File name:

Gater Proxy 8.9 cracked exploithacker.rar

Full analysis: https://app.any.run/tasks/e9e403f6-6d74-428d-b0ef-af00551ff50d
Verdict: Malicious activity
Analysis date: October 12, 2019, 19:51:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

4A2D41B9C5110BB292FC34F8C162B7C6

SHA1:

926BFF559B48D2EED46EB440ECD72B1F9FB2E464

SHA256:

002DC74FAD03D910E317706060D2E02B1D8F2C049ABA13AEA8DFDAF8EA1A3640

SSDEEP:

49152:mn0dkNs1VGr67gFKi4AfhIv2hEWhIluKn5qbzb9ehvY7KDUw3w:mnmuso6MFNZwaWQe52KdUZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2724)
    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2724)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 992)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe gather proxy.exe

Process information

PID
CMD
Path
Indicators
Parent process
992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gater Proxy 8.9 cracked exploithacker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2724"C:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Gather Proxy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Gather Proxy.exe
WinRAR.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 8.8 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
8.9.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa992.44795\gater proxy 8.9 cracked e ploithacker\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
472
Read events
460
Write events
12
Delete events
0

Modification events

(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(992) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Gater Proxy 8.9 cracked exploithacker.rar
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
11
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Data\geo.mmdb
MD5:
SHA256:
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Gather Proxy.exeexecutable
MD5:12683F462645A4A152A7BC579856B0F9
SHA256:9C1C87ABF7A1FBFF43007F4310F3A722AD6798EC4C42D599509C5C3E3D214284
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\FacebookAPIClass.dllexecutable
MD5:5F13FF94ECD5DEC20E90C1D5F2FEA13A
SHA256:CB2BC93CA31653C3297C3D07875E1AF9545F00D5BEB9C13762C3FD3525F4FB4C
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Data\planetlab.txttext
MD5:4AA755C53F5741125462955E02440DD1
SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\GC.dllexecutable
MD5:BEA3694CC7C60877D1B3C07DE352ADAB
SHA256:CEDB323B29D5C3104EB42D39E93AECC5CC3A69D2BA507F732F176A7051ECBCC3
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Gather Proxy.exe.configxml
MD5:365E8A1FAE1391145F187F048680FC08
SHA256:40A15F3B0184FB80CC36F771B589D2338CDA22EBC2F0EF0711E0C69B4DBCE4CC
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\MaxMind.Db.dllexecutable
MD5:4D1FC03277F904C3172A4C23ED36B032
SHA256:68540771C4099BAB7A26AB31F59F92E12182B9050D84E625BE7BD5778871F475
992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa992.44795\Gater Proxy 8.9 cracked e ploithacker\Data\autosp.initext
MD5:0AB7386476BFD6E6A7FDCAA91DA04D4F
SHA256:BA4DB1C4843A36822F68556D4F2AC5B815F3E7B063D28D8905FD6084B594EC40
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2724
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=95S%2bq4N4YusZwpqdOBFCqbJOR%2f72F9g85f42CfYNwwggkTKKJnVOG%2bgHSiTc3dEitKzKKVL7%2f7jJY2t2%2f%2felydYGpE%2fRn1%2fI0UbWerZQIk6JZ7qrWNJq2dZRg4gOaJlTVgaF98laEo4TFZDEJFp1hSF0CipGqji67NSZ3Y48AapwGjimj1laFqmx2cKN2Y0W
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2724
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info