File name:

Bochs-2.5.pre1.exe

Full analysis: https://app.any.run/tasks/6622186c-0e3d-4f76-842e-acd0bcfb9203
Verdict: Malicious activity
Analysis date: March 02, 2024, 20:57:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

7FB2EECC2C09AB4D3EF66A2B5DA48F21

SHA1:

1E2C148F168F814A9B6A7A88B92FF2782355C087

SHA256:

5C8E6F1C28AA1F4D0813578525508C6B49D3B0B0826AB1B2981E49FEDBBAEAF8

SSDEEP:

98304:lldLn6FbTFRA/kj8/yMqoWBUHkCQld/8osb1LV2OLqLqOCZlMY7Ca7kosSnpsVwz:AUuBkjvyS7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Bochs-2.5.pre1.exe (PID: 3772)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Creates a software uninstall entry

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Executable content was dropped or overwritten

      • Bochs-2.5.pre1.exe (PID: 3772)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1688)
      • sipnotify.exe (PID: 1956)
  • INFO

    • Checks supported languages

      • Bochs-2.5.pre1.exe (PID: 3772)
      • bochs.exe (PID: 1696)
    • Reads the computer name

      • Bochs-2.5.pre1.exe (PID: 3772)
      • bochs.exe (PID: 1696)
    • Creates files or folders in the user directory

      • bochs.exe (PID: 1696)
      • Bochs-2.5.pre1.exe (PID: 3772)
    • Reads the machine GUID from the registry

      • bochs.exe (PID: 1696)
    • Creates files in the program directory

      • Bochs-2.5.pre1.exe (PID: 3772)
    • Manual execution by a user

      • cmd.exe (PID: 2124)
      • IMEKLMG.EXE (PID: 2060)
      • IMEKLMG.EXE (PID: 2072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:02:21 19:46:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30fa
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
90
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bochs-2.5.pre1.exe notepad.exe no specs notepad.exe no specs cmd.exe no specs bochs.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs bochs-2.5.pre1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1688C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1696..\bochs -q -f bochsrc.bxrcC:\Program Files\Bochs-2.5.pre1\bochs.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1073807364
Modules
Images
c:\program files\bochs-2.5.pre1\bochs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
1956C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
2060"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
2072"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
2124C:\Windows\system32\cmd.exe /c ""C:\Program Files\Bochs-2.5.pre1\dlxlinux\run.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1073807364
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2444notepad.exe C:\Program Files\Bochs-2.5.pre1\CHANGES.TXTC:\Windows\System32\notepad.exeBochs-2.5.pre1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3212notepad.exe C:\Program Files\Bochs-2.5.pre1\README.txtC:\Windows\System32\notepad.exeBochs-2.5.pre1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3668"C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\bochs-2.5.pre1.exe
c:\windows\system32\ntdll.dll
3772"C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe" C:\Users\admin\AppData\Local\Temp\Bochs-2.5.pre1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bochs-2.5.pre1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
8 167
Read events
8 104
Write events
58
Delete events
5

Modification events

(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayName
Value:
Bochs 2.5.pre1 (remove only)
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bochs-2.5.pre1\bochs.ico,0
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:DisplayVersion
Value:
2.5.pre1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:Publisher
Value:
The Bochs Project
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:URLInfoAbout
Value:
http://bochs.sourceforge.net
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:Readme
Value:
C:\Program Files\Bochs-2.5.pre1\Readme.txt
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:NoModify
Value:
1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:NoRepair
Value:
1
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:InstallLocation
Value:
C:\Program Files\Bochs-2.5.pre1\
(PID) Process:(3772) Bochs-2.5.pre1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bochs 2.5.pre1
Operation:writeName:UninstallString
Value:
"C:\Program Files\Bochs-2.5.pre1\Uninstall.exe"
Executable files
7
Suspicious files
10
Text files
135
Unknown types
7

Dropped files

PID
Process
Filename
Type
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bochsdbg.exeexecutable
MD5:711246E178655950C50A9890D0A38394
SHA256:99BC58BA2BCBA5F6816309BB0210B0C8B70978802A5D2919FB6674764E99C37D
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\CHANGES.txttext
MD5:FB5C6D9AEEC3D379C64A7EE5248F1807
SHA256:8A9E963915484EC56FBED4FB7E850CB602C2B5F11FF46A8D1150AD4E20A02C7D
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\keymaps\sdl-pc-de.maptext
MD5:136EC8AADA36A12C00E2F92727987685
SHA256:33A4BC929A048D81A2CDB7242717689A058B29B39E2ED7B7305E39D8FE340F86
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\README.txttext
MD5:70CE54A08B1A883546ABE665C6211D65
SHA256:05FC0770AEED080D4B1B262357BE65C2633D8F874433823B249873DFA12936D3
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bochs.icoimage
MD5:FC95A21F41CD84907D200C837F18E6DA
SHA256:3C64B4132FE2BCB7C7125E185C9A3B63132BE99494BF3278ADF6F864ADDB2BB3
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\bxcommit.exeexecutable
MD5:3BD700D04A99DAB2B5A65D3622C3247A
SHA256:C9C23380EEB4A3888C7B3631F821020A8587C4E8E692CBFA1E8C61CBA6C673F7
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\TODO.txttext
MD5:3815DA3A639AF6904C4EEDC46961154E
SHA256:235345BE9183B3A8465FD331B296AA607616EE313935555CBEDD1DB4DB4D2D90
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\niclist.exeexecutable
MD5:430DA2E1B1FE601F632E865A3D455F5A
SHA256:697AC35AF5F3AC6D4A3EBA849B10C67792E222A81BAE56A388C1765E3C4F9ECF
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\sb16ctrl.exeexecutable
MD5:40266BA8B1AF90C51ABA1CAC50082F3A
SHA256:3AC7C6A957F660733705A2DFA5DE9654DEAF388954716C37A4A268CE024A8EA6
3772Bochs-2.5.pre1.exeC:\Program Files\Bochs-2.5.pre1\COPYING.txttext
MD5:3101CD8F3A6E3A7666E0CF09D70E1A7C
SHA256:3C6750AD9E73219F202928CF03B946EA5792044F2B24F768A53BA70A43B24E3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
23.50.98.211:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133538867506710000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1112
svchost.exe
224.0.0.252:5355
unknown
1956
sipnotify.exe
23.50.98.211:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
CH
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.50.98.211
whitelisted

Threats

No threats detected
No debug info