File name:

Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe

Full analysis: https://app.any.run/tasks/e87117a4-3608-4b5b-aa85-ff47575cd5ef
Verdict: Malicious activity
Analysis date: November 02, 2023, 13:52:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F6880FD202498CB4DF823E6BEE36D3F3

SHA1:

CF5E22597D2C96F57D0AB3034818D1C4EA8D9A78

SHA256:

9DB4741B83FE24B9D047C7A18E0EEC751585693F544A4ABD443200BA39D49C6F

SSDEEP:

24576:pWvknOMEBHEDHbC3gSS3rCZaKKOwj/SmincSw4XtJNy8xRhG6ek9wbwkqMRXA:pUeOMAHEDH4ar16wDliPw4XtJNyNDgMC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe (PID: 3156)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe (PID: 3156)
    • Drops 7-zip archiver for unpacking

      • Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe (PID: 3156)
  • INFO

    • Checks supported languages

      • Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe (PID: 3156)
    • Create files in a temporary directory

      • Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe (PID: 3156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 17:27:33+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 127488
InitializedDataSize: 54272
UninitializedDataSize: -
EntryPoint: 0x1d262
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.20.0.0
ProductVersionNumber: 9.20.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 9.2
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFileName: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.2
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start portable-virtualbox_v5.1.22-starter_v6.4.10-win_all.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe" C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeexplorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\portable-virtualbox_v5.1.22-starter_v6.4.10-win_all.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
20
Read events
20
Write events
0
Delete events
0

Modification events

No data
Executable files
10
Suspicious files
9
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\LiesMich.txttext
MD5:72DF5C8552D255ABB5D0CB3C38946A9E
SHA256:EBC19DBF36DE807FFB59291DEF3EC364414D851280172DD30A9A33A89B3179FF
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\ReadMe.txttext
MD5:693935AED9537B9D19DD8A6925D2C2CE
SHA256:CF732E610C1637809521B23637DB8BDE4F1CD7E7FA4BB83EFE6245E7C7D1EA55
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\french.initext
MD5:B3E341CF53FBBACE1E03A510BC5D8AC4
SHA256:F569DA7DE0871E94146AA4D1E91D3075A6A239103E45E0FA344888B90618AB39
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\english.inibinary
MD5:936C053A22D02646B6F58D8CDED429E6
SHA256:0C34FDD5CBB58B3CB3F9E1C240A89F7CCFEBA50F6B494D9F939BAFEDCF322701
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\chinese.inibinary
MD5:ED729F7AF83E0BA452B23995758D7D66
SHA256:07366ACDAEA738FABAC1D570F29570195DA4742AD06959C417F5892D4357C9CB
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\catalan.initext
MD5:6C604F2BAEAC972790A0B2DE62E7062C
SHA256:2F6313D7BD2B392AB6CBC50A0623EFB7A4766EC4348CBCD75EC71A2A9E9730D9
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\german.inibinary
MD5:6636D79F07AD562A816F9E1DD199D519
SHA256:9E223411101C82D8370E7D74F5FE5402984A1F5A9D66B94AB41AFDA9F4D32792
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\italian.inibinary
MD5:551B80785BEFCC403F4B8A3E430C6B06
SHA256:33470BBE960141B47AAC1CABF4460C3A569965F4149E966473F5E3C00E158A39
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\source\VirtualBox.icoimage
MD5:B2225F7DAB1376284FF6803D092C45F2
SHA256:E9DC92B3905885F3FE107897D642BBD0098D7333D7D4AE451E8683D4795F208D
3156Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exeC:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\portuguese.inibinary
MD5:64893DA06BDAE25853120E46A2FD5796
SHA256:7CFC4904CA4DD6645683DB4A3A095EB18FB8DDC7527E63E93A71C5FE90846B55
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info