File name:

Steam hour booster mpgh_mpgh.net.zip

Full analysis: https://app.any.run/tasks/0c01dd47-c01c-40cb-8cc6-4edebc058878
Verdict: Malicious activity
Analysis date: January 27, 2019, 23:25:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B8CE29FEDECA3E4EE3C263BD855C985F

SHA1:

3D8AACE11EF0E7F4D4F8CFB5235AB6C714BE138C

SHA256:

328069748C399890FE36674DCC5695E4398F828D6A436755E4A05A57C17D1A36

SSDEEP:

98304:AmyVSLHwz1dAoZ1q3SYsu8il7BOO92f7W4BLhdZudQijqWN+pXGdapa0OmY:FyVSDwZ2pn8ilFOOY9BDU9GWW2oemY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SingleBoostr.exe (PID: 3840)
      • SearchProtocolHost.exe (PID: 1708)
      • HourBoostr.exe (PID: 3168)
    • Application was dropped or rewritten from another process

      • SingleBoostr.exe (PID: 3840)
      • HourBoostr.exe (PID: 3168)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2968)
    • Reads the machine GUID from the registry

      • HourBoostr.exe (PID: 3168)
    • Changes IE settings (feature browser emulation)

      • SingleBoostr.exe (PID: 3840)
    • Connects to unusual port

      • HourBoostr.exe (PID: 3168)
    • Creates files in the program directory

      • HourBoostr.exe (PID: 3168)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:01:15 16:06:16
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Steam hour booster mpgh_mpgh.net/HourBoostr/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs singleboostr.exe no specs singleboostr.game.exe no specs hourboostr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1708"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2968"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Steam hour booster mpgh_mpgh.net.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2996"C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\SingleBoostr\SingleBoostr.Game.exe" C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\SingleBoostr\SingleBoostr.Game.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SingleBoostr.Game
Exit code:
0
Version:
3.2.1
Modules
Images
c:\users\admin\desktop\steam hour booster mpgh_mpgh.net\singleboostr\singleboostr.game.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3168"C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\HourBoostr\HourBoostr.exe" C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\HourBoostr\HourBoostr.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
HourBoostr
Exit code:
0
Version:
3.2.1
Modules
Images
c:\users\admin\desktop\steam hour booster mpgh_mpgh.net\hourboostr\hourboostr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3840"C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\SingleBoostr\SingleBoostr.exe" C:\Users\admin\Desktop\Steam hour booster mpgh_mpgh.net\SingleBoostr\SingleBoostr.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SingleBoostr
Exit code:
0
Version:
3.2.1
Modules
Images
c:\users\admin\desktop\steam hour booster mpgh_mpgh.net\singleboostr\singleboostr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
841
Read events
808
Write events
33
Delete events
0

Modification events

(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Steam hour booster mpgh_mpgh.net.zip
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1708) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1708) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
25
Suspicious files
0
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\Settings.jsontext
MD5:
SHA256:
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\GlobalDB.hbtext
MD5:
SHA256:
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\HourBoostr.exeexecutable
MD5:14D147B084BEB8F4522338DD72B044DB
SHA256:83AA3FD68FB59C8B7A94D210DD5814AE40C2DBFF2FE7B114AB5601ED7500E601
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\netstandard.dllexecutable
MD5:A1180CC66D8184B3F713EFEA2569DD0B
SHA256:6504456B966FD4702BB8103234865051AAFCC23CCC9D8A248DEDE3D7A409DE14
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\Newtonsoft.Json.dllexecutable
MD5:2B770CEA3A15C2B0EB36E9061AC5BC64
SHA256:1C245F4C85C2ADA130BC59942C90B701C24C06EDBE3EB25838ED8DE4F852535C
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\Settings.exeexecutable
MD5:AD39FB135D8303B29F67FD3C56AFE1BF
SHA256:A666E0E68194E5A839293D033941F3C3B155960336B4A07619428045CFE7DAE1
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\Microsoft.Win32.Registry.dllexecutable
MD5:EC2F38296EC7D2DDB1BCA1A46120CA2A
SHA256:A277C4095D58AB0065F1EC458ED6A02A57A9F265F65C3292BD85E8C5E2B0A8A2
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\protobuf-net.dllexecutable
MD5:0328D67FC2071670F11CE17970B8ECDA
SHA256:0EDF2382691A7706CFA740D95DA85830560AD006D038D7F70CDA6D745C872F85
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\System.Globalization.Extensions.dllexecutable
MD5:5A05FC7075E65BEF125FE62C1FD8EA6E
SHA256:F2561608B95A34D2F625EFA8A50EFE614781F8DCB7248DB3D3D69EEF4570DABD
2968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2968.4563\Steam hour booster mpgh_mpgh.net\HourBoostr\System.Net.Http.dllexecutable
MD5:E2266732C01008C2D1E42F601BB928F5
SHA256:2A43D045E7A3D39494E88933AE3A3CAA0A8738192EC2EDFE44349DCC4106F46C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3168
HourBoostr.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious
3168
HourBoostr.exe
104.111.228.157:443
api.steampowered.com
Akamai International B.V.
NL
whitelisted
3168
HourBoostr.exe
162.254.196.84:27019
Valve Corporation
GB
unknown

DNS requests

Domain
IP
Reputation
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared
api.steampowered.com
  • 104.111.228.157
suspicious

Threats

No threats detected
No debug info