File name:

proxy tools.rar

Full analysis: https://app.any.run/tasks/61ba7460-7936-4608-b8f5-0756c114fda6
Verdict: Malicious activity
Analysis date: January 20, 2019, 04:07:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0130375D151326539DC75770078BAEBC

SHA1:

1459C1880F6F2B4B402F8BD482317D4935FD78E2

SHA256:

1C86F99EB36960058F800D7619EF332CD119992B78E4511CEE2B214947AA085E

SSDEEP:

393216:bug/etTqF+/UTWVueIM71uIB99P7HlQ8601n60bcXxQMA37OX/J:beBqF+8KueIQjJTFdd6bB7AreJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2848)
      • Proxy Buddy.exe (PID: 2276)
    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2848)
      • Proxy Buddy.exe (PID: 3856)
      • Proxy Buddy.exe (PID: 2276)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3388)
      • WinRAR.exe (PID: 2908)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2908)
      • WinRAR.exe (PID: 2852)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 10065
UncompressedSize: 10086
OperatingSystem: Win32
ModifyDate: 2018:09:20 00:13:27
PackingMethod: Normal
ArchivedFileName: Proxy Grabber by Mathian.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs winrar.exe gather proxy.exe winrar.exe proxy buddy.exe no specs proxy buddy.exe

Process information

PID
CMD
Path
Indicators
Parent process
2276"C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe
WinRAR.exe
User:
admin
Company:
GSoftwareLab
Integrity Level:
HIGH
Description:
Proxy Buddy
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2852.32299\proxy buddy v1.5 cracked by pc-ret\proxy buddy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2848"C:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Gather Proxy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Gather Proxy.exe
WinRAR.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 8.8 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
8.9.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2908.28651\gatherproxy v8.9 cracked by 3dsboy08\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2908.31259\Proxy Buddy v1.5 Cracked by PC-RET.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa3388.27320\GatherProxy v8.9 Cracked by 3DSBOY08.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3388"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\proxy tools.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3856"C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exeWinRAR.exe
User:
admin
Company:
GSoftwareLab
Integrity Level:
MEDIUM
Description:
Proxy Buddy
Exit code:
3221226540
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2852.32299\proxy buddy v1.5 cracked by pc-ret\proxy buddy.exe
c:\systemroot\system32\ntdll.dll
Total events
1 423
Read events
1 354
Write events
69
Delete events
0

Modification events

(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\proxy tools.rar
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
27
Suspicious files
2
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\geo.mmdb
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\agents.txttext
MD5:8520DC38FF84C55CEFA74D492D271DA4
SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\planetlab.txttext
MD5:4AA755C53F5741125462955E02440DD1
SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\FacebookAPIClass.dllexecutable
MD5:5F13FF94ECD5DEC20E90C1D5F2FEA13A
SHA256:CB2BC93CA31653C3297C3D07875E1AF9545F00D5BEB9C13762C3FD3525F4FB4C
2852WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\data\bannedips.csv
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\ref.reftext
MD5:EDF1E41F9FE226BE3E61845B747A2C6E
SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\HtmlAgilityPack.dllexecutable
MD5:B768306987227D31BF07277C1AE65A57
SHA256:DB48B1FEA16C5DA3B80CBDE4D351D614957240CA70213FA82B6A7535B02AAF28
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\MaxMind.Db.dllexecutable
MD5:4D1FC03277F904C3172A4C23ED36B032
SHA256:68540771C4099BAB7A26AB31F59F92E12182B9050D84E625BE7BD5778871F475
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Gather Proxy.exeexecutable
MD5:12683F462645A4A152A7BC579856B0F9
SHA256:9C1C87ABF7A1FBFF43007F4310F3A722AD6798EC4C42D599509C5C3E3D214284
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2848
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=fRBlQe0FWLv8WJzDbjNG%2ff9VJ7wZ3ikvbwvW1xRIsYvT%2bZug%2b%2f%2b29k2NZPMan1iHM%2fkhsJipxaVK6%2b6xNW41JDwIHmMNXVD3vOgK%2fWmSSOTpFyQ1Kp%2b9VkknWF39kTpL9aH1KDYXQLQcErh%2bLnR4N%2f7w0BPWtefVqzDN2gOiTvLhZiEgt%2fGgwXjYEw0hQwcZ
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2848
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info