| File name: | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe |
| Full analysis: | https://app.any.run/tasks/e87117a4-3608-4b5b-aa85-ff47575cd5ef |
| Verdict: | Malicious activity |
| Analysis date: | November 02, 2023, 13:52:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F6880FD202498CB4DF823E6BEE36D3F3 |
| SHA1: | CF5E22597D2C96F57D0AB3034818D1C4EA8D9A78 |
| SHA256: | 9DB4741B83FE24B9D047C7A18E0EEC751585693F544A4ABD443200BA39D49C6F |
| SSDEEP: | 24576:pWvknOMEBHEDHbC3gSS3rCZaKKOwj/SmincSw4XtJNy8xRhG6ek9wbwkqMRXA:pUeOMAHEDH4ar16wDliPw4XtJNyNDgMC |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 17:27:33+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 127488 |
| InitializedDataSize: | 54272 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d262 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.20.0.0 |
| ProductVersionNumber: | 9.20.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Igor Pavlov |
| FileDescription: | 7z SFX |
| FileVersion: | 9.2 |
| InternalName: | 7z.sfx |
| LegalCopyright: | Copyright (c) 1999-2010 Igor Pavlov |
| OriginalFileName: | 7z.sfx.exe |
| ProductName: | 7-Zip |
| ProductVersion: | 9.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3156 | "C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe" | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7z SFX Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\LiesMich.txt | text | |
MD5:72DF5C8552D255ABB5D0CB3C38946A9E | SHA256:EBC19DBF36DE807FFB59291DEF3EC364414D851280172DD30A9A33A89B3179FF | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\ReadMe.txt | text | |
MD5:693935AED9537B9D19DD8A6925D2C2CE | SHA256:CF732E610C1637809521B23637DB8BDE4F1CD7E7FA4BB83EFE6245E7C7D1EA55 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\french.ini | text | |
MD5:B3E341CF53FBBACE1E03A510BC5D8AC4 | SHA256:F569DA7DE0871E94146AA4D1E91D3075A6A239103E45E0FA344888B90618AB39 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\english.ini | binary | |
MD5:936C053A22D02646B6F58D8CDED429E6 | SHA256:0C34FDD5CBB58B3CB3F9E1C240A89F7CCFEBA50F6B494D9F939BAFEDCF322701 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\chinese.ini | binary | |
MD5:ED729F7AF83E0BA452B23995758D7D66 | SHA256:07366ACDAEA738FABAC1D570F29570195DA4742AD06959C417F5892D4357C9CB | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\catalan.ini | text | |
MD5:6C604F2BAEAC972790A0B2DE62E7062C | SHA256:2F6313D7BD2B392AB6CBC50A0623EFB7A4766EC4348CBCD75EC71A2A9E9730D9 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\german.ini | binary | |
MD5:6636D79F07AD562A816F9E1DD199D519 | SHA256:9E223411101C82D8370E7D74F5FE5402984A1F5A9D66B94AB41AFDA9F4D32792 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\italian.ini | binary | |
MD5:551B80785BEFCC403F4B8A3E430C6B06 | SHA256:33470BBE960141B47AAC1CABF4460C3A569965F4149E966473F5E3C00E158A39 | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\source\VirtualBox.ico | image | |
MD5:B2225F7DAB1376284FF6803D092C45F2 | SHA256:E9DC92B3905885F3FE107897D642BBD0098D7333D7D4AE451E8683D4795F208D | |||
| 3156 | Portable-VirtualBox_v5.1.22-Starter_v6.4.10-Win_all.exe | C:\Users\admin\AppData\Local\Temp\Portable-VirtualBox\data\language\portuguese.ini | binary | |
MD5:64893DA06BDAE25853120E46A2FD5796 | SHA256:7CFC4904CA4DD6645683DB4A3A095EB18FB8DDC7527E63E93A71C5FE90846B55 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |