File name:

synapse-launcher-11-17-21.zip

Full analysis: https://app.any.run/tasks/e17dd739-e3b4-46aa-995f-dcd4cf6ca465
Verdict: Malicious activity
Analysis date: May 17, 2022, 01:16:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E5EB2CB7B70701AB11A279B8ECA15EDA

SHA1:

9760D0724E6E03CE62565FD16404B9CA0577C227

SHA256:

0314DE51CAA9B0A86A8EB4947F6868707DE4C45C0BE8165C77D77F22D6F38E5F

SSDEEP:

6144:nSGO4OZazXXGIz2HA/J0OqystAilL2hDO5Hp2ypz89S49ttWZIw/E1y5e:SG+ZEX2IzyEeLy2pLpz89xCOwM1y5e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Synapse Launcher.exe (PID: 3720)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3060)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
      • Synapse Launcher.exe (PID: 3720)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1448)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
  • SUSPICIOUS

    • Checks supported languages

      • Synapse Launcher.exe (PID: 3720)
      • WinRAR.exe (PID: 3060)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
    • Reads the computer name

      • WinRAR.exe (PID: 3060)
      • Synapse Launcher.exe (PID: 3720)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3060)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
      • Synapse Launcher.exe (PID: 3720)
    • Reads Environment values

      • Synapse Launcher.exe (PID: 3720)
      • Synapse Launcher.exe (PID: 1232)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3060)
      • Synapse Launcher.exe (PID: 3720)
      • Synapse Launcher.exe (PID: 1232)
      • xuGid.bin (PID: 3380)
    • Starts application with an unusual extension

      • Synapse Launcher.exe (PID: 1232)
    • Starts itself from another location

      • xuGid.bin (PID: 3380)
    • Reads CPU info

      • 1NLbz5sRnL8kR.exe (PID: 3780)
  • INFO

    • Manual execution by user

      • Synapse Launcher.exe (PID: 3720)
      • Synapse Launcher.exe (PID: 1232)
    • Reads settings of System Certificates

      • Synapse Launcher.exe (PID: 1232)
      • Synapse Launcher.exe (PID: 3720)
      • 1NLbz5sRnL8kR.exe (PID: 3780)
    • Checks supported languages

      • WISPTIS.EXE (PID: 1576)
    • Reads the computer name

      • WISPTIS.EXE (PID: 1576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: synapse-launcher-11-17-21/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2021:11:17 13:43:03
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe synapse launcher.exe synapse launcher.exe xugid.bin searchprotocolhost.exe no specs 1nlbz5srnl8kr.exe wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
1232"C:\Users\admin\Desktop\synapse-launcher-11-17-21\Synapse Launcher.exe" C:\Users\admin\Desktop\synapse-launcher-11-17-21\Synapse Launcher.exe
Explorer.EXE
User:
admin
Company:
Synapse Softworks LLC
Integrity Level:
MEDIUM
Description:
Synapse Softworks Launcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\synapse-launcher-11-17-21\synapse launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1448"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1576"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE
1NLbz5sRnL8kR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3060"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\synapse-launcher-11-17-21.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3300"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE1NLbz5sRnL8kR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
3380"bin\xuGid.bin"C:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\xuGid.bin
Synapse Launcher.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\synapse-launcher-11-17-21\bin\xugid.bin
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3720"C:\Users\admin\Desktop\synapse-launcher-11-17-21\Synapse Launcher.exe" C:\Users\admin\Desktop\synapse-launcher-11-17-21\Synapse Launcher.exe
Explorer.EXE
User:
admin
Company:
Synapse Softworks LLC
Integrity Level:
MEDIUM
Description:
Synapse Softworks Launcher
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\synapse-launcher-11-17-21\synapse launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
3780"bin\1NLbz5sRnL8kR.exe"C:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\1NLbz5sRnL8kR.exe
xuGid.bin
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\synapse-launcher-11-17-21\bin\1nlbz5srnl8kr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
10 357
Read events
10 246
Write events
111
Delete events
0

Modification events

(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3060) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\synapse-launcher-11-17-21.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.37073\synapse-launcher-11-17-21\README.txttext
MD5:DC2B17CED7F566C8C8FA76E76388100E
SHA256:5E546413B92E3B07CC9BDE569A8ECFD9FCBC6C5FF0A65608C893B927B8AACDE7
3720Synapse Launcher.exeC:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\xuGid.binexecutable
MD5:
SHA256:
3380xuGid.binC:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\1NLbz5sRnL8kR.exeexecutable
MD5:
SHA256:
37801NLbz5sRnL8kR.exeC:\Users\admin\Desktop\synapse-launcher-11-17-21\auth\options.bintext
MD5:
SHA256:
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.37710\synapse-launcher-11-17-21\Synapse Launcher.exeexecutable
MD5:154E1239C1BB0E04B18F27AABFFCD6E7
SHA256:93FC4441B3648A74D3BC72CC5F34CED564CECA74A5E560961178B42A6C8416B0
3380xuGid.binC:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\SLAgent.dllexecutable
MD5:9B248DFFF1D2B73FD639324741FE2E08
SHA256:39943C30732988289CA346902F007A72124BD98B82E08B0B9739241CDAB4018E
37801NLbz5sRnL8kR.exeC:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\theme-wpf.jsonbinary
MD5:F92E57A56C890DA7B29A80219EDA8B76
SHA256:A55CF3C1A752CECCE303C97F08FEA682644297CDE884AFFB25849E2CB7B90A30
1232Synapse Launcher.exeC:\Users\admin\Desktop\synapse-launcher-11-17-21\bin\SynapseInjector.dllexecutable
MD5:9B248DFFF1D2B73FD639324741FE2E08
SHA256:39943C30732988289CA346902F007A72124BD98B82E08B0B9739241CDAB4018E
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.37710\synapse-launcher-11-17-21\README.txttext
MD5:DC2B17CED7F566C8C8FA76E76388100E
SHA256:5E546413B92E3B07CC9BDE569A8ECFD9FCBC6C5FF0A65608C893B927B8AACDE7
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.37073\synapse-launcher-11-17-21\Synapse Launcher.exeexecutable
MD5:154E1239C1BB0E04B18F27AABFFCD6E7
SHA256:93FC4441B3648A74D3BC72CC5F34CED564CECA74A5E560961178B42A6C8416B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
2
Threats
2

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1232
Synapse Launcher.exe
104.18.13.83:443
synapse.to
Cloudflare Inc
US
suspicious
3720
Synapse Launcher.exe
104.18.13.83:443
synapse.to
Cloudflare Inc
US
suspicious
3780
1NLbz5sRnL8kR.exe
104.18.13.83:443
synapse.to
Cloudflare Inc
US
suspicious

DNS requests

Domain
IP
Reputation
synapse.to
  • 104.18.13.83
  • 104.18.12.83
whitelisted
cdn.synapse.to
  • 104.18.13.83
  • 104.18.12.83
suspicious

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query for .to TLD
Potentially Bad Traffic
ET DNS Query for .to TLD
No debug info