File name: | emu8086-microprocessor-emulator-4.08rt-installer.exe |
Full analysis: | https://app.any.run/tasks/e0f60b4c-6e0a-4bea-a4d8-5a965c9f9ac8 |
Verdict: | Malicious activity |
Analysis date: | May 04, 2024, 18:55:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=store |
MD5: | 097938653C4D6600FE2B8BF3719CF907 |
SHA1: | AA71B46EE9259E5B31A300C820277E551969DA7B |
SHA256: | D56D6E42FE170C52DF5ABD6002B1E8FEF0B840EB8D8807D77819FE1FC2E17AFD |
SSDEEP: | 49152:xIad5a3uFmO8bpECqd7OSEs98ymS94MGGhUDuOZxSNgEVT4oh1dbPWsKoB6Ls8Fe:fRoW3mC39hUCOZxSNB4yYoBmRFTdw/T |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2015:11:25 06:47:10 |
ZipCRC: | 0x79730b6b |
ZipCompressedSize: | 75 |
ZipUncompressedSize: | 75 |
ZipFileName: | ReadMe.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
308 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\olepro32.dll" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
552 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\comcat.dll" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
728 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\Mscomctl.ocx" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1060 | "C:\Windows\system32\NOTEPAD.EXE" C:\emu8086\ReadMe.txt | C:\Windows\System32\notepad.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1604 | "C:\emu8086\emu8086.exe" | C:\emu8086\emu8086.exe | — | explorer.exe | |||||||||||
User: admin Company: www.emu8086.com Integrity Level: MEDIUM Description: emu8086 Version: 4.00.0008 Modules
| |||||||||||||||
1756 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\oleaut32.dll" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1772 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msvbvm60.dll" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2032 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4004.25819\setup.exe" /SPAWNWND=$20178 /NOTIFYWND=$4015A | C:\Users\admin\AppData\Local\Temp\Rar$EXa4004.25819\setup.exe | setup.tmp | ||||||||||||
User: admin Company: emu8086 Integrity Level: HIGH Description: emu8086 microprocessor emulator Setup Exit code: 0 Version: Modules
| |||||||||||||||
2040 | "C:\Users\admin\AppData\Local\Temp\is-DCSEO.tmp\setup.tmp" /SL5="$30176,2791895,141824,C:\Users\admin\AppData\Local\Temp\Rar$EXa4004.25819\setup.exe" /SPAWNWND=$20178 /NOTIFYWND=$4015A | C:\Users\admin\AppData\Local\Temp\is-DCSEO.tmp\setup.tmp | setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1050.0.0 Modules
| |||||||||||||||
2304 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\cmax20.ocx" | C:\Windows\System32\regsvr32.exe | — | setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\emu8086-microprocessor-emulator-4.08rt-installer.exe.zip | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2032 | setup.exe | C:\Users\admin\AppData\Local\Temp\is-DCSEO.tmp\setup.tmp | executable | |
MD5:7B8ABC441B2182FC23AADCEA3D77829F | SHA256:B2BCFAB22C960440B361328FF89E5F2EE6CF525BBCE1D3679C11BEAC1E181FE3 | |||
2040 | setup.tmp | C:\emu8086\is-3EKJ3.tmp | text | |
MD5:71AEF01B4CF4B6F9741C3EA2E2D84841 | SHA256:E00DD0AEB0550B4BA9FB54D179E3BC1CB3F35747A99514C3B8A46F2FC7DBC7AE | |||
2040 | setup.tmp | C:\emu8086\diasm.dll | executable | |
MD5:8541EDBE276B8C0BD2B5E959F8E1B489 | SHA256:F9BACEA9A5C298767D2948D8AE41853AF7A011A9D0CA3A0B8CD1165D3F899C22 | |||
2040 | setup.tmp | C:\emu8086\BIOS_ROM | vxd | |
MD5:1B6191478F74B44090E904045BEB7E08 | SHA256:8FF8497D11497710AC612F36A276B8E2D8CBCF36DCEBE43257F7468A586BE318 | |||
2040 | setup.tmp | C:\emu8086\unins000.exe | executable | |
MD5:DDA768F6126921EB126D640693A6D83C | SHA256:ECD7D85D3C2907A1BEC307EA48E91E1A667194DD8B2896172E00A32D1FB630B8 | |||
2040 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-L15MD.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
2040 | setup.tmp | C:\emu8086\ReadMe.txt | text | |
MD5:B3CFACFA6D7A9831FFAC508EFB247664 | SHA256:CF53EE7F20020DE88D8D3FDBB783E2AD7ECA776C50AA6766306AFF3DD0E7F699 | |||
2040 | setup.tmp | C:\emu8086\is-H85CH.tmp | executable | |
MD5:C6F57EF28CD8D63793731E4332D5501D | SHA256:DBA99F7C8795DF28BE4B153F8E979B0C572EF825D8B70FB779609F8303A055E9 | |||
2040 | setup.tmp | C:\emu8086\default.binf | text | |
MD5:71AEF01B4CF4B6F9741C3EA2E2D84841 | SHA256:E00DD0AEB0550B4BA9FB54D179E3BC1CB3F35747A99514C3B8A46F2FC7DBC7AE | |||
2040 | setup.tmp | C:\emu8086\emu8086.ini | text | |
MD5:1B490C7752B8475E1B0ECAEE0072B3AA | SHA256:DE5EB64543658011A1732A9FEFEFECE6E5D4D640BB00028C1D1CEF0C5182512B |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |