File name:

tor-relay-scanner-ed0f89f.exe.zip

Full analysis: https://app.any.run/tasks/6a9cd05d-81e7-4cf0-ad70-6d1a8c8113dc
Verdict: Malicious activity
Analysis date: September 21, 2024, 10:23:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

3A66CA825A0CE2C56359574F0159BFFB

SHA1:

8CB1BDC8A71C006E00C360CF420B9603C76E74B0

SHA256:

4BED97367187AB182AB76290FEACD94E3A2B5571296F1896AB94A66BCEF70C22

SSDEEP:

98304:nkeMbsn7Lx2lq90dhOL43e7M0VIx71BGqDZ53HMjvOU03iunSfjfrZmp3aQE9IeH:f7oCAu9Nh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • tor-relay-scanner-ed0f89f.exe (PID: 3956)
    • Process drops legitimate windows executable

      • tor-relay-scanner-ed0f89f.exe (PID: 3956)
    • The process drops C-runtime libraries

      • tor-relay-scanner-ed0f89f.exe (PID: 3956)
    • Executable content was dropped or overwritten

      • tor-relay-scanner-ed0f89f.exe (PID: 3956)
    • Application launched itself

      • tor-relay-scanner-ed0f89f.exe (PID: 3956)
    • Connects to unusual port

      • tor-relay-scanner-ed0f89f.exe (PID: 3348)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 3752)
      • wmpnscfg.exe (PID: 2392)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2352)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 2352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0008
ZipCompression: Deflated
ZipModifyDate: 2024:09:21 10:15:26
ZipCRC: 0x2ed71468
ZipCompressedSize: 5936934
ZipUncompressedSize: 6077184
ZipFileName: tor-relay-scanner-ed0f89f.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs tor-relay-scanner-ed0f89f.exe tor-relay-scanner-ed0f89f.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2352"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\tor-relay-scanner-ed0f89f.exe.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2392"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3348C:\Users\admin\Desktop\tor-relay-scanner-ed0f89f.exeC:\Users\admin\Desktop\tor-relay-scanner-ed0f89f.exe
tor-relay-scanner-ed0f89f.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\tor-relay-scanner-ed0f89f.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3752"C:\Windows\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3956C:\Users\admin\Desktop\tor-relay-scanner-ed0f89f.exeC:\Users\admin\Desktop\tor-relay-scanner-ed0f89f.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\tor-relay-scanner-ed0f89f.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 357
Read events
1 335
Write events
22
Delete events
0

Modification events

(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2352) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\tor-relay-scanner-ed0f89f.exe.zip
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2352) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
20
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_asyncio.pydexecutable
MD5:C109DB7C30EBC7145F669B0C45AC9D7B
SHA256:89B48A77BE8FA5B1614152F79C85B56BC26F026B0491749908CDF2186407B06F
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_hashlib.pydexecutable
MD5:FE12F0301B1E8749108627F1085FD10C
SHA256:8929B5818AAA0F595B8CC3B6AADDC630F2B27BCDE3A29D44C13D95037596AA1B
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_socket.pydexecutable
MD5:E7AD342AF27EF2B62C6FBA44A2456FBA
SHA256:48F1F1842E6845A197C9BE50027BB2A67A868E743BFA81B8D8753C24CDC08B7B
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_multiprocessing.pydexecutable
MD5:26D9F2A3CDF70306E43828F0371570F6
SHA256:0913C9B7A21FE0ABD97E27194FB2D5744CA121561D9FDEA71D1A9409B93A8FFF
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\certifi\cacert.pemtext
MD5:50EA156B773E8803F6C1FE712F746CBA
SHA256:94EDEB66E91774FCAE93A05650914E29096259A5C7E871A1F65D461AB5201B47
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_ctypes.pydexecutable
MD5:76816A27C925F301F9776FFD76E6F6D4
SHA256:3A94A3525B0531524AABC7F8FC9F1253894CD612A9823D9CDD5070AB81B9D329
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_lzma.pydexecutable
MD5:B23D17B4B3B15DAB84E384B8DD1D8FC6
SHA256:D3350AD957D6C37B2C75F56A5A149F0EEB58295227F78C15048669A2E816AE3A
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_bz2.pydexecutable
MD5:18CD8755E6D4559840D07467DF26AF34
SHA256:82A85187FAF8786216C82AC1C4CCF32C8839048E242025ED4E7A1E3AB870255F
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_overlapped.pydexecutable
MD5:C95D500C9C11C1A4024B69A81543BA3D
SHA256:D0E3998106623FD5197A4FB274E91243823C16A8FBBA1B42DBCCB4BCABD9F074
3956tor-relay-scanner-ed0f89f.exeC:\Users\admin\AppData\Local\Temp\_MEI39562\_queue.pydexecutable
MD5:D4D66184D157D9DD8C8337E75EB03914
SHA256:E8D293CF77B9F94395C18A26CE38CC1CA01A183DB3E9105ED9040338EA252AE4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
35
DNS requests
2
Threats
37

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
239.255.255.250:3702
whitelisted
224.0.0.252:5355
whitelisted
3348
tor-relay-scanner-ed0f89f.exe
49.12.57.137:443
onionoo.torproject.org
Hetzner Online GmbH
DE
suspicious
3348
tor-relay-scanner-ed0f89f.exe
193.26.115.43:8430
RELIABLESITE
US
unknown
3348
tor-relay-scanner-ed0f89f.exe
199.195.253.180:9100
PONYNET
US
unknown
3348
tor-relay-scanner-ed0f89f.exe
64.227.119.130:443
DIGITALOCEAN-ASN
DE
unknown
3348
tor-relay-scanner-ed0f89f.exe
15.204.166.245:443
OVH SAS
US
unknown
3348
tor-relay-scanner-ed0f89f.exe
82.115.6.77:443
SPRINTLINK
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
onionoo.torproject.org
  • 49.12.57.137
  • 116.202.120.171
unknown

Threats

PID
Process
Class
Message
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 129
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 43
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Exit Node Traffic group 104
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Exit Node Traffic group 98
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 260
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Exit Node Traffic group 42
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 706
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 104
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 98
3348
tor-relay-scanner-ed0f89f.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 307
No debug info