File name:

Galaxy Swapper v2 Pass 123.zip

Full analysis: https://app.any.run/tasks/c4c6eb70-061d-4236-9c44-62f51b3b13bc
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: October 10, 2021, 19:15:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

BF2EA3B29E863E7A514CF43A7D2478B3

SHA1:

A2871D813543B3ED0808CE59B780DA01C6641E79

SHA256:

1723EC252BB491054969761A6C1997612615AE571F77FFE1926C2DADC0C26651

SSDEEP:

196608:N4BK+D848hZ9c4FZ7Co1mKoFAWLQDxCBQ04Jx:N4s+D8XhZf1hWcF3n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 332)
    • Application was dropped or rewritten from another process

      • Galaxy_Swapper_v2.exe (PID: 564)
      • Galaxy_Swapper_v2.exe (PID: 3216)
    • REDLINE was detected

      • Galaxy_Swapper_v2.exe (PID: 564)
    • Connects to CnC server

      • Galaxy_Swapper_v2.exe (PID: 564)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 4020)
    • Reads the computer name

      • WinRAR.exe (PID: 4020)
      • Galaxy_Swapper_v2.exe (PID: 564)
      • Galaxy_Swapper_v2.exe (PID: 3216)
    • Checks supported languages

      • WinRAR.exe (PID: 4020)
      • Galaxy_Swapper_v2.exe (PID: 564)
      • Galaxy_Swapper_v2.exe (PID: 3216)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 4020)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4020)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 4020)
    • Reads Environment values

      • Galaxy_Swapper_v2.exe (PID: 564)
  • INFO

    • Manual execution by user

      • Galaxy_Swapper_v2.exe (PID: 564)
      • Galaxy_Swapper_v2.exe (PID: 3216)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:10:05 12:55:04
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Galaxy Swapper v2 Pass 123/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs #REDLINE galaxy_swapper_v2.exe galaxy_swapper_v2.exe

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
564"C:\Users\admin\Desktop\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2 pass 123\galaxy_swapper_v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3216"C:\Users\admin\Desktop\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2 pass 123\galaxy_swapper_v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4020"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Galaxy Swapper v2 Pass 123.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 608
Read events
2 572
Write events
36
Delete events
0

Modification events

(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4020) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Galaxy Swapper v2 Pass 123.zip
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
13
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.dllexecutable
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\DotNetZip.dllexecutable
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Galaxy_Swapper.dllexecutable
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Galaxy_Swapper_v2.exeexecutable
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Bunifu_UI_v1.52.dllexecutable
MD5:3764580D568E4FC506048E04DB90562C
SHA256:27C8CEA7E793ACE737415881A5C16B4E2D98CE46609D272E82C6C905AD2D9F36
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Readme.txttext
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Galaxy_Swapper.deps.jsontext
MD5:
SHA256:
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\K4os.Compression.LZ4.Streams.dllexecutable
MD5:6CB6006087B7A6DDFBD60244D95F95BE
SHA256:A4E3FF56B2A29E933CFCFAD7F9F281817CDDC69B71832A88A67F1E6DF89325A1
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\K4os.Hash.xxHash.dllexecutable
MD5:ED559F870FC1166B8AAC6FCBC3E3117D
SHA256:999C632C467DF0EC47DC68F75845266CD1A3704536AAC16E3D5A02086F8292AB
4020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4020.244\Galaxy Swapper v2 Pass 123\Newtonsoft.Json.dllexecutable
MD5:1F478E39A4C06EA7C6DCE92238F23EC1
SHA256:B9B4E633EA6C728BAD5F7CBBEF7F8B842F7E10181731DBE5EC3CD995A6F60287
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
3
Threats
4

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
US
whitelisted
1936
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
Microsoft Corporation
GB
whitelisted
564
Galaxy_Swapper_v2.exe
80.85.139.135:1855
Interstroom Informatietechnologie BV
NL
malicious
564
Galaxy_Swapper_v2.exe
81.177.141.85:443
tuq.ckauni.ru
JSC RTComm.RU
RU
malicious
3216
Galaxy_Swapper_v2.exe
80.85.139.135:1855
Interstroom Informatietechnologie BV
NL
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
tuq.ckauni.ru
  • 81.177.141.85
malicious

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
No debug info