analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Steam Account Generator_mpgh.net.zip

Full analysis: https://app.any.run/tasks/c06c63d9-6e23-4030-88fd-b2e6577f0cdb
Verdict: Malicious activity
Analysis date: June 16, 2019, 06:31:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

10F40C776953EE0828F3DD4E4A8A4372

SHA1:

BB09D21FFA8B5AE689E9A8734CE78297E6E662D6

SHA256:

461E09A92A20C9C40D180EA73CE28DA85F73F3BCC1B1FBC87A73BB7CCEE4A8F2

SSDEEP:

24576:c1lSUXX8Ts7ud3kXQ7Wc8LLmJDnNBhupZlTHf7i7P3wtQwf4os3sEk/:cRX8Ts7uRkXQ7J8eJDxAvWPwf4OEU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • explorer.exe (PID: 2044)
      • SearchProtocolHost.exe (PID: 2920)
    • Application was dropped or rewritten from another process

      • SteamAccCreator.exe (PID: 1288)
      • SteamAccCreator.exe (PID: 320)
  • SUSPICIOUS

    • Starts Internet Explorer

      • SteamAccCreator.exe (PID: 1288)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2716)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2560)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3508)
    • Creates files in the user directory

      • iexplore.exe (PID: 3508)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:10:15 17:58:27
ZipCRC: 0x9f13d1b7
ZipCompressedSize: 18405
ZipUncompressedSize: 167296
ZipFileName: RestSharp.xml
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs explorer.exe no specs steamacccreator.exe no specs iexplore.exe iexplore.exe steamacccreator.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2716"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Steam Account Generator_mpgh.net.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
2044C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1288"C:\Users\admin\Documents\SteamAccCreator.exe" C:\Users\admin\Documents\SteamAccCreator.exeexplorer.exe
User:
admin
Company:
@DedSec1337
Integrity Level:
MEDIUM
Description:
SteamAccountGenerator
Exit code:
2148734720
Version:
1.1.2.0
2560"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
SteamAccCreator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3508"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2560 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
320"C:\Users\admin\Documents\SteamAccCreator.exe" C:\Users\admin\Documents\SteamAccCreator.exeexplorer.exe
User:
admin
Company:
@DedSec1337
Integrity Level:
MEDIUM
Description:
SteamAccountGenerator
Exit code:
2148734720
Version:
1.1.2.0
Total events
1 465
Read events
1 359
Write events
0
Delete events
0

Modification events

No data
Executable files
17
Suspicious files
4
Text files
25
Unknown types
4

Dropped files

PID
Process
Filename
Type
2716WinRAR.exeC:\Users\admin\Documents\SteamAccCreator.exeexecutable
MD5:218CA831AB8A3622AD5419117AF5CA39
SHA256:0B9A51E5C61B2515CE81F272C73C12DD86A9A9F4852912D27935FECB2A54772D
2716WinRAR.exeC:\Users\admin\Documents\SteamAccCreator.exe.configxml
MD5:B856C26BFC43CC1E2C4D23ACAD7DD9CC
SHA256:E4545F958516644574D0A39FE2D9FABA65FF7A8B0F87AFE61F71B29910194939
2716WinRAR.exeC:\Users\admin\Documents\RestSharp.xmlxml
MD5:13F24C6AE64C88ECB609520F0A4A5B36
SHA256:9721B32D25C3BA7F6D0351437EECAFF1FF1501C1D1336CE65357701BFF81CD33
2716WinRAR.exeC:\Users\admin\Documents\log\2019-04-06.logtext
MD5:E6ED5499D0C30FB222A1E9933540FE15
SHA256:153DE51A5050F1E32EE10B32AF8735B43726E38341268BEDDF512CE583E9B542
2716WinRAR.exeC:\Users\admin\Documents\System.Diagnostics.StackTrace.dllexecutable
MD5:C20C268EABDCC95DA38AD646A0AA0310
SHA256:E932B25F50E3B09DD7759FF5B9E9ABFA8FC115EA171B768164AE21387FEAC7E8
2716WinRAR.exeC:\Users\admin\Documents\Newtonsoft.Json.xmlxml
MD5:479550F04AE5BADDE08753E3F29E4FFE
SHA256:BFB2B3619BB456629CB3B3BB321FF751D06E1C04C8749E2114E85F4578EFD4B0
2716WinRAR.exeC:\Users\admin\Documents\System.Net.Http.dllexecutable
MD5:5A5E18C377228FDB1D3DB74F1140C1BF
SHA256:8646A26A64928866BBE8746F3323A1F446C5A28C10B6B81DF9BF4A08336B8C02
2716WinRAR.exeC:\Users\admin\Documents\Newtonsoft.Json.dllexecutable
MD5:D827DD8A8C4B2A2CFA23C7F90F3CCE95
SHA256:B66749B81E1489FCD8D754B2AD39EBE0DB681344E392A3F49DC9235643BDBD06
2716WinRAR.exeC:\Users\admin\Documents\System.Net.Sockets.dllexecutable
MD5:B59AF5CBDDAFDC5DC5FF3E34533D6857
SHA256:A4B4BB8B9BE478600F48E43AE8571E6C123F8130923067F10FC92546D0900FB6
2716WinRAR.exeC:\Users\admin\Documents\System.Security.SecureString.dllexecutable
MD5:A6DE3093FFB397AF3E4D2A91FA46B738
SHA256:9239DE3543EA4DCF71AD86F16AA23EEB760566BC69078925900D0E41EEC859AC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3508
iexplore.exe
GET
302
104.90.156.189:80
http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch&plcid=0x409&o1=.NETFramework,Version=v4.7.1&processName=SteamAccCreator.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.0
NL
whitelisted
2560
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2560
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3508
iexplore.exe
23.96.207.177:443
dotnetdownloadservice.azurewebsites.net
Microsoft Corporation
US
whitelisted
3508
iexplore.exe
104.90.156.189:80
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted
3508
iexplore.exe
104.90.156.189:443
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 104.90.156.189
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dotnetdownloadservice.azurewebsites.net
  • 23.96.207.177
unknown

Threats

No threats detected
No debug info