analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

OqMineBot.zip

Full analysis: https://app.any.run/tasks/960a9ec4-3317-40c9-a4a3-d1f3897a831b
Verdict: Malicious activity
Analysis date: January 18, 2019, 21:51:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

75D78B2F023B13B8854BF005411C1E79

SHA1:

C2A2E08C8E4A11E8711DBC9CC344E18861208B60

SHA256:

44D52F3CA0062743A931F7CFD7F8B110679295B2FF85E3B545A1177399415890

SSDEEP:

49152:t4+l0ljAAckfK3v8wJH3CVf6lYWRlnZDycI+NBegkYKR0FqTby1VSUok8NxvH:t4KQck4rH3SCYWFlI2B+2FRDSUoDL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • OQ.MineBot.GUI.exe (PID: 2444)
      • SearchProtocolHost.exe (PID: 1200)
      • OQ.MineBot.GUI.exe (PID: 3072)
      • OQ.MineBot.GUI.exe (PID: 3708)
    • Application was dropped or rewritten from another process

      • OQ.MineBot.GUI.exe (PID: 2444)
      • OQ.MineBot.GUI.exe (PID: 3708)
      • OQ.MineBot.GUI.exe (PID: 3072)
  • SUSPICIOUS

    • Connects to unusual port

      • OQ.MineBot.GUI.exe (PID: 2444)
      • OQ.MineBot.GUI.exe (PID: 3072)
      • OQ.MineBot.GUI.exe (PID: 3708)
    • Reads Environment values

      • OQ.MineBot.GUI.exe (PID: 2444)
      • OQ.MineBot.GUI.exe (PID: 3072)
      • OQ.MineBot.GUI.exe (PID: 3708)
    • Creates files in the user directory

      • OQ.MineBot.GUI.exe (PID: 2444)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2884)
  • INFO

    • Reads settings of System Certificates

      • OQ.MineBot.GUI.exe (PID: 2444)
      • OQ.MineBot.GUI.exe (PID: 3072)
      • OQ.MineBot.GUI.exe (PID: 3708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Antlr3.Runtime.dll
ZipUncompressedSize: 103424
ZipCompressedSize: 43817
ZipCRC: 0x46a327ea
ZipModifyDate: 2018:12:08 00:53:12
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs oq.minebot.gui.exe oq.minebot.gui.exe oq.minebot.gui.exe

Process information

PID
CMD
Path
Indicators
Parent process
2884"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\OqMineBot.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
1200"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
2444"C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe" C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
OQ.MineBot
Exit code:
3221225786
Version:
1.0.0.0
3708"C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe" C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OQ.MineBot
Exit code:
0
Version:
1.0.0.0
3072"C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe" C:\Users\admin\Desktop\Minebot\OQ.MineBot.GUI.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
OQ.MineBot
Exit code:
0
Version:
1.0.0.0
Total events
907
Read events
866
Write events
41
Delete events
0

Modification events

(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2884) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OqMineBot.zip
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2884) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2444) OQ.MineBot.GUI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
OQ.MineBot.GUI.exe
(PID) Process:(2444) OQ.MineBot.GUI.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
16
Suspicious files
9
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2444OQ.MineBot.GUI.exeC:\Users\admin\AppData\Local\Temp\Cab21C2.tmp
MD5:
SHA256:
2444OQ.MineBot.GUI.exeC:\Users\admin\AppData\Local\Temp\Tar21C3.tmp
MD5:
SHA256:
2444OQ.MineBot.GUI.exeC:\Users\admin\AppData\Local\Temp\Cab21D3.tmp
MD5:
SHA256:
2444OQ.MineBot.GUI.exeC:\Users\admin\AppData\Local\Temp\Tar21D4.tmp
MD5:
SHA256:
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\OQ.MineBot.GUI.exeexecutable
MD5:6977D58B0FB31209871CCE8EDD76A2A5
SHA256:0811912B0493CA7896AE428444AB78F6AB1E4D5003045ECD6E848732962A21A2
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\MinecraftIds.exeexecutable
MD5:6926EA666C7CE10DD32CC39D7E56A3B5
SHA256:045204F5BFA52B491344158D4BF3852ACDC630D7D2C71DF956E5C5E67F2FA9D0
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\starksoft.aspen.dllexecutable
MD5:2F96049C08E6FAD65603878D00DC7044
SHA256:4189D0D903F9A3EAA9C07D882F8F691B9503BF9C8DD9868AA9598FAC75333A5A
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\Refit.dllexecutable
MD5:03FAA07C6705A00FB3FCD21341CDB6D7
SHA256:43DC6E6E4B81EAF3FBB15723DD89327A6DFF502C19616ABCE747061144AAE636
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\Newtonsoft.Json.dllexecutable
MD5:A94583EE47F673118B0BF822BF8E425D
SHA256:030E739CBA60C3B4604EE1574497AEBC892B7CEB0CE44DD39FD1EF7767A2F134
2884WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2884.34085\OQ.MineBot.PluginBase.dllexecutable
MD5:FFCC3B054E6F25F206989A26CCEB936D
SHA256:F1CA22B89FB9A0376808E3533530045BD0E573635873769F4C1351830E3F607C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2444
OQ.MineBot.GUI.exe
GET
200
2.16.186.81:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2444
OQ.MineBot.GUI.exe
2.16.186.81:80
www.download.windowsupdate.com
Akamai International B.V.
whitelisted
2444
OQ.MineBot.GUI.exe
144.217.162.188:49248
www.minecraftbot.com
OVH SAS
CA
unknown
3708
OQ.MineBot.GUI.exe
144.217.162.188:49248
www.minecraftbot.com
OVH SAS
CA
unknown
3072
OQ.MineBot.GUI.exe
144.217.162.188:49248
www.minecraftbot.com
OVH SAS
CA
unknown

DNS requests

Domain
IP
Reputation
www.minecraftbot.com
  • 144.217.162.188
malicious
www.download.windowsupdate.com
  • 2.16.186.81
  • 2.16.186.56
whitelisted

Threats

No threats detected
No debug info