File name:

BatToExePortable_3.2_Dev_Test_1.paf.exe

Full analysis: https://app.any.run/tasks/81a2a8bf-1146-4b14-8a46-a29918b34221
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:54:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

9A35E910967475490CA24631C07DDD48

SHA1:

227F582DD642F79B6E34F629155EBD057F55A4A3

SHA256:

AFF48C00FD4C805239E920934640B5DB8A532E2EADC92A4409862B8D024D9686

SSDEEP:

98304:1aX8S9BQfj5XtqrAc+2FbVsI1bEFtygX6lZ3ADO/mfziDCGQIC95bMkpQ/sFMlIq:GhxT7Y7ub

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
    • Executable content was dropped or overwritten

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Creates file in the systems drive root

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • The process creates files with name similar to system file names

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
    • There is functionality for taking screenshot (YARA)

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
    • Reads security settings of Internet Explorer

      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
  • INFO

    • Reads the computer name

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Checks supported languages

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • The sample compiled with english language support

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Create files in a temporary directory

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • The sample compiled with german language support

      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:01+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 428544
UninitializedDataSize: 16384
EntryPoint: 0x34a5
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.1.99.1
ProductVersionNumber: 3.1.99.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: BatToExe Portable
FileVersion: 3.1.99.1
InternalName: BatToExe Portable
LegalCopyright: 2007-2019 PortableApps.com, PortableApps.com Installer 3.5.14.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: BatToExePortable_3.2_Dev_Test_1.paf.exe
PortableAppscomAppID: BatToExePortable
PortableAppscomFormatVersion: 3.5.14
PortableAppscomInstallerVersion: 3.5.14.0
ProductName: BatToExe Portable
ProductVersion: 3.1.99.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start battoexeportable_3.2_dev_test_1.paf.exe sppextcomobj.exe no specs slui.exe no specs battoexeportable.exe bat_to_exe_converter_(x64).exe

Process information

PID
CMD
Path
Indicators
Parent process
7432"C:\Users\admin\AppData\Local\Temp\BatToExePortable_3.2_Dev_Test_1.paf.exe" C:\Users\admin\AppData\Local\Temp\BatToExePortable_3.2_Dev_Test_1.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
BatToExe Portable
Exit code:
0
Version:
3.1.99.1
Modules
Images
c:\users\admin\appdata\local\temp\battoexeportable_3.2_dev_test_1.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7468C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7500"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8100"C:\BatToExePortable\BatToExePortable.exe"C:\BatToExePortable\BatToExePortable.exe
BatToExePortable_3.2_Dev_Test_1.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
BatToExe Portable (PortableApps.com Launcher)
Version:
2.2.1.0
Modules
Images
c:\battoexeportable\battoexeportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8148"C:\BatToExePortable\App\BatToExe\Bat_To_Exe_Converter_(x64).exe"C:\BatToExePortable\App\BatToExe\Bat_To_Exe_Converter_(x64).exe
BatToExePortable.exe
User:
admin
Company:
Fatih Kodak
Integrity Level:
MEDIUM
Description:
Bat To Exe Converter
Version:
3.2
Modules
Images
c:\battoexeportable\app\battoexe\bat_to_exe_converter_(x64).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 578
Read events
7 503
Write events
72
Delete events
3

Modification events

(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
114
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
CF93106800000000
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
04000000030000000E00000000000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
Operation:writeName:MRUListEx
Value:
040000000000000005000000020000000100000003000000FFFFFFFF
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
Operation:writeName:SniffedFolderType
Value:
Documents
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Operation:writeName:Mode
Value:
4
Executable files
16
Suspicious files
9
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon.icoimage
MD5:62FF8D6E66BE21AB6B7386416210EFB4
SHA256:66A766E7A3A8975EFC956387E1B419AD2DFA0E4AD8F2E860A8F8C7EAE1EE0FEE
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nswC7C8.tmp\modern-wizard.bmpimage
MD5:4DF53EFCAA2C52F39618B2AAD77BB552
SHA256:EE13539F3D66CC0592942EA1A4C35D8FD9AF67B1A7F272D0D791931E6E9CE4EB
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nswC7C8.tmp\w7tbp.dllexecutable
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5
SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_128.pngimage
MD5:D98CE0C8E5B655D444C24B7193EFD125
SHA256:99951FAAA1ACD9DF13DC70385FDE6777DC8EB86FACBC4B12B99C503E2443441B
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\help.htmlhtml
MD5:2B32E4B535E3C9AD961AD10E8B089B6D
SHA256:ACEC52FA400C5DABBE9B78BE5F5224E7FAB91CD875AE71642B0D8E3694263ADC
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_256.pngimage
MD5:377BA5E995B77449DEF27DAAA1AC774D
SHA256:678D1081714C13650B69882DD78CF5299264E162C4DB84783FA54F9D7161820A
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_32.pngimage
MD5:E3816E99C6D23BF36E3BBBC4FEB18619
SHA256:62473CFBE986876B23D92A179B3A93FEEDAE6558FC1476F1C44FFD7C87FDF05B
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\pac_installer_log.initext
MD5:3BF23F9F43ED6CC43B1A1E0751D9BAEA
SHA256:1EFE59441A940788C21BFCCC0505389A9B5042F1C4FBDF642DA975F31427B980
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_75.pngimage
MD5:5643F215D73253F8A83E4950BDE8C097
SHA256:89E9AFC1F829AF6284C4EB94F4168091D2F48DA5FCCF31225BFDCF7286B2230E
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\Launcher\BatToExePortable.initext
MD5:DF5CBC34420C2543FDC9D0705956A57E
SHA256:EB4B1865E2CC4672B8913D2E7C3B4382700E4554F6A4FAD36D764DD125265E42
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8176
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8176
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.58:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
8176
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.58
  • 2.16.164.99
  • 2.16.164.74
  • 2.16.164.48
  • 2.16.164.9
  • 2.16.164.72
  • 2.16.164.106
  • 2.16.164.120
  • 2.16.164.42
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.0
  • 20.190.159.73
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info