File name:

jdiskreport-1_4_1-win.exe

Full analysis: https://app.any.run/tasks/bd14cf98-c0f6-4e1e-9289-533e27824d36
Verdict: Malicious activity
Analysis date: November 16, 2023, 02:15:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

2D454A43765C7817990ED8135B4C065E

SHA1:

0D6CDFBD36F403847445CFB41F707F4058B1AEF4

SHA256:

FEEBC371274E0DA64A950E13033A70AEF6E47C2C0AFC978953ECA45196FF88E4

SSDEEP:

24576:IkMWFD6A12iaNHq5JGjJv652KUQoxqCf1wEMvwBhdgHjlVtGsyyqVIvxOfxtbhN3:IkM2D6A1ZaNHq5JOJv652KUQoxqCf1wC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • jdiskreport-1_4_1-win.exe (PID: 3524)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 3876)
  • SUSPICIOUS

    • Checks for Java to be installed

      • javaw.exe (PID: 3876)
    • Reads the Internet Settings

      • jdiskreport-1_4_1-win.exe (PID: 3524)
  • INFO

    • Checks supported languages

      • jdiskreport-1_4_1-win.exe (PID: 3524)
      • javaw.exe (PID: 3876)
    • Reads the computer name

      • jdiskreport-1_4_1-win.exe (PID: 3524)
      • javaw.exe (PID: 3876)
    • Create files in a temporary directory

      • jdiskreport-1_4_1-win.exe (PID: 3524)
      • javaw.exe (PID: 3876)
    • Manual execution by a user

      • javaw.exe (PID: 3876)
    • Creates files in the program directory

      • jdiskreport-1_4_1-win.exe (PID: 3524)
      • javaw.exe (PID: 3876)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 3876)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 3876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:46+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x323c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start jdiskreport-1_4_1-win.exe javaw.exe icacls.exe no specs Copy/Move/Rename/Delete/Link Object no specs Copy/Move/Rename/Delete/Link Object no specs jdiskreport-1_4_1-win.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1420C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2748C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3432"C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe" C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\jdiskreport-1_4_1-win.exe
c:\windows\system32\ntdll.dll
3524"C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe" C:\Users\admin\Desktop\jdiskreport-1_4_1-win.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\jdiskreport-1_4_1-win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3776C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
3876"C:\Program Files\Common Files\Oracle\Java\javapath\javaw.exe" -Xmx384m -jar "C:\Program Files\JGoodies\JDiskReport 1.4.1\jdiskreport-1.4.1.jar"C:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\javaw.exe
explorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 592
Read events
1 584
Write events
8
Delete events
0

Modification events

(PID) Process:(3876) javaw.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3876) javaw.exeKey:HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com\jgoodies\jdiskreport\jdiskreport\[0,0,1280,720]
Operation:writeName:main.window_bounds
Value:
336, 104, 608, 487
(PID) Process:(3876) javaw.exeKey:HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com\jgoodies\jdiskreport\jdiskreport\[0,0,1280,720]
Operation:writeName:main.frame_state
Value:
0
(PID) Process:(3876) javaw.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
3
Suspicious files
10
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
3524jdiskreport-1_4_1-win.exeC:\Users\admin\AppData\Local\Temp\nsz7611.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3524jdiskreport-1_4_1-win.exeC:\Program Files\JGoodies\JDiskReport 1.4.1\README.txttext
MD5:CFE71BC0B034D8A5A00E8A63979904F6
SHA256:07657FD749230EA6D5AA8A29E8D7CCB789ABD02BC16622E8A99B906E17CD4616
3524jdiskreport-1_4_1-win.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\Release Notes.lnkbinary
MD5:196298D64C232D3C165D2A3DAA19B0D9
SHA256:BFB7002B8B79DF16AE61C1BF2AD48863FD870091A782F1DF05D6408CE32FE5E8
3524jdiskreport-1_4_1-win.exeC:\Program Files\JGoodies\JDiskReport 1.4.1\Uninstall.exeexecutable
MD5:3B40401E90078338A6E89DF5D53C02B7
SHA256:B0C8CE2D03312263E650EF5F887E8BA5763980E30D7F01486D3415CF83A021D0
3524jdiskreport-1_4_1-win.exeC:\Users\Administrator\Desktop\JDiskReport.lnkbinary
MD5:9C149D9AADE8BE5D33824297D1F69610
SHA256:D2974B15994CFADDE676BABEB679E30F045478CE34D99D6F86EE088D4ED44131
3524jdiskreport-1_4_1-win.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\JDiskReport 1.4.1.lnkbinary
MD5:C1D53E45775F0E0D097D2F3D6C505B9A
SHA256:CB7CC7B73CA545D1927AA372D8F3841A3FD39951EEF9ED951758A67D7AAE111A
3524jdiskreport-1_4_1-win.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\Readme.lnkbinary
MD5:A1E1A3972E2923BC665713CFD31EAA34
SHA256:DF58AB8D747E0920687E85A0EEF8AE3E63D5F5E16FC83D74C019EBF7FB58A784
3524jdiskreport-1_4_1-win.exeC:\Program Files\JGoodies\JDiskReport 1.4.1\jdiskreport.icoimage
MD5:068AF8D9C26B9ABF70AC8201ACE13E6B
SHA256:4324B0C15D481F3E9B8DBC8BA44D6EEB7E3D52779B083AA1A7417F7F58A69C7B
3524jdiskreport-1_4_1-win.exeC:\Users\admin\Desktop\JDiskReport.lnkbinary
MD5:9C149D9AADE8BE5D33824297D1F69610
SHA256:D2974B15994CFADDE676BABEB679E30F045478CE34D99D6F86EE088D4ED44131
3524jdiskreport-1_4_1-win.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\Uninstall.lnkbinary
MD5:54027A0C41EED1179FAA201F4D6437A7
SHA256:CDE9F572A4C2D3DF79460EA7298101CA204D810131654DC25F34730EE8DD8E4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info