File name:

Proxy Finder Enterprise Edition.exe

Full analysis: https://app.any.run/tasks/df108f44-ed04-4fbc-a192-36a50536d948
Verdict: Malicious activity
Analysis date: December 10, 2023, 03:16:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0B76B73BCC7FC3E8A8C5C94E873BD764

SHA1:

9DC3BD786C94AC1C898B7A30B730EF981176E905

SHA256:

31BB3540B935F9123B177F7C3C32DE87B3BC51DD05A9510922879DC96BB3E104

SSDEEP:

24576:TnjuP60BgrOOdWuGifBjLZddjRt4qxckC:TnjuP60BgrOiWuGi5jLZddjRt4qxckC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Adds/modifies Windows certificates

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Reads settings of System Certificates

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Reads security settings of Internet Explorer

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Checks Windows Trust Settings

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
  • INFO

    • Reads the computer name

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
      • wmpnscfg.exe (PID: 3092)
    • Checks supported languages

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
      • wmpnscfg.exe (PID: 3092)
    • Reads the machine GUID from the registry

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Creates files or folders in the user directory

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Checks proxy server information

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3092)
    • Create files in a temporary directory

      • Proxy Finder Enterprise Edition.exe (PID: 1352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:10:22 18:01:09+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 393216
InitializedDataSize: 274944
UninitializedDataSize: -
EntryPoint: 0x326d5
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.0
ProductVersionNumber: 4.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: www.Dr-FarFar.com
CompanyName: Dr.FarFar | www.Dr-FarFar.com
FileDescription: Proxy Finder Enterprise Edition (ViP)
FileVersion: 4.0.0.0
InternalName: Proxy Finder Enterprise Edition.exe
LegalCopyright: Copyright © Dr.FarFar
LegalTrademarks: www.Dr-FarFar.com
OriginalFileName: Proxy Finder Enterprise Edition.exe
ProductName: Proxy Finder Enterprise Edition (ViP)
ProductVersion: 4.0.0.0
AssemblyVersion: 4.0.0.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start proxy finder enterprise edition.exe wmpnscfg.exe no specs proxy finder enterprise edition.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Users\admin\AppData\Local\Temp\Proxy Finder Enterprise Edition.exe" C:\Users\admin\AppData\Local\Temp\Proxy Finder Enterprise Edition.exe
explorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
HIGH
Description:
Proxy Finder Enterprise Edition (ViP)
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\proxy finder enterprise edition.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
1864"C:\Users\admin\AppData\Local\Temp\Proxy Finder Enterprise Edition.exe" C:\Users\admin\AppData\Local\Temp\Proxy Finder Enterprise Edition.exeexplorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
MEDIUM
Description:
Proxy Finder Enterprise Edition (ViP)
Exit code:
3221226540
Version:
4.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\proxy finder enterprise edition.exe
c:\windows\system32\ntdll.dll
3092"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
19 837
Read events
19 785
Write events
52
Delete events
0

Modification events

(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(1352) Proxy Finder Enterprise Edition.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47}
Operation:writeName:WpadDecisionTime
Value:
E2C5363A172BDA01
Executable files
0
Suspicious files
38
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\Local\Temp\tmp10B8.tmphtml
MD5:5E3C0CF593E78C0E9974746270634BB0
SHA256:630E21FA721047F89C03C797FEFCEC45170DFF456E1146D2F21E1C14A18E25EB
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:8AEAFC3E1414143E19B8E224612D6709
SHA256:BFAAECF49B19BD1F32B764FB44796DC1D68B216D0A5F6A38CB718823900738FA
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E21A44ACD52731318E7BCFA0A51E8910_2D9826F57BF59427C5895D4528AEB769binary
MD5:E0AAF0D7616CF63F4A947E6820ABC3D5
SHA256:838DB66B83A866911EA43C872289827B3E7CB92D835D88DEAED3317EC4D685DC
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:BA782E85C2416CDF2DCB345700AB6C53
SHA256:9F940DE89048B4B84284C04C0ED1A3A3F442F27B83EA16668F58B26EE95211E3
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E21A44ACD52731318E7BCFA0A51E8910_2D9826F57BF59427C5895D4528AEB769binary
MD5:67A663EEC5361D7FA51E87A3B24ADC2E
SHA256:3E88D5A6D5B0F3FF8640A2AA1B456EA26F2DED3A61853764CD4BB06D66985117
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:A73795947F57351CC7133210220C938B
SHA256:1AB005DA4117758CF12BB32A8F77B939095F6319EC64096C0F51153EC1AFDADE
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_862BA1770B2FEE013603D2FF9ABEAFDAder
MD5:E3D3D99C142561706E628E385C81FD21
SHA256:23B109562A00F172664ACEACB0FD7AA7B47183A723443CB67E7FFD5A7E55C8D8
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4C0CF7534171D84A18A692DFF4B4BCCCder
MD5:D8E9F56CEA040B03034F4896EE90D326
SHA256:20701C403FB64F68AE8CF2D5FB5D0BACBF825D2E893799F2D285A668BAFD18A2
1352Proxy Finder Enterprise Edition.exeC:\Users\admin\AppData\Local\Temp\Cab1698.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
196
TCP/UDP connections
210
DNS requests
62
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1352
Proxy Finder Enterprise Edition.exe
GET
302
3.33.130.190:80
http://proxy-list.biz/
unknown
html
142 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
302
142.54.187.20:80
http://proxy.6te.net/proxy.php?id=latest
unknown
html
227 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
410
3.64.163.50:80
http://www.proxyrss.com/proxylists/all.gz
unknown
html
110 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
410
3.64.163.50:80
http://www.proxyrss.com/proxylists/all.gz
unknown
html
110 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
301
141.164.58.109:80
http://www.proxylists.net/http.txt
unknown
html
162 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
301
91.229.90.155:80
http://www.samair.ru/proxy/fresh-proxy-list.htm
unknown
html
707 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
301
141.164.58.109:80
http://proxylists.net/http_highanon.txt
unknown
html
162 b
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
200
66.81.203.134:80
http://www.proxy-tool.com/168.txt.gz
unknown
html
1.35 Kb
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
200
198.144.184.20:80
http://proxy.ipcn.org/proxylist.html
unknown
html
3.91 Kb
unknown
1352
Proxy Finder Enterprise Edition.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ef0cb276c6261700
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1352
Proxy Finder Enterprise Edition.exe
3.33.130.190:80
proxy-list.biz
AMAZON-02
US
unknown
1352
Proxy Finder Enterprise Edition.exe
141.164.58.109:80
www.proxylists.net
AS-CHOOPA
KR
unknown
1352
Proxy Finder Enterprise Edition.exe
142.54.187.20:80
proxy.6te.net
NOCIX
US
unknown
1352
Proxy Finder Enterprise Edition.exe
3.64.163.50:80
www.proxyrss.com
AMAZON-02
DE
unknown
1352
Proxy Finder Enterprise Edition.exe
3.33.130.190:443
proxy-list.biz
AMAZON-02
US
unknown
1352
Proxy Finder Enterprise Edition.exe
91.229.90.155:80
www.samair.ru
LLC Baxet
UA
unknown

DNS requests

Domain
IP
Reputation
proxy.6te.net
  • 142.54.187.20
unknown
www.juntuan.net
  • 101.32.216.84
unknown
proxy-list.biz
  • 3.33.130.190
  • 15.197.148.33
whitelisted
www.proxylists.net
  • 141.164.58.109
unknown
proxylists.net
  • 141.164.58.109
unknown
proxy.ipcn.org
  • 198.144.184.20
unknown
www.samair.ru
  • 91.229.90.155
unknown
www.proxy-tool.com
  • 66.81.203.134
  • 66.81.203.9
  • 66.81.203.199
unknown
www.proxyrss.com
  • 3.64.163.50
unknown
www.proxyserverprivacy.com
  • 162.252.82.104
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
1352
Proxy Finder Enterprise Edition.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1352
Proxy Finder Enterprise Edition.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
No debug info