File name:

Steam Account Generator_mpgh.net.zip

Full analysis: https://app.any.run/tasks/c06c63d9-6e23-4030-88fd-b2e6577f0cdb
Verdict: Malicious activity
Analysis date: June 16, 2019, 06:31:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

10F40C776953EE0828F3DD4E4A8A4372

SHA1:

BB09D21FFA8B5AE689E9A8734CE78297E6E662D6

SHA256:

461E09A92A20C9C40D180EA73CE28DA85F73F3BCC1B1FBC87A73BB7CCEE4A8F2

SSDEEP:

24576:c1lSUXX8Ts7ud3kXQ7Wc8LLmJDnNBhupZlTHf7i7P3wtQwf4os3sEk/:cRX8Ts7uRkXQ7J8eJDxAvWPwf4OEU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2920)
      • explorer.exe (PID: 2044)
    • Application was dropped or rewritten from another process

      • SteamAccCreator.exe (PID: 1288)
      • SteamAccCreator.exe (PID: 320)
  • SUSPICIOUS

    • Starts Internet Explorer

      • SteamAccCreator.exe (PID: 1288)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2716)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3508)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3508)
    • Creates files in the user directory

      • iexplore.exe (PID: 3508)
    • Changes internet zones settings

      • iexplore.exe (PID: 2560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:10:15 17:58:27
ZipCRC: 0x9f13d1b7
ZipCompressedSize: 18405
ZipUncompressedSize: 167296
ZipFileName: RestSharp.xml
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs explorer.exe no specs steamacccreator.exe no specs iexplore.exe iexplore.exe steamacccreator.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Users\admin\Documents\SteamAccCreator.exe" C:\Users\admin\Documents\SteamAccCreator.exeexplorer.exe
User:
admin
Company:
@DedSec1337
Integrity Level:
MEDIUM
Description:
SteamAccountGenerator
Exit code:
2148734720
Version:
1.1.2.0
Modules
Images
c:\users\admin\documents\steamacccreator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1288"C:\Users\admin\Documents\SteamAccCreator.exe" C:\Users\admin\Documents\SteamAccCreator.exeexplorer.exe
User:
admin
Company:
@DedSec1337
Integrity Level:
MEDIUM
Description:
SteamAccountGenerator
Exit code:
2148734720
Version:
1.1.2.0
Modules
Images
c:\users\admin\documents\steamacccreator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2044C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2560"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
SteamAccCreator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2716"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Steam Account Generator_mpgh.net.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3508"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2560 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 465
Read events
1 359
Write events
105
Delete events
1

Modification events

(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2716) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Steam Account Generator_mpgh.net.zip
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2716) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2044) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(2044) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:MRUList
Value:
a
Executable files
17
Suspicious files
4
Text files
25
Unknown types
4

Dropped files

PID
Process
Filename
Type
2716WinRAR.exeC:\Users\admin\Documents\SteamAccCreator.exeexecutable
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\Documents\SteamAccCreator.exe.configxml
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\Documents\log\2019-04-06.logtext
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\Documents\System.Diagnostics.StackTrace.dllexecutable
MD5:C20C268EABDCC95DA38AD646A0AA0310
SHA256:E932B25F50E3B09DD7759FF5B9E9ABFA8FC115EA171B768164AE21387FEAC7E8
2716WinRAR.exeC:\Users\admin\Documents\System.Security.SecureString.dllexecutable
MD5:A6DE3093FFB397AF3E4D2A91FA46B738
SHA256:9239DE3543EA4DCF71AD86F16AA23EEB760566BC69078925900D0E41EEC859AC
2716WinRAR.exeC:\Users\admin\Documents\RestSharp.xmlxml
MD5:13F24C6AE64C88ECB609520F0A4A5B36
SHA256:9721B32D25C3BA7F6D0351437EECAFF1FF1501C1D1336CE65357701BFF81CD33
2716WinRAR.exeC:\Users\admin\Documents\System.Diagnostics.Tracing.dllexecutable
MD5:482573CB18B537A7415DCC00C906611D
SHA256:D4A59FB62D8A7A138A49911110F8B2AB416196DF95F4CFC599ABB6EC61629E5E
2716WinRAR.exeC:\Users\admin\Documents\System.Globalization.Extensions.dllexecutable
MD5:8DE05921A38C0FF54E6D4B4ED0C32235
SHA256:F690794A0296D8DAD4F30D626A8A89121DF51B5909E440DA08707B09518D040E
2716WinRAR.exeC:\Users\admin\Documents\System.Threading.Overlapped.dllexecutable
MD5:C8CE5A96458742641AB9752B5B564039
SHA256:A74A34E69B5226F0EE4882F7AC1FC0A88602139ED439202C5FC5C8ED489BFA11
2716WinRAR.exeC:\Users\admin\Documents\System.Runtime.Serialization.Primitives.dllexecutable
MD5:A84B438DBD4DF29560EEB5765E03723A
SHA256:A576D1609CC08C46A46CE708B7FDAE33452A3BEFB701128A5BC9D6FF1F1B6DFD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3508
iexplore.exe
GET
302
104.90.156.189:80
http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch&plcid=0x409&o1=.NETFramework,Version=v4.7.1&processName=SteamAccCreator.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.0
NL
whitelisted
2560
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3508
iexplore.exe
104.90.156.189:443
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted
3508
iexplore.exe
23.96.207.177:443
dotnetdownloadservice.azurewebsites.net
Microsoft Corporation
US
whitelisted
2560
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3508
iexplore.exe
104.90.156.189:80
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 104.90.156.189
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dotnetdownloadservice.azurewebsites.net
  • 23.96.207.177
unknown

Threats

No threats detected
No debug info