download:

APK+Easy+Tool+v1.50+portable.zip

Full analysis: https://app.any.run/tasks/3348bbd8-4eb9-4457-8269-27bcbbeb8234
Verdict: Malicious activity
Analysis date: June 18, 2018, 06:59:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D64460EB4DD1860BB94C6E16742867CF

SHA1:

FA403FCE201B4591E470F6E59A437BBB07016923

SHA256:

2AB1F286343537D35F34E7C7B9CA33E1ABDD75883E728837E3521625D2A733FC

SSDEEP:

393216:NoIJsz3dJb74UHXM6zEDh8+UtGqSswyOV:1JsrdJP4UHXM634qvH4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1172)
      • 7zFM.exe (PID: 3944)
    • Application was dropped or rewritten from another process

      • APK Easy Tool.exe (PID: 3716)
  • SUSPICIOUS

    • Reads internet explorer settings

      • APK Easy Tool.exe (PID: 3716)
    • Starts CMD.EXE for commands execution

      • APK Easy Tool.exe (PID: 3716)
    • Creates files in the user directory

      • APK Easy Tool.exe (PID: 3716)
    • Executable content was dropped or overwritten

      • 7zFM.exe (PID: 3944)
  • INFO

    • Dropped object may contain URL's

      • 7zFM.exe (PID: 3944)
      • APK Easy Tool.exe (PID: 3716)
    • Reads settings of System Certificates

      • APK Easy Tool.exe (PID: 3716)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:02:13 12:29:01
ZipCRC: 0x61cda964
ZipCompressedSize: 250674
ZipUncompressedSize: 667648
ZipFileName: APK Easy Tool.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7zfm.exe searchprotocolhost.exe no specs apk easy tool.exe cmd.exe no specs java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1172"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2104java -version C:\ProgramData\Oracle\Java\javapath\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\java.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2996"cmd.exe" /c "java -version "C:\Windows\system32\cmd.exeAPK Easy Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3716"C:\Users\admin\Desktop\APK Easy Tool.exe" C:\Users\admin\Desktop\APK Easy Tool.exe
explorer.exe
User:
admin
Company:
evildog1/iAH
Integrity Level:
MEDIUM
Description:
APK Easy Tool
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\apk easy tool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3944"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\APK+Easy+Tool+v1.50+portable.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
527
Read events
495
Write events
32
Delete events
0

Modification events

(PID) Process:(1172) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1172) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3716) APK Easy Tool.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\APK Easy Tool_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
9
Suspicious files
9
Text files
8
Unknown types
3

Dropped files

PID
Process
Filename
Type
39447zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86F13D74\APK Easy Tool.exeexecutable
MD5:
SHA256:
39447zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86F13D74\Resources\aapt.exeexecutable
MD5:
SHA256:
39447zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86F13D74\Resources\apksigner.jarjava
MD5:
SHA256:
3716APK Easy Tool.exeC:\Users\admin\AppData\Local\Temp\Cab926B.tmp
MD5:
SHA256:
3716APK Easy Tool.exeC:\Users\admin\AppData\Local\Temp\Tar926C.tmp
MD5:
SHA256:
3716APK Easy Tool.exeC:\Users\admin\AppData\Local\Temp\Cab927C.tmp
MD5:
SHA256:
3716APK Easy Tool.exeC:\Users\admin\AppData\Local\Temp\Tar927D.tmp
MD5:
SHA256:
39447zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86F13D74\Resources\zipalign.exeexecutable
MD5:
SHA256:
39447zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86F13D74\Changelog.txttext
MD5:
SHA256:
3716APK Easy Tool.exeC:\Users\admin\AppData\Local\Temp\Cab92DC.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3716
APK Easy Tool.exe
GET
301
104.192.143.12:80
http://evildog1.bitbucket.io/apkeasytool/index.html
US
suspicious
3716
APK Easy Tool.exe
GET
200
192.35.177.64:80
http://apps.identrust.com/roots/dstrootcax3.p7c
US
cat
893 b
shared
3716
APK Easy Tool.exe
GET
200
8.248.141.254:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
52.5 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3716
APK Easy Tool.exe
104.192.143.12:443
evildog1.bitbucket.io
ATLASSIAN PTY LTD
US
unknown
3716
APK Easy Tool.exe
104.192.143.12:80
evildog1.bitbucket.io
ATLASSIAN PTY LTD
US
unknown
3716
APK Easy Tool.exe
216.58.208.42:443
fonts.googleapis.com
Google Inc.
US
whitelisted
3716
APK Easy Tool.exe
192.35.177.64:80
apps.identrust.com
IdenTrust
US
malicious
3716
APK Easy Tool.exe
8.248.141.254:80
www.download.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
3716
APK Easy Tool.exe
172.217.23.131:443
fonts.gstatic.com
Google Inc.
US
whitelisted
3716
APK Easy Tool.exe
205.185.208.52:443
code.jquery.com
Highwinds Network Group, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
evildog1.bitbucket.io
  • 104.192.143.12
  • 104.192.143.11
  • 104.192.143.10
suspicious
fonts.googleapis.com
  • 216.58.208.42
whitelisted
code.jquery.com
  • 205.185.208.52
whitelisted
apps.identrust.com
  • 192.35.177.64
shared
fonts.gstatic.com
  • 172.217.23.131
whitelisted
www.download.windowsupdate.com
  • 8.248.141.254
  • 8.248.101.254
  • 8.253.190.120
  • 67.26.75.254
  • 8.248.103.254
whitelisted

Threats

No threats detected
No debug info