download:

Trojan-Qt5-Windows.7z

Full analysis: https://app.any.run/tasks/2e64b12b-3614-4d69-b26b-5fa683f35379
Verdict: Malicious activity
Analysis date: September 10, 2020, 07:28:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

54AEE2FB9A38EE0913FA00BEA143B49D

SHA1:

AB76E9FF54CE50BFB8E7DE37814FCB8F52311696

SHA256:

369D50BDE8985A01CA1D6C807E5098209ADF59540404D3D5584F0AB7F16523A0

SSDEEP:

393216:dyGykBica/DDy9PV2U2Gs32fjO/IOoYevoLhpCP5G13AILiZHoQHmxseAfxSWvRK:4GraqNsx2fjOQOoYkyhsP5GbLg4xse6E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • trojan-qt5.exe (PID: 796)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3536)
      • trojan-qt5.exe (PID: 796)
  • SUSPICIOUS

    • Creates files in the user directory

      • trojan-qt5.exe (PID: 796)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2492)
    • Modifies the open verb of a shell class

      • trojan-qt5.exe (PID: 796)
  • INFO

    • Manual execution by user

      • notepad.exe (PID: 3652)
      • trojan-qt5.exe (PID: 796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs trojan-qt5.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
796"C:\Users\admin\Desktop\Trojan-Qt5-Windows\trojan-qt5.exe" C:\Users\admin\Desktop\Trojan-Qt5-Windows\trojan-qt5.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\trojan-qt5-windows\trojan-qt5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\trojan-qt5-windows\libprotobuf.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2492"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Trojan-Qt5-Windows.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3536"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3652"C:\Windows\system32\notepad.exe" C:\Windows\system32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
763
Read events
685
Write events
78
Delete events
0

Modification events

(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2492) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2492) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Trojan-Qt5-Windows.7z
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Trojan-Qt5-Windows
Executable files
23
Suspicious files
1
Text files
10
Unknown types
22

Dropped files

PID
Process
Filename
Type
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_bg.qmqm
MD5:6BCB7BF161BBE019CFAEEE7D331E3E79
SHA256:47F5749032C655F8399563728B8E5591B796AABABB631D0BCA9F18D74F4ED6F0
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_cs.qmqm
MD5:987E045E06AEBA29A8E05A074E6BDB91
SHA256:86E174EFF79F096D81146860DD5CA9E946C643A3464C7DA8919C972747B8DF09
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_de.qmqm
MD5:73911D71DB30DE43F856D4EA9E911837
SHA256:AE34D874BD5A6D11A2EEE605E07A7C6DB2FFDBC998CEB8CFB7C346DD914332BB
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ca.qmqm
MD5:D1D7AB4DA8BC6A6097AF2DB42C9BD14E
SHA256:44C6B11B0F7BF6B6423D03089BCB603DA37CB9B46BA7B10B7DC07F75FDF9708F
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_da.qmqm
MD5:D541CC7F5EA2248E72D2E86CE6CBFA45
SHA256:423E88732439997DEB776F45F1B808F446F8023AB25FA925E949EC27724AB7E0
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_en.qmqm
MD5:4AEF4415F2E976B2CC6F24B877804A57
SHA256:307CEF95DD5B36FF215055D427E1885B7FC3650C9224CF76D63056545996FF60
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_fi.qmqm
MD5:FF556242E6061DAC90683223351ABD61
SHA256:D04666A656680BE2756B58CE45DB175B846C5928EB6AF62DBA841444DD10E03A
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ar.qmqm
MD5:E7EC8B6E07D62634777DBCB47BD611D3
SHA256:820EB8876A61022B371D557EEBD83A99A3872C6E93ACBF3E98026DFCB3CE8EFB
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ko.qmqm
MD5:D3EB25E0FFF5719E8840612727896B1D
SHA256:487755EB0841D47748CCBC2AB8D255CA12277DD0FB687D6DDC730982F8DA77BA
2492WinRAR.exeC:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_it.qmqm
MD5:B183FE971035ADA2E95401263C79AA3B
SHA256:54BDD9856E6007B443F553F03B5B83BCA9F08595BF18D3293663517F04E89333
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
796
trojan-qt5.exe
37.58.57.238:123
pool.ntp.org
Leaseweb Deutschland GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
pool.ntp.org
  • 37.58.57.238
  • 94.16.114.254
  • 173.249.33.207
  • 94.16.115.123
malicious

Threats

No threats detected
No debug info