| File name: | CryptoBOX.zip |
| Full analysis: | https://app.any.run/tasks/08356468-4652-499c-8230-eeb66d7e91ca |
| Verdict: | Malicious activity |
| Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
| Analysis date: | September 13, 2019, 11:39:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | CCFA3B56BC2568106D2D7EAB9576C3FB |
| SHA1: | 7B0691180B3DF17206E816F212A2392847A954A9 |
| SHA256: | 247E028CFBBEA2740B11A3823588B8A1F766C87B06F2307D9A0CC0BD09581F01 |
| SSDEEP: | 49152:5KOfw491xKOfw491jSzW2DXRl8klLRUsWFbzFPFXVylj6ADD6147yiOWdGnmjNGg:QOI7OIASzrRl8+WFNPF4tDy4zdhAOI47 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:09:10 11:24:28 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CryptoBOX/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2196 | C:\Windows\system32\timeout.exe 3 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2360 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\CryptoBOX.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3256 | "C:\Users\admin\Desktop\CryptoBOX.exe" | C:\Users\admin\Desktop\CryptoBOX.exe | explorer.exe | ||||||||||||
User: admin Company: Crypto BOX Integrity Level: MEDIUM Description: Crypto BOX Exit code: 0 Version: 3.2 Modules
| |||||||||||||||
| 3412 | "C:\Windows\system32\cmd.exe" /c C:\Windows\system32\timeout.exe 3 & del "CryptoBOX.exe" | C:\Windows\system32\cmd.exe | — | CryptoBOX.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\CryptoBOX.zip | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (752) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEE00000086000000AE0400007B020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\bin\faucetCORE.dll | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\captcha\Captchamodex3.dll | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\core\Modeactivated.ini | text | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\faucetlist.txt | text | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\CryptoBOX.exe | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\PACAPIps.dll | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\IcdMSCom.dll | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\FrankPACAPI.dll | executable | |
MD5:— | SHA256:— | |||
| 2360 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2360.31291\CryptoBOX\core\Mode.dll | executable | |
MD5:— | SHA256:— | |||
| 3256 | CryptoBOX.exe | C:\Users\admin\AppData\Local\Temp\9622D276\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:6D778E83F74A4C7FE4C077DC279F6867 | SHA256:A97DCCA76CDB12E985DFF71040815F28508C655AB2B073512E386DD63F4DA325 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3256 | CryptoBOX.exe | POST | 200 | 91.227.16.126:80 | http://h141748.s26.test-hf.su/index.php | RU | binary | 4.27 Mb | malicious |
3256 | CryptoBOX.exe | POST | 200 | 91.227.16.126:80 | http://h141748.s26.test-hf.su/index.php | RU | text | 2 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3256 | CryptoBOX.exe | 91.227.16.126:80 | h141748.s26.test-hf.su | LLC Eximius | RU | malicious |
Domain | IP | Reputation |
|---|---|---|
h141748.s26.test-hf.su |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .su TLD (Soviet Union) Often Malware Related |
3256 | CryptoBOX.exe | A Network Trojan was detected | AV TROJAN Azorult CnC Beacon |
3256 | CryptoBOX.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult.Stealer HTTP Header |
3256 | CryptoBOX.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult Request |
3256 | CryptoBOX.exe | Potentially Bad Traffic | ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related |
3256 | CryptoBOX.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult Response |
3256 | CryptoBOX.exe | Potentially Bad Traffic | ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related |
3256 | CryptoBOX.exe | A Network Trojan was detected | ET TROJAN Generic - POST To .php w/Extended ASCII Characters (Likely Zeus Derivative) |
Process | Message |
|---|---|
CryptoBOX.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|