File name:

Polaris Bios Editor 1.7.4.zip

Full analysis: https://app.any.run/tasks/4f56cc9e-210c-406e-9f6c-49bfb86e2c58
Verdict: Malicious activity
Analysis date: November 25, 2020, 20:39:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

DF1AA1174BCCBB72F84804A835958943

SHA1:

79B5196743AD000092C21716C8021689FE703AC5

SHA256:

34D9030DF19ABBD44F886A1C847F66A77F8F387CD806453F3BC3B8E17FB74546

SSDEEP:

49152:8cv7+ppafvLqYJMyVfjXr8HZTs0sRvhF5LaXtge:Arafosbb8HZg0ivRkOe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Polaris Bios editor.exe (PID: 1872)
    • Application was dropped or rewritten from another process

      • PolarisBiosEditor.exe (PID: 1788)
      • 11232020-804.exe (PID: 2532)
    • Changes settings of System certificates

      • PolarisBiosEditor.exe (PID: 1788)
    • Loads dropped or rewritten executable

      • Polaris Bios editor.exe (PID: 1872)
      • Polaris Bios editor.exe (PID: 2824)
  • SUSPICIOUS

    • Application launched itself

      • Polaris Bios editor.exe (PID: 496)
      • Polaris Bios editor.exe (PID: 2824)
    • Reads Windows owner or organization settings

      • Polaris Bios editor.exe (PID: 1872)
      • Polaris Bios editor.exe (PID: 2824)
    • Reads the Windows organization settings

      • Polaris Bios editor.exe (PID: 2824)
      • Polaris Bios editor.exe (PID: 1872)
    • Executable content was dropped or overwritten

      • Polaris Bios editor.exe (PID: 1872)
    • Drops a file with too old compile date

      • Polaris Bios editor.exe (PID: 1872)
    • Drops a file that was compiled in debug mode

      • Polaris Bios editor.exe (PID: 1872)
    • Creates files in the user directory

      • Polaris Bios editor.exe (PID: 1872)
    • Drops a file with a compile date too recent

      • Polaris Bios editor.exe (PID: 1872)
    • Creates files in the program directory

      • Polaris Bios editor.exe (PID: 1872)
    • Adds / modifies Windows certificates

      • PolarisBiosEditor.exe (PID: 1788)
  • INFO

    • Manual execution by user

      • Polaris Bios editor.exe (PID: 496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:11:23 08:06:15
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Polaris Bios Editor 1.7.4.0/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs polaris bios editor.exe no specs polaris bios editor.exe polaris bios editor.exe polarisbioseditor.exe 11232020-804.exe no specs extrac32.exe

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe" C:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exeexplorer.exe
User:
admin
Company:
mining-bios.europe
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\polaris bios editor 1.7.4.0\polaris bios editor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1692"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Polaris Bios Editor 1.7.4.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1788"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PolarisBiosEditor.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PolarisBiosEditor.exe
Polaris Bios editor.exe
User:
admin
Company:
https://mining-bios.eu
Integrity Level:
HIGH
Description:
PolarisBiosEditor
Exit code:
0
Version:
1.7.4.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\polarisbioseditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1872"C:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe" /VERYSILENTC:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe
Polaris Bios editor.exe
User:
admin
Company:
mining-bios.europe
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\polaris bios editor 1.7.4.0\polaris bios editor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2532"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\11232020-804.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\11232020-804.exePolaris Bios editor.exe
User:
admin
Company:
Windows Winhlp32 Stub
Integrity Level:
HIGH
Description:
Windows Winhlp32 Stub
Exit code:
0
Version:
10.0.19042.5
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\11232020-804.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
2824"C:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe" /SPAWNWND=$101E4 /NOTIFYWND=$101E4 C:\Users\admin\Desktop\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe
Polaris Bios editor.exe
User:
admin
Company:
mining-bios.europe
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\desktop\polaris bios editor 1.7.4.0\polaris bios editor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2852"C:\Windows\system32\extrac32.exe"C:\Windows\system32\extrac32.exe
11232020-804.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® CAB File Extract Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\extrac32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
Total events
803
Read events
748
Write events
55
Delete events
0

Modification events

(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1692) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Polaris Bios Editor 1.7.4.zip
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2824) Polaris Bios editor.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2824) Polaris Bios editor.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
3
Suspicious files
0
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\App.config
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\bios.png
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\build.sh
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\notice
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\Polaris Bios editor-0.bin
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\Polaris Bios editor-1.bin
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\Polaris Bios editor.exe
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\PolarisBiosEditor.cs
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\PolarisBiosEditor.csproj
MD5:
SHA256:
1692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1692.13436\Polaris Bios Editor 1.7.4.0\README.md
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1788
PolarisBiosEditor.exe
151.101.192.133:443
raw.githubusercontent.com
Fastly
US
suspicious
151.101.12.193:443
i.imgur.com
Fastly
US
malicious
2852
extrac32.exe
151.101.12.193:443
i.imgur.com
Fastly
US
malicious

DNS requests

Domain
IP
Reputation
raw.githubusercontent.com
  • 151.101.192.133
  • 151.101.64.133
  • 151.101.0.133
  • 151.101.128.133
shared
i.imgur.com
  • 151.101.12.193
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info