| File name: | jdiskreport-1_4_1-win.exe |
| Full analysis: | https://app.any.run/tasks/bd14cf98-c0f6-4e1e-9289-533e27824d36 |
| Verdict: | Malicious activity |
| Analysis date: | November 16, 2023, 02:15:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 2D454A43765C7817990ED8135B4C065E |
| SHA1: | 0D6CDFBD36F403847445CFB41F707F4058B1AEF4 |
| SHA256: | FEEBC371274E0DA64A950E13033A70AEF6E47C2C0AFC978953ECA45196FF88E4 |
| SSDEEP: | 24576:IkMWFD6A12iaNHq5JGjJv652KUQoxqCf1wEMvwBhdgHjlVtGsyyqVIvxOfxtbhN3:IkM2D6A1ZaNHq5JOJv652KUQoxqCf1wC |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:12:05 23:50:46+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 119808 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x323c |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1420 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 2748 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | |||||||||||||||
| 3432 | "C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe" | C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3524 | "C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe" | C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3776 | C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | C:\Windows\System32\icacls.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3876 | "C:\Program Files\Common Files\Oracle\Java\javapath\javaw.exe" -Xmx384m -jar "C:\Program Files\JGoodies\JDiskReport 1.4.1\jdiskreport-1.4.1.jar" | C:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\javaw.exe | explorer.exe | ||||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.2710.9 Modules
| |||||||||||||||
| (PID) Process: | (3876) javaw.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
| (PID) Process: | (3876) javaw.exe | Key: | HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com\jgoodies\jdiskreport\jdiskreport\[0,0,1280,720] |
| Operation: | write | Name: | main.window_bounds |
Value: 336, 104, 608, 487 | |||
| (PID) Process: | (3876) javaw.exe | Key: | HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com\jgoodies\jdiskreport\jdiskreport\[0,0,1280,720] |
| Operation: | write | Name: | main.frame_state |
Value: 0 | |||
| (PID) Process: | (3876) javaw.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3524 | jdiskreport-1_4_1-win.exe | C:\Users\admin\AppData\Local\Temp\nsz7611.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\JGoodies Home Page.lnk | binary | |
MD5:961B6A02ECBD402CDEE63D3035CB8B1C | SHA256:D95E5A4DE22588253CBCD574DA9A329AF9B3402EFA4D8155C0D4B1C09A71B739 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\Program Files\JGoodies\JDiskReport 1.4.1\jdiskreport.ico | image | |
MD5:068AF8D9C26B9ABF70AC8201ACE13E6B | SHA256:4324B0C15D481F3E9B8DBC8BA44D6EEB7E3D52779B083AA1A7417F7F58A69C7B | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\Program Files\JGoodies\JDiskReport 1.4.1\README.txt | text | |
MD5:CFE71BC0B034D8A5A00E8A63979904F6 | SHA256:07657FD749230EA6D5AA8A29E8D7CCB789ABD02BC16622E8A99B906E17CD4616 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\Program Files\JGoodies\JDiskReport 1.4.1\LICENSE.txt | text | |
MD5:55242ECB7384FAFEBEBECEA32BE2C358 | SHA256:11C219C5E9DE679F2B788D852B1DFF849FD1FD28C0F4E2D25E4FB493A3D94C90 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\Program Files\JGoodies\JDiskReport 1.4.1\RELEASE-NOTES.txt | text | |
MD5:99C0E39A75058AB77A75E73B2D29E980 | SHA256:C4E285C942D125D6F909A0B018EBD2271432B9488EBBA1B9140F019E7ADFD162 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\JDiskReport 1.4.1.lnk | binary | |
MD5:C1D53E45775F0E0D097D2F3D6C505B9A | SHA256:CB7CC7B73CA545D1927AA372D8F3841A3FD39951EEF9ED951758A67D7AAE111A | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\Program Files\JGoodies\JDiskReport 1.4.1\Uninstall.exe | executable | |
MD5:3B40401E90078338A6E89DF5D53C02B7 | SHA256:B0C8CE2D03312263E650EF5F887E8BA5763980E30D7F01486D3415CF83A021D0 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\Release Notes.lnk | binary | |
MD5:196298D64C232D3C165D2A3DAA19B0D9 | SHA256:BFB7002B8B79DF16AE61C1BF2AD48863FD870091A782F1DF05D6408CE32FE5E8 | |||
| 3524 | jdiskreport-1_4_1-win.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\Readme.lnk | binary | |
MD5:A1E1A3972E2923BC665713CFD31EAA34 | SHA256:DF58AB8D747E0920687E85A0EEF8AE3E63D5F5E16FC83D74C019EBF7FB58A784 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |