File name:

BatToExePortable_3.2_Dev_Test_1.paf.exe

Full analysis: https://app.any.run/tasks/81a2a8bf-1146-4b14-8a46-a29918b34221
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:54:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

9A35E910967475490CA24631C07DDD48

SHA1:

227F582DD642F79B6E34F629155EBD057F55A4A3

SHA256:

AFF48C00FD4C805239E920934640B5DB8A532E2EADC92A4409862B8D024D9686

SSDEEP:

98304:1aX8S9BQfj5XtqrAc+2FbVsI1bEFtygX6lZ3ADO/mfziDCGQIC95bMkpQ/sFMlIq:GhxT7Y7ub

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
    • Executable content was dropped or overwritten

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • The process creates files with name similar to system file names

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
    • There is functionality for taking screenshot (YARA)

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
    • Creates file in the systems drive root

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Reads security settings of Internet Explorer

      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
  • INFO

    • The sample compiled with english language support

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Reads the computer name

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Checks supported languages

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • Create files in a temporary directory

      • BatToExePortable_3.2_Dev_Test_1.paf.exe (PID: 7432)
      • BatToExePortable.exe (PID: 8100)
      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
    • The sample compiled with german language support

      • Bat_To_Exe_Converter_(x64).exe (PID: 8148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:01+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 428544
UninitializedDataSize: 16384
EntryPoint: 0x34a5
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.1.99.1
ProductVersionNumber: 3.1.99.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: BatToExe Portable
FileVersion: 3.1.99.1
InternalName: BatToExe Portable
LegalCopyright: 2007-2019 PortableApps.com, PortableApps.com Installer 3.5.14.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: BatToExePortable_3.2_Dev_Test_1.paf.exe
PortableAppscomAppID: BatToExePortable
PortableAppscomFormatVersion: 3.5.14
PortableAppscomInstallerVersion: 3.5.14.0
ProductName: BatToExe Portable
ProductVersion: 3.1.99.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start battoexeportable_3.2_dev_test_1.paf.exe sppextcomobj.exe no specs slui.exe no specs battoexeportable.exe bat_to_exe_converter_(x64).exe

Process information

PID
CMD
Path
Indicators
Parent process
7432"C:\Users\admin\AppData\Local\Temp\BatToExePortable_3.2_Dev_Test_1.paf.exe" C:\Users\admin\AppData\Local\Temp\BatToExePortable_3.2_Dev_Test_1.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
BatToExe Portable
Exit code:
0
Version:
3.1.99.1
Modules
Images
c:\users\admin\appdata\local\temp\battoexeportable_3.2_dev_test_1.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7468C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7500"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8100"C:\BatToExePortable\BatToExePortable.exe"C:\BatToExePortable\BatToExePortable.exe
BatToExePortable_3.2_Dev_Test_1.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
BatToExe Portable (PortableApps.com Launcher)
Version:
2.2.1.0
Modules
Images
c:\battoexeportable\battoexeportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8148"C:\BatToExePortable\App\BatToExe\Bat_To_Exe_Converter_(x64).exe"C:\BatToExePortable\App\BatToExe\Bat_To_Exe_Converter_(x64).exe
BatToExePortable.exe
User:
admin
Company:
Fatih Kodak
Integrity Level:
MEDIUM
Description:
Bat To Exe Converter
Version:
3.2
Modules
Images
c:\battoexeportable\app\battoexe\bat_to_exe_converter_(x64).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 578
Read events
7 503
Write events
72
Delete events
3

Modification events

(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
114
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
CF93106800000000
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(7432) BatToExePortable_3.2_Dev_Test_1.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
04000000030000000E00000000000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
Operation:writeName:MRUListEx
Value:
040000000000000005000000020000000100000003000000FFFFFFFF
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
Operation:writeName:SniffedFolderType
Value:
Documents
(PID) Process:(8148) Bat_To_Exe_Converter_(x64).exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Operation:writeName:Mode
Value:
4
Executable files
16
Suspicious files
9
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nswC7C8.tmp\LangDLL.dllexecutable
MD5:AB1DB56369412FE8476FEFFFD11E4CC0
SHA256:6F14C8F01F50A30743DAC68C5AC813451463DFB427EB4E35FCDFE2410E1A913B
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\help.htmlhtml
MD5:2B32E4B535E3C9AD961AD10E8B089B6D
SHA256:ACEC52FA400C5DABBE9B78BE5F5224E7FAB91CD875AE71642B0D8E3694263ADC
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\Users\admin\AppData\Local\Temp\nswC7C8.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_128.pngimage
MD5:D98CE0C8E5B655D444C24B7193EFD125
SHA256:99951FAAA1ACD9DF13DC70385FDE6777DC8EB86FACBC4B12B99C503E2443441B
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appinfo.initext
MD5:169E9BFF640BABC35EDD87159DC91AA3
SHA256:9FF15104375E5C17FD2174855A971FD2304BAF81DE5A2B32595F44F49D048CB8
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\Launcher\Splash.jpgimage
MD5:403F92170392F5FC3B60F1FBD3BFCF01
SHA256:18D35DDAB3A06343043709FB35ACB32DA39778E21565F69167D4868EE37759D5
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\BatToExePortable.exeexecutable
MD5:A7AF46DED9A327FAA37A8C94FC05DB1C
SHA256:61A170DF15C43CA758BE15B0C17D638C39D32ADF84C8E8C3ABAF409C126DA979
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\Launcher\BatToExePortable.initext
MD5:DF5CBC34420C2543FDC9D0705956A57E
SHA256:EB4B1865E2CC4672B8913D2E7C3B4382700E4554F6A4FAD36D764DD125265E42
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon_16.pngimage
MD5:528FC97837B4D7EAC46BD0A58F655C39
SHA256:DA65002E27BA9CBA8ECBEDF9EE28F042319D9FE0B6C3551EC4DCC8DB30C530E1
7432BatToExePortable_3.2_Dev_Test_1.paf.exeC:\BatToExePortable\App\AppInfo\appicon.icoimage
MD5:62FF8D6E66BE21AB6B7386416210EFB4
SHA256:66A766E7A3A8975EFC956387E1B419AD2DFA0E4AD8F2E860A8F8C7EAE1EE0FEE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
18
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8176
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8176
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.58:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
8176
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.58
  • 2.16.164.99
  • 2.16.164.74
  • 2.16.164.48
  • 2.16.164.9
  • 2.16.164.72
  • 2.16.164.106
  • 2.16.164.120
  • 2.16.164.42
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.0
  • 20.190.159.73
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info