:\Program Files\Bochs-2.5.pre1\README.txt | C:\Windows\System32\notepad.exe | — | Bochs-2.5.pre1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" | C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" | C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayName |
Value: Bochs 2.5.pre1 (remove only) | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Bochs-2.5.pre1\bochs.ico,0 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | DisplayVersion |
Value: 2.5.pre1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | Publisher |
Value: The Bochs Project | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | URLInfoAbout |
Value: http://bochs.sourceforge.net | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | Readme |
Value: C:\Program Files\Bochs-2.5.pre1\Readme.txt | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Bochs-2.5.pre1\ | |||
| (PID) Process: | (3772) Bochs-2.5.pre1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1 |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\Bochs-2.5.pre1\Uninstall.exe" | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bochs.exe | executable | |
MD5:9A76E49EDC6E4C6D2B32062BDCB63323 | SHA256:8E22E6263B02DA5E5926767F3FF92D151CA8648E93A8F849DD37F1B4B3686049 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bochsdbg.exe | executable | |
MD5:711246E178655950C50A9890D0A38394 | SHA256:99BC58BA2BCBA5F6816309BB0210B0C8B70978802A5D2919FB6674764E99C37D | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\bximage.exe | executable | |
MD5:2E9AC852882FCA8F16E96DE68138BE01 | SHA256:210766C129DA13F6F6A29BDDA5B41D706A1127C5E21248C703F534981A278791 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\VGABIOS-elpin-LICENSE.txt | text | |
MD5:2BDDA477104CC07404D449CD4DCA0472 | SHA256:6196D9B1CFA67172DC0707B6E7F01D5ACADC7CC7B1A96D2D59CFFE36EC4868A6 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\sb16ctrl.exe | executable | |
MD5:40266BA8B1AF90C51ABA1CAC50082F3A | SHA256:3AC7C6A957F660733705A2DFA5DE9654DEAF388954716C37A4A268CE024A8EA6 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\VGABIOS-lgpl-README.txt | text | |
MD5:B1AB25E6B02AFA4D89534AFD372C61DE | SHA256:7309406F5EEE846601D7C297678EDB79CB36DBC32A070965877709329C37AC95 | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\CHANGES.txt | text | |
MD5:FB5C6D9AEEC3D379C64A7EE5248F1807 | SHA256:8A9E963915484EC56FBED4FB7E850CB602C2B5F11FF46A8D1150AD4E20A02C7D | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\niclist.exe | executable | |
MD5:430DA2E1B1FE601F632E865A3D455F5A | SHA256:697AC35AF5F3AC6D4A3EBA849B10C67792E222A81BAE56A388C1765E3C4F9ECF | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\COPYING.txt | text | |
MD5:3101CD8F3A6E3A7666E0CF09D70E1A7C | SHA256:3C6750AD9E73219F202928CF03B946EA5792044F2B24F768A53BA70A43B24E3F | |||
| 3772 | Bochs-2.5.pre1.exe | C:\Program Files\Bochs-2.5.pre1\keymaps\sdl-pc-us.map | text | |
MD5:53BE549922D6634DA1B4DE085399AB8E | SHA256:CF594B6FA3C6A80986AB60A1429BABA050E0E9F9FFBBB2C494384C46C3842EBA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.50.98.211:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133538867506710000 | CH | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1112 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | sipnotify.exe | 23.50.98.211:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | CH | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |