File name:

Bochs-2.5.pre1.exe

Full analysis: https://app.any.run/tasks/6622186c-0e3d-4f76-842e-acd0bcfb9203
Verdict: Malicious activity
Analysis date: March 02, 2024, 20:57:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

7FB2EECC2C09AB4D3EF66A2B5DA48F21

SHA1:

1E2C148F168F814A9B6A7A88B92FF2782355C087

SHA256:

5C8E6F1C28AA1F4D0813578525508C6B49D3B0B0826AB1B2981E49FEDBBAEAF8

SSDEEP:

98304:lldLn6FbTFRA/kj8/yMqoWBUHkCQld/8osb1LV2OLqLqOCZlMY7Ca7kosSnpsVwz:AUuBkjvyS7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Bochs-2.5.pre1.exe (PID: 3772)
  • SUSPICIOUS

    • Creates a software uninstall entry

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Executable content was dropped or overwritten

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Start notepad (likely ransomware note)

      • Bochs-2.5.pre1.exe (PID: 3772)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1688)
      • sipnotify.exe (PID: 1956)
  • INFO

    • Reads the computer name

      • Bochs-2.5.pre1.exe (PID: 3772)
      • bochs.exe (PID: 1696)
    • Checks supported languages

      • Bochs-2.5.pre1.exe (PID: 3772)
      • bochs.exe (PID: 1696)
    • Creates files or folders in the user directory

      • Bochs-2.5.pre1.exe (PID: 3772)
      • bochs.exe (PID: 1696)
    • Creates files in the program directory

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Reads the machine GUID from the registry

      • bochs.exe (PID: 1696)
    • Manual execution by a user

      • cmd.exe (PID: 2124)
      • IMEKLMG.EXE (PID: 2072)
      • IMEKLMG.EXE (PID: 2060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:02:21 19:46:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30fa
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
90
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bochs-2.5.pre1.exe notepad.exe no specs notepad.exe no specs cmd.exe no specs bochs.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs bochs-2.5.pre1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1688C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1696..\bochs -q -f bochsrc.bxrcC:\Program Files\Bochs-2.5.pre1\bochs.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1073807364
Modules
Images
c:\program files\bochs-2.5.pre1\bochs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
1956C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
2060"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
2072"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
2124C:\Windows\system32\cmd.exe /c ""C:\Program Files\Bochs-2.5.pre1\dlxlinux\run.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1073807364
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2444notepad.exe C:\Program Files\Bochs-2.5.pre1\CHANGES.TXTC:\Windows\System32\notepad.exeBochs-2.5.pre1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3212notepad.exe C:\Program Files\Bochs-2.5.pre1\README.txtC:\Windows\System32\notepad.exeBochs-2.5.pre1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3668"C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\bochs-2.5.pre1.exe
c:\windows\system32\ntdll.dll
3772"C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bochs-2.5.pre1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
8 167
Read events
8 104
Write events
58
Delete events
5

Modification events

(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayName
Value:
Bochs 2.5.pre1 (remove only)
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bochs-2.5.pre1\bochs.ico,0
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayVersion
Value:
2.5.pre1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:Publisher
Value:
The Bochs Project
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:URLInfoAbout
Value:
http://bochs.sourceforge.net
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:Readme
Value:
C:\Program Files\Bochs-2.5.pre1\Readme.txt
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:NoModify
Value:
1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:NoRepair
Value:
1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Bochs-2.5.pre1\
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:UninstallString
Value:
"C:\Program Files\Bochs-2.5.pre1\Uninstall.exe"
Executable files
7
Suspicious files
10
Text files
135
Unknown types
7

Dropped files

PID
Process
Filename
Type
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bochs.exeexecutable
MD5:9A76E49EDC6E4C6D2B32062BDCB63323
SHA256:8E22E6263B02DA5E5926767F3FF92D151CA8648E93A8F849DD37F1B4B3686049
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bochsdbg.exeexecutable
MD5:711246E178655950C50A9890D0A38394
SHA256:99BC58BA2BCBA5F6816309BB0210B0C8B70978802A5D2919FB6674764E99C37D
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bximage.exeexecutable
MD5:2E9AC852882FCA8F16E96DE68138BE01
SHA256:210766C129DA13F6F6A29BDDA5B41D706A1127C5E21248C703F534981A278791
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\VGABIOS-elpin-LICENSE.txttext
MD5:2BDDA477104CC07404D449CD4DCA0472
SHA256:6196D9B1CFA67172DC0707B6E7F01D5ACADC7CC7B1A96D2D59CFFE36EC4868A6
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\sb16ctrl.exeexecutable
MD5:40266BA8B1AF90C51ABA1CAC50082F3A
SHA256:3AC7C6A957F660733705A2DFA5DE9654DEAF388954716C37A4A268CE024A8EA6
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\VGABIOS-lgpl-README.txttext
MD5:B1AB25E6B02AFA4D89534AFD372C61DE
SHA256:7309406F5EEE846601D7C297678EDB79CB36DBC32A070965877709329C37AC95
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\CHANGES.txttext
MD5:FB5C6D9AEEC3D379C64A7EE5248F1807
SHA256:8A9E963915484EC56FBED4FB7E850CB602C2B5F11FF46A8D1150AD4E20A02C7D
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\niclist.exeexecutable
MD5:430DA2E1B1FE601F632E865A3D455F5A
SHA256:697AC35AF5F3AC6D4A3EBA849B10C67792E222A81BAE56A388C1765E3C4F9ECF
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\COPYING.txttext
MD5:3101CD8F3A6E3A7666E0CF09D70E1A7C
SHA256:3C6750AD9E73219F202928CF03B946EA5792044F2B24F768A53BA70A43B24E3F
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\keymaps\sdl-pc-us.maptext
MD5:53BE549922D6634DA1B4DE085399AB8E
SHA256:CF594B6FA3C6A80986AB60A1429BABA050E0E9F9FFBBB2C494384C46C3842EBA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
23.50.98.211:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133538867506710000
CH
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1112
svchost.exe
224.0.0.252:5355
unknown
1956
sipnotify.exe
23.50.98.211:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
CH
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.50.98.211
whitelisted

Threats

No threats detected
No debug info