File name:

proxy tools.rar

Full analysis: https://app.any.run/tasks/61ba7460-7936-4608-b8f5-0756c114fda6
Verdict: Malicious activity
Analysis date: January 20, 2019, 04:07:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0130375D151326539DC75770078BAEBC

SHA1:

1459C1880F6F2B4B402F8BD482317D4935FD78E2

SHA256:

1C86F99EB36960058F800D7619EF332CD119992B78E4511CEE2B214947AA085E

SSDEEP:

393216:bug/etTqF+/UTWVueIM71uIB99P7HlQ8601n60bcXxQMA37OX/J:beBqF+8KueIQjJTFdd6bB7AreJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Gather Proxy.exe (PID: 2848)
      • Proxy Buddy.exe (PID: 2276)
    • Application was dropped or rewritten from another process

      • Gather Proxy.exe (PID: 2848)
      • Proxy Buddy.exe (PID: 3856)
      • Proxy Buddy.exe (PID: 2276)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3388)
      • WinRAR.exe (PID: 2908)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2908)
      • WinRAR.exe (PID: 2852)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 10065
UncompressedSize: 10086
OperatingSystem: Win32
ModifyDate: 2018:09:20 00:13:27
PackingMethod: Normal
ArchivedFileName: Proxy Grabber by Mathian.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs winrar.exe gather proxy.exe winrar.exe proxy buddy.exe no specs proxy buddy.exe

Process information

PID
CMD
Path
Indicators
Parent process
2276"C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe
WinRAR.exe
User:
admin
Company:
GSoftwareLab
Integrity Level:
HIGH
Description:
Proxy Buddy
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2852.32299\proxy buddy v1.5 cracked by pc-ret\proxy buddy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2848"C:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Gather Proxy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Gather Proxy.exe
WinRAR.exe
User:
admin
Company:
GatherProxy.com
Integrity Level:
MEDIUM
Description:
Gather Proxy 8.8 - Free Pro Proxy and Socks Scraper
Exit code:
0
Version:
8.9.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2908.28651\gatherproxy v8.9 cracked by 3dsboy08\gather proxy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2908.31259\Proxy Buddy v1.5 Cracked by PC-RET.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa3388.27320\GatherProxy v8.9 Cracked by 3DSBOY08.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3388"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\proxy tools.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3856"C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\Proxy Buddy.exeWinRAR.exe
User:
admin
Company:
GSoftwareLab
Integrity Level:
MEDIUM
Description:
Proxy Buddy
Exit code:
3221226540
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2852.32299\proxy buddy v1.5 cracked by pc-ret\proxy buddy.exe
c:\systemroot\system32\ntdll.dll
Total events
1 423
Read events
1 354
Write events
69
Delete events
0

Modification events

(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\proxy tools.rar
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
27
Suspicious files
2
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\geo.mmdb
MD5:
SHA256:
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3388.27320\GatherProxy v8.9 Cracked by 3DSBOY08.rarcompressed
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\country.txttext
MD5:F349544550AB3FA73C515A02B1E28A46
SHA256:3E1DF9E1B2BCDD9223B8092D216F22472685788255441144F935795193454E24
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\autosp.initext
MD5:0AB7386476BFD6E6A7FDCAA91DA04D4F
SHA256:BA4DB1C4843A36822F68556D4F2AC5B815F3E7B063D28D8905FD6084B594EC40
2852WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2852.32299\Proxy Buddy v1.5 Cracked by PC-RET\data\bannedips.csv
MD5:
SHA256:
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\agents.txttext
MD5:8520DC38FF84C55CEFA74D492D271DA4
SHA256:FC73F46883AECB0AC9C944A2756CA2CF1AC0E60F963D92700C0DD62EADC3D72B
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\configs.gptext
MD5:84592DF7DFBE37A0FFD354ACC32EC930
SHA256:908A674AED0DC3815DEA44B67FA3290DA8B2B544C136FB14AD2EC4D696F692E4
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\ref.reftext
MD5:EDF1E41F9FE226BE3E61845B747A2C6E
SHA256:C78BA0953491DCCBD7EE2B03CF6AE3A295676715D524B278345FBB31245FBCD5
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\referrals.txttext
MD5:B5CE4C46FD94C0F038FB7E04B1EF6666
SHA256:04983579DE0B2559D6E55E6447AB60FA1AC97A8DE7FC91B79899DB496571736F
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2908.28651\GatherProxy v8.9 Cracked by 3DSBOY08\Data\planetlab.txttext
MD5:4AA755C53F5741125462955E02440DD1
SHA256:B26C86587F82AE186D1860BD03F71858C74F2E1DBA624E7FF85A9DE67FE80D56
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2848
Gather Proxy.exe
GET
200
97.74.233.74:80
http://update.snaware.com/auth/?k=fRBlQe0FWLv8WJzDbjNG%2ff9VJ7wZ3ikvbwvW1xRIsYvT%2bZug%2b%2f%2b29k2NZPMan1iHM%2fkhsJipxaVK6%2b6xNW41JDwIHmMNXVD3vOgK%2fWmSSOTpFyQ1Kp%2b9VkknWF39kTpL9aH1KDYXQLQcErh%2bLnR4N%2f7w0BPWtefVqzDN2gOiTvLhZiEgt%2fGgwXjYEw0hQwcZ
US
text
1.31 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2848
Gather Proxy.exe
97.74.233.74:80
update.snaware.com
GoDaddy.com, LLC
US
unknown

DNS requests

Domain
IP
Reputation
update.snaware.com
  • 97.74.233.74
malicious

Threats

No threats detected
No debug info