File name:

tokengrab-x86.zip

Full analysis: https://app.any.run/tasks/4fdb1f6f-c9f4-4491-be5b-37934c168823
Verdict: Malicious activity
Analysis date: June 27, 2023, 11:24:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

ABDDE44FEC1B7028FE8B5D75C3C8AE1F

SHA1:

99EB82AFB5204135DF5942B789E80C587893C430

SHA256:

1CF310487504506837B1BDD40339CD79ECA4E40D4CFD1A51B3CFD4AEAA9E94C0

SSDEEP:

1536:tTDPYZsMMSLJwM3HHNNFN4jwiO3zLfdKC7KelPu5qp:V2HLJwEHPfEwZzDAhelusp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • tokengrab.exe (PID: 2876)
      • tokengrab.exe (PID: 1092)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • tokengrab.exe (PID: 2876)
      • tokengrab.exe (PID: 1092)
    • Checks supported languages

      • tokengrab.exe (PID: 2876)
      • tokengrab.exe (PID: 1092)
    • Manual execution by a user

      • tokengrab.exe (PID: 1092)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: tokengrab.dll
ZipUncompressedSize: 12288
ZipCompressedSize: 5266
ZipCRC: 0x62016a46
ZipModifyDate: 2023:06:27 13:18:02
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe tokengrab.exe searchprotocolhost.exe no specs tokengrab.exe

Process information

PID
CMD
Path
Indicators
Parent process
1092"C:\Users\admin\Desktop\tokengrab.exe" C:\Users\admin\Desktop\tokengrab.exe
explorer.exe
User:
admin
Company:
tokengrab
Integrity Level:
MEDIUM
Description:
tokengrab
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\tokengrab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
2216"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2876"C:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.exe
WinRAR.exe
User:
admin
Company:
tokengrab
Integrity Level:
MEDIUM
Description:
tokengrab
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3140.5672\tokengrab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3140"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\tokengrab-x86.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
1 042
Read events
1 023
Write events
19
Delete events
0

Modification events

(PID) Process:(3140) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.dllexecutable
MD5:F60E89782D0B9FDA8B9B4719D4DD1517
SHA256:F99C5701271AE646CE4224A3567D08BEA5955FAED758F5DEA16ACA46FC638FEF
3140WinRAR.exeC:\Users\admin\Desktop\tokengrab.pdbbinary
MD5:A17A4481A32E115F4B6E732C799EB0AA
SHA256:FC7AEA39BB9CB5636ABB640B46AD22B5A51427B7E0918DA48D0D54BF13B60F4D
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.pdbbinary
MD5:A17A4481A32E115F4B6E732C799EB0AA
SHA256:FC7AEA39BB9CB5636ABB640B46AD22B5A51427B7E0918DA48D0D54BF13B60F4D
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.exeexecutable
MD5:29DE64F0EBCC2FE3DDE9216D1C6FB5B7
SHA256:51A27B751AF8A1D8BDCDDEE4B78F2F5CADE117F149514C3D24AC3208EA1DE824
3140WinRAR.exeC:\Users\admin\Desktop\tokengrab.dllexecutable
MD5:F60E89782D0B9FDA8B9B4719D4DD1517
SHA256:F99C5701271AE646CE4224A3567D08BEA5955FAED758F5DEA16ACA46FC638FEF
3140WinRAR.exeC:\Users\admin\Desktop\tokengrab.exeexecutable
MD5:29DE64F0EBCC2FE3DDE9216D1C6FB5B7
SHA256:51A27B751AF8A1D8BDCDDEE4B78F2F5CADE117F149514C3D24AC3208EA1DE824
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2624
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
tokengrab.exe
You must install .NET to run this application. App: C:\Users\admin\AppData\Local\Temp\Rar$EXa3140.5672\tokengrab.exe Architecture: x86 App host version: 6.0.19 .NET location: Not found Learn about runtime installation: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x86&rid=win7-x86&apphost_version=6.0.19
tokengrab.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\tokengrab.exe Architecture: x86 App host version: 6.0.19 .NET location: Not found Learn about runtime installation: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x86&rid=win7-x86&apphost_version=6.0.19