File name:

__.exe

Full analysis: https://app.any.run/tasks/135b5eb1-6fd5-4d41-8428-17d5fc4c0d10
Verdict: Malicious activity
Threats:

zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.

Analysis date: March 29, 2024, 23:04:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
zgrat
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5:

5FD249A523F8006DAE95752B5CF9BF49

SHA1:

E6E02DA45574070C899C51F2400F9BD3171B02F0

SHA256:

443B3B9929156D71ED73E99850A671A89D4D0D38CC8ACC7F286696DD4F24895E

SSDEEP:

3072:XchRVv3/O4FLrFGJn/xRSPB61FsYqcmQTgRB:XK//O41mQYqS0X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • __.exe (PID: 2292)
      • setup.exe (PID: 748)
      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
      • AdGuardVpnSvc.exe (PID: 3132)
    • Changes the autorun value in the registry

      • installer.exe (PID: 1368)
      • setup.exe (PID: 3068)
    • [YARA] zgRAT detected by memory dumps

      • AdGuardVpnSvc.exe (PID: 3132)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
    • Adds/modifies Windows certificates

      • __.exe (PID: 2292)
      • AdGuardVpnSvc.exe (PID: 3132)
    • Reads the Internet Settings

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • AdGuardVpn.exe (PID: 4032)
    • Reads security settings of Internet Explorer

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • AdGuardVpn.exe (PID: 4032)
      • AdGuardVpnSvc.exe (PID: 3132)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 3068)
    • Process drops legitimate windows executable

      • setup.exe (PID: 3068)
    • Creates a software uninstall entry

      • installer.exe (PID: 1368)
    • Searches for installed software

      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
    • Process requests binary or script from the Internet

      • setup.exe (PID: 3068)
    • Starts itself from another location

      • setup.exe (PID: 3068)
    • Checks Windows Trust Settings

      • __.exe (PID: 2292)
      • AdGuardVpnSvc.exe (PID: 3132)
    • Executes as Windows Service

      • AdGuardVpnSvc.exe (PID: 3132)
    • Starts CMD.EXE for commands execution

      • AdGuardVpnSvc.exe (PID: 3132)
    • Starts SC.EXE for service management

      • setup.exe (PID: 3068)
      • AdGuardVpnSvc.exe (PID: 3132)
    • Process uses IPCONFIG to clear DNS cache

      • cmd.exe (PID: 3588)
    • The process executes via Task Scheduler

      • AdGuardVpn.exe (PID: 4032)
  • INFO

    • Checks proxy server information

      • __.exe (PID: 2292)
    • Checks supported languages

      • __.exe (PID: 2292)
      • setup.exe (PID: 748)
      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
      • AdGuardVpnSvc.exe (PID: 3132)
      • AdGuardVpn.exe (PID: 4032)
    • Reads the computer name

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
      • AdGuardVpnSvc.exe (PID: 3132)
      • AdGuardVpn.exe (PID: 4032)
    • Reads the machine GUID from the registry

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
      • AdGuardVpnSvc.exe (PID: 3132)
      • AdGuardVpn.exe (PID: 4032)
    • Reads the software policy settings

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • AdGuardVpnSvc.exe (PID: 3132)
    • Create files in a temporary directory

      • __.exe (PID: 2292)
      • setup.exe (PID: 3068)
      • installer.exe (PID: 1368)
    • Creates files or folders in the user directory

      • __.exe (PID: 2292)
      • AdGuardVpn.exe (PID: 4032)
    • Reads Environment values

      • setup.exe (PID: 3068)
      • AdGuardVpnSvc.exe (PID: 3132)
      • AdGuardVpn.exe (PID: 4032)
    • Creates files in the program directory

      • installer.exe (PID: 1368)
      • setup.exe (PID: 3068)
      • AdGuardVpnSvc.exe (PID: 3132)
      • AdGuardVpn.exe (PID: 4032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:12:07 14:17:23+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.39
CodeSize: 45568
InitializedDataSize: 102912
UninitializedDataSize: 3072
EntryPoint: 0x14b0
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: AdGuard Web Installer
LegalCopyright: (C) 2009-2018 Adguard Software Ltd
ProductName: AdGuard Web Installer
ProductVersion: 1
CompanyName: Adguard Software Ltd
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
18
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start __.exe setup.exe no specs setup.exe installer.exe #ZGRAT adguardvpnsvc.exe sc.exe no specs cmd.exe no specs schtasks.exe no specs sc.exe no specs sc.exe no specs cmd.exe no specs ipconfig.exe no specs cmd.exe no specs schtasks.exe no specs adguardvpn.exe cmd.exe no specs schtasks.exe no specs __.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"sc" sdset "Adguard VPN Service" D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCRPLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)C:\Windows\System32\sc.exeAdGuardVpnSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
748C:\Users\admin\AppData\Local\Temp\adguard\setup.exe "AID=31220"C:\Users\admin\AppData\Local\Temp\adguard\setup.exe__.exe
User:
admin
Company:
Adguard Software Limited
Integrity Level:
HIGH
Description:
AdGuardVPN
Exit code:
0
Version:
2.2.1271.0
Modules
Images
c:\users\admin\appdata\local\temp\adguard\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
884schtasks /create /xml "C:\ProgramData\AdguardVPN\config-aa344b842501496483068a4b7b0fb6d1.xml" /tn aa344b842501496483068a4b7b0fb6d1 /fC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1368"C:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.be\installer.exe" -q -burn.elevated BurnPipe.{8EA901E1-22BE-4614-8B4C-F911C13FAD63} {850D3048-3FFD-4685-A131-4BD0078995F4} 3068C:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.be\installer.exe
setup.exe
User:
admin
Company:
Adguard Software Limited
Integrity Level:
HIGH
Description:
AdGuardVPN
Exit code:
0
Version:
2.2.1271.0
Modules
Images
c:\windows\temp\{4b951ffd-ac3f-4dc8-9d75-d9dbf2495cdb}\.be\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2292"C:\Users\admin\AppData\Local\Temp\__.exe" C:\Users\admin\AppData\Local\Temp\__.exe
explorer.exe
User:
admin
Company:
Adguard Software Ltd
Integrity Level:
HIGH
Description:
AdGuard Web Installer
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\__.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2500"cmd.exe" /C "schtasks /delete /tn aa344b842501496483068a4b7b0fb6d1 /f"C:\Windows\System32\cmd.exeAdGuardVpnSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2512schtasks /delete /tn aa344b842501496483068a4b7b0fb6d1 /fC:\Windows\System32\schtasks.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2824"sc" sdshow "Adguard VPN Service"C:\Windows\System32\sc.exeAdGuardVpnSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2868"sc" query adgvpnnetworktdidrvC:\Windows\System32\sc.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3068"C:\Windows\Temp\{4BA88BF7-21B9-41C2-BE67-5C282B3E4E29}\.cr\setup.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\adguard\setup.exe" -burn.filehandle.attached=268 -burn.filehandle.self=276 "AID=31220"C:\Windows\Temp\{4BA88BF7-21B9-41C2-BE67-5C282B3E4E29}\.cr\setup.exe
setup.exe
User:
admin
Company:
Adguard Software Limited
Integrity Level:
HIGH
Description:
AdGuardVPN
Exit code:
0
Version:
2.2.1271.0
Modules
Images
c:\windows\temp\{4ba88bf7-21b9-41c2-be67-5c282b3e4e29}\.cr\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
23 158
Read events
22 954
Write events
174
Delete events
30

Modification events

(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2292) __.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
89
Suspicious files
5
Text files
40
Unknown types
101

Dropped files

PID
Process
Filename
Type
2292__.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2292__.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:
SHA256:
2292__.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:
SHA256:
2292__.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\installer[1].exeexecutable
MD5:
SHA256:
2292__.exeC:\Users\admin\AppData\Local\Temp\adguard\setup.exeexecutable
MD5:
SHA256:
748setup.exeC:\Windows\Temp\{4BA88BF7-21B9-41C2-BE67-5C282B3E4E29}\.cr\setup.exeexecutable
MD5:
SHA256:
3068setup.exeC:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.ba\mbahost.dllexecutable
MD5:
SHA256:
3068setup.exeC:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.ba\BootstrapperCore.dllexecutable
MD5:
SHA256:
3068setup.exeC:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.ba\mbapreq.wxlxml
MD5:
SHA256:
3068setup.exeC:\Windows\Temp\{4B951FFD-AC3F-4DC8-9D75-D9DBF2495CDB}\.ba\1030\mbapreq.wxlxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
28
DNS requests
7
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2292
__.exe
GET
304
23.216.77.78:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?04b2dea8abd60a79
unknown
unknown
2292
__.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
unknown
3068
setup.exe
GET
301
156.146.33.138:80
http://static.adguard.com/installer.v1.0.json
unknown
unknown
3068
setup.exe
GET
200
23.216.77.78:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d9993a3118f4f6b2
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2292
__.exe
156.146.33.138:443
static.adguardvpn.com
Datacamp Limited
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2292
__.exe
23.216.77.78:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2292
__.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
3068
setup.exe
20.101.57.9:123
time.windows.com
unknown
3068
setup.exe
156.146.33.138:80
static.adguardvpn.com
Datacamp Limited
DE
unknown
3068
setup.exe
156.146.33.138:443
static.adguardvpn.com
Datacamp Limited
DE
unknown
3068
setup.exe
23.216.77.78:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
static.adguardvpn.com
  • 156.146.33.138
  • 212.102.56.178
  • 156.146.33.141
  • 195.181.170.19
  • 195.181.175.15
  • 195.181.175.40
  • 212.102.56.181
unknown
ctldl.windowsupdate.com
  • 23.216.77.78
  • 23.216.77.80
  • 23.216.77.62
  • 23.216.77.48
  • 23.216.77.81
  • 23.216.77.46
  • 23.216.77.44
  • 23.216.77.75
  • 23.216.77.69
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
time.windows.com
  • 20.101.57.9
whitelisted
static.adguard.com
  • 156.146.33.138
  • 156.146.33.140
  • 212.102.56.182
  • 212.102.56.179
  • 195.181.175.41
  • 195.181.175.15
  • 195.181.170.18
unknown
api.undersizedoutgoingmesh.xyz
  • 188.114.97.3
  • 188.114.96.3
unknown

Threats

PID
Process
Class
Message
920
rundll32.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
920
rundll32.exe
Misc activity
ET INFO Observed Google DNS over HTTPS Domain (dns .google in TLS SNI)
920
rundll32.exe
Misc activity
ET INFO Observed DNS Over HTTPS Domain (dns .alidns .com in TLS SNI)
No debug info