| File name: | Patch-Proteus-8.16-SP3-36097.0.exe |
| Full analysis: | https://app.any.run/tasks/623d450d-6f3b-4a00-8d78-98ba6abbe5ce |
| Verdict: | Malicious activity |
| Analysis date: | February 21, 2024, 14:37:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | CC4D5485B540C520B1B08766B8A9D7F8 |
| SHA1: | 01502DC675737E40E528EC4B4D46A10442FC8EEA |
| SHA256: | 8DA492EC20E29D7C7153EC476A44298938849C675D400E447BF1992BE90C361A |
| SSDEEP: | 49152:6wE0tiseX1R/ZgNIhy334y/YxAfctNHf+oEtq1osvNEjIADRJtJRPYF606Y0efCC:o0ti3xgNIhu34y6OOHf+y1SjTD4FZ92C |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 13:27:46+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | My Company |
| FileDescription: | Patch for Proteus |
| FileVersion: | 1.0.0.0 |
| LegalCopyright: | Anonymous |
| ProductName: | Proteus |
| ProductVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1696 | "C:\Windows\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\OnStartupCode.bat"" | C:\Windows\System32\cmd.exe | — | Patch-Proteus-8.16-SP3-36097.0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\AppData\Local\Temp\is-HP5PT.tmp\Patch-Proteus-8.16-SP3-36097.0.tmp" /SL5="$100130,1298840,121344,C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-HP5PT.tmp\Patch-Proteus-8.16-SP3-36097.0.tmp | Patch-Proteus-8.16-SP3-36097.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2848 | "C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe" /SPAWNWND=$18013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe | Patch-Proteus-8.16-SP3-36097.0.tmp | ||||||||||||
User: admin Company: My Company Integrity Level: HIGH Description: Patch for Proteus Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3460 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe" | C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe | explorer.exe | ||||||||||||
User: admin Company: My Company Integrity Level: MEDIUM Description: Patch for Proteus Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3680 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\is-6KKVE.tmp\Patch-Proteus-8.16-SP3-36097.0.tmp" /SL5="$E0170,1298840,121344,C:\Users\admin\AppData\Local\Temp\Patch-Proteus-8.16-SP3-36097.0.exe" | C:\Users\admin\AppData\Local\Temp\is-6KKVE.tmp\Patch-Proteus-8.16-SP3-36097.0.tmp | — | Patch-Proteus-8.16-SP3-36097.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2840) Patch-Proteus-8.16-SP3-36097.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 180B0000A8845686D364DA01 | |||
| (PID) Process: | (2840) Patch-Proteus-8.16-SP3-36097.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: E6D771D6F1B5A82F84E31919B3EC5B09FB0919075464EDEB33259201C665E968 | |||
| (PID) Process: | (2840) Patch-Proteus-8.16-SP3-36097.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2840) Patch-Proteus-8.16-SP3-36097.0.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\OnStartupCode.bat | — | |
MD5:— | SHA256:— | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\OnBeforeCode.bat | — | |
MD5:— | SHA256:— | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\OnFinishCode.bat | — | |
MD5:— | SHA256:— | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\isproc.dll | executable | |
MD5:4BAFB0739C5FCD96BE991F2A3CC9AC2F | SHA256:7F74F1C445BF5E9456AAE6FAE695A8CA60E1D0EB5A2F44AC2CF0239A71F1A8A1 | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\lang\Dutch.ini | text | |
MD5:19EFA220A5C5FF287A83075BF69C8D92 | SHA256:377ED1A0F6D26AC799BDDC35F7677BAFF122E03CCE70DF1A80C7358B658372D6 | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\lang\French.ini | text | |
MD5:97ED308DD6499E0B6E01760C318CDB24 | SHA256:984DA665563F2701306DB7815E16E6077679836576B6D98C5C65B4DCA7374FB2 | |||
| 3672 | Patch-Proteus-8.16-SP3-36097.0.exe | C:\Users\admin\AppData\Local\Temp\is-6KKVE.tmp\Patch-Proteus-8.16-SP3-36097.0.tmp | executable | |
MD5:34ACC2BDB45A9C436181426828C4CB49 | SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07 | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\lang\Portuguese.ini | text | |
MD5:97F4CE0805B41B213B57760BFE19D8AD | SHA256:5EE928ABDD572EFE72E4AC05FBCD9596DF2954883A898A4014151E8D994FA572 | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\lang\English.ini | text | |
MD5:4FB66AF3052A25731D1F9C96BD17A654 | SHA256:C15E8CE6FE9CBF5FF30D3002619A55774F8C6198678CF6DA26C6768F2A56B6FA | |||
| 2840 | Patch-Proteus-8.16-SP3-36097.0.tmp | C:\Users\admin\AppData\Local\Temp\is-3E190.tmp\wintb.dll | executable | |
MD5:9436DF49E08C83BAD8DDC906478C2041 | SHA256:1910537AA95684142250CA0C7426A0B5F082E39F6FBDBDBA649AECB179541435 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |