i have analyzed this file, i'm new i want to learn

can somebody anayze this file and compare with me their results?
at least i can learn much more

i have upload here ,
few seconds ago

re-upload with password winarar 5
password infected
hope now it's ok

i will appreciate it a lot
sorry for my poor english

i have upload but i got this error
Uploaded file over size limit. for this reason i added Malwr - Malware Analysis by Cuckoo Sandbox
Content Creator
i have analyzed this file, i'm new i want to learn

can somebody anayze this file and compare with me their results?
at least i can learn much more

i have upload here ,
few seconds ago

i will appreciate it a lot
sorry for my poor english

i have upload but i got this error
Uploaded file over size limit. for this reason i added Malwr - Malware Analysis by Cuckoo Sandbox
FYI when the file is over size limit, you can still check the download link on Virus Total.


We cannot help you because you haven't actually provided us a sample to analyse; the Malwr URL doesn't point to analysis where registered users can download the sample.

Can you please upload the sample to Zippyshare and then post it here with a format of "hxxp://" instead of "http://"/"https://", an example would be the following:
Make sure to put the sample in a password protected archive (set the password as "infected" without the "").

Edit: Sorry I missed the Zippshare link in the original post, I apologise for being blind.


Content Creator
@giulia None told you to upload to malwr the password protected file. Obviously it can't take password protected files because the engine will then be unable to analyze the file and will have no point for them to get the sample.
What @Wave wanted was a zippyshare upload but password protected and the url changed to follow the rules and not be deleted so he can get it and check the sample.

All are good now so don't worry. Someone will check it.


@giulia None told you to upload to malwr the password protected file. Obviously it can't take password protected files because the engine will then be unable to analyze the file and will have no point for them to get the sample.
What @Wave wanted was a zippyshare upload but password protected and the url changed to follow the rules and not be deleted so he can get it and check the sample.

All are good now so don't worry. Someone will check it.
i have upload with password here zippyshare , i don't upload in malwr with the password, i just try to upload it again in malwr and i upload the exe but the file is too huge and i got the error , while in zippyshare winrar and with the password infected

All are good now so don't worry. Someone will check it.
i hope it

The sample you uploaded appears to be a crack for genuine software provided by Postbox Inc (although the crack is not digitally signed).

I managed to track down a source of the sample you submitted, it should have come from the following source:
(the download link at the bottom will redirect to multiple sites containing advertisements and pop-ups, which may or may not be malicious (e.g. normal advertisements, but also fake AV alerts as I saw for myself), eventually you will reach the download stage and within the archive will be the exact same sample under a different file-name).

The original file name to the sample was: "Postbox 5.0.5 Repack -" and it was re-named to "Postbox.exe". Both file sizes are the same and you can check the HEX to both executable's so you know they are the same, as well as the checksum comparisons.

The real installer has a file size of 22,67KB (22.7MB rounded upwards, otherwise 22.6MB) and is digitally signed without the timestamp verification by "Postbox, Inc", unlike the sample from this thread.

Due to some personal health problems for the past few days I am unable to do proper PC work today; that being said, I have left some details below regarding static analysis for you to look at, which will help in you deciding a verdict. The below information was quickly obtained through a speedy static analysis overview, therefore I have not properly performed decompilation analysis and worked with disassembly.

The sample uses the Caphyon Advanced Installer; if not it at least references it for registry-related actions in the Strings output. We already know that the sample can perform registry operations because it imports the following functions: Advapi32.dll!RegCreateKeyW; Advapi32.dll!RegDeleteValueA; Advapi32.dll!RegQueryValueExA; Advapi32.dll!RegDeleteValueW; Advapi32.dll!RegCreateKeyExW; Advapi32.dll!RegSetValueExW, and some others.

As an addition to this, the imports implies that the sample may at some point attempt to either modify existing windows services, or attempt to start it's own, since it imports the following functions: Advapi32.dll!OpenSCManagerW; Advapi32.dll!OpenServiceW; Advapi32.dll!StartServiceW. It does not import Advapi32.dll!CreateServiceA/W therefore I am convinced it will probably alter an existing one.

Another thing about the sample: it will attempt to adjust it's privileges. It imports the following functions: Advapi32.dll!AdjustTokenPrivileges; Advapi32.dll!LookupPrivilegeValueW; Advapi32.dll!OpenProcessToken, and some others. This implies it will attempt to adjust it's token privileges, probably to enable debugging rights (SeDebugPrivilege), since it does not require administrative privileges. As well as this, it imports the function GetCurrentProcess from Kernel32.dll and while this can be used for a number of things, it would match well with this usage.

The sample works with the resources therefore it'd be wise for you to perform some manual analysis to check the resources and see if you can find anything interesting. It would also be wise to check the Strings output first for any more indicators on this.

The sample does have the ability to perform networking actions, via the wininet library (wininet.dll).

There is a high chance that this sample is an installer since it works with the Msi library however without dynamic analysis it's hard to really know - I have not performed any dynamic analysis or any real decompilation/disassembly due to specific reasons, and the above is just lightwork details for you to interpret however you like.

The above details do not mean that the sample is malicious at all, however I did submit the sample to Avira and I will let you know on their verdict once they get back to me. That being said, it appears to be a crack, therefore it's automatically Riskware at the least.

Bad response, I know... You were expecting much better. I'm sorry I could not be of much use to anyone today but hopefully the above information can be found useful at least a little bit...

Stay safe,
Wave. ;)


thanks a lot
i will read it very carefully
may i ask you a question? does the installer work on your virtual machine? i mean can you install it ?
under sandboxie it doesn't work (the installer)
I was originally going to perform dynamic analysis and monitor the API call executions, registry modifications, file operations, etc... But I had to remove my environment for analysis the other day and I need to re-create it, and I don't have time to do this for a few more days. Therefore, if no one has tested this for you still in a few days, then I will re-set things up and check that for you. :)

I doubt it would work under Sandboxie since Sandboxie will set hooks and redirect execution which will limit software from actually working properly in a lot of cases, causing them to break or just not function as expected. This is why a Virtual Machine is much better for testing, since you give the software a more accurate chance to function without modifications to it's execution flow while it's executing in memory.

Have you tried to execute it in a Virtual Machine yet? If so, make sure to disable shared clipboard/folder prior to running the sample, and also make sure to have some sort of VPN protection set-up (it can be on the Host, that should be good enough).

Thanks @Wave !! :)

Interesting imports, especially the imports related to clipboard( OpenClipboard, CloseClipboard, setClipBoardData and EmptyClipboard), so it definetely use deep malicious functions, but also SendMessage, HTTPQuery, and internet related imports.
Maybe it is able to retrieve data from ClipBoard (such as passwords) and send them to a server.


I doubt it would work under Sandboxie since Sandboxie will set hooks and redirect execution which will limit software from actually working properly in a lot of cases, causing them to break or just not function as expected. This is why a Virtual Machine is much better for testing, since you give the software a more accurate chance to function without modifications to it's execution flow while it's executing in memory.

Have you tried to execute it in a Virtual Machine yet? If so, make sure to disable shared clipboard/folder prior to running the sample, and also make sure to have some sort of VPN protection set-up (it can be on the Host, that should be good enough).
yes i run under virtual machine but i have not disabled shared clipboard/folder and not VPN protection set-up
i have run it even outside a virtual machine under sandboxie
now i'm worried!!!


Thanks @Wave !! :)

Interesting imports, especially the imports related to clipboard( OpenClipboard, CloseClipboard, setClipBoardData and EmptyClipboard), so it definetely use deep malicious functions, but also SendMessage, HTTPQuery, and internet related imports.
Maybe it is able to retrieve data from ClipBoard (such as passwords) and send them to a server.
that's makes me even more worried


yes i run under virtual machine but i have not disabled shared clipboard/folder and not VPN protection set-up
i have run it even outside a virtual machine under sandboxie
now i'm worried!!!
Never perform malware analysis on your Host system at all to be on the safe side, unless within a Guest environment (such as a Virtual Machine). Sandboxie is not real virtualisation, it's just redirecting execution flow via API hooks and is not as secure as a lot of people really believe (sorry if the developer reads this and feels offended but if he/she does, look into VT-x utilisation).

Your IP address becomes exposed to many sites every day when you are browsing, like MalwareTips for example. Chances are nothing will happen, and there is no guarantee that the sample is even actually malicious yet, I said Riskware as a temporary place-holder since I did not do a full analysis for specific reasons, but Avira will tell me their verdict soon.

As for the shared folders and clipboard, they should be disabled as they could potentially be attack vectors for exploitation from running malware on the Guest OS, that does not mean all samples will try to do such a thing and even in itself it would be extremely rare to see - this sample definitely does nothing like this so you don't need to worry about that, this sample doesn't even know if it's functions were hooked let alone unhook/circumvent the hooks, either (in the case of Sandboxie).

But remember to keep all testing within a Virtual Environment or a dedicated malware analysis system. Remember that data theft can still occur within the analysis environment, also.

