File name:

uProxy Tool 2.0.rar

Full analysis: https://app.any.run/tasks/086db868-007b-4c0c-a062-e401a19c592a
Verdict: Malicious activity
Analysis date: May 02, 2019, 06:04:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2FCAA049CE024A32E77DC0FE281D3968

SHA1:

17839083B913392441338E05F33DCC08BF787015

SHA256:

33D28742CDA003D8EBE7914A83A2140CB2B2C153EB436D8B092589B1785FA43D

SSDEEP:

49152:P7l9cHpYZ9A5fq1kFzHJAVjjgM/8M1KUw/aF1dQULPtkvVXjWSkxYx2l:P0YZXiFzox8MKCjdnLPWNzxkrl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • uProxy Tool.exe (PID: 2480)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1816)
  • INFO

    • Reads settings of System Certificates

      • uProxy Tool.exe (PID: 2480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe uproxy tool.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1816"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\uProxy Tool 2.0.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2480"C:\Users\admin\AppData\Local\Temp\Rar$EXa1816.10160\uProxy Tool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1816.10160\uProxy Tool.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
uProxy Tool
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1816.10160\uproxy tool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3264"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Novo Documento de Texto.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
1 078
Read events
971
Write events
106
Delete events
1

Modification events

(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1816) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\uProxy Tool 2.0.rar
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1816) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(1816) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
1
Suspicious files
10
Text files
14
Unknown types
3

Dropped files

PID
Process
Filename
Type
1816WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1816.9954\Novo Documento de Texto.txt
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\CabF2B8.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\TarF2B9.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\CabF2CA.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\TarF2CB.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\CabF2DB.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\TarF2DC.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\CabF3A9.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\TarF3AA.tmp
MD5:
SHA256:
2480uProxy Tool.exeC:\Users\admin\AppData\Local\Temp\CabF3D9.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
56
TCP/UDP connections
136
DNS requests
14
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2480
uProxy Tool.exe
GET
120.79.135.209:443
http://azenv.net/
CN
suspicious
2480
uProxy Tool.exe
GET
45.77.130.80:80
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
146.145.199.114:8080
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
146.145.199.126:8080
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
146.145.199.98:8080
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
146.145.199.108:8080
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
185.162.128.135:9050
http://azenv.net/
NL
unknown
2480
uProxy Tool.exe
GET
184.174.74.144:51724
http://azenv.net/
GB
unknown
2480
uProxy Tool.exe
GET
146.145.199.112:8080
http://azenv.net/
US
unknown
2480
uProxy Tool.exe
GET
146.145.199.101:8080
http://azenv.net/
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2480
uProxy Tool.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious
2480
uProxy Tool.exe
46.105.57.150:26804
OVH SAS
FR
suspicious
2480
uProxy Tool.exe
46.105.99.152:33014
OVH SAS
FR
suspicious
2480
uProxy Tool.exe
146.145.199.114:8080
ATX Telecommunications Services
US
unknown
2480
uProxy Tool.exe
146.145.199.98:8080
ATX Telecommunications Services
US
unknown
2480
uProxy Tool.exe
46.105.99.152:50793
OVH SAS
FR
suspicious
2480
uProxy Tool.exe
46.105.99.152:3147
OVH SAS
FR
suspicious
2480
uProxy Tool.exe
46.105.99.152:19296
OVH SAS
FR
suspicious
2480
uProxy Tool.exe
185.162.128.135:9006
Hosting Solution Ltd.
NL
unknown
2480
uProxy Tool.exe
46.105.99.152:61860
OVH SAS
FR
suspicious

DNS requests

Domain
IP
Reputation
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared
x.ss2.us
  • 52.85.182.102
  • 52.85.182.72
  • 52.85.182.31
  • 52.85.182.64
whitelisted
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
www.proxydocker.com
  • 164.132.235.17
unknown
sslproxies24.blogspot.in
  • 216.58.207.33
whitelisted
www.proxyserverlist24.top
  • 216.58.205.243
whitelisted
www.live-socks.net
  • 216.58.205.243
whitelisted
proxyunique.com
  • 144.217.88.10
suspicious
www.sslproxies24.top
  • 216.58.205.243
whitelisted

Threats

PID
Process
Class
Message
1056
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
2480
uProxy Tool.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
No debug info